ShinyHunters publicly boasted about breaching ReliaQuest, but the claims appear to be mostly hot air.
In this episode of "What We Missed," Dark Reading's Rob Wright and Alex Culafi discuss some of the recent news events and topics that didn't make it into the publication, starting with ShinyHunters' taunting of ReliaQuest.
Last week, the cybersecurity vendor warned of a "widespread ShinyHunters campaign" using spoofed company domains in a now-deleted post on social media platform X. A account associated with ShinyHunters replied with a post that said "Who's hunting who?" and contained screenshots that appear to be a compromised Okta account for a ReliaQuest employee. The notorious threat group also added ReliaQuest to its data leak site (though the listing only contained a few screenshots).
Later that day, ReliaQuest disclosed that a threat actor successfully vished an employee who entered their credentials into a fake single sign-on (SSO) page. However, the vendor said the attacker has view-only access to its SSO portal, and all attempts to access applications or move laterally were thwarted. So was ReliaQuest really breached?
Related:Offensive Security Investments Surge as AI Threats Increase
Also discussed on this episode: New research from Palo Alto Networks' Unit 42 indicates that AI-generated malware isn't a prevalent threat — at least, not yet; and two alleged members of the infamous TeamPCP gang were identified and arrested.
What We Missed With Rob Wright & Alex Culafi: Full Transcript
Dark Reading's Rob Wright: Hello, I'm Rob Wright with Dark Reading.
Dark Reading's Alex Culafi: And I'm Alex Culafi with Dark Reading.
DR's Rob Wright: And this is "What We Missed." This is a discussion about some of the stories that we didn't get a chance to cover, some of the recent stories, in the pages of Dark Reading — pages, pods, and videos of Dark Reading. And first up, we have Shiny Hunters breaches ReliaQuest — or did they? This was an interesting story, Alex.
... continue reading