amvinfe
amvinfe@infosec.exchange
<p>Cyber security researcher and blogger</p>
Posts
-
Post #4496258
๐๐ข๐ง๐ ๐ข๐ง๐ ๐๐ข๐ฏ๐๐ซ ๐๐๐๐ฅ๐ญ๐ก ๐๐ฒ๐ฌ๐ญ๐๐ฆ: ๐๐๐ญ๐ฐ๐๐๐ง ๐๐๐ง๐ฌ๐จ๐ฆ๐ฐ๐๐ซ๐, ๐๐๐ ๐๐ฅ ๐๐ข๐ฌ๐ฉ๐ฎ๐ญ๐๐ฌ, ๐๐ง๐ ๐๐๐๐ฎ๐ซ๐ซ๐ข๐ง๐ ๐๐ฎ๐ฅ๐ง๐๐ซ๐๐๐ข๐ฅ๐ข๐ญ๐ข๐๐ฌ Just over two years after the devastating ransomware attack attributed to the Rhysida group, Singing River Health System (SRHS) has once again fallen victim to cybercrime. This time, the Anubis ransomware group has claimed responsibility for compromising the healthcare organizationโs IT systems, stating that it stole sensitive data belonging to patients and employees before encrypting the infrastructu...
-
Post #4496257
๐๐ฏ๐๐ซ๐๐ฌ๐ญ: ๐๐ข๐ฑ ๐๐๐๐ซ๐ฌ ๐จ๐ ๐๐ฏ๐จ๐ฅ๐ฎ๐ญ๐ข๐จ๐ง ๐๐ซ๐จ๐ฆ ๐๐๐ญ๐ ๐๐๐๐ค ๐ญ๐จ ๐๐จ๐ฎ๐๐ฅ๐ ๐๐ฑ๐ญ๐จ๐ซ๐ญ๐ข๐จ๐ง โ ๐ญ๐ก๐ ๐ข๐ง๐ญ๐๐ซ๐ฏ๐ข๐๐ฐ The responses provided to SuspectFile paint a picture of a group that claims to have grown gradually and demonstrated a consistent ability to adapt. One of the most interesting aspects concerns the shift from extortion based solely on stolen data to the adoption of encryption. https://www.suspectfile.com/everest-six-years-of-evolution-from-data-leak-to-double-extortion-the-interview/ #ALPHV #Black_Basta #Doubl...
-
Post #4496256
@verisizintisi @PogoWasRight @jerry @JayeLTee Hi, I read your article on HCRG and I think you may be mistaken about some of your writing. In one passage, you write, &quot;The entity directly affected by the attack is CRG Medical Services, a subsidiary of HCRG that provides forensic medical services to police forces.&quot; Can I ask where you got this information? Has it been verified by you? If it has been verified, can you provide evidence? I think, I&#39;m sure, you&#39;re mis...
-
Post #4496255
๐ก๐ผ๐๐ฎ ๐๐น๐ฎ๐ถ๐บ๐ ๐๐ฐ๐ฐ๐ฒ๐๐ ๐๐ผ ๐ก๐ฆ๐ช ๐ฆ๐๐๐๐ฒ๐บ๐: ๐๐ฒ๐๐๐ฒ๐ฒ๐ป ๐ฐ๐ฌ๐ฌ ๐๐ ๐๐ ๐ณ๐ถ๐น๐๐ฟ๐ฎ๐๐ฒ๐ฑ ๐ฎ๐ป๐ฑ ๐๐ฎ๐๐ฎ ๐๐ถ๐๐ฝ๐๐๐ฒ๐ฑ ๐ฏ๐ ๐๐๐๐ต๐ผ๐ฟ๐ถ๐๐ถ๐ฒ๐ The story emerged in recent days via the ๐๐จ๐ฏ๐ ๐ ๐ซ๐จ๐ฎ๐ฉโ๐ฌ ๐๐๐ญ๐ ๐ฅ๐๐๐ค ๐ฉ๐จ๐ซ๐ญ๐๐ฅ, where the ransomware operators ๐น๐ถ๐๐๐ฒ๐ฑ ๐๐ต๐ฒ ๐ก๐ฒ๐ ๐ฆ๐ผ๐๐๐ต ๐ช๐ฎ๐น๐ฒ๐ ๐ด๐ผ๐๐ฒ๐ฟ๐ป๐บ๐ฒ๐ป๐ among their alleged victims, claiming to have gained access to a hashtag #Citrix system and exfiltrated a significant amount of data. https://www.suspectfile.com/nova-claims-access-to-nsw-systems-between-400-gb-exfiltrated-and-data-disputed-by-authorities/ #Cit...
