What you'll see on this feed:
π Live threats hitting Texas businesses (anonymized, real data)
π¨ CVE-of-the-Week breakdowns for non-security teams
π‘ Ransomware tactics we're seeing in active engagements
β‘ Practical hardening tips for SMBs
Built by senior ethical hackers. β CoreRecon.com
Good artice, #uruguay#pampaleaks πΊπΎ
Posted on June 7, 2026 by Dissent
DataBreaches recently recommended an article by Alberto Daniel Hill about digital security in Argentina, Uruguay, and Mexico. In describing his article, DataBreaches reported:
In one section of his report, Hill calls out a company for allegedly manufacturing cyber threats, which he claims they then use to create public panic through media amplification. With the public panicking over their manufactured threats, the company then sells its monitoring platform to enterprises for $29,000 annually, Hill reports.
That paragraph originally named the company, BCA Ltd., a threat intelligence firm registered in the U.K.
Following publication, DataBreaches was contacted by Mauro Eldritch of BCA Ltd, who requested we remove the firmβs name, claiming that the allegations were untrue and harmful to their reputation. DataBreaches agreed to remove their name from the original post while we investigated the matter in more depth.
Read whole article:
databreaches.net/2026/06/07/β¦
Previous:
databreaches.net/2026/06/01/β¦
CC:
@VECERTRADAR@DailyDarkWeb@BleepinComputer@InfoSecSherpa@CoreRecon@0xToxSec@PacketWalker@DigitalArmyio@MigueGaspar@ElQueNews#PampaLeaks#SamaritanAPI#ArgentinaAPI#ThreatIntel#OSINT#RadicalTransparency#argentina#uruguay
0:10
10
11
1,106
CoreRecon - Cyber Security and IT Services retweeted
Texas businesses get hacked every 39 seconds.
Most won't know for 207 days.
I'm a senior ethical hacker. Here's what I see breaking real companies in 2026 β and what to actually do about it. π§΅
8/ If this thread made you nervous about your own setup β good. That's the first honest step.
We're CoreRecon. Texas-based. We do real adversary simulation, 24/7 SOC, and incident response.
No theater. No checkbox security. Just the truth about your exposure.
β CoreRecon.com
DM open.
9/ One more thing β if you're a Texas business owner reading this and your "security plan" is your insurance policy, that's not a plan, that's a payout. Insurers are denying claims left and right in 2026 for failure to maintain "reasonable controls." Get assessed before the bad day, not after. β CoreRecon.com
Resilience > prevention is finally getting the airtime it deserves. The companies recovering in hours instead of weeks aren't the ones with the biggest security stack β they're the ones who actually tested their IR plan against a live red team in the last 90 days. Tabletop exercises don't count.
Cyber resilience requires more than prevention alone.
A new Triple-I and @Fenix24_dr study examines how #insurers are strengthening recovery readiness and operational resilience as #cybersecurity threats evolve.
Learn more: bit.ly/4um5PKg
Reminder for every CISO reading this: your patch SLA is only as good as your asset inventory. If you can't answer "do we run WebSphere anywhere?" in under 10 minutes, that's the vulnerability β the CVE is just the symptom. Attack surface management is non-negotiable in 2026.
π¨ CVE-2026-8633 β CVSS 9.8/10
ββββββββββ
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application...
Severity: CRITICAL
Patch now.
#cybersecurity#CVE
The skills conversation in cyber keeps missing the obvious: AI didn't kill the analyst β it killed the analyst who only knew one tool. The operators thriving in 2026 are the ones who can read a packet capture, write a detection rule, AND prompt an LLM into a useful triage assistant. Generalist depth wins.
Cybersecurity is evolving fast with AI platforms like Mythos reshaping the game. Heath Renfrow, CISO at Fenix24, breaks down what skills you'll need in the next 5 years to stay ahead.
Donβt miss out on these insights! okt.to/HkvSBo#CyberSecurity#AI#CareerTips
Honest question for IT leaders:
If an attacker breached your network at 2am on a Saturday⦠how would you know?
β’ Would your alerts actually fire, or get buried in noise?
β’ Is anyone watching them at 2am?
β’ Do you have a playbook, or just hope?
β’ When was the last time you tested any of this?
Most orgs can't answer cleanly. That gap is the whole game.
DM us. We pressure-test it for real. β CoreRecon.com
Last week, a Corpus Christi manufacturer asked us to "just run a quick vuln scan."
6 hours in, we'd already found:
β Domain admin creds in a public S3 bucket
β An RDP server exposed to the internet with no MFA
β A legacy ERP system 4 major versions behind
β Backups stored on the same network as production
They thought they were "too small to be a target."
Ransomware groups don't care how big you are. They care how easy you are.
Get a real adversary-simulation assessment. β CoreRecon.com
π¨ CoreRecon Threat Pulse β May 26
What the SOC is watching this week:
β’ Cisco Secure Workload 10.0 β critical flaw, patch now
β’ Drupal CVE-2026-9082 β ~670 unpatched instances in the wild
β’ CERT-In drops the patch window to 12 hours for critical CVEs
β’ ClickFix social-engineering hitting 700 Ghost CMS sites
β’ Rogue AI agents using stolen employee creds (not theoretical anymore)
If any of these are blind spots, talk to us. β CoreRecon.com
Unpopular opinion from someone who breaks into networks for a living:
Your firewall isn't your problem.
Your EDR isn't your problem.
Your SIEM isn't your problem.
Your problem is the 14 forgotten subdomains, the intern's old AWS key on GitHub, and the VPN appliance nobody patched since 2023.
Attackers don't pick locks. They walk through doors you forgot existed.
That's what we hunt. β CoreRecon.com
Every 39 seconds, a business gets hacked.
By the time you finish reading this post, 3 more will be compromised.
Most won't know for 207 days.
If your last pen test was "compliance-driven" instead of adversary-driven, you have a problem you can't see.
We fix that. β CoreRecon.com