PT-2026-80869 · Bluesky+4 · Bluesky+4
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
RansomLook (affected versions not specified)
Description
RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic verifies if an individual post is private but fails to check the privacy configuration of the associated group or market. This allows victim information from private entities to be automatically published via Rocket.Chat, Mastodon, Bluesky, and e-mail notification channels. Additionally, the public MISP feed (Malware Information Sharing Platform) incorrectly determined privacy using the
groupinfo() function, which only queries the group database and ignores market privacy flags. Unauthorized parties accessing these channels or the feed may obtain sensitive data, including victim names and incident information from privately monitored entities.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bluesky
Misp
Mastodon
Ransomlook
Rocket.Chat