en
Feedback
ScorpSec

ScorpSec

Open in Telegram

ScorpSec Telegram Channel is sharing cyber security news, ethical hacking resources, educational content on online security and privacy.

Show more
1 962
Subscribers
No data24 hours
-47 days
-1730 days

Data loading in progress...

Similar Channels
No data
Any problems? Please refresh the page or contact our support manager.
Incoming and Outgoing Mentions
---
---
---
---
---
---
Attracting Subscribers
September '26
September '260
in 0 channels
August '26
+4
in 0 channels
Get PRO
July '26
+8
in 0 channels
Get PRO
June '26
+16
in 0 channels
Get PRO
May '26
+17
in 0 channels
Get PRO
April '26
+12
in 0 channels
Get PRO
March '26
+12
in 1 channels
Get PRO
February '26
+28
in 0 channels
Get PRO
January '26
+36
in 0 channels
Get PRO
December '25
+68
in 0 channels
Get PRO
November '25
+235
in 1 channels
Get PRO
October '25
+71
in 0 channels
Get PRO
September '25
+311
in 0 channels
Get PRO
August '25
+141
in 0 channels
Get PRO
July '25
+42
in 0 channels
Get PRO
June '25
+145
in 1 channels
Get PRO
May '25
+190
in 2 channels
Get PRO
April '25
+99
in 1 channels
Get PRO
March '25
+421
in 1 channels
Get PRO
February '25
+596
in 0 channels
Date
Subscriber Growth
Mentions
Channels
06 September0
05 September0
04 September0
03 September0
02 September0
01 September0
Channel Posts
South Korea Reveals Months-Long Breach of Diplomatic Training System 🔐 South Korea has disclosed a major cyberattack that compromised the online education platform used by the Ministry of Foreign Affairs. Hackers reportedly accessed the system in April 2025 and remained undetected for nearly 10 months, exposing data belonging to at least 6,000 people, including diplomats stationed overseas. 📂 The leaked information includes user IDs, names, email addresses, and encrypted passwords. Officials said national ID numbers, phone numbers, home addresses, photographs, and other highly sensitive personal data were not exposed. 🛡️ Authorities have taken the platform offline, strengthened security measures, and urged affected individuals to be alert for phishing emails and other suspicious communications. The government said the disclosure was delayed due to the sensitive nature of diplomatic and national security matters. ⚠️ Local reports suggest the actual number of victims could reach 10,000, with job titles and departmental affiliations also exposed. The breach was reportedly discovered by South Korea's National Intelligence Service in February 2026, and investigators believe the attackers remained hidden because the compromised server was excluded from routine security monitoring.

2
Hackers Use Fake Entra Passkey Enrollment to Hijack Microsoft 365 Accounts 📞 A voice phishing (vishing) campaign is tricking Microsoft 365 users into enrolling a fake Microsoft Entra passkey. Attackers call employees pretending to be IT staff, claiming a security upgrade is required, then direct them to convincing phishing websites. 🎭 The fake sites closely imitate the official Entra passkey enrollment process and even use the victim organization's branding. Instead of creating a legitimate passkey, victims unknowingly register a passkey controlled by the attacker, giving criminals access to their accounts. 💾 According to Okta, the campaign is linked to the Pink extortion group, which targets organizations across multiple industries. Once inside an account, the attackers quickly steal data from SharePoint and OneDrive, then use it for extortion. ⚠️ Researchers warn that legitimate Microsoft Entra passkey enrollment does not use BIP-39 recovery phrases. Organizations are urged to verify helpdesk requests, train employees to recognize vishing attacks, and restrict suspicious login attempts from unexpected locations.
419
3
Global IT Services Company Confirms Cyberattack After Hacker Puts Stolen Data Up for Sale 🔓 A global IT services and consulting company, Accenture, has confirmed it suffered a cyberattack after a threat actor known as "888" claimed to be selling 35 GB of stolen company data on a cybercrime forum. The company says the incident has been contained and that there has been no impact on its operations or services. 📂 The attacker alleges the stolen data includes source code, RSA and SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files. A screenshot shared by the hacker appears to show access to an Azure DevOps repository, although the full extent of the breach has not been independently verified. 🛡️ While Accenture confirmed the breach, it did not verify the hacker's claims about the amount or type of stolen data. The company also has not disclosed how the attackers gained access or whether customer information was affected. ⚠️ This is not the first security incident involving Accenture. The company previously dealt with a LockBit ransomware attack in 2021, and the same threat actor attempted to sell Accenture employee data following a third-party breach in 2024. The investigation is ongoing, and more details may emerge as it progresses.
