Attackers Offered $25,000 for Access to CrowdStrike
Attackers Offered $25,000 for Access to CrowdStrike#### CrowdStrike insider caught selling access for $25K, WhatsApp API flaw exposing billions of users, Grafana’s critical CVSS 10.0 vulnerability, and a massive 2.3 TB breach hitting Italian railways.

American security firm CrowdStrike discovered and terminated an employee in October who shared screenshots of internal systems with the hacking group “Scattered Lapsus$ Hunters” (an alliance of Lapsus$, ShinyHunters, and Scattered Spider members).
The hacking group claims they offered the insider $25,000 for access and also obtained SSO cookies from them. However, CrowdStrike states in their announcement that by the time the cookies were used, the insider’s access had already been revoked. The company confirmed that no client data was compromised and that the leak was limited to screenshots only.
The attackers also attempted to purchase internal company reports but received none.
The hackers also claim they gained access to CrowdStrike through an alleged vulnerability at CRM company Gainsight, which serves Salesforce application customers. CrowdStrike denies this version of events.
CrowdStrike used the incident to emphasize the importance of strong insider threat detection mechanisms. The company has strengthened internal activity monitoring and implemented additional control processes to minimize the risk of similar incidents recurring.
Images of internal systems appeared on the hacking group’s Telegram account.


WhatsApp API Flaw Enabled Data Collection on Billions of Accounts
Researchers discovered a critical vulnerability in WhatsApp’s API that allowed exploitation of the contact-discovery feature through insufficient rate limiting, enabling the collection of information on 3.5 billion accounts.
Within a few days, they managed to send over 100 million queries per hour, which WhatsApp did not restrict in any way.
Beyond confirming whether a phone number was active on WhatsApp, the researchers were able to obtain profile pictures, statuses, and information about connected devices.
The researchers further warn that any party could collect data using the same method and abuse it for spam, phishing, or targeted attacks. For example, government authorities in countries where WhatsApp is blocked could use this to monitor their citizens (2.3 million active accounts were detected in China).
A similar issue existed on WhatsApp back in 2017, but Meta did not implement stronger API call restrictions. They only implemented protections now under pressure from the researchers.
Grafana Patches Critical Vulnerability with CVSS Score of 10
Grafana recently released security updates addressing an extremely severe vulnerability tracked as CVE-2025–41115 with a CVSS score of 10.0. The flaw affects the SCIM (System for Cross-domain Identity Management) component, which is used for automating user management.
Under certain conditions, the vulnerability allows an attacker or compromised SCIM client to create a user with a specific numeric externalId. This value can subsequently overwrite an internal user ID, leading to impersonation or privilege escalation within the system.
Two conditions must be met for successful exploitation: enableSCIM must be set to true, and the user_sync_enabled option must be enabled in the [auth.scim] section. Affected versions are Grafana Enterprise 12.0.0 through 12.2.1.
The flaw lies in Grafana mapping the SCIM externalId directly to the internal user.uid. If an attacker provides a numeric value, the newly created user may be treated as an existing internal account, such as an administrator, opening the door to abuse.
The vulnerability was discovered internally during an audit and testing on November 4, 2025, and subsequently patched in the following versions: Grafana Enterprise 12.0.6+security-01, 12.1.3+security-01, 12.2.1+security-01, and 12.3.0.
2.3 TB Data Leak from Italian Railways
A hacker claims to have obtained 2.3 TB of data from Italian group Almaviva, an IT services provider for national railway operator FS Italiane Group.
According to experts, the leaked data includes internal files, technical documentation, public sector contracts, personnel archives, accounting data, and complete databases of several companies within the FS group.
Almaviva confirmed the incident and stated that the attack was detected and isolated thanks to security monitoring services.
It remains unclear whether the leaked data includes passenger information or whether the incident affects other clients beyond the FS group.