惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
博客园 - 司徒正美
Last Week in AI
Last Week in AI
Recent Announcements
Recent Announcements
Y
Y Combinator Blog
博客园 - 聂微东
M
MIT News - Artificial intelligence
博客园_首页
Jina AI
Jina AI
博客园 - 叶小钗
酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hackread – Cybersecurity News, Data Breaches, AI and More
J
Java Code Geeks
F
Fortinet All Blogs
aimingoo的专栏
aimingoo的专栏
小众软件
小众软件
Vercel News
Vercel News
The Cloudflare Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
云风的 BLOG
云风的 BLOG
N
Netflix TechBlog - Medium
B
Blog
Google DeepMind News
Google DeepMind News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

The Register

Shadow IT has given way to shadow AI. Enter AI-BOMs Zed team releases version 1.0 of Rust-built editor: Traditional editor and AI tool Microsoft boss tells investors the company is working to 'win back fans' What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia NASA boss: Make Pluto A Planet Again GitHub says sorry and vows to do better as uptime slips and devs complain Age checks could turn internet into an ID checkpoint, complains Proton CEO Microsoft gives your Word documents an AI co-author you didn’t ask for Datadog digs down into GPU efficiency as AI costs soar If malware via monitor cables is a matter of national security, this might be the gadget for you Thunderbird in hand worth 2 Outlooks as fresh FOSS fave and Firefox arrive Grafana offers AI assistant for free, warns users not to go mad Right to repair champ Framework punts modular 13in laptop with Core Ultra Series 3 France's 'Secure' ID agency probes breach as crooks claim 19M records Scotland Yard can keep using live facial recognition on Londoners, say judges UK tribunal sends £2B claim accusing Microsoft of overcharging for licensing to trial Nation-states want to cause harm, not just steal cash - stop handing your cyber defenses to the cheapest contractor Murder, she wrote: Ex-FBI chief wants some ransomware crims charged with homicide Phone-to-satellite use goes into orbit, growing 25% in 8 months macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets Anthropic bakes memory fixes into Bun 1.1.13 as developers complain of leaks The spaghettified DBMS chart that shows Oracle's crown is slowly slipping Yet another ex-ransomware negotiator admits turning rogue after payoff from crimelords FAA grounds Blue Origin's New Glenn as it probes missed satellite delivery 'mishap' AMD's Ryzen 9 9950X3D2 Dual Edition tested: Gratuitous overkill with a price to match AI-assisted intruders pwned Vercel via OAuth abuse and a pilfered employee account Met police trials snoop tech platform in push to cuff more London shoplifters England's school phone ban gets teeth, just in time to bite no one Adaptavist Group breach spawns imposter emails as ransomware crew claims mega-haul Panasonic creates device-locked QR codes to speed facial biometric capture
Crook claims to leak 'video surveillance footage' of comp...
Connor Jones · 2026-04-21 · via The Register

A Mexican IT infrastructure and digital transformation biz is on clean-up duty after a criminal posted screenshots of what they claimed was company video surveillance footage to a cybercrime forum.

Monterrey-based Be Prime confirmed that it was the victim of a "cybersecurity incident" on Thursday, after the criminal, who used the alias "dylanmarly," made sweeping claims about an attack they claim to have carried out.

Screenshots published by the attacker depicted access to Be Prime's Cisco Meraki Vision panel, which, if true, would have allowed access to live feeds around its clients' offices, including cameras overlooking different teams' workspaces.

Dylanmarly also leaked what they claimed was 12.6 GB worth of data belonging to the company and some of its high-profile clients, which range from energy giants and household retail names to national pharmacies.

In its statement, Be Prime did not address the claims about client data being leaked online, nor did it speak about whether or not it uses Cisco Meraki Vision, which the attacker claims to have accessed. It did, however, admit that it had suffered a cyberattack, which it said it was working with Cisco Talos to remediate.

"In times like these, we believe it's right to speak clearly, humbly, and with complete transparency," the statement posted to LinkedIn reads (machine translated from Spanish). "No organization is immune to cybersecurity incidents, and today it has happened to us. Therefore, we want to communicate the facts, the actions taken, and our position on this situation directly and responsibly.

"Be Prime was the target of a cyberattack, so we immediately activated our containment, mitigation, investigation, and remediation protocols. Based on the information analyzed so far, there is no evidence of any impact on Be Prime's operational continuity or on our clients' operations.

"From the outset of the incident, we implemented a comprehensive response process. To date, the most critical phases of containment and remediation have been executed and completed, and we are continuing with additional strengthening and follow-up actions in communication with the Talos Cybersecurity Intelligence Center."

According to dylanmarly's narrative, shared by Mexican journalist Ignacio Gómez Villaseñor, the attacker gained access to admin accounts because Be Prime failed to implement two-factor authentication.

The attacker also claimed they accessed the Meraki API keys and used them to gain control of thousands of Be Prime network devices, including the security camera feeds of its clients.

Whomever these feeds belonged to, it is not clear why the cameras would have overlooked workspaces, although it is not uncommon for companies to deploy surveillance in commercially sensitive locations, such as server rooms, to assist in criminal investigations.

Be Prime has not explicitly addressed the attacker's specific claims regarding the API keys or the thousands of accessed devices in its public communications, but has warned that defamation lawsuits would be brought against any person or media outlet it believes has disseminated inaccurate or out-of-context information.

The Register asked Be Prime to clarify every aspect of the attacker's claims, identifying which were true and which were false. The company did not respond.

Be Prime went on to say in its public disclosure (machine translated from Spanish) that it wished to thank its clients for their support, and remind them that there is a dedicated contact method the company had shared with them, should they have any queries about the attack.

"We will continue to maintain direct communication with our clients to provide them with reassurance, support, and assistance," Be Prime stated. "We have established and communicated a specific point of contact to address any questions, clarifications, or requests related to this incident."

"We also want to express our sincere gratitude to our clients, partners, collaborators, specialists, and everyone who has given us their support, trust, and backing during this time," it added. 

"We know that a situation of this nature can happen to any organization, and today it has fallen to us to face it. We accept it with responsibility, seriousness, and total commitment. We reiterate that our priority is to protect operations, further strengthen our security capabilities, and respond with action, not just words. We will continue to provide updates through the appropriate channels as the investigations and additional actions underway progress." ®