362
4
🇪🇸 Spain Arrests Suspected Pro-Russian Hacktivist Supporter 🚔 Spanish police have arrested a man in Palencia suspected of supporting the pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest. Investigators say he provided logistical and operational support to a Ukrainian hacker linked to the groups. ⚠️ CARR has been connected to attacks on critical infrastructure in the U.S. and Europe, including water, food-processing, and energy systems. Authorities also believe the group has ties to the Russian state-backed Sandworm (APT44) threat actor. 💻 According to police, the suspect used encrypted messaging apps to coordinate with other members and allegedly took part in operations claimed by NoName057(16), which promoted pro-Russian and anti-Western narratives online. 🔍 The investigation began in August 2025 after information was shared by the FBI. During a March 2026 raid, police seized computers and cryptocurrency storage devices, while also freezing crypto wallets believed to contain proceeds from the sale of stolen data. ⚖️ The suspect has not been formally charged, but remains under investigation for alleged membership in a terrorist organization, collaboration, glorification of terrorism, and computer-related offenses.
352
5
🇵🇱 Poland Arrests SIM Swapping Gang Behind Multi Million Dollar Crypto Thefts 📱 Polish authorities have arrested four members of a cybercrime group accused of carrying out sophisticated SIM swapping attacks that stole millions of dollars in cryptocurrency. The operation was supported by the FBI and U.S. Homeland Security Investigations. 💻 Investigators say the hackers used social engineering and specialized software to infiltrate telecommunications partners and employee email accounts. This allowed them to hijack victims' phone numbers, intercept SMS codes, and gain access to cryptocurrency exchange accounts. 💰 The stolen funds were allegedly laundered through multiple bank accounts and digital wallets across several countries. Authorities estimate that more than tens of millions of Polish złoty, equivalent to at least $5 million, were moved through the network. ⚖️ The suspects have been placed in pre trial detention and face charges including organized cybercrime, unauthorized access to IT systems, theft, and money laundering. If convicted, they could receive up to 25 years in prison.
468
6
🇧🇷 Unauthorized Emergency Alert Sparks Hacking Fears Across Brazil 📱 Brazilian authorities suspect a cyberattack after an unauthorized alert was sent to mobile phones in several states during the early hours of Saturday. 🚨 The unexpected message reached users through the country's citizen notification system and reportedly contained the word "misanthropy," meaning hatred of humanity. 🛡️ Following the incident, the National Protection and Civil Defense Secretariat took the alert platform offline around 1:30 a.m. local time to contain the issue and investigate what happened. 🔎 Officials believe the event may have been caused by a hacker intrusion, although the exact source and scope of the incident are still under investigation. 🇧🇷 The disruption affected parts of Brazil, raising concerns about the security of systems used to deliver emergency notifications to the public.
470
7
Hackers Abuse WordPress Plugin Flaw to Steal API Keys from 100,000 Sites 🛑 Threat actors are actively exploiting a recently patched flaw in the Gravity SMTP WordPress plugin, which is installed on around 100,000 websites. The bug, tracked as CVE-2026-4020, allows attackers to access sensitive information without authentication. 🔑 By abusing a vulnerable REST API endpoint, attackers can extract API keys, OAuth tokens, secrets, and configuration data linked to email providers such as Amazon SES, Google, Mailjet, Resend, and Zoho. The flaw also exposes system reports containing detailed information about the website environment. 📋 The leaked data may reveal PHP versions, active plugins, themes, database details, and server configurations, giving attackers valuable intelligence for follow-up attacks. Stolen credentials could also be abused to send emails on behalf of compromised websites. 📈 According to Wordfence, more than 17 million exploit attempts have already been blocked. Attack activity began in May 2026 and surged in early June, peaking at over 4 million requests in a single day, with multiple IP addresses linked to the campaign. ⚠️ Website owners using vulnerable versions should upgrade to Gravity SMTP 2.1.5 immediately, rotate all exposed credentials, and review server logs for suspicious requests. Sites using third-party email integrations are advised to assume compromise and take remediation steps as soon as possible.
379
8
Texas Data Breach Exposes Over 3 Million License Records 🛑 The Texas Parks and Wildlife Department (TPWD) confirmed a data breach affecting its license system vendor, exposing information tied to more than 3.08 million individuals who purchased hunting and fishing licenses. 📄 The leaked data may include driver’s license details, passport numbers, email addresses, phone numbers, and residential addresses, making the exposed records highly sensitive for identity tracking. 🔎 Officials said there is no evidence of Social Security Numbers (SSNs), credit cards, or other financial data being compromised. The incident is under investigation by Texas Cyber Command, which is assessing the full scope. 🎣 Authorities warned that the exposed information could be used for phishing and social engineering attacks, where scammers impersonate officials or companies to trick victims into revealing more personal data or installing malware. 🛡️ TPWD is working with its vendor to strengthen security and is offering one year of free credit monitoring to affected individuals, along with advice to place a credit freeze or fraud alert and stay alert for suspicious messages.
