LAPSUS$
📈 Análisis del canal de Telegram LAPSUS$
El canal LAPSUS$ (@minsaudebr) en el segmento lingüístico de Inglés es un actor destacado. Actualmente la comunidad reúne a 57 390 suscriptores, ocupando la posición en la categoría Otro.
📊 Métricas de audiencia y dinámica
Desde su creación el невідомо, el proyecto ha mostrado un crecimiento acelerado, reuniendo a 57 390 suscriptores.
Según los últimos datos del 08 septiembre, 2024, el canal mantiene una actividad estable. En los últimos 30 días la variación de miembros fue de 0, y en las últimas 24 horas de 0, conservando un alto alcance.
- Estado de verificación: No verificado
- Tasa de interacción (ER): El promedio de interacción de la audiencia es 0%. Durante las primeras 24 horas tras publicar, el contenido suele obtener N/A% de reacciones respecto al total de suscriptores.
- Alcance de las publicaciones: Cada publicación recibe en promedio 0 visualizaciones. En el primer día suele acumular 0 visualizaciones.
- Reacciones e interacción: La audiencia responde de forma activa: el promedio de reacciones por publicación es 0.
📝 Descripción y política de contenido
No se ha proporcionado la descripción del canal.
Gracias a la alta frecuencia de actualizaciones (últimos datos recibidos el 09 septiembre, 2024), el canal mantiene la vigencia y un amplio alcance. La analítica demuestra que la audiencia interactúa activamente con el contenido, lo que lo convierte en un punto de referencia dentro de la categoría Otro.
Carga de datos en curso...
| Fecha | Crecimiento de Suscriptores | Menciones | Canales | |
| 30 marzo | 0 | |||
| 29 marzo | +1 | |||
| 28 marzo | +5 | |||
| 27 marzo | 0 | |||
| 26 marzo | +1 | |||
| 25 marzo | +4 | |||
| 24 marzo | +4 | |||
| 23 marzo | +5 | |||
| 22 marzo | +1 | |||
| 21 marzo | +1 | |||
| 20 marzo | +4 | |||
| 19 marzo | +2 | |||
| 18 marzo | 0 | |||
| 17 marzo | 0 | |||
| 16 marzo | 0 | |||
| 15 marzo | +4 | |||
| 14 marzo | +3 | |||
| 13 marzo | 0 | |||
| 12 marzo | +2 | |||
| 11 marzo | +1 | |||
| 10 marzo | +1 | |||
| 09 marzo | +1 | |||
| 08 marzo | +3 | |||
| 07 marzo | +2 | |||
| 06 marzo | +2 | |||
| 05 marzo | +4 | |||
| 04 marzo | 0 | |||
| 03 marzo | +2 | |||
| 02 marzo | +8 | |||
| 01 marzo | 0 |
| 2 | Leak of some customers source code from Globant.com corp GHE and GHE
Around 70gb.
Enjoy! | 126 419 |
| 3 | For anyone who is interested about the poor security practices in use at Globant.com. i will expose the admin credentials for ALL there devops platforms below.
https://confluence.globant.com/
https://confluence.corp.globant.com/ (massive, over 3000 spaces of customer documents)
admin
oighiegh
https://crucible.globant.com/
https://crucible.corp.globant.com/
admin
aiyiushe
https://jira.globant.com/
https://jira.corp.globant.com/
admin
ohgheibi
admin2
ohgheibi
https://github.globant.com/
https://github.corp.globant.com/
syed.aleem
New123456789!!! | 114 218 |
| 4 | We are officially back from a vacation (spoiler above) | 89 268 |
| 5 | Sin texto... | 89 496 |
| 6 | @fuckmox call +44 7784 154619 +44 7932 860730 kkkkkkkkkkkkkk | 1 |
| 7 | It has come to our attention that many users are impersonating Lapsus$ staff. Reminder that anyone claiming to be lapsus$ is most likely false, the only public username is @Lapsusjobs where you can work as an insider and get paid. Lapsus$ will never have “double your bitcoin” scheme. The only official Lapsus$ media is t.me/minsaudebr and t.me/saudechat. | 119 685 |
| 8 | We would like to advise everyone not to respond to any message or deal with @fuckmox as their telegram handle was stolen, and they are scamming our users. The official fuckmox currently does not have a username. More information will be announced shortly. | 11 |
| 9 | Welcome a new member @fuckmox | 22 690 |
| 10 | A few of our members has a vacation until 30/3/2022.
