LAPSUS$
Kanalga Telegram’da o‘tish
Ko'proq ko'rsatish
Mamlakat belgilanmaganToif belgilanmagan
📈 Telegram kanali LAPSUS$ analitikasi
LAPSUS$ (@minsaudebr) Ingliz til segmentidagi kanali faol ishtirokchi. Hozirda hamjamiyat 57 390 obunachidan iborat bo'lib, Boshqa toifasida -o'rinni egallagan.
📊 Auditoriya ko‘rsatkichlari va dinamika
невідомо sanasidan buyon loyiha tez o‘sib, 57 390 obunachiga ega bo‘ldi.
08 Sentabr, 2024 dagi oxirgi ma’lumotlarga ko‘ra kanal barqaror faollikka ega. Oxirgi 30 kunda obunachilar soni 0 ga, so‘nggi 24 soatda esa 0 ga o‘zgardi va umumiy qamrov yuqori darajada qolmoqda.
- Tasdiqlash holati: Tasdiqlanmagan
- Jalb etish (ER): Auditoriya o‘rtacha 0% darajada jalb etiladi. Nashrdan keyingi dastlabki 24 soatda kontent odatda umumiy obunachilar sonining N/A% ini tashkil etuvchi reaksiyalarni to‘playdi.
- Post qamrovi: Har bir post o‘rtacha 0 marta ko‘riladi; birinchi sutkada odatda 0 ta ko‘rish yig‘iladi.
- Reaksiyalar va o‘zaro ta’sir: Auditoriya faol: har bir postga o‘rtacha 0 ta reaksiya keladi.
📝 Tavsif va kontent siyosati
Kanal uchun tavsif kiritilmagan.
Yuqori yangilanish chastotasi (oxirgi ma’lumot 09 Sentabr, 2024 da olingan) sababli kanal doimo dolzarb va katta qamrovli bo‘lib qoladi. Analitika auditoriya kontent bilan faol hamkorlik qilishini, uni Boshqa toifasidagi muhim ta’sir nuqtasiga aylantirishini ko‘rsatadi.
57 390
Obunachilar
Ma'lumot yo'q24 soatlar
Ma'lumot yo'q7 kun
Ma'lumot yo'q30 kun
Postlar arxiv
57 390
We created a Element/Matrix chat in the case this Telegram is deleted!
https://matrix.to/#/#lapsus:matrix.org
We advise everyone to join it!
57 390
For anyone who is interested about the poor security practices in use at Globant.com. i will expose the admin credentials for ALL there devops platforms below.
https://confluence.globant.com/
https://confluence.corp.globant.com/ (massive, over 3000 spaces of customer documents)
admin
oighiegh
https://crucible.globant.com/
https://crucible.corp.globant.com/
admin
aiyiushe
https://jira.globant.com/
https://jira.corp.globant.com/
admin
ohgheibi
admin2
ohgheibi
https://github.globant.com/
https://github.corp.globant.com/
syed.aleem
New123456789!!!
57 390
It has come to our attention that many users are impersonating Lapsus$ staff. Reminder that anyone claiming to be lapsus$ is most likely false, the only public username is @Lapsusjobs where you can work as an insider and get paid. Lapsus$ will never have “double your bitcoin” scheme. The only official Lapsus$ media is t.me/minsaudebr and t.me/saudechat.
57 390
A few of our members has a vacation until 30/3/2022.
We might be quiet for some times.
Thanks for understand us. - we will try to leak stuff ASAP.
57 390
https://www.okta.com/blog/2022/03/updated-okta-statement-on-lapsus/
I do enjoy the lies given by Okta.
1. We didn't compromise any laptop? It was a thin client.
2. "Okta detected an unsuccessful attempt to compromise the account of a customer support engineer working for a third-party provider." -
I'm STILL unsure how its a unsuccessful attempt? Logged in to superuser portal with the ability to reset the Password and MFA of ~95% of clients isn't successful?
4. For a company that supports Zero-Trust. *Support Engineers* seem to have excessive access to Slack? 8.6k channels? (You may want to search AKIA* on your Slack, rather a bad security practice to store AWS keys in Slack channels 😉)
5. Support engineers are also able to facilitate the resetting of passwords and MFA factors for users, but are unable to obtain those passwords. -
Uhm? I hope no-one can read passwords? not just support engineers, LOL. - are you implying passwords are stored in plaintext?
6. You claim a laptop was compromised? In that case what *suspicious IP addresses* do you have available to report?
7. The potential impact to Okta customers is NOT limited, I'm pretty certain resetting passwords and MFA would result in complete compromise of many clients systems.
8. If you are committed to transparency how about you hire a firm such as Mandiant and PUBLISH their report? I'm sure it would be very different to your report :)
_________________________________________________________________________________________________________________________________________________________________________________________________________
https://www.okta.com/sites/default/files/2021-12/okta-security-privacy-documentation.pdf
*21. Security Breach Management.
a) Notification: In the event of a Security Breach, Okta notifies impacted customers of such Security Breach. Okta
cooperates with an impacted customer’s reasonable request for information regarding such Security Breach, and Okta
provides regular updates on any such Security Breach and the investigative action and corrective action(s) taken.* -
But customers only found out today? Why wait this long?
9. Access Controls. Okta has in place policies, procedures, and logical controls that are designed:
b. Controls to ensure that all Okta personnel who are granted access to any Customer Data are based on leastprivilege principles;
kkkkkkkkkkkkkkk
1. Security Standards. Okta’s ISMP includes adherence to and regular testing of the key controls, systems and procedures of
its ISMP to validate that they are properly implemented and effective in addressing the threats and risks identified. Such
testing includes:
a) Internal risk assessments;
b) ISO 27001, 27002, 27017 and 27018 certifications;
c) NIST guidance; and
d) SOC2 Type II (or successor standard) audits annually performed by accredited third-party auditors (“Audit
Report”).
I don't think storing AWS keys within Slack would comply to any of these standards?
57 390
Leak of some Bing , Bing Maps and Cortana source code - Bing maps is 90% complete dump. Bing and Cortana around 45%.
Enjoy everyone!
57 390
URGENTE: https://g1.globo.com/politica/noticia/2022/03/18/moraes-determina-bloqueio-do-aplicativo-de-mensagens-telegram-em-todo-o-brasil.ghtml
ENTREM NESSE CANAL E SE CONECTEM A ALGUM PROXY: https://t.me/ProxyMTProto
(only for brazil users!!!!)
