Building a Safe Cybersecurity Lab with Virtual Machines, Nmap, and Wireshark
β–² 3 r/pwnhub

Building a Safe Cybersecurity Lab with Virtual Machines, Nmap, and Wireshark

This guide explains how to set up an isolated home lab using virtual machines to safely practice network scanning with Nmap and traffic analysis with Wireshark.

Key Points:

  • Use hypervisors like VirtualBox, VMware, or Hyper-V to create isolated guest operating systems on a host machine.
  • Configure virtual machines in Bridged Mode to allow realistic network interactions and independent IP addressing.
  • Install Kali Linux as the attacking system and Windows as the target system to simulate real-world security testing.
  • Use Wireshark on the target system to capture and filter network packets in real-time.
  • Execute Nmap scans from the attacking system to observe how port scanning generates detectable network traffic.

A home lab provides a controlled environment where beginners can practice ethical hacking and cybersecurity skills without risking real systems or sensitive data. By using virtual machines, you can run multiple operating systems simultaneously on a single physical computer. The setup typically involves a host machine running a hypervisor, which manages the resources for guest operating systems. For this exercise, Kali Linux serves as the attacking system equipped with security tools, while a Windows VM acts as the target system. Configuring the network in Bridged Mode is crucial, as it allows each virtual machine to act as a standalone entity on the network, mimicking the behavior of physical machines.

Learn More: Dark Marc

Want to stay updated on the latest cyber threats?

πŸ‘‰ Subscribe to /r/PwnHub

u/_cybersecurity_ β€” 1 day ago
β–² 4 r/pwnhub

CISA Confirms Ransomware Gangs Exploiting Windows Task Host Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Windows privilege escalation flaw to its actively exploited list, noting that ransomware groups are currently abusing the vulnerability to gain full system control.

Key Points:

  • CISA added CVE-2025-60710 to its Known Exploited Vulnerabilities Catalog, confirming active exploitation by ransomware gangs.
  • The flaw allows attackers with basic user permissions to escalate privileges to SYSTEM level on unpatched Windows 11 and Windows Server 2025 devices.
  • Microsoft patched the vulnerability in November 2025, but CISA has urged Federal Civilian Executive Branch agencies to secure systems within two weeks.
  • This follows a recent warning about ransomware exploiting a separate Microsoft SharePoint vulnerability, highlighting a pattern of targeted attacks on Microsoft products.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially confirmed that ransomware groups are actively exploiting a high-severity vulnerability in the Windows Task Host component, tracked as CVE-2025-60710. This flaw, which stems from a link following weakness, affects Windows 11 and Windows Server 2025. Although Microsoft released a patch in November 2025, the continued exploitation indicates that many systems remain unsecured. Successful exploitation allows local attackers with standard user permissions to escalate their privileges to SYSTEM level, effectively taking full control of the compromised device.

Learn More: Bleeping Computer

Want to stay updated on the latest cyber threats?

πŸ‘‰ Subscribe to /r/PwnHub

u/_cybersecurity_ β€” 1 day ago
β–² 28 r/pwnhub

Microsoft removes WMIC tool from Windows 11 to block cybercriminals

Microsoft has removed the legacy WMIC command-line utility from Windows 11 24H2 and 25H2 to prevent threat actors from abusing the tool for malicious activities.

Key Points:

  • WMIC is removed from Windows 11 24H2, 25H2, and beta builds, ending its availability as a Feature on Demand.
  • The tool was frequently abused by malware, ransomware, and attackers to disable security software and delete system backups.
  • The underlying Windows Management Instrumentation (WMI) system remains active, but administrators must use PowerShell or other modern tools.
  • This action follows a deprecation timeline that began with Windows Server 2012 and Windows 10 21H1.

Microsoft has officially removed the Windows Management Instrumentation Command-line (WMIC) tool from the latest versions of Windows 11, specifically versions 24H2 and 25H2, as well as recent beta builds. This removal is the final step in a deprecation process that started years ago, initially converting WMIC into an optional feature before disabling it by default. The legacy tool is no longer available for installation on new systems, marking a significant shift in how Windows manages system administration commands.

Learn More: Bleeping Computer

Want to stay updated on the latest cyber threats?

πŸ‘‰ Subscribe to /r/PwnHub

u/_cybersecurity_ β€” 1 day ago
β–² 7 r/pwnhub

Apple Pays Sentry Founder $150,000 for Private Cloud Compute Vulnerability

Apple has awarded $150,000 to the founder of Sentry for discovering a security vulnerability in its Private Cloud Compute service.

