๐Ÿ”ช Slice For Life ๐Ÿ”ช
3.39K subscribers
826 photos
2 videos
693 links
Download Telegram
โ€ผ๏ธ๐Ÿ‡ง๐Ÿ‡ท A threat actor is allegedly selling full access to a Brazilian Police investigation panel and law enforcement webmail from Sรฃo Paulo's Civil Police (Polรญcia Civil do Estado de Sรฃo Paulo).

The access reportedly comes bundled with an internal VPN, a functional policiacivil.sp.gov.br webmail, bypass, and a full investigation panel with lookups for Receita Federal tax records, national vehicle queries (DETRAN/RENAVAM), PIX transaction data, criminal records, court cases, driver licenses, and integrated criminal/intel databases (SINESP, INFOSEG).

The threat actor notes the institutional email is also used for law enforcement communications.
โ€ผ๏ธ๐Ÿ‡ฎ๐Ÿ‡น A threat actor is allegedly selling full network access to a cargo bike retailer based in Milan, Italy.

The access includes SSH and cPanel with full control privileges, containing mail and database access. The threat actor also claims to have n8n admin and Brevo API keys.

Screenshots show the cPanel dashboard, file system directory structure with WordPress installations and mail folders, and database records showing shop orders in EUR.

Price: $2,000.
โ€ผ๏ธ๐Ÿ‡ฎ๐Ÿ‡ฑ Shlomo Insurance has fallen victim to Kill Security Ransomware
โ€ผ๏ธ๐Ÿ‡ช๐Ÿ‡ธ A threat actor is allegedly selling a Spanish IBAN leads database containing 8,145,987 lines.

The sample data includes full names, addresses, emails, phone numbers, IBAN numbers, and associated bank names from major Spanish financial institutions.
Cyberattack Alert
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Victim: Stryker
Domain: stryker.com

Country: ๐Ÿ‡ฎ๐Ÿ‡ช IE
Date: Mar 10th, 2026

Summary:
A group of hackers supported by Iran, identified as Handala, is suspected of causing a sophisticated cyberattack paralyzing the global operations of the American medical technology company Stryker. This attack, which occurred last night, resulted in the closure of all the company's computer systems, affecting its sites in Europe, Asia and the United States, and forcing the removal of data on its 4,000 employees in Cork. Although the root cause has not yet been confirmed, the incident has resulted in a total cessation of the company's activities, which employs more than 56,000 people in 61 countries.

Source: https://www.irishmirror.ie/news/irish-news/stryker-cyber-attack-thousands-irish-36850017.amp
โ€ผ๏ธ DOJ Press Release
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

DOJ, VA Sign Agreement to Improve Care for Nationโ€™s Most Vulnerable Veterans

Full Press Release โ†’ justice.gov

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
๐Ÿ•ต๏ธ Dark Web Informer โ€ข DOJ Monitor
โ€ผ๏ธ๐ŸŒ A threat actor is allegedly selling a bundle of 19 corporate accesses targeting companies across Spain, UK, Brazil, Guatemala, Mexico, and India.

The access reportedly includes GitLab/GitHub repos and tokens, SSO/IdP configurations (Okta, Azure AD, OpenAM), CI/CD secrets, Jira/Confluence admin, AWS Lambda with payment code, vulnerability data, Slack webhooks, and customer databases.

Targets range from large enterprises (โ‚ฌ2Bโ€“โ‚ฌ38B revenue in retail, insurance, banking) to mid-sized firms (โ‚ฌ15Mโ€“โ‚ฌ450M in IT, SaaS, fintech) and smaller cybersecurity companies. Available as a package or individually.
โ€ผ๏ธ๐Ÿ‡ช๐Ÿ‡ธ Colegio Retamar has fallen victim to Qilin Ransomware
โ€ผ๏ธ DOJ Press Release
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Aetna Agrees to Pay $117.7 Million to Resolve False Claims Act Allegations

Full Press Release โ†’ justice.gov

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”
๐Ÿ•ต๏ธ Dark Web Informer โ€ข DOJ Monitor
โš ๏ธ FBI Watchdog - DNS Change (SOA) โš ๏ธ
๐Ÿ”— DarkWebInformer.com - Cyber Threat Intelligence

Domain: thesecure.biz
Record Type: DNS Change (SOA)
Time Detected: 2026-03-11 16:25:00 UTC

Previous Records:
edna.ns.cloudflare.com. dns.cloudflare.com. 2397922649 10000 2400 604800 1800

New Records:
edna.ns.cloudflare.com. dns.cloudflare.com. 2398729597 10000 2400 604800 1800
โš ๏ธ FBI Watchdog - DNS Change (SOA) โš ๏ธ
๐Ÿ”— DarkWebInformer.com - Cyber Threat Intelligence

Domain: ps4pkg.com
Record Type: DNS Change (SOA)
Time Detected: 2026-03-11 17:13:40 UTC

Previous Records:
ns1.fbi.seized.gov. dns.cloudflare.com. 2398103745 10000 2400 604800 1800

New Records:
ns1.fbi.seized.gov. dns.cloudflare.com. 2398734186 10000 2400 604800 1800
โ€ผ๏ธ๐Ÿ‡บ๐Ÿ‡ธ Stryker is currently offline due to a wiper malware attack by Handala.

https://x.com/BleepinComputer/status/2031782605616492593

Edit: Flag was set to Israel, should have been USA
๐Ÿ”ฅ2
Do you want me to delete the DOJ articles that are not cyber related when I see them? Currently all of the articles come in unfiltered rather than by keyword so nothing is missed.
Anonymous Poll
70%
Yes
18%
No
11%
Show Results
โ€ผ๏ธ๐Ÿ‡บ๐Ÿ‡ธ Handala has confirmed an attack on Verifone, a global payments technology company.

They also have a message on their attack on Stryker.
โค2
โš ๏ธ FBI Watchdog - DNS Change (SOA) โš ๏ธ
๐Ÿ”— DarkWebInformer.com - Cyber Threat Intelligence

Domain: ps5pkg.net
Record Type: DNS Change (SOA)
Time Detected: 2026-03-11 19:17:07 UTC

Previous Records:
ns1.fbi.seized.gov. dns.cloudflare.com. 2398068487 10000 2400 604800 1800

New Records:
ns1.fbi.seized.gov. dns.cloudflare.com. 2398741935 10000 2400 604800 1800
โ€ผ๏ธ๐Ÿ‡บ๐Ÿ‡ธ Coinbase Cartel Claims Staples as a victim
Cybersecurity Incident Disclosure

Wed, 11 Mar 2026 17:24:57 EDT
A cybersecurity incident has been disclosed by STRYKER CORP, Inc CIK: 0000310764, Ticker: $SYK.

View SEC Filing