Brutkey

Kevin Beaumont
@GossiTheDog@cyberplace.social
Kevin Beaumont
@GossiTheDog@cyberplace.social

I understand the people released have not been charged.

Kevin Beaumont
@GossiTheDog@cyberplace.social

The Amazon War of the Worlds movie is indeed worse than I thought.

βœ…βœ… PlayStation 2 visual effects
βœ…βœ… Amazon are the good guys
βœ…βœ… Joe Rogan and Tucker Carlson tweet integration

I’d be lying if I said I didn’t enjoy it though.

Kevin Beaumont
@GossiTheDog@cyberplace.social

What a time to be alive

Tl;dr of the Scatter Spider LAPSUS$ chat aka fuckmandiantunit221bcr0wdshart is:

- they’ve owned a lot of big companies by phoning them up and asking for access - this includes orgs who haven’t disclosed their incidents

- they also appear to have an Oracle WebLogic exploit (unclear if zero day) and a SAP Netweaver exploit and used that to get inside orgs

- They appear to also be (or owned) ShinyHunters ransomware, as they include internal ShinyHunter emails and IMs.

Kevin Beaumont
@GossiTheDog@cyberplace.social

It has strong rings of former LAPSUS$ activity due to a range of things, including many of the same victim orgs, screenshots from historic incidents 2021-2022 which weren’t public, targeting Portuguese speaking orgs again, staying up to 4am, the lingo, UK links etc.

They also appear to targeting UK justice system network, goading the NCA and going after more retailers.

Kevin Beaumont
@GossiTheDog@cyberplace.social

What a time to be alive

Tl;dr of the Scatter Spider LAPSUS$ chat aka fuckmandiantunit221bcr0wdshart is:

- they’ve owned a lot of big companies by phoning them up and asking for access - this includes orgs who haven’t disclosed their incidents

- they also appear to have an Oracle WebLogic exploit (unclear if zero day) and a SAP Netweaver exploit and used that to get inside orgs

- They appear to also be (or owned) ShinyHunters ransomware, as they include internal ShinyHunter emails and IMs.

Kevin Beaumont
@GossiTheDog@cyberplace.social

https://www.bbc.co.uk/news/live/c1dxndnkq6yt

Kevin Beaumont
@GossiTheDog@cyberplace.social

That one was Rockstar Games internal build environment, 100%, from a few years ago. They’re also posting screenshots for Victoria’s Secret etc.

Kevin Beaumont
@GossiTheDog@cyberplace.social

The NCA might want to urgently pick up the LAPSUS guys again.

Kevin Beaumont
@GossiTheDog@cyberplace.social

An update on the MITRE ATT&CK situation.

Kevin Beaumont
@GossiTheDog@cyberplace.social

RIP AOL dial up

Kevin Beaumont
@GossiTheDog@cyberplace.social

Battlefield 6 Open Beta early access code, if anybody wants one.

56CZ-RNMK-BCSD-WLGS

Redeem link:
https://www.ea.com/games/battlefield/battlefield-6/redeem