Key Points:

  • Apple paid $150,000 to the founder of Sentry for a vulnerability report.
  • The vulnerability was located within Apple's Private Cloud Compute infrastructure.
  • The payment reflects Apple's bug bounty program valuation for this specific finding.
  • The incident highlights ongoing security assessments of Apple's cloud services.

Apple has confirmed a payment of $150,000 to the founder of Sentry, a developer productivity platform, for reporting a security flaw. The vulnerability was identified within the architecture of Apple's Private Cloud Compute service, a feature designed to process sensitive data on-device or in a secure cloud environment to enhance user privacy.

This transaction underscores the value Apple places on external security research and responsible disclosure. By compensating the researcher, Apple reinforces its commitment to maintaining the integrity of its cloud infrastructure. The specific nature of the vulnerability was not detailed in the immediate report, but the significant bounty indicates a finding that could have impacted the security or privacy of the service.

The Private Cloud Compute service is a critical component of Apple's strategy to offer advanced AI and processing capabilities while adhering to strict privacy standards. Security flaws in such services are of high interest to both researchers and the company, as they could potentially expose user data or compromise system integrity. This payment serves as a public acknowledgment of the researcher's contribution to securing the platform.

How does the compensation for cloud infrastructure vulnerabilities compare to those for consumer-facing iOS bugs?

Learn More: Hack Read

Want to stay updated on the latest cyber threats?

πŸ‘‰ Subscribe to /r/PwnHub

u/_cybersecurity_ β€” 1 day ago
β–² 9 r/pwnhub

MessiahGPT Criminal AI Service Advertised on BreachForums

A new artificial intelligence service marketed for criminal activities has been advertised on the BreachForums hacking community.

Key Points:

  • MessiahGPT is a criminal AI service currently being promoted on BreachForums.
  • The service is advertised to individuals interested in illicit cyber activities.
  • The listing indicates the emergence of new AI tools targeted at the underground market.

A service known as MessiahGPT has appeared on BreachForums, a well-known online forum for cybercriminals. The platform is being advertised as an artificial intelligence tool designed to facilitate criminal operations. This development highlights the growing intersection between advanced AI technology and underground hacking communities.

The presence of such a service on BreachForums suggests that threat actors are actively seeking to leverage AI for malicious purposes. While specific technical details of the service's capabilities are not provided in the initial advertisement, its existence signals a potential shift in how cybercriminals may conduct their activities. Security researchers and organizations should monitor this development for further details on the tool's functionality and potential impact.

How do you think the availability of criminal AI services like MessiahGPT will change the landscape of cyber threats in the coming year?

Learn More: Hack Read

Want to stay updated on the latest cyber threats?

πŸ‘‰ Subscribe to /r/PwnHub

u/_cybersecurity_ β€” 1 day ago
β–² 3 r/pwnhub

Google Docs misconfigurations expose sensitive data and credentials

Recent incidents highlight how easily sensitive information, including login credentials and personal data, becomes publicly accessible through misconfigured sharing settings in Google Docs and similar platforms.

Key Points:

  • Pageloot exposed staging environment credentials after a contractor set a Google Doc to 'anyone with the link' and it was indexed by Google Search.
  • Japanese developer Ateam left 1,369 files containing personal data for nearly one million people publicly accessible for six years.
  • Scale AI had 85 Google Docs with training material for major tech companies set to editable by anyone with a link.
  • A Metomic scan of 6.5 million Google Drive files found that 0.5% were fully public, representing thousands of exposed files.
  • Verizon attributes approximately 60% of breaches to human factors such as misconfiguration and misuse of valid credentials.

The core issue stems from the ease with which users can inadvertently share sensitive data using collaborative tools. In the case of Pageloot, a contractor stored login details in a Google Doc with 'anyone with the link' permissions. Although these files are not automatically indexed, the document became discoverable via Google Search autocomplete, exposing the credentials until the company detected and remediated the issue. This incident underscores the risk of relying on shared documents for secure information storage rather than dedicated password managers.

This is not an isolated event but part of a broader trend of data exposure due to misconfiguration. Ateam, a Japanese game developer, left a vast amount of personal data publicly accessible for nearly seven years, while Scale AI exposed editable training materials for major AI companies. These examples illustrate that even large organizations struggle with access control, often leaving sensitive data open to the public due to human error or lack of oversight.

