Cybersecurity Analyst | Security Researcher | CTI Deleted my own Facebook and hacked yours. thecybershow.blogspot.com

127.0.0.1
BREAKING Microsoft allegedly breached. @campuscodi @vxunderground #cybersecurity #infosec @Microsoft
33
322
936
Dominic Alvieri retweeted
Saif Al-Din Khader a/k/a "Rey" has been arrested in Jordan for his involvement in the FBIJobs hack and ShinyHunters
27
53
484
30,005
The World Cup 2034 has been breached Via - The China Railway Construction Corporation Saudi Arabia branch which was compromised by WallStreet. WallStreet is a stupid name for a threat group but this group is real. WallStreet has breached at least: 3 US hospitals 2 US cities 1 US Police Department and now a branch of the China Railway Corporation in Saudi Arabia no less. Watch this WallStreet
1
5
15
1,350
‼️ BREAKING: Microsoft's official X account with over 13 million followers was hijacked to boost a fake Clippy account tied to a crypto scam. Microsoft wrote an apology threatening legal action, then deleted that post too. The account followed and reposted the impersonator and swapped its profile picture for Clippy.
24
148
959
69,421
ShinyHunters DLS is back again posting glucose monitoring firm DexCom and oh, oh, oh O’Rielly Automotive - Oww
3
8
34
3,108
Revel in your abandon
ShinyHunters is reviving /shinypog… as a backup in case of seizure since the main site is still unreachable, and it’s not down by adding DDoS protection. They are redirecting the old url to their main DLS which is still down, duh. ShinyHunters DLS has NOT been seized (so far)
2
857
ShinyHunters is reviving /shinypog… as a backup in case of seizure since the main site is still unreachable, and it’s not down by adding DDoS protection. They are redirecting the old url to their main DLS which is still down, duh. ShinyHunters DLS has NOT been seized (so far)
9
29
167
16,355
Lapsus is now extorting a Thailand Tech and Lottery Company - Loxley is the alleged target here They’ll never learn
3
13
1,229
Graybar Electric has allegedly been breached by Redact. Fortune 500 Graybar is the largest distributor of data networking and communications products with over 11,000 employees and 11B in revenue. Redact is the rebrand of BlackFile.
6
1,089
ShinyHunters is exploiting Oracle PeopleSoft CVE-2026-35273 Another popular ShinyHunters tactic is using victim-specific subdomains Here is one recently reregistered being used with an interesting old subdomain: /support.report (live) /apple.support.report @apple
5
21
83
8,573
More live Shiny sites /erc.report
1
4
1,113
Dominic Alvieri retweeted
Dutch Authorities have arrested 23-year-old Pepijn van der Stap A/K/A "Umbreon", on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters
30
80
815
55,915
Dominic Alvieri retweeted
BREAKING: Chinese illicit actors laundering funds from the $387M Bitget exploit on behalf of the alleged DPRK attackers are openly asking for support with orders in public Discord servers and Telegram channels of services they use. Notably, Alias 4 (below) was also seen laundering funds from the Kelp DAO $292M exploit earlier this year. I've observed the same pattern after multiple TraderTraitor attributed exploits, and I've closely tracked these groups. I plan to share more of my data on them in coming weeks. Currently, funds are being chain-hopped via bridges and being deposited into mixing services such as Wasabi. Alias 1 - Cc Discord: cc02006 Discord ID: 1351486674386948148 Txn: F08657EFAEAE7B58217CD17A22BF4779582E5D080C2E92E173BC239A5D828363 Alias 2 - jack Discord: jack_34808 Discord ID: 1553705721768714377 Txn: 68583D313A0CCC99F2702D61D05A242A69C86CAE09ED252B65F34B677C377F69 Alias 3 - Melon Discord: under0346 Discord ID: 1394240539108573215 Txn 1: ABE2AEF8B10057E60F8259CA2CA2CD5D71D38D254960FEEE89CB3C95A964873F Txn 2: 7BE290865901DEB1680A6D692A11392D1FDDACA0D31C48F26DCB249F2444BD6B Alias 4 - lolo / Marin TG: pvpcz TGID: 6223514198 Discord: losern Discord ID: 1024415186527985704 Txn: 8E935C19D00F40639B78BF1FD094FE48C92118F3E586AB52DF93851080CCCE15 Alias 5 - HELP ME Discord: helpme031897 Discord ID: 1554035533817188384 Txn: 7C58CAD760EBBED54F2CA4D2146D056910B7B6688B4F524396DC8807353C2379
640
849
6,487
1,626,709
‼️ BREAKING: Google says ShinyHunters is mass-exploiting an Oracle PeopleSoft flaw, using a trick that slips past the firewall rules companies relied on instead of patching, and has planted web shells on dozens of systems worldwide. The campaign has spread from universities to healthcare, government, tech and transportation, and some servers got a new backdoor called SIDEEYE, hidden inside a booby-trapped media player installer signed with a valid certificate. Google has published IOCs, file hashes and a fix-it guide for CVE-2026-35273, and warns victims to prepare for extortion.
30
283
1,335
74,063
Dominic Alvieri retweeted
Replying to @bestnftseen
Have no current plans to monitor the Bitget exploit by DPRK. I stopped wasting my time on helping people in the industry who are not supporters of my work (donors, clients, longtime followers, etc).
122
62
2,649
301,367
Bitget customers protected by @ $454 million security fund but the North Korea nuclear fund is ballooning again
Lazarus now being confirmed behind the new $352 million Bitget hack today.
1
6
2,016
Lazarus now being confirmed behind the new $352 million Bitget hack today.
Made with AI
1
7
67
5,937
Multiple confirmations ⤵️
Regarding who is behind the hack: I present to you THE LAZARUS GROUP. just linked this hack to the AFX hack, which stole $24M in July and was specifically attributed to TraderTraitor. The stolen XRP from Bitget was bridged and can be directly linked to the funds stolen in the AFX hack. Stay smart.
1
3
958