Tag
high
threat
ShinyHunters Ransomware Group Claims icsecurity.com Victim, Exfiltrates 2.7M Records
2 rules 7 TTPs 2 CVEs 13 IOCsThe financially motivated ShinyHunters ransomware group, operating its shinysp1d3r RaaS, has claimed icsecurity.com as a new victim, compromising over 2.7 million records via credential stuffing and exploitation of cloud services like Snowflake, with the intent to extort through data leakage.
PoC
Oracle E-Business Suite +9
ShinyHunters
ransomware
data-theft
extortion
cloud-security
threat-actor-group
credential-stuffing
2r
7t
2c
13i
updated
medium
advisory
Azure AD Failed Authentication Increase
2 rules 1 TTPDetects a significant increase (10% or greater) in failed Azure AD sign-in attempts, potentially indicating brute-force attacks, credential stuffing, or other unauthorized access attempts.
Azure Active Directory
azuread
brute-force
credential-stuffing
authentication
2r
1t
medium
advisory
Okta Credential Stuffing Attempt Detection
2 rules 1 TTPThis brief focuses on detecting credential stuffing attacks against Okta, characterized by multiple failed login attempts from a single source, potentially indicating automated attempts to compromise user accounts.
Okta
credential-stuffing
account-takeover
2r
1t