The scale of the problem is significant. A scan of 6.5 million Google Drive files revealed that a small percentage of fully public files still amounts to thousands of exposed documents. With Verizon reporting that 60% of breaches involve human factors like misconfiguration, the reliance on manual sharing settings in collaborative tools presents a substantial security risk for both consumers and enterprises.

Do you use a password manager to avoid storing credentials in shared documents, or do you rely on other methods?

Learn More: Malwarebytes

Want to stay updated on the latest cyber threats?

πŸ‘‰ Subscribe to /r/PwnHub

u/_cybersecurity_ β€” 1 day ago
β–² 4 r/pwnhub

Heights Finance Breach Exposes Data of Over 730,000 Customers

Heights Finance Holdings confirmed a data breach affecting up to 734,828 individuals, exposing sensitive personal, banking, and identity information stored on a third-party cloud platform.

Key Points:

  • Heights Finance discovered unauthorized access to a third-party cloud platform on May 7, potentially exposing customer data.
  • The breach affects approximately 734,828 people, including current and former customers of Heights Finance and related CURO Management brands.
  • Exposed data includes Social Security numbers, bank account details, driver's license numbers, and contact information.
  • The combination of identity and financial data increases risks for identity fraud, account takeover, and targeted phishing scams.

Heights Finance Holdings, a consumer lender operating in several southern states, reported that an unauthorized party accessed a third-party cloud platform containing customer data. The company filed a report with Texas regulators indicating that 734,828 individuals may be affected. This figure includes not only direct customers of Heights Finance but also those who inquired about loans or were customers of former parent company CURO Management and its associated brands. The breach was discovered on May 7, and the investigation suggests the intruder may have viewed or copied the information stored in the environment.

The nature of the exposed data poses significant risks beyond simple contact information leakage. Victims may have their Social Security numbers, dates of birth, home addresses, and bank account details compromised. This specific combination of data allows cybercriminals to impersonate victims, target their bank accounts, or create highly convincing phishing attempts. Additionally, personal circumstances disclosed during customer service interactions could be used to make social engineering scams more persuasive and harmful.

Affected individuals are advised to follow the instructions in the notification letter and enroll in the offered protection service. Those who believe they may be affected but did not receive a notice should contact Heights Finance using official details found on their website, rather than responding to unsolicited communications. The incident highlights the ongoing risks associated with third-party cloud storage and the severe consequences of exposing sensitive financial and identity information.

Learn More: Malwarebytes

Want to stay updated on the latest cyber threats?

πŸ‘‰ Subscribe to /r/PwnHub

u/_cybersecurity_ β€” 1 day ago
β–² 2 r/pwnhub

CISA Adds Actively Exploited Ray Framework Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical vulnerability in the Ray distributed computing framework to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation in the wild.

Key Points:

  • CVE-2025-62593 is a critical flaw (CVSS 9.4) allowing remote code execution via DNS rebinding attacks in Firefox and Safari browsers.
  • The vulnerability stems from a lack of authentication on critical Ray API endpoints, enabling attackers to execute arbitrary code on developer machines.
  • Threat actors, including the RondoDox DDoS botnet, have already weaponized the flaw, and unpatched instances are being targeted for cryptocurrency mining.
  • Federal Civilian Executive Branch agencies are directed to apply fixes by August 20, 2026, while users are urged to upgrade to version 2.52.0 immediately.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical vulnerability in the open-source Ray framework to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, identified as CVE-2025-62593, carries a CVSS score of 9.4 and allows attackers to achieve remote code execution. This is primarily achieved through DNS rebinding attacks that exploit browsers like Mozilla Firefox and Apple Safari. The core issue lies in the Ray framework's design, which lacks authentication on critical API endpoints, allowing a malicious website or advertisement to trick a developer's browser into executing arbitrary shell code on their local machine.

Learn More: The Hacker News

Want to stay updated on the latest cyber threats?

πŸ‘‰ Subscribe to /r/PwnHub

u/_cybersecurity_ β€” 1 day ago
β–² 3 r/pwnhub

Free Handout: Hacking AI Coding Agents (Claude Code, Gemini CLI, Codex), with Novee Security's Elad Meged

Novee Security researcher Elad Meged did an AMA in the PWN community fresh off his Black Hat USA 2026 and DEF CON 34 talk on breaking AI coding agents. We turned the talk into a free handout that teaches the material.

