/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Cisco confirms the Yanluowang ransomware group breached its network in May 2022; Yanluowang claimed to have stolen 2.75GB of data, or ~3.1K files including NDAs

Cisco confirmed today that the Yanluowang ransomware group breached its corporate network in late May and that the actor tried … Source: Cisco Talos Intelligence Group .

BleepingComputer Sergiu Gatlan

Discussion

  • @ido_cohen2 @ido_cohen2 on x
    🌐 Yanluowang #Ransomware team add CISCO to the victim's list 🚨 The group shares a TXT file with all the stolen files, a Total of 82G of data, looks bad 🧐 #Yanluowang https://twitter.com/...
  • @craiu Costin Raiu on x
    Kudos to #Cisco for publishing details of their security breach by initial access broker (IAB) with ties to #UNC2447, #Lapsus$ and #Yanluowang. There are so many lessons to be drawn from this highlighted part about the initial access: https://twitter.com/...
  • @vxunderground @vxunderground on x
    Yanluowang ransomware group claims to have breached Cisco. Intel and images provided via @Gi7w0rm https://twitter.com/...
  • @danielcid Daniel Cid on x
    Great details on how Cisco got hacked. 1- Personal Google account of an employee gets compromised - it has password synced enabled. 2- Got all the employee's passwords, including their Cisco VPN credentials. 3- Phishing to accept 2FA 4- They are in https://blog.talosintelligence.…
  • @eastdakota Matthew Prince on x
    These are getting more scary. Hard keys and a solution like @Cloudflare Access are the only long term protection that will stay ahead of the attackers. https://blog.talosintelligence.com/ ...
  • @pogowasright Dissent Doe, PhD on x
    Wow. Yanluowang claims to have hit @CISCO and has posted a file directory. Nothing from @CISCO on their TL or on their website home page at this point.
  • @racheltobac Rachel Tobac on x
    Social engineering in the news big time this week. Cisco hack described in the blog below today featured the attacker voice phishing (attacking by talking over a phone call) and impersonating trusted orgs to convince the target to accept the MFA push. https://blog.talosintelligen…
  • @lawrenceabrams Lawrence Abrams on x
    Cisco hacked by the Yanluowang ransomware gang - no ransomware deployed, but 2.8GB data allegedly stolen. https://twitter.com/...