323
9
Nintendo Confirms Employee Survey Data Stolen in Third-Party Breach 🔐 Nintendo of America has confirmed that data was stolen from TinyPulse, a third-party employee survey platform owned by WebMD Health Services. The company stressed that Nintendo's own systems were not compromised and that customer and financial data remained safe. 📊 According to Nintendo, the exposed information is limited to internal employee survey content involving a small number of staff members. Most of the affected data reportedly dates back several years, and the company is working with the service provider to address the incident. 💰 The Shadowbyt3$ cybercrime group claims it stole nearly 1GB of data and demanded a $2 million ransom. The group alleges the files contain employee names, email addresses, survey analytics, bank statements, W-9 forms, employee IDs, and other internal records spanning 2016 to 2026. ⚠️ Nintendo disputes the broader claims, maintaining that the breach was limited to survey-related information. The hackers later stated that the incident affected only a small number of Nintendo employees who had used TinyPulse and did not impact Nintendo's gaming services. 🛡️ The authenticity of the leaked files has not been independently verified. Regardless, Nintendo customers do not need to take any action, as there is currently no evidence that customer accounts or personal customer data were exposed.
309
10
454,600 Students Impacted in Massive University Data Breach 🔓 The University of Nottingham has confirmed a major cyberattack that exposed a significant amount of student data. The incident impacted both current students and alumni, and has been reported to UK authorities, including the Information Commissioner's Office. ⚠️ The ShinyHunters cybercriminal group has claimed responsibility, alleging it stole more than 40GB of sensitive records from Nottingham and its Malaysia and China campuses. The leaked data reportedly includes financial information, payment records, and personal details. 📂 According to the attackers, the stolen information contains full names, home addresses, phone numbers, dates of birth, and IP addresses. Data breach tracking service Have I Been Pwned says the breach affects approximately 454,600 current and former students. 🛡️ Researchers believe the attack is part of a wider campaign targeting Oracle PeopleSoft systems. ShinyHunters claims it exploited a combination of zero-day vulnerabilities and older security flaws to breach more than 100 organizations worldwide. 🎓 Nottingham is the second major UK university to disclose a cyber incident in recent days. The news follows recent breaches affecting both the University of Oxford and the Canvas learning management platform, highlighting ongoing cybersecurity risks across the education sector.
400
11
Meta AI Support Flaw Leads to Theft of 20,000+ Instagram Accounts 🔓 Meta has confirmed that 20,225 Instagram accounts were hijacked after attackers exploited a bug in its AI-powered High Touch Support (HTS) account recovery system. The flaw allowed criminals to obtain password reset links and take over accounts. ⚠️ The vulnerability failed to properly verify whether a requested email address actually belonged to the targeted Instagram account. As a result, attackers could receive password reset links for other users and gain access to accounts that did not have two-factor authentication (2FA) enabled. 📱 The compromised accounts may have exposed email addresses, phone numbers, dates of birth, photos, videos, stories, direct messages, profile details, and other account activity. Meta says it has not confirmed exactly what data was accessed. 🛠️ After discovering the attacks, Meta disabled the HTS system, revoked all generated password reset links, secured affected accounts, and required impacted users to reset passwords and re-authenticate. The company is also reviewing similar recovery systems across its platforms. 📊 The breach was discovered on May 31, 2026, with reports indicating exploitation may have begun as early as April 17. Meta says it will strengthen verification checks before relaunching the support tool and continues investigating the incident.
374
12
Hackers Turn Stripe Into a Credit Card Theft Hub 💳 A newly discovered Magecart campaign is abusing Stripe’s API infrastructure to steal and store payment card data. The attack hides behind trusted services like Google Tag Manager (GTM) and Stripe domains, helping it evade many security controls. 🛒 The malware is delivered through legitimate-looking GTM containers and activates when shoppers reach checkout pages. It secretly collects credit card numbers, CVV codes, expiration dates, names, addresses, emails, and phone numbers from affected online stores. 🔐 Instead of sending stolen data to suspicious servers, the attackers use Stripe customer records as a storage system. The malware disguises each victim's payment details as a fake customer profile, making malicious activity blend in with normal payment traffic. ☁️ Researchers also found a variant that uses Google Firestore to host the malicious code and store stolen information. By mimicking payment and bot-protection services, the operation becomes even harder to detect. ⚠️ Evidence suggests the campaign may have been active since December 2025. Security experts recommend using one-time virtual payment cards with spending limits to reduce the risk of financial theft if card details are compromised.
