#initialaccess

6 posts · Last used 6d

Back to Timeline
DarkWebSonar @darkwebsonar@infosec.exchange · 6d ago
🇷🇴 We tracked NoName057(16) claiming unauthorized access to CCTV surveillance at a Romanian nursing home, reporting real-time access to 15 camera feeds covering multiple facility areas. Actor attributes the access to weak security practices. We've logged 80 incidents from this actor in the past 30 days. #InitialAccess #Healthcare #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/noname057-16-mastodon
0
0
0
DarkWebSonar @darkwebsonar@infosec.exchange · Jul 28, 2026
We picked up forum user Rici144 allegedly offering webshell access to multiple .edu domain institutions, providing initial access into educational networks. We've tracked Rici144 across 12 incidents, mostly in the education and government sectors, with activity spiking recently. #InitialAccess #Education #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/rici144-mastodon
0
0
0
DarkWebSonar @darkwebsonar@infosec.exchange · Jul 19, 2026
🇺🇸 We tracked forum actor miyako advertising alleged initial access to a large US casino and resort property, listed for $500 with escrow transaction through a designated middleman. We've logged 22 miyako listings in the past 30 days across our monitoring. #InitialAccess #Hospitality #ThreatIntel Details + live feed → https://go.darkwebsonar.io/miyako-mastodon
0
0
0
DarkWebSonar @darkwebsonar@infosec.exchange · Jul 11, 2026
🇪🇸 We tracked charlee listing decrypted remote access credentials allegedly obtained from Add4u, a municipal document management platform serving more than 30 Spanish city councils. The credentials span FortiClient, SonicWall, GlobalProtect, Citrix, OpenVPN, WireGuard, and AnyDesk. We've logged 3 incidents from charlee in the past 30 days, all targeting Spanish government infrastructure. #InitialAccess #Government #ThreatIntel This entry + more → https://go.darkwebsonar.io/charlee-mastodon
0
0
0
DarkWebSonar @darkwebsonar@infosec.exchange · Jul 08, 2026
🇬🇷 We tracked lastopsecbroker claiming initial access to the Hellenic Navy web application. The listing includes admin panel credentials, origin IP to bypass Cloudflare protection, and API endpoint details. Actor alleges the access originated from a compromised general officer's computer. We've logged 3 lastopsecbroker incidents in the past 30 days. #InitialAccess #ThreatIntel More on this and other incidents → https://go.darkwebsonar.io/lastopsecbroker-mastodon
0
0
0
Mike Williamson @sleepycat@infosec.exchange · Jan 13, 2026
Replying to @sleepycat@infosec.exchange
"This is the second part of our two-blog series, where we explore various #initialaccess vectors into #Kubernetes environments, analyze the associated attack angles, and clarify the relevant risks. " #wiz #security https://www.wiz.io/blog/kubernetes-data-plane
0
0
0

You've seen all posts