We might be quiet for some times.
Thanks for understand us. - we will try to leak stuff ASAP. | 140 110 |
| 11 | https://www.okta.com/blog/2022/03/updated-okta-statement-on-lapsus/
I do enjoy the lies given by Okta.
1. We didn't compromise any laptop? It was a thin client.
2. "Okta detected an unsuccessful attempt to compromise the account of a customer support engineer working for a third-party provider." -
I'm STILL unsure how its a unsuccessful attempt? Logged in to superuser portal with the ability to reset the Password and MFA of ~95% of clients isn't successful?
4. For a company that supports Zero-Trust. *Support Engineers* seem to have excessive access to Slack? 8.6k channels? (You may want to search AKIA* on your Slack, rather a bad security practice to store AWS keys in Slack channels 😉)
5. Support engineers are also able to facilitate the resetting of passwords and MFA factors for users, but are unable to obtain those passwords. -
Uhm? I hope no-one can read passwords? not just support engineers, LOL. - are you implying passwords are stored in plaintext?
6. You claim a laptop was compromised? In that case what *suspicious IP addresses* do you have available to report?
7. The potential impact to Okta customers is NOT limited, I'm pretty certain resetting passwords and MFA would result in complete compromise of many clients systems.
8. If you are committed to transparency how about you hire a firm such as Mandiant and PUBLISH their report? I'm sure it would be very different to your report :)
_________________________________________________________________________________________________________________________________________________________________________________________________________
https://www.okta.com/sites/default/files/2021-12/okta-security-privacy-documentation.pdf
*21. Security Breach Management.
a) Notification: In the event of a Security Breach, Okta notifies impacted customers of such Security Breach. Okta
cooperates with an impacted customer’s reasonable request for information regarding such Security Breach, and Okta
provides regular updates on any such Security Breach and the investigative action and corrective action(s) taken.* -
But customers only found out today? Why wait this long?
9. Access Controls. Okta has in place policies, procedures, and logical controls that are designed:
b. Controls to ensure that all Okta personnel who are granted access to any Customer Data are based on leastprivilege principles;
kkkkkkkkkkkkkkk
1. Security Standards. Okta’s ISMP includes adherence to and regular testing of the key controls, systems and procedures of
its ISMP to validate that they are properly implemented and effective in addressing the threats and risks identified. Such
testing includes:
a) Internal risk assessments;
b) ISO 27001, 27002, 27017 and 27018 certifications;
c) NIST guidance; and
d) SOC2 Type II (or successor standard) audits annually performed by accredited third-party auditors (“Audit
Report”).
I don't think storing AWS keys within Slack would comply to any of these standards? | 128 059 |
| 12 | Just some photos from our access to Okta.com Superuser/Admin and various other systems.
For a service that powers authentication systems to many of the largest corporations, I think these security measures are pretty poor. | 122 958 |
| 13 | Leak of some Bing , Bing Maps and Cortana source code - Bing maps is 90% complete dump. Bing and Cortana around 45%.
Enjoy everyone! | 124 086 |
| 14 | Dump of all hashes for LGE.com employee's and service accounts - second time we hacked them in ~1 years.
Dump of LG's infrastructure confluence will be released soon.
Might be a good idea to consider a new CSIRT team! | 99 953 |
| 15 | Deleted for now will repost later | 87 286 |
| 16 | Sin texto... | 194 |
| 17 | image_2022-03-20_04-54-28.png | 9 |
| 18 | URGENTE: https://g1.globo.com/politica/noticia/2022/03/18/moraes-determina-bloqueio-do-aplicativo-de-mensagens-telegram-em-todo-o-brasil.ghtml
ENTREM NESSE CANAL E SE CONECTEM A ALGUM PROXY: https://t.me/ProxyMTProto
(only for brazil users!!!!) | 100 388 |
| 19 | Vodafone winner.
We work to ready the data! | 24 734 |
| 20 | We have just hit 30000 members 🥳
Stay tuned! More stuff coming soon | 105 913 |