Hacking AI Coding Agents Handout: This handout explains how a single untrusted GitHub issue can hijack Claude Code, Gemini CLI, and Codex running in CI/CD, with plain-English breakdowns of all three vendor findings, why prompt injection is only the delivery and not the bug, and how to defend the agents you put in your own pipeline.

Featured Expert: Elad Meged is a founding-team vulnerability researcher at Novee Security. His research showed how a single untrusted GitHub issue could compromise the AI coding agents from Anthropic, Google, and OpenAI (Claude Code, Gemini CLI, and Codex), leading to remote code execution and credential theft. Read the research.


DOWNLOAD HANDOUT PDF


Did you miss the AMA?

View all of the questions and answers here.

u/_cybersecurity_ β€” 2 days ago
β–² 2 r/pwnhub

Free Handout: Enterprise Java Pre-Auth RCE, with Novee Security's Lidor B. (thisis0xczar)

Novee Security researcher Lidor B. (thisis0xczar) did an AMA in the PWN community fresh off his Black Hat USA 2026 talk on pre-auth remote code execution in enterprise Java. We turned the talk into a free handout that teaches the material.

Enterprise Java RCE Handout: This handout breaks down how an unauthenticated attacker chains together small, overlooked flaws in enterprise Java "plumbing" to reach remote code execution, walking through the real Bonita BPM and Apache OFBiz chains, the audit checklist for your own stack, and Lidor's methodology for finding this class of bug.

Featured Expert: Lidor B. (thisis0xczar) is a founding-team vulnerability researcher at Novee Security. At Black Hat this year he presented pre-auth remote code execution chains in enterprise Java platforms, reached through routing logic, unsafe deserialization, and template evaluation. Read the research.


DOWNLOAD HANDOUT PDF


Did you miss the AMA?

View all of the questions and answers here.

u/_cybersecurity_ β€” 2 days ago
β–² 2 r/pwnhub

Is a breach notification actually enough?

One user shared what happened after RingCentral data landed in Have I Been Pwned. Roughly 1.6 million accounts were exposed, with names, phone numbers, and physical addresses bundled together and already circulating online.

That combination is a strong starting point for targeted phishing, impersonation, and account recovery attacks.

What do you think? Does an email alert do anything useful, or do breached companies owe people far more?

reddit.com
u/_cybersecurity_ β€” 3 days ago
β–² 3 r/pwnhub

Should AI coding agents have system access?

Researchers at Novee Security showed how a single GitHub issue can hijack AI coding agents from Anthropic, Google, and OpenAI. Lidor B. and Elad Meged presented the work at Black Hat this year, showing Claude Code, Gemini CLI, and Codex leading to remote code execution and credential theft.

Developers hand these tools deep access to real systems every day.

What do you think? Should AI agents keep high level system access, or be locked down?

reddit.com
u/_cybersecurity_ β€” 3 days ago
β–² 2 r/pwnhub

Can AI coding tools ever be trusted?

Two Novee Security researchers are running an AMA today on hijacking AI coding agents after presenting at Black Hat.

Their work showed that one untrusted GitHub issue could compromise Claude Code, Gemini CLI, and Codex, leading to stolen credentials. The same researchers also found pre-auth remote code execution in widely deployed enterprise Java platforms.

What do you think? Are AI coding assistants safe enough for real work, or still too easy to turn against you?

reddit.com
u/_cybersecurity_ β€” 3 days ago
β–² 4 r/pwnhub

Should companies trust open source build tools?

Researchers traced six major breaches back to compromised LiteLLM and Trivy pipelines, stolen tokens and configurations feeding later extortion. Named victims include Cisco, S&P Global, Telnyx, Mercor, and the European Commission.

The attack spread through everyday developer tools that thousands of companies pull into their own systems without much scrutiny.

What do you think? Is open source tooling worth the risk, or should firms lock down what enters their pipelines?

u/_cybersecurity_ β€” 3 days ago
β–² 57 r/pwnhub

Should you know when police use Flock to search your plate?

A new website lets drivers check whether their license plate has been searched in Flock Safety's camera network.

Flock's automated readers are used by thousands of US police departments and log plates and locations as cars drive past. Supporters call the lookup tool basic transparency, while some law enforcement groups say it could tip off people under investigation.

What do you think? Should drivers see every search run on their plate, or should those records stay closed?

u/_cybersecurity_ β€” 3 days ago
β–² 2 r/pwnhub

How Public Documentation and Default Passwords Expose Critical Infrastructure

Attackers are bypassing complex exploits by using search engines and public manuals to find internet-connected systems left unprotected with default credentials.