414
13
Dutch Police Arrest Suspect in Major Football Club System Hack ⚽ Dutch authorities arrested a 35-year-old man from Buren over the alleged hacking of AFC Ajax’s computer systems. Investigators say the suspect illegally accessed the club’s network multiple times earlier this year. 💻 The breach reportedly exposed sensitive fan information and allowed the hacker to alter stadium bans and transfer match tickets. Ajax revealed in March that vulnerabilities in its IT systems had been exploited to access data linked to hundreds of people. 🔓 According to local reports, the attacker demonstrated access to more than 300,000 accounts, along with the ability to manipulate 42,000 season tickets and hundreds of supporter bans through insecure APIs and shared keys. 🛡️ Ajax has since patched the vulnerabilities and notified both the police and the Dutch Data Protection Authority. Authorities launched a criminal investigation shortly after the incident was reported. 🇳🇱 The arrest comes amid a broader Dutch crackdown on cybercrime. In recent months, police also detained suspects linked to Russian espionage activities and dismantled a hosting network allegedly tied to cyberattacks and disinformation campaigns.
565
14
🇳🇱 Netherlands Seizes 800 Servers Tied to Pro-Russian Cyber Operations 🔒 Dutch authorities arrested two suspects and seized 800 servers linked to a hosting network accused of enabling cyberattacks, disinformation campaigns, and interference operations across Europe. 💻 Investigators say the infrastructure was connected to Stark Industries, a hosting company sanctioned by the European Union for allegedly supporting Russian and Belarusian entities after the invasion of Ukraine. 🚨 Raids were carried out in multiple Dutch cities, where officials confiscated servers, laptops, phones, and administrative records. Authorities believe a newer company, WorkTitans B.V., acted as a front operation after sanctions hit Stark Industries. 🌐 Reports also link the infrastructure to the pro-Russian hacktivist group NoName057(16), known for launching large-scale DDoS attacks against critical organizations in Europe. ⚠️ Another provider, Mirhosting, allegedly handled connectivity and server operations tied to the network. The company denied knowingly supporting illegal activity and claimed it acted quickly after receiving abuse reports.
588
15
GitHub Breach Traced to Malicious VS Code Extension 💻 GitHub confirmed that attackers accessed thousands of internal repositories after a compromised version of a popular Visual Studio Code extension was installed on an employee device. The incident is linked to a wider software supply-chain attack that recently targeted multiple developer platforms and open-source projects. 🛠️ According to investigators, the malicious extension was designed to quietly steal credentials, authentication tokens, and other sensitive access data from developer environments. The stolen information was then allegedly used to gain deeper access to internal systems and repositories. 🔐 GitHub says it has since secured the affected device, rotated critical credentials, and increased monitoring across its infrastructure. The company added that there is currently no evidence that customer data outside the impacted repositories was compromised. 💰 The threat group known as TeamPCP has claimed responsibility for the attack and says it obtained data from nearly 4,000 private repositories. The group is reportedly attempting to sell the stolen information online. ⚠️ Security experts say the breach highlights the growing danger of supply-chain attacks, where hackers target trusted software tools and updates to infiltrate larger organizations. These incidents are becoming increasingly common across the developer ecosystem.
553
16
OpenAI Hit by Sophisticated Supply Chain Malware Attack 🚨 OpenAI says two employee devices were infected in the Mini Shai-Hulud attack, a supply chain malware campaign that spread through TanStack, a popular open-source JavaScript development framework. The company says no user data, production systems, or AI models were compromised. 🔐 According to OpenAI, attackers gained access to a small number of internal code repositories and stole limited credential-related data. The company quickly revoked sessions, rotated credentials, restricted deployment systems, and replaced code-signing certificates used to verify official apps. 💻 macOS users of ChatGPT Desktop, Codex App, Codex CLI, and Atlas must install the latest updates before June 12, 2026. OpenAI says old certificates will be revoked to stop attackers from distributing fake applications pretending to be legitimate OpenAI software. 🌐 Researchers linked the campaign to TeamPCP, a cybercrime group behind several recent software supply chain attacks targeting companies including Mistral AI - a French artificial intelligence startup, UiPath - an automation software company, and OpenSearch - an open-source search and analytics platform. The malware is designed to steal AWS cloud credentials, SSH keys, Docker secrets, and environment variables from infected systems. 🔥 Cybersecurity analysts say the malware is extremely advanced and resilient. It uses backup command-and-control systems, including hidden instructions stored in public GitHub commits, to stay active even if servers are shut down. Researchers also found destructive features that can wipe files on systems located in Israel or Iran, suggesting the operation may have geopolitical motives.
