[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f78JCM7a1G4eioZIbsEkLAhWk7jgY0jIsTOXHpmFT7hs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"cb9b587d-3a85-47e3-a36a-643acfd62d09","lapsus-group-establishes-new-command-infrastructure","b49b800e-f8a6-4af4-9aa1-24a9a63d4949","LAPSUS$ Group Establishes New Command Infrastructure","The LAPSUS$ hacking group has established a new clearnet domain (lapsus[.]bz) for their operations, demonstrating how threat actors adapt and evolve their infrastructure to evade detection. This development highlights the importance of continuous threat intelligence monitoring and proactive blocking of known malicious domains. Organizations must maintain vigilance against this group's sophisticated social engineering and insider threat tactics. The emergence of new infrastructure domains signals potential upcoming attack campaigns targeting high-value organizations.","**Immediate actions:**\n- Block the new LAPSUS$ domain (lapsus[.]bz) in DNS filtering and web security gateways\n- Review and update threat intelligence feeds to include latest LAPSUS$ indicators of compromise\n- Alert security teams to monitor for LAPSUS$ tactics, techniques, and procedures (TTPs)\n\n**Long-term improvements:**\n- Implement automated threat intelligence integration with security tools for real-time blocking\n- Establish continuous monitoring of dark web and clearnet sites for threat actor communications\n- Develop incident response playbooks specific to LAPSUS$ group tactics including social engineering and insider threats\n\n**Detection measures:**\n- Deploy enhanced monitoring for privileged account access and multi-factor authentication bypass attempts\n- Monitor for suspicious communications to known threat actor domains and infrastructure",[12,13,14,15,16],"CIS Control 13","NIST IR-4","NIST IR-8","CIS Control 6","NIST SI-4","published","2026-06-12T19:20:17.443653+00:00","2026-06-12T19:20:17.073+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fx.com\u002FDarkWebInformer\u002Fstatus\u002F2065502801728307639","new-lapsus-group-clearnet-domain-lapsus-bz-https-t-co-zsm0rf8lux-d24728","🚨 New LAPSUS$ Group clearnet domain:\n\nlapsus[.]bz https:\u002F\u002Ft.co\u002FzSM0rF8LuX",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":32,"name":33,"slug":34,"description":35,"color":36},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",[]]