-
Post #4496254
๐๐น๐ผ๐ฏ๐ฎ๐น ๐ฆ๐ฐ๐ต๐ผ๐ผ๐น๐ ๐๐ฟ๐ผ๐๐ฝ ๐ฎ๐ป๐ฑ ๐๐๐น๐ฐ๐ฟ๐๐บ๐ฆ๐ฒ๐ฐ: ๐ ๐ ๐ฎ๐๐๐ถ๐๐ฒ ๐๐ฎ๐๐ฎ ๐๐ฟ๐ฒ๐ฎ๐ฐ๐ต ๐ฎ๐ป๐ฑ ๐๐ต๐ฒ ๐ช๐ผ๐ฟ๐น๐ฑ๐๐ถ๐ฑ๐ฒ ๐ฃ๐๐๐ต ๐๐ผ ๐ฆ๐๐ฝ๐ฝ๐ฟ๐ฒ๐๐ ๐ฅ๐ฒ๐ฝ๐ผ๐ฟ๐๐ถ๐ป๐ด ๐ผ๐ป ๐๐ Among the statements attributed to FulcrumSec are allegations of particularly poor security practices. The group claims to have identified administrative credentials reused across numerous systems, passwords stored in plaintext, #AWS access keys embedded directly within application code, and databases relying on credentials that had reportedly remained unchanged for years. https://www....
-
Post #4496253
๐๐๐ฏ๐ฒ๐ฟ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐๐ป๐ฐ๐ถ๐ฑ๐ฒ๐ป๐๐: ๐ช๐ต๐ฒ๐ป ๐๐ต๐ฒ ๐ฃ๐ฟ๐ผ๐ฏ๐น๐ฒ๐บ ๐๐ ๐ก๐ผ๐ ๐ข๐ป๐น๐ ๐ช๐ต๐ผ ๐๐๐๐ฎ๐ฐ๐ธ๐ In this context, attackersโ ability to exploit existing vulnerabilities is intertwined with a less discussed but equally crucial reality: the accumulation of technical and organizational weaknesses that often remains unresolved until data exfiltration occurs. https://www.suspectfile.com/cybersecurity-incidents-when-the-problem-is-not-only-who-attacks/ #Cybersecurity #Data_Breaches #Data_Protection #Digital_Privacy #Ransomware
-
Post #4496252
๐๐น๐ผ๐ฏ๐ฎ๐น ๐ฆ๐ฐ๐ต๐ผ๐ผ๐น๐ ๐๐ฟ๐ผ๐๐ฝ, ๐ฟ๐ฒ๐ป๐ฒ๐๐ฒ๐ฑ ๐ฝ๐ฟ๐ฒ๐๐๐๐ฟ๐ฒ ๐ผ๐ป ๐๐ฎ๐๐ฎ๐๐ฟ๐ฒ๐ฎ๐ฐ๐ต๐ฒ๐: ๐๐ต๐ฒ ๐จ๐ฆ ๐๐ถ๐๐ฒ ๐ฟ๐ฒ๐ท๐ฒ๐ฐ๐๐ ๐ฎ๐๐๐ฒ๐บ๐ฝ๐๐ ๐๐ผ ๐ฐ๐ฒ๐ป๐๐ผ๐ฟ ๐ฑ๐ฎ๐๐ฎ ๐ฏ๐ฟ๐ฒ๐ฎ๐ฐ๐ต ๐ฐ๐ผ๐๐ฒ๐ฟ๐ฎ๐ด๐ฒ The U.S. site emphasizes that it was not named in either ordinance and has no presence or activity in India or Singapore. For this reason, he had already responded to the law firm on June 23, stating that he did not consider himself subject to the jurisdiction of the courts of the two countries and that she did not intend to take any action as a result of the injunctions. https:/...