Key Points:

  • Broken access control allows unauthorized users to view private data, take over accounts, and access critical systems simply because they were left exposed.
  • Publicly available installation guides and setup manuals often contain default admin credentials that manufacturers fail to remove or change.
  • Search engines and specialized indexing tools like Shodan and ZoomEye allow attackers to locate exposed admin panels at scale.
  • Real-world examples include vulnerable apartment intercoms, hotel entertainment systems, and emergency services dispatch platforms.

The core issue described is broken access control, a failure to properly restrict who can access what. Instead of using sophisticated hacking techniques, attackers rely on the fact that many companies and device manufacturers leave systems online with little to no protection. These systems, ranging from industrial control panels to medical devices, often retain factory-default passwords or weak authentication methods. Because these credentials are frequently listed in publicly accessible installation guides, anyone with basic search skills can find them.

Learn More: Dark Marc

Want to stay updated on the latest cyber threats?

πŸ‘‰ Subscribe to /r/PwnHub

u/_cybersecurity_ β€” 3 days ago
β–² 6 r/pwnhub

Ukraine claims cyberattack disrupted Russian e-commerce giant Wildberries alongside drone strikes

Ukraine's military intelligence alleges a coordinated cyber and kinetic operation severely disrupted the operations of Russia's largest online marketplace, Wildberries, targeting its logistics and payment infrastructure.

Key Points:

  • Ukraine's Main Intelligence Directorate (HUR) and the Cyber Corps hacker group claim to have caused widespread disruption to Wildberries' customer service, contact centers, and payment systems.
  • The cyber operation is described as an amplification of recent kinetic drone strikes that have taken seven of the company's ten largest logistics centers out of operation.
  • Wildberries, often compared to Amazon, is targeted for its role in Russia's logistics network and its reported sale of military equipment, including drone components and body armor.
  • The attack resulted in numerous customer complaints regarding payment failures, though the claims could not be independently verified and Wildberries has not publicly commented.
  • This incident follows a pattern of HUR cooperating with hacker groups to complement major Ukrainian drone or missile strikes on Russian infrastructure.

Ukraine's military intelligence has announced a joint cyber operation with the Cyber Corps hacker group that targeted Wildberries, Russia's largest e-commerce platform. The attack reportedly disrupted critical digital infrastructure, including customer service channels and payment processing, leading to widespread complaints from users unable to complete transactions. This digital assault was designed to compound the physical damage inflicted by recent Ukrainian drone strikes, which have reportedly destroyed over 1.2 million square meters of warehouse space and disabled seven of the retailer's ten largest logistics centers.

The targeting of Wildberries highlights the intersection of commercial infrastructure and military logistics in the ongoing conflict. While the platform primarily sells consumer goods, it has also been reported to sell military equipment such as drone components and body armor. By disrupting both the physical supply chain through kinetic strikes and the digital sales infrastructure through cyberattacks, Ukraine aims to inflict significant economic losses on a company that supports the Russian war effort. This strategy mirrors previous operations where cyber intrusions were used to amplify the impact of physical attacks on Russian state-owned enterprises and government services.

How should international platforms handle the sale of dual-use military goods on their marketplaces during active conflicts?

Learn More: The Record

Want to stay updated on the latest cyber threats?

πŸ‘‰ Subscribe to /r/PwnHub

u/_cybersecurity_ β€” 3 days ago
β–² 2 r/pwnhub

Microsoft Patches Certighost CVE-2026-54121 Allowing Low-Privilege Users to Hijack Domain Controllers

A critical vulnerability in Active Directory Certificate Services allows standard domain users to forge Domain Controller certificates and achieve full domain compromise.

Key Points:

  • Microsoft released a patch on July 14, 2026, for CVE-2026-54121, rated 8.8 on the CVSS scale.
  • The flaw allows low-privileged Active Directory users to coerce Enterprise CAs into issuing valid authentication certificates for Domain Controllers.
  • Attackers use the forged certificate with PKINIT to obtain Ticket Granting Tickets and perform DCSync operations to steal credential material.
  • The attack leverages default Active Directory settings, specifically the MachineAccountQuota, which allows users to create machine accounts.
  • No confirmed exploitation in the wild has been reported as of public disclosure.

