Bob Diachenko ๐Ÿ‡บ๐Ÿ‡ฆ (@mayhemdayone) 's Twitter Profile
Bob Diachenko ๐Ÿ‡บ๐Ÿ‡ฆ

@mayhemdayone

Cyber Threat Intelligence @ securitydiscovery.com, journalist, OSINT | Responsible disclosures | Security consultancy | Contact me: [email protected]

ID: 702497747786715136

linkhttps://linkedin.com/in/vdyachenko calendar_today24-02-2016 14:18:09

1,1K Tweet

18,18K Followers

559 Following

Bob Diachenko ๐Ÿ‡บ๐Ÿ‡ฆ (@mayhemdayone) 's Twitter Profile Photo

Current developments on this as of Sep 27: - I got in touch with AWS security team so they would contact the owner of the secret keys/buckets and get them rotated/secured; - Apparently, someone responsible for the gov't portal IT maintenance was made aware of this "overlap" and

Bob Diachenko ๐Ÿ‡บ๐Ÿ‡ฆ (@mayhemdayone) 's Twitter Profile Photo

Here is the final update on the Indian gov't portal exposure I've talked about last week: The National Logistics Portal + its environment. Now secured. cybernews.com/security/natioโ€ฆ

Bob Diachenko ๐Ÿ‡บ๐Ÿ‡ฆ (@mayhemdayone) 's Twitter Profile Photo

[NEW REPORT] "World-In-HD is the best French torrent tracker out there. Getting in there is very hard." Now all the 97k+ account details (real IPs, emails, torrent activity, logs etc.) were exposed as a result of another misconfiguration incident. Read more:

[NEW REPORT] "World-In-HD is the best French torrent tracker out there. Getting in there is very hard." 
Now all the 97k+ account details (real IPs, emails, torrent activity, logs etc.) were exposed as a result of another misconfiguration incident. Read more:
Bob Diachenko ๐Ÿ‡บ๐Ÿ‡ฆ (@mayhemdayone) 's Twitter Profile Photo

[NEW REPORT] A popular parental control app exposed its activity logs, leaving users' private data in www for at least a month. Payment info, user PII, tracking details - literally everything. Logstash updated daily, with gigabytes of data, usual story. Infected with readme note.

[NEW REPORT] A popular parental control app exposed its activity logs, leaving users' private data in www for at least a month. Payment info, user PII, tracking details - literally everything. Logstash updated daily, with gigabytes of data, usual story. Infected with readme note.
Bob Diachenko ๐Ÿ‡บ๐Ÿ‡ฆ (@mayhemdayone) 's Twitter Profile Photo

Every single data breach ever reported or sold was carefully collected by an unknown actor and left in a misconfigured instance. I'd say it is even bigger than Troy Hunt's HIBP.

Bob Diachenko ๐Ÿ‡บ๐Ÿ‡ฆ (@mayhemdayone) 's Twitter Profile Photo

Some random 'Mother of All Breaches' #MOAB stats / interesting info, FYI: 1) the total number of datasets in MOAB = 4145 2) out of it = 1448 have more than 100k records 3) out of it = 601 have more than 1M recs 4) 203 datasets have less than 100 recs 5) instance was updated in

Some random 'Mother of All Breaches' #MOAB stats / interesting info, FYI: 
1) the total number of datasets in MOAB = 4145
2) out of it = 1448 have more than 100k records
3) out of it = 601 have more than 1M recs
4) 203 datasets have less than 100 recs
5) instance was updated in
CyberNews (@cybernews) 's Twitter Profile Photo

โ–ช๏ธCyberNews researchโ–ช๏ธ Football Australia leak exposes playersโ€™ detailsโคต๏ธ #Australia #FootballAustralia #dataleak #data #cybersecurity #infosec cybernews.com/security/footbโ€ฆ

Bob Diachenko ๐Ÿ‡บ๐Ÿ‡ฆ (@mayhemdayone) 's Twitter Profile Photo

Will add a few details about this one. - Reported it to Football Australia on Nov 22, 2023 - At least one bucket was public - A couple of screenshots with proofs below

Will add a few details about this one. 
- Reported it to Football Australia on Nov 22, 2023
- At least one bucket was public
- A couple of screenshots with proofs below
Bob Diachenko ๐Ÿ‡บ๐Ÿ‡ฆ (@mayhemdayone) 's Twitter Profile Photo

[NEW REPORT] Still a lot of UA entities and persons use uCoz resources to host sites. Now we know for sure, and a lot more to investigate... cybernews.com/security/web-hโ€ฆ

Bob Diachenko ๐Ÿ‡บ๐Ÿ‡ฆ (@mayhemdayone) 's Twitter Profile Photo

We are working with Nik and Sรฉbastien ๐Ÿ‡บ๐Ÿ‡ฆ on a project that should help companies quickly respond to the fast-growing issue with API keys leaks. Unfortunately, Shopify, Stripe, PayPal and other industry players underestimate this problem and prefer not to mention numerous