Hackers Release Second Batch of Stolen Cisco Data

Teilen:
  • Hackers’ Claims: IntelBroker released a second batch of extracted Cisco data, amounting to 4.84 GB, from the October 2024 breach, claiming it is part of a 4.5 TB trove.
  • Leaked Data Contents: The data includes sensitive files such as software artifacts, network configurations, testing logs, cloud server images, and cryptographic signatures, exposing intellectual property and operational insights.
  • Misconfigured Resource Exploitation: The data originated from a misconfigured, public-facing DevHub resource left exposed without password protection, allowing hackers to download it.
  • Cisco’s Response: Cisco acknowledged the incident, stated public access was disabled, and confirmed no servers were breached or sensitive data compromised, though hackers contest this claim.
  • IntelBroker’s Track Record: The hacker, known for breaching Apple, AMD, Europol, and others, highlights ongoing exploitation of misconfigured systems, a persistent issue in cybersecurity.

Hackers have released what they claim to be the second batch of data stolen in the alleged Cisco data incident from October 2024. According to IntelBroker, the hacker behind the breach, the latest leak, published on Christmas Eve on Breach Forums, contains 4.84 GB of data, part of an allegedly stolen 4.5 TB.

IntelBroker on Breach Forums (Screenshot credit: Hackread.com)

As seen by Hackread.com, the leaked data includes a trove of sensitive files, such as proprietary software development artifacts like Java binaries, source code, and application archives; network-related files including Cisco XRv9K virtual router images and configurations; testing logs and scripts; operational data such as Zero Touch Provisioning (ZTP) logs and packages; cloud server disk images; and cryptographic signatures for payment SDKs like Weixin Pay.

Additionally, the leak contains configuration files, internal project archives, and other miscellaneous documents, potentially exposing intellectual property, network configurations, and operational insights.

File tree shared by IntelBroker on Breach Forums (Screenshot credit: Hackread.com)

Background

Notably, the leaked data originates from a misconfigured, public-facing DevHub resource that Cisco reportedly left exposed without password protection or security authentication, enabling the hackers to download the entire dataset in October 2024.

IntelBroker who accessed the misconfigured server claims they managed to extract 4.5TB of information. The first part of the data leak, which included 2.9 GB of files, was published on December 17, 2024.

Die Antwort von Cisco

Cisco acknowledged (PDF) the October 2024 incident and stated that public access was disabled. The company also confirmed that none of its servers were breached and no sensitive data was compromised. However, the hackers claim otherwise, particularly regarding the extracted data.

Regarding the latest leak, Cisco noted on its incident response page that it is aware of the claims made by IntelBroker, asserting that the data published this time also stems from the October 14, 2024, incident.

“On Wednesday, December 25, 2024, at 17:07 EST, the threat actor IntelBroker posted on X about releasing more data. At 17:40 EST, IntelBroker released 4.45 GB of data for free on BreachForums. We have analyzed the post data, and it aligns with the known data set from October 14, 2024.”

Cisco

Intel Broker und frühere Verstöße

Intel Broker ist für aufsehenerregende Datenschutzverletzungen bekannt. Im Juni 2024behauptete der Hacker, in die Apple Inc. eingedrungen zu sein und Quellcode für interne Tools gestohlen zu haben. Derselbe Hacker brüstete sich damit Verletzung der AMD (Advanced Micro Devices, Inc.), und stiehlt Mitarbeiter- und Produktinformationen.

Im Mai 2024Intel Broker hackte Europol, was die Behörde später bestätigte. Einige frühere Datenschutzverletzungen des Hackers sind unten aufgeführt:

  • Technik in Asien
  • Weltraum-Augen
  • Heimdepot
  • Facebook-Marktplatz
  • Personalvermittlungsriese Robert Half
  • Der US-Auftragnehmer Acuity Inc.
  • Internationaler Flughafen Los Angeles
  • Mutmaßliche Verstöße von HSBC und Barclays Bank

Dennoch zeigt das partielle Leck, dass falsch konfigurierte Systeme und ungeschützte Daten weiterhin ausgenutzt werden. Das Ausmaß der Ausbeutung ist offensichtlich, da selbst hochrangige Hacker wie ShinyHunters und Nemesis haben zum Ziel falsch konfigurierte Server und S3-Buckets.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:14 pm, Jan. 16, 2025
Wetter-Symbol 7°C
L: 7° | H: 8°
overcast clouds
Luftfeuchtigkeit: 85 %
Druck: 1035 mb
Wind: 5 mph S
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:58 am
Sonnenuntergang: 4:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 9:00 pm
Wetter-Symbol
7° | 8°°C 0 mm 0% 5 mph 96 % 1035 mb 0 mm/h
Sa. Jan. 18 9:00 pm
Wetter-Symbol
2° | 7°°C 0 mm 0% 4 mph 83 % 1034 mb 0 mm/h
So. Jan. 19 9:00 pm
Wetter-Symbol
2° | 6°°C 0 mm 0% 7 mph 88 % 1023 mb 0 mm/h
Mo. Jan. 20 9:00 pm
Wetter-Symbol
3° | 7°°C 0 mm 0% 7 mph 93 % 1021 mb 0 mm/h
Di. Jan. 21 9:00 pm
Wetter-Symbol
3° | 7°°C 0 mm 0% 3 mph 96 % 1021 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
4° | 6°°C 0 mm 0% 3 mph 89 % 1035 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
4° | 5°°C 0 mm 0% 4 mph 93 % 1034 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 3 mph 96 % 1035 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 3 mph 95 % 1035 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
7° | 7°°C 0 mm 0% 5 mph 77 % 1035 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
7° | 7°°C 0 mm 0% 3 mph 76 % 1034 mb 0 mm/h
Tomorrow 6:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 88 % 1034 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 3 mph 86 % 1034 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€97,024.47
0.34%
Ethereum(ETH)
€3,218.81
-3.40%
XRP(XRP)
€3.19
8.30%
Fesseln(USDT)
€0.97
-0.03%
Solana(SOL)
€205.52
4.36%
Dogecoin(DOGE)
€0.369332
0.97%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000021
-0.58%
Pepe(PEPE)
€0.000017
-2.11%
Peanut das Eichhörnchen(PNUT)
€0.59
-4.85%
Nach oben scrollen