[Update]Detailed Analysis of LAPSUS$ Cybercriminal Group that has Compromised Nvidia, Microsoft, Okta, and Globant
ID: fdf70bdc-e20e-54c6-8297-8a6c301f5eaf
STIX ID: report--fdf70bdc-e20e-54c6-8297-8a6c301f5eaf
Feed Name: CloudSEK Blog
Lapsus$ has claimed and in some cases been confirmed to have exfiltrated source code, credentials, certificates and limited PII from major technology firms (Microsoft, Okta, Nvidia, Globant, Samsung). The group leverages human-targeted techniques (credential theft, insider recruitment), public secrets, and exploitation of unpatched services to gain access; leaked materials include source code, private keys and certificates that have been used to sign malware, increasing risk of follow-on attacks. The report includes IoCs (SHA256s, IPs, domains), a CVE focus list, and recommends resetting credentials, enforcing MFA, patching vulnerable systems, and monitoring for anomalous activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
