CTI Updates
236 subscribers
159 photos
1 video
3 files
21 links
Updates about all things threat intel & updates about stuffs going on in the cybersec, OSINT, and hacking communities.
Download Telegram
Qilin ransomware group lists Isuzu Motors Thailand (isuzu-motors.co.th) as a victim.
👍1
CTI Updates pinned «Our X account: https://x.com/CTI__Updates»
WorldLeaks ransomware group lists India-based Tata Electronics.

The group claims to have stolen confidential data totaling approximately 4.5 GB across more than 4,000 files, including a small set of passport-related files.

hxxps://worldleaksartrjm3c6vasllvgacbi5u3mgzkluehrzhk2jz4taufuid[.]onion/companies/8541753929/overview
🔥1
🚨 An update on DaMaGeLiB forum:

"Friends of Damaga!

A few words about the current situation and the team’s future plans. As industry media have already reported, gliderexpert disappeared on June 3, 2026, at approximately 5:30 p.m. At the same time, servers with a forum, file sharing service and git went offline. Bad news: gliderexpert was the only one with access to the full forum backup.

Of course, it’s our fault as organizers that we lost backups, but OpSec sites and overall security have always been and remain a priority. We don't know what happened to gliderexpert and we have no way to find out. He doesn’t answer all available contacts, and as the classic said: "Guys, we are no longer family friends and don’t drink beer together."

What's next? We gathered as a team and decided that Damaga’s work needed to be continued. After all, there’s some good news: access to the clearnet domains, XSS parsing, all scripts and plugins that we’ve developed, including cipher code, all remain in the logs.

Guys, we decided to make DaMaGeLiB 2.0! Of course, we will lose almost a year of forum life, but this is not the first time this has happened to Damaga. Moreover, there is an understanding that we will catch up. Despite the critics, we are confident that we have found our niche and the non-profit forum is quite viable.

Once again, it will be useful for everyone to change their nicknames and start all over again. Why not take this wonderful tradition of changing nicknames once a year? You can verify all members of our team using public PGP keys. Learning to verify each other with cryptography together!

At the moment, we ask you to be patient, wait for news from us AND NOT GIVE IN TO PROVOCATIONS. There is no official site at the moment, but honeypots may appear.

All official information will be published only on the following domains: damagelib[.]hk, damagelib[.]tw; in the telegram channel: TG damagelib and in X: damagelib

Have a nice week and a great weekend at the DACHA with barbecue:)

Best regards,
your Damaga"
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Website: darkwebinformer.com
Pricing (Includes Crypto): darkwebinformer.com/pricing
API Access: darkwebinformer.com/api-details
Socials: darkwebinformer.com/socials
Donations: darkwebinformer.com/donations
World Leaks ransomware group has listed India based Reliance Group.
🔥2
ShinyHunters lists two new victims

- Nexstar Media Group
- Ralph Lauren Corporation
👀2
Forwarded from Tor Zireael
Как пишут грузинские издания, грузины совместно с поляками и американцами задержали в Грузии 2 иностранцев (украинец и россиянин), которые ответственны за крипто-обменник AudiA6 и дакрнет форум Dark2Web.

Сейчас вижу обсуждения того, что форум Dark2Web держал AudiA6, это не так, Dark2Web был партнером ауди и менял ему крипту, т.е. по факту Ауди ресселил его услуги под своим брендом)), если это можно так назвать.
👍1
A threat actor is claiming to have full NASA .gov infra control & data dump
2
Qilin ransomware group lists MAVA Healthcare, also known as MAVA Behavioral Health.

MAVA Behavioral Health provides mental health services for children, teens, and adults, including care for anxiety, depression, ADHD, bipolar disorder, PTSD, and other conditions.
a threat actor named Nemoris_Hacking claims they have access to NCIC (National Criminal Information Center) and that they have exfil'd data from correctional facilities across the US
👀2
BrainCipher ransomware group lists The Mint Gaming Hall, a Kentucky-based gambling and casino company.

The group claims to have data on more than 250,000 players.
👀2
kekekeke we got some weekend RaaS drama from Prinzeugen (some weird ass group that just popped up out of nowhere) trolling Ransomware.live
😁3👏1
DNM vendor "daddybiden" is alleged to have been raided by LE
👀2🤔1
Qilin ransomware group lists Taiwan Sintong Machinery Co., Ltd., a Taiwan-based heavy machinery and foundry equipment manufacturer established in 1968.
👍1
Qilin ransomware group lists the Central Bank of Libya, an independent financial institution wholly owned by the Libyan state.
👀2🤷1