Bob Diachenko πŸ‡ΊπŸ‡¦ (@mayhemdayone) 's Twitter Profile
Bob Diachenko πŸ‡ΊπŸ‡¦

@mayhemdayone

Cyber Threat Intelligence @ securitydiscovery.com, journalist, OSINT | Responsible disclosures | Security consultancy | Contact me: [email protected]

ID: 702497747786715136

linkhttps://linkedin.com/in/vdyachenko calendar_today24-02-2016 14:18:09

1,1K Tweet

18,18K Followers

547 Following

Bob Diachenko πŸ‡ΊπŸ‡¦ (@mayhemdayone) 's Twitter Profile Photo

[NEW REPORT] A popular parental control app exposed its activity logs, leaving users' private data in www for at least a month. Payment info, user PII, tracking details - literally everything. Logstash updated daily, with gigabytes of data, usual story. Infected with readme note.

[NEW REPORT] A popular parental control app exposed its activity logs, leaving users' private data in www for at least a month. Payment info, user PII, tracking details - literally everything. Logstash updated daily, with gigabytes of data, usual story. Infected with readme note.
Bob Diachenko πŸ‡ΊπŸ‡¦ (@mayhemdayone) 's Twitter Profile Photo

Every single data breach ever reported or sold was carefully collected by an unknown actor and left in a misconfigured instance. I'd say it is even bigger than Troy Hunt's HIBP.

Bob Diachenko πŸ‡ΊπŸ‡¦ (@mayhemdayone) 's Twitter Profile Photo

Some random 'Mother of All Breaches' #MOAB stats / interesting info, FYI: 1) the total number of datasets in MOAB = 4145 2) out of it = 1448 have more than 100k records 3) out of it = 601 have more than 1M recs 4) 203 datasets have less than 100 recs 5) instance was updated in

Some random 'Mother of All Breaches' #MOAB stats / interesting info, FYI: 
1) the total number of datasets in MOAB = 4145
2) out of it = 1448 have more than 100k records
3) out of it = 601 have more than 1M recs
4) 203 datasets have less than 100 recs
5) instance was updated in
Cybernews (@cybernews) 's Twitter Profile Photo

β–ͺ️Cybernews researchβ–ͺ️ Football Australia leak exposes players’ details‡️ #Australia #FootballAustralia #dataleak #data #cybersecurity #infosec cybernews.com/security/footb…

Bob Diachenko πŸ‡ΊπŸ‡¦ (@mayhemdayone) 's Twitter Profile Photo

Will add a few details about this one. - Reported it to Football Australia on Nov 22, 2023 - At least one bucket was public - A couple of screenshots with proofs below

Will add a few details about this one. 
- Reported it to Football Australia on Nov 22, 2023
- At least one bucket was public
- A couple of screenshots with proofs below
Bob Diachenko πŸ‡ΊπŸ‡¦ (@mayhemdayone) 's Twitter Profile Photo

[NEW REPORT] Still a lot of UA entities and persons use uCoz resources to host sites. Now we know for sure, and a lot more to investigate... cybernews.com/security/web-h…

Bob Diachenko πŸ‡ΊπŸ‡¦ (@mayhemdayone) 's Twitter Profile Photo

We are working with @cybersecdawg and SΓ©bastien πŸ‡ΊπŸ‡¦ on a project that should help companies quickly respond to the fast-growing issue with API keys leaks. Unfortunately, Shopify, Stripe, PayPal and other industry players underestimate this problem and prefer not to mention numerous