Top stories.
- Law enforcement seizes BreachForums domains.
- Juniper Networks patches over 200 flaws.
- RondoDox botnet targets dozens of vulnerabilities.
Law enforcement seizes BreachForums domains.
US and French law enforcement last night seized all domains for the latest version of BreachForums, which was set up by the ShinyHunters gang (now part of the Scattered Lapsus$ Hunters criminal collective) as a portal for leaking data stolen in extortion attacks. ShinyHunters confirmed the takedown and said they would not be launching another BreachForums, BleepingComputer reports.
Scattered Lapsus$ Hunters had been using the site to extort companies breached in the ongoing wave of Salesforce attacks. The data were stolen via social engineering attacks targeting dozens of major companies, including FedEx, Disney/Hulu, HBO Max, Home Depot, Marriott, Google, Cisco, Toyota, Gap, McDonald's, Walgreens, Instacart, Cartier, and Adidas. The crooks set a deadline to leak one billion records at midnight tonight, and said the takedown will not disrupt their plans. The Register notes that this latest threat looks "more like a desperate scramble to monetize old stolen data before law enforcement closes in."