-
Post #4496251
๐ฅ๐ฎ๐ป๐๐ผ๐บ๐๐ฎ๐ฟ๐ฒ ๐ถ๐ป ๐๐๐ฎ๐น๐: ๐ฅ๐ฒ๐ฑ๐๐๐ง ๐ฟ๐ฒ๐ฝ๐ผ๐ฟ๐ ๐๐ต๐ฒ๐ฑ๐ ๐น๐ถ๐ด๐ต๐ ๐ผ๐ป ๐ฎ๐ป ๐ฒ๐๐ผ๐น๐๐ถ๐ป๐ด ๐๐ต๐ฟ๐ฒ๐ฎ๐ ๐ฒ๐ป๐๐ถ๐ฟ๐ผ๐ป๐บ๐ฒ๐ป๐ The report highlights how Italy continues to represent a frequent target for numerous ransomware groups. Organizations affected belong to very different sectors, including manufacturing, services, healthcare, technology, and industrial companies. https://www.suspectfile.com/ransomware-in-italy-redact-report-sheds-light-on-an-evolving-threat-environment/ #Cyber_Threat_Intelligence #Cybercrime #OSINT #ransomNews_on...
-
Post #4427861
๐ข๐ฉ๐ฃ ๐๐ฒ๐ฎ๐น๐๐ต ๐๐ฎ๐ฟ๐ด๐ฒ๐๐ฒ๐ฑ ๐ฏ๐ ๐ฆ๐๐ผ๐ฟ๐บ: ๐ฟ๐ฎ๐ป๐๐ผ๐บ๐๐ฎ๐ฟ๐ฒ ๐ด๐ฟ๐ผ๐๐ฝ ๐ฐ๐น๐ฎ๐ถ๐บ๐ ๐๐ต๐ฒ๐ณ๐ ๐ผ๐ณ ๐ญ๐ฏ๐ฌ ๐๐ ๐ผ๐ณ ๐ต๐ฒ๐ฎ๐น๐๐ต๐ฐ๐ฎ๐ฟ๐ฒ ๐ฑ๐ฎ๐๐ฎ One characteristic Storm claims to have adopted concerns the negotiation process. The operators stated that there is no human negotiator involved within the service and that all negotiation stages are automated. Human assistance would reportedly be limited exclusively to technical issues and decryption-related requests. https://www.suspectfile.com/ovp-health-targeted-by-storm-ransomware-group-claims-theft-...
-
Post #4174239
๐๐ ๐ฐ๐น๐๐๐ถ๐๐ฒ: ๐๐ฎ๐๐ต ๐๐ถ๐๐๐ฒ๐ฟ ๐๐น๐ฎ๐ถ๐บ๐ฒ๐ฑ ๐ฏ๐ ๐๐ป๐๐ฏ๐ถ๐ ๐ฅ๐ฎ๐ป๐๐ผ๐บ๐๐ฎ๐ฟ๐ฒ, ๐๐น๐น๐ฒ๐ด๐ฒ๐ฑ ๐ฒ๐ฌ๐ฌ ๐๐ ๐๐ฎ๐๐ฎ ๐ง๐ต๐ฒ๐ณ๐ ๐๐ผ๐น๐น๐ผ๐๐ฒ๐ฑ ๐ฏ๐ ๐ฎ $๐ฎ.๐ฏ๐ฑ ๐ ๐ถ๐น๐น๐ถ๐ผ๐ป ๐๐ ๐๐ผ๐ฟ๐๐ถ๐ผ๐ป ๐ก๐ฒ๐ด๐ผ๐๐ถ๐ฎ๐๐ถ๐ผ๐ป The negotiations, a copy of which was provided by Anubis to SuspectFile, document a familiar pattern increasingly observed in modern double-extortion ransomware operations: technical proof of compromise, demonstrations of data possession, decryptor testing, financial negotiations, and the eventual threat of public disclosure. https://www.suspectfile.com/exclusive-bat...