588
17
Windows 11 and Microsoft Edge Hacked at Pwn2Own Berlin 2026 Event 🔥 Windows 11 and Microsoft Edge fell on day one of Pwn2Own Berlin 2026, where researchers earned over $523,000 for uncovering 24 unique zero-days. 💻 Researchers also successfully hacked major AI and enterprise targets, including OpenAI Codex, LiteLLM, LM Studio, NVIDIA Megatron Bridge, and the NVIDIA Container Toolkit, with rewards reaching up to $50,000 per exploit. 🏆 The DEVCORE Research Team currently leads the competition with $205,000 in winnings, while Valentina Palmiotti holds second place with $70,000 after compromising both Red Hat Linux for Workstations and NVIDIA software. ⚡ The contest runs until May 16 at OffensiveCon Berlin, with upcoming targets including Microsoft Exchange, Safari, Firefox, Claude Code, and more. Vendors now have 90 days to release patches for all disclosed vulnerabilities.
506
18
UK Water Supplier Fined $1.3M After Massive Customer Data Breach 🛑 UK regulators fined South Staffordshire Water £963,900 ($1.3 million) after a cyberattack exposed the personal data of nearly 664,000 customers and employees. The breach remained undetected for almost two years. 📂 Investigators found the attack started with a phishing email, allowing hackers to install malware and quietly expand access across the company’s network. Attackers eventually gained domain administrator privileges before the breach was discovered in 2022. ⚠️ The leaked data included names, addresses, phone numbers, dates of birth, bank details, account credentials, and sensitive employee HR records. The stolen information later appeared on the dark web. 🔍 The UK ICO blamed the incident on major cybersecurity failures, including outdated Windows Server 2003 systems, missing security patches, weak monitoring, and poor vulnerability management. Only about 5% of the IT environment was actively monitored. 💰 Regulators initially planned a larger penalty, but the fine was reduced by 40% after South Staffordshire admitted liability, cooperated with investigators, and agreed to settle without appeal.
522
19
Telegram Mini Apps exploited for large-scale crypto scams and malware delivery 🚨 Cybersecurity researchers have uncovered a massive fraud operation abusing Telegram’s Mini Apps to run crypto scams, brand impersonation, and Android malware campaigns. The platform, known as FEMITBOT, uses bots and embedded apps to create convincing in-app experiences that trick users without leaving Telegram. ⚠️ Attackers launch phishing Mini Apps through Telegram bots, showing fake dashboards, balances, and earnings. These scams often include countdown timers and urgent offers to pressure users. When victims try to withdraw funds, they are asked to deposit money or complete tasks, a classic advance-fee scam tactic. 🎭 The operation heavily relies on impersonating major global brands to build trust. Despite different appearances, campaigns share the same backend infrastructure, allowing scammers to quickly switch domains, languages, and themes while scaling attacks efficiently. 📲 Some campaigns go further by pushing malicious Android APK downloads disguised as legitimate apps. These files are hosted on trusted-looking domains and named to avoid suspicion, increasing the risk of malware infections for users who install them. 🔐 Users are advised to stay cautious with Telegram bots promoting investments or downloads. Avoid sideloading APK files and interacting with suspicious Mini Apps, especially those requesting payments or sensitive actions.
702
20
🇫🇷 Teen Hacker Detained In France For Selling Stolen Government Data 🔐 A 15-year-old has been detained in France for allegedly selling stolen data from a cyberattack targeting the national agency ANTS, responsible for official documents. The suspect is believed to have operated under the alias “breach3d” on a cybercrime forum. 📅 The breach was first detected on April 13, with authorities notified days later. Investigators say the teen attempted to sell between 12 and 18 million records, making it one of the more serious recent data exposure cases involving a government system. ⚖️ The minor faces charges including unauthorized access, system persistence, and data exfiltration, along with possession of hacking tools. These offenses carry penalties of up to 7 years in prison and a €300,000 fine, though formal charges are still pending. 📂 Exposed data includes names, emails, birthdates, addresses, and phone numbers from both individuals and professionals. Initially, claims suggested up to 19 million records, but officials later confirmed around 11.7 million accounts were affected. 🧑‍⚖️ A judge is now reviewing the case, and prosecutors are seeking to place the suspect under judicial supervision. Authorities also stated that the stolen data could not be directly used for unauthorized account access, limiting immediate risk despite the massive breach.
497