mastodontech.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Offen für alle (über 16) und bereitgestellt von Markus'Blog

Serverstatistik:

1,4 Tsd.
aktive Profile

#shinyhunters

6 Beiträge6 Beteiligte0 Beiträge heute

🔥 Latest issue of my curated #cybersecurity and #infosec list of resources for week #38/2025 is out!

→ It includes the following and much more:

💰 💰 #ShinyHunters claims 1.5 billion #Salesforce records stolen in Drift hacks;

🇬🇧 Jaguar Land Rover has extended its production shutdown by a week;

🇫🇷 Kering, which owns #Gucci, #Balenciaga and other luxury brands, confirmed a #databreach;

🇺🇸 ⚖️ "Pompompurin" was resentenced to three years in prison;

🪱 ♾️ Self-replicating worm named "Shai-Hulud" infected at least 187 JavaScript packages on #NPM;

🇺🇸 🤖 Salesforce launches ‘Missonforce’, a national security-focused business unit;

👉 NEVER MISS my curations and updates on information security and cybersecurity news and challenges 📨 Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

infosec-mashup.santolaria.net/

ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks; Jaguar Land Rover has extended its production shutdown by a week; "Pompompurin" was resentenced to three years in prison; Self-replicating worm named Shai-Hulud infected at least 187 JavaScript packages on NPM; Salesforce launches ‘Missonforce’, a national security-focused business unit;
X’s InfoSec Newsletter · 🕵🏻‍♂️ [InfoSec MASHUP] 38/2025Von Xavier Santolaria

NEW: When “Goodbye” isn’t the end: Scattered LAPSUS$ Hunters hack on

Others seem to have interpreted their "goodbye" message differently than I had. Were they lying or did people just not understand a significant statement in their message?

And while headlines focus on them hitting a bank, I think we need to take a closer look at their attacks on the aviation sector.

databreaches.net/2025/09/21/wh

#databreach #ScatteredSpider #ShinyHunters #LAPSUS$ #CollinsAerospace #airlines #airports

DataBreaches.Net · When “Goodbye” isn’t the end: Scattered LAPSUS$ Hunters hack on – DataBreaches.Net“Goodbye isn't the end. It's the beginning of what happens next.” -- Joshua Shaw Reading the news, I see some headlines suggesting that "Scattered LAPSUS$ Hunte

So many news reports have repeated the BBC's mistaken estimate about the number of customers affected by the Kering data breaches. So...

No, folks, it's not 7.4 million affected or fewer. It's a lot more because the BBC's estimate was based on just the second and smaller breach (Balenciaga, Brioni, and Alexander McQueen), and not the Gucci data which allegedly has more than 43 million records. Even assuming repeat customers are in there, there are likely a lot of unique customers in the Gucci data.

If we use the same percent based on 7.4 million out of almost 13 million recordsin the second data set, then that would yield 24-25 million unique email addresses for the Gucci data set, for an estimated total of more than 31 million customers all told.

I didn't estimate the number of unique customers in my reporting because it's too sloppy. But it's highly unlikely to be 7.4 million or fewer as BBC reported.

#Kering #Gucci #Balenciaga #Brioni #AlexanderMcQueen #databreach #Salesforce #ShinyHunters #UNC6040 #incidentresponse #transparency

My reports:
databreaches.net/2025/09/11/ex

databreaches.net/2025/09/15/up

@euroinfosec @zackwhittaker

DataBreaches.Net · Exclusive: High-end fashion retailers Gucci, Balenciaga, Brion, and Alexander McQueen hit by Salesforce attacks – DataBreaches.NetThose readers who aren't A-listers (including yours truly) may never have heard of Kering , but you may have heard of their high-end fashion brands: Gucci. Yves

Last week, I broke the story about Gucci and other Kering brands being hacked by ShinyHunters as part of the Salesforce campaign. In my reporting, I included chat logs and other exclusive details. You can read my original reporting here: databreaches.net/2025/09/11/ex

There is now an update that refutes Kering's reported claim today that they didn't have any conversations with the hackers. I also highlight their failures to be more transparent about the incidents:
databreaches.net/2025/09/15/up

DataBreaches.Net · Exclusive: High-end fashion retailers Gucci, Balenciaga, Brion, and Alexander McQueen hit by Salesforce attacks – DataBreaches.NetThose readers who aren't A-listers (including yours truly) may never have heard of Kering , but you may have heard of their high-end fashion brands: Gucci. Yves
Fortgeführter Thread

Some of the LAPSUS$/ScatteredSpider folks seem to be struggling with the idea of being silent.

After posting 4 screengrabs that appear to be from the CJIS background check service, they subsequently posted two screengrabs from Google's Law Enforcement Request System that seem to indicate that they were able to establish/create an account there. When they created that account and what they may have done with that account is unknown at this point. An inquiry has been sent to Google about it.

#Google #LERS #ShinyHunters #ScatteredSpider #Lapsus$