-
Post #3886266
๐ก๐ฎ๐๐ถ๐ด๐ฎ๐๐ฒ๐ฏ๐ฒ๐ฌ ๐ฎ๐ป๐ฑ ๐ฃ๐ฏ ๐๐น๐ผ๐ฏ๐ฎ๐น ๐๐ป๐๐ฒ๐น: ๐๐ฟ๐ผ๐บ ๐๐ต๐ฒ ๐ฝ๐ฟ๐ผ๐บ๐ถ๐๐ฒ ๐ผ๐ณ โ๐ฎ๐ฌ+ ๐๐ฒ๐ฎ๐ฟ๐ ๐ฎ๐ป๐ฑ ๐๐ฒ๐ฟ๐ผ ๐๐ถ๐ผ๐น๐ฎ๐๐ถ๐ผ๐ป๐โ ๐๐ผ ๐๐ต๐ฟ๐ฒ๐ฒ ๐บ๐ผ๐ป๐๐ต๐ ๐ผ๐ณ ๐๐ถ๐น๐ฒ๐ป๐ฐ๐ฒ The P3 Global Intel platform was designed to collect reports regarding potentially critical situations within school communities. This means that the information involved could pertain to incidents, behaviors, or circumstances that fall within an extremely private aspect of the lives of students and their families. https://www.suspectfile.com/navigate360-and-p3-global-intel-from-the...
-
Post #3836561
๐๐๐ณ๐น๐ผ๐ฐ๐ธ ๐ฎ๐ป๐ฑ ๐ก๐ผ๐๐ฎ: ๐ ๐ฃ๐ฟ๐ถ๐๐ฎ๐๐ฒ ๐๐ผ๐ป๐๐ฒ๐ฟ๐๐ฎ๐๐ถ๐ผ๐ป ๐ฃ๐ฟ๐ผ๐๐ถ๐ฑ๐ฒ๐ ๐ฎ ๐๐น๐ถ๐บ๐ฝ๐๐ฒ ๐ถ๐ป๐๐ผ ๐ฅ๐ฎ๐ป๐๐ผ๐บ๐๐ฎ๐ฟ๐ฒ ๐๐ฟ๐ผ๐๐ฝ ๐๐๐ป๐ฎ๐บ๐ถ๐ฐ๐ The chat, which took place between July 1 and July 6, 2026, concerns a request to join Novaโs affiliate program and contains a series of statements regarding the Hyflock group, the interlocutorโs role, and his alleged technical expertise. https://www.suspectfile.com/hyflock-and-nova-a-private-conversation-provides-a-glimpse-into-ransomware-group-dynamics/ #Hyflock #LockBit #Nova #Qilin #RaaS #Ransomware
-
Post #3770691
๐ก๐ผ๐ฟ๐๐ต๐ฒ๐ฎ๐๐ ๐ฃ๐ฒ๐ฑ๐ถ๐ฎ๐๐ฟ๐ถ๐ฐ๐ ๐ฒ๐ป๐๐ฒ๐ฟ๐ ๐ป๐ฒ๐ด๐ผ๐๐ถ๐ฎ๐๐ถ๐ผ๐ป๐ ๐๐ถ๐๐ต ๐๐ป๐๐ฏ๐ถ๐, ๐๐ต๐ฒ๐ป ๐๐ถ๐น๐ฒ๐ป๐ฐ๐ฒ. ๐ฆ๐๐๐ฝ๐ฒ๐ฐ๐๐๐ถ๐น๐ฒ ๐ฟ๐ฒ๐ฐ๐ผ๐ป๐๐๐ฟ๐๐ฐ๐๐ ๐๐ต๐ฒ ๐ป๐ฒ๐ด๐ผ๐๐ถ๐ฎ๐๐ถ๐ผ๐ป ๐๐ต๐ฎ๐ ๐ฝ๐ฟ๐ฒ๐ฐ๐ฒ๐ฑ๐ฒ๐ฑ ๐๐ต๐ฒ ๐ฑ๐ฎ๐๐ฎ ๐ฝ๐๐ฏ๐น๐ถ๐ฐ๐ฎ๐๐ถ๐ผ๐ป For ethical and privacy reasons, SuspectFile has chosen not to analyze or describe documentation relating to minor patients, as Northeast Pediatrics is a healthcare facility specialized in pediatric care. https://www.suspectfile.com/northeast-pediatrics-enters-negotiations-with-anubis-then-silence-suspectfile-reconstructs-the-negotiation-that-preceded-...