Certighost, tracked as CVE-2026-54121, exposes a severe trust validation failure in Microsoft's Active Directory Certificate Services (AD CS). The vulnerability resides in the CA's

reddit.com
u/_cybersecurity_ β€” 3 days ago
β–² 2 r/pwnhub

Philips, GE, and Shell Investigate Clop Ransomware Breach via PTC Vulnerability

Major corporations including Philips, GE, and Shell are investigating data theft claims by the Clop ransomware gang exploiting a critical vulnerability in PTC enterprise software.

Key Points:

  • Philips confirmed a breach of an internal server but stated customer environments were unaffected, while GE and Shell are actively investigating the claims.
  • The attacks exploit CVE-2026-12569, a critical improper input validation flaw in PTC Windchill and FlexPLM platforms used by thousands of global enterprises.
  • CISA and German authorities have mandated emergency patching after confirming the vulnerability is being actively exploited in the wild.
  • The Clop gang claims to have stolen sensitive data such as blueprints and project plans from the targeted companies.

The Clop ransomware group has claimed responsibility for breaching the systems of industrial giants Philips, General Electric, and Shell. Philips has verified that an internal enterprise server was compromised but emphasized that the incident was contained and did not impact customer data. GE and Shell have acknowledged the potential incidents and are working with security teams to assess the scope, though they have not yet confirmed specific data losses. The gang lists these companies among 43 new victims targeted in a coordinated campaign.

The root cause of these intrusions is CVE-2026-12569, a critical vulnerability in PTC Windchill and FlexPLM software, which are widely used in aerospace, defense, automotive, and medtech sectors. The flaw allows attackers to perform improper input validation, leading to unauthorized access. In response to confirmed in-the-wild exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its catalog of known exploited vulnerabilities, requiring federal agencies to patch within three days. German authorities also issued urgent warnings to customers to secure their instances immediately.

How are organizations prioritizing patching for critical vulnerabilities in widely used enterprise software like PTC Windchill?

Learn More: Bleeping Computer

Want to stay updated on the latest cyber threats?

πŸ‘‰ Subscribe to /r/PwnHub

u/_cybersecurity_ β€” 3 days ago
β–² 2 r/pwnhub

French Tax Authority Breach Exposes Data of 678,000 Individuals

The French Ministry of the Economy and Finance confirmed that attackers accessed tax and property records belonging to 678,000 people, marking the latest in a series of cyberattacks on French government agencies.

Key Points:

  • The breach affects 678,000 individuals and professionals, with stolen data including tax income, family quotient, withholding tax rates, and property details.
  • The threat actor, known as ZeroBytes, claimed responsibility on August 12 and listed the stolen database for sale on PwnForums.
  • User IDs and passwords were not compromised, and online accounts remain secure, though sensitive financial and cadastral data was extracted.
  • The French Finance Ministry is notifying affected individuals via email or letter starting next week with details on precautions to take.
  • This incident follows recent breaches at France Travail, the national bank account registry, and the National Agency for Secure Documents.

The French General Directorate of Public Finances (DGFiP) disclosed that an attacker gained access to its systems and extracted sensitive information regarding 678,000 individuals and businesses. The stolen data includes specific tax metrics such as reference tax income, family quotient, and withholding tax rates, as well as business identifiers like company names and SIREN numbers. Additionally, the attacker accessed the Serveur Professionnel de DonnΓ©es Cadastrales (SPDC), a platform linked to the national land registry, though the ministry confirmed that user credentials and online accounts were not compromised.

The breach was identified after the threat actor, operating under the handle ZeroBytes, claimed responsibility on August 12 and attempted to sell the stolen database on the PwnForums hacking forum. In their post, the attacker noted that while they had access to data on roughly 20 million citizens through the property platform, they only managed to extract records for over 2 million people before listing the data for sale. The French Finance Ministry has since shut down access to the affected sensitive information systems and is working with the National Cybersecurity Agency of France (ANSSI) to assess the full impact.

This event is part of a broader pattern of cyberattacks targeting French government entities in recent months. Earlier this year, the national employment agency France Travail was fined €5 million after a breach exposed the personal information of 43 million people, and the Ministry of Finance disclosed a separate breach affecting over 1.2 million user accounts in the national bank account registry. The ministry plans to contact all affected individuals starting next week to inform them of the data accessed and provide necessary security precautions.

How should government agencies balance transparency with security when notifying the public of data breaches involving sensitive financial information?

Learn More: Bleeping Computer

Want to stay updated on the latest cyber threats?

πŸ‘‰ Subscribe to /r/PwnHub

u/_cybersecurity_ β€” 3 days ago