CTI Updates
236 subscribers
159 photos
1 video
3 files
21 links
Updates about all things threat intel & updates about stuffs going on in the cybersec, OSINT, and hacking communities.
Download Telegram
Akira ransomware group lists three new victims on its DLS: Oaks Park, Kennon Worldwide, and T/CCI Manufacturing.

The group claims it will soon publish 10 GB of data from Oaks Park, 30 GB from Kennon Worldwide, and 35 GB from T/CCI Manufacturing. Alleged data includes employee information, payment details, contracts, NDAs, client information, financials, and confidential files.
👍2
Krybit ransomware group lists Shantou Huashan Electronic Devices Co., Ltd. (SHEDCL), a Chinese manufacturer of semiconductor devices and electronic components based in Shantou, Guangdong Province.

The company produces and distributes components including voltage regulators, transistors, Schottky diodes, wafers, capacitors, inductors, and resistors.
👍1
Akira ransomware group lists HRC Sicherheitsdienste, a family-owned security service provider with more than 45 years of experience.

The group claims it will soon publish 24 GB of corporate data, including employee information, German passports and IDs, credit cards, payment details, financials, agreements, contracts, and confidential documents.
👍1
Qilin ransomware group lists Isuzu Motors Thailand (isuzu-motors.co.th) as a victim.
👍1
CTI Updates pinned «Our X account: https://x.com/CTI__Updates»
WorldLeaks ransomware group lists India-based Tata Electronics.

The group claims to have stolen confidential data totaling approximately 4.5 GB across more than 4,000 files, including a small set of passport-related files.

hxxps://worldleaksartrjm3c6vasllvgacbi5u3mgzkluehrzhk2jz4taufuid[.]onion/companies/8541753929/overview
🔥1
🚨 An update on DaMaGeLiB forum:

"Friends of Damaga!

A few words about the current situation and the team’s future plans. As industry media have already reported, gliderexpert disappeared on June 3, 2026, at approximately 5:30 p.m. At the same time, servers with a forum, file sharing service and git went offline. Bad news: gliderexpert was the only one with access to the full forum backup.

Of course, it’s our fault as organizers that we lost backups, but OpSec sites and overall security have always been and remain a priority. We don't know what happened to gliderexpert and we have no way to find out. He doesn’t answer all available contacts, and as the classic said: "Guys, we are no longer family friends and don’t drink beer together."

What's next? We gathered as a team and decided that Damaga’s work needed to be continued. After all, there’s some good news: access to the clearnet domains, XSS parsing, all scripts and plugins that we’ve developed, including cipher code, all remain in the logs.

Guys, we decided to make DaMaGeLiB 2.0! Of course, we will lose almost a year of forum life, but this is not the first time this has happened to Damaga. Moreover, there is an understanding that we will catch up. Despite the critics, we are confident that we have found our niche and the non-profit forum is quite viable.

Once again, it will be useful for everyone to change their nicknames and start all over again. Why not take this wonderful tradition of changing nicknames once a year? You can verify all members of our team using public PGP keys. Learning to verify each other with cryptography together!

At the moment, we ask you to be patient, wait for news from us AND NOT GIVE IN TO PROVOCATIONS. There is no official site at the moment, but honeypots may appear.

All official information will be published only on the following domains: damagelib[.]hk, damagelib[.]tw; in the telegram channel: TG damagelib and in X: damagelib

Have a nice week and a great weekend at the DACHA with barbecue:)

Best regards,
your Damaga"
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
World Leaks ransomware group has listed India based Reliance Group.
🔥2
ShinyHunters lists two new victims

- Nexstar Media Group
- Ralph Lauren Corporation
👀2
Forwarded from Tor Zireael
Как пишут грузинские издания, грузины совместно с поляками и американцами задержали в Грузии 2 иностранцев (украинец и россиянин), которые ответственны за крипто-обменник AudiA6 и дакрнет форум Dark2Web.

Сейчас вижу обсуждения того, что форум Dark2Web держал AudiA6, это не так, Dark2Web был партнером ауди и менял ему крипту, т.е. по факту Ауди ресселил его услуги под своим брендом)), если это можно так назвать.
👍1
A threat actor is claiming to have full NASA .gov infra control & data dump
2
Qilin ransomware group lists MAVA Healthcare, also known as MAVA Behavioral Health.

MAVA Behavioral Health provides mental health services for children, teens, and adults, including care for anxiety, depression, ADHD, bipolar disorder, PTSD, and other conditions.
a threat actor named Nemoris_Hacking claims they have access to NCIC (National Criminal Information Center) and that they have exfil'd data from correctional facilities across the US
👀2
BrainCipher ransomware group lists The Mint Gaming Hall, a Kentucky-based gambling and casino company.

The group claims to have data on more than 250,000 players.
👀2