ZeroHour

Search: “certification”

3 stories in the last 3d

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

Hunt.io found an attacker holding root access inside Thai ISP 3BB via a MeshCentral backdoor, targeting subscriber RADIUS credential databases.

Hunt.io discovered an exposed attacker server on June 3, 2026 revealing an ongoing intrusion at 3BB, one of Thailand's largest broadband providers. The attacker maintained hidden MeshCentral agents reporting to www.ayuthayatech[.]com (device group TH-3BB) and held root on internal servers. Recovered scripts sprayed passwords over SSH against more than 55 internal machines, planted web shells, added SSH keys, searched for stored credentials, and targeted RADIUS subscriber credential databases, though exfiltration was not confirmed. The toolkit included a full exploit for FortiGate SSL-VPN flaw CVE-2024-21762 against mail.3bb.co[.]th, but the initial access vector is unestablished, and a cleanup script erased logs while preserving the backdoor.

The Hacker Newsupdated · 2d agofirst · 2d agoData breach in the wild 3 sourcesCVE-2024-217621

Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database

ShinyHunters published hundreds of thousands of records from Florida's DAVID vehicle database, including SSNs and passports, after an unpaid ransom demand.

The ShinyHunters group published hundreds of thousands of files from Florida's DAVID motor vehicle database on its leak site, saying the victim did not pay a ransom. Stolen records include vehicle ownership certificates with names, addresses, and VINs, plus a smaller number of Social Security numbers, non-US passports, and immigration documents. FLHSMV confirmed the breach, which followed theft of a police officer's credentials stored on a personal device. It comes the same month as the IDScan hack exposing over 150 million driver's license images.

TechCrunch · Security · 14h agoData breach 3 sources

Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen

CenterPoint Energy confirmed a breach after a hacker claimed stealing 7.49 million customer records, including partial Social Security numbers, via an unprotected API.

CenterPoint Energy disclosed in an SEC 8-K filing that an unauthorized third party obtained personal information of a portion of its customers through an external-facing system. A threat actor using the alias '4d722e4d656f77' claimed on a cybercrime forum to have extracted over 7.49 million records, including names, addresses, account numbers, billing data, and partial Social Security numbers, via an API lacking authentication, rate limiting, and WAF protection. The company confirmed the breach but not the record count; energy services were unaffected and the investigation is ongoing.

Security Affairsupdated · 17h agofirst · 1d agoData breach in the wild 5 sources