π¨STORM Windows info stealer advertised for $350 per month
A forum actor is advertising STORM, a Windows-based information stealer written in C++ and marketed with uniquely compiled builds, obfuscation, encrypted delivery, and a web-based control panel.
The listing claims the malware can extract browser data, passwords, cookies, cryptocurrency wallets, password manager data, messenger sessions, Discord tokens, files, screenshots, and detailed system information. It also includes a configurable loader capable of downloading and executing additional EXE, DLL, and PowerShell files.
The standard license is priced at $350 per month, while a team license with 100 user slots and 200 build slots costs $700 per month. The seller states that the malware will not target systems located in Russia or the CIS.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor is advertising STORM, a Windows-based information stealer written in C++ and marketed with uniquely compiled builds, obfuscation, encrypted delivery, and a web-based control panel.
The listing claims the malware can extract browser data, passwords, cookies, cryptocurrency wallets, password manager data, messenger sessions, Discord tokens, files, screenshots, and detailed system information. It also includes a configurable loader capable of downloading and executing additional EXE, DLL, and PowerShell files.
The standard license is priced at $350 per month, while a team license with 100 user slots and 200 build slots costs $700 per month. The seller states that the malware will not target systems located in Russia or the CIS.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
βΌοΈ New Dark Web Informer Blog Post!
Title: Romanian Land Registry Agency ANCPI Allegedly Breached and Hit With Ransomware, Citizen Data and Source Code for Sale
Link: https://darkwebinformer.com/romanian-land-registry-agency-ancpi-allegedly-breached-and-hit-with-ransomware-citizen-data-and-source-code-for-sale/
Title: Romanian Land Registry Agency ANCPI Allegedly Breached and Hit With Ransomware, Citizen Data and Source Code for Sale
Link: https://darkwebinformer.com/romanian-land-registry-agency-ancpi-allegedly-breached-and-hit-with-ransomware-citizen-data-and-source-code-for-sale/
Dark Web Informer
Romanian Land Registry Agency ANCPI Allegedly Breached and Hit With Ransomware, Citizen Data and Source Code for Sale
A threat actor using the alias bytetobreach is advertising the sale of data they claim to have stolen from ANCPI, Romania's National Agency for Cadastre and Land Registration, which maintains the country's land-registry and property records.
βΌοΈ New Dark Web Informer Blog Post!
Title: Unpatched Cursor Zero-Day Lets Malicious Git Repositories Trigger Windows Code Execution
Link: https://darkwebinformer.com/unpatched-cursor-zero-day-lets-malicious-git-repositories-trigger-windows-code-execution/
Title: Unpatched Cursor Zero-Day Lets Malicious Git Repositories Trigger Windows Code Execution
Link: https://darkwebinformer.com/unpatched-cursor-zero-day-lets-malicious-git-repositories-trigger-windows-code-execution/
Dark Web Informer
Unpatched Cursor Zero-Day Lets Malicious Git Repositories Trigger Windows Code Execution
Security researchers have disclosed an unpatched Cursor vulnerability that can allow a malicious Git repository to execute attacker-controlled code automatically when opened on a Windows system.
FBI Watchdog alerts are moving back to: https://t.me/FBI_Watchdog
Telegram
FBI Watchdog Alerts by Dark Web Informer
Website: darkwebinformer.com
Website Pricing (Includes Crypto): darkwebinformer.com/pricing
Socials: darkwebinformer.com/socials
API: https://darkwebinformer.com/api-details
Main: https://t.me/SliceForLifeee
Website Pricing (Includes Crypto): darkwebinformer.com/pricing
Socials: darkwebinformer.com/socials
API: https://darkwebinformer.com/api-details
Main: https://t.me/SliceForLifeee
π¨π¦πΊ Bendigo Law Courts dataset allegedly leaked
A forum actor claims to have leaked more than 28,600 records allegedly obtained from Bendigo Law Courts, a multi-jurisdictional courthouse complex serving Bendigo and the Loddon-Mallee region in Victoria, Australia.
The dataset is described as containing court booking and hearing information across the Magistratesβ Court, Childrenβs Court, County Court, Supreme Court, Victorian Civil and Administrative Tribunal, and federal courts.
The allegedly exposed information includes case titles and numbers, hearing dates and times, courtrooms, divisions, participant names and email addresses, dates of birth, custody locations, agency details, notes, Webex meeting links, meeting numbers, passwords, host information, and PINs.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have leaked more than 28,600 records allegedly obtained from Bendigo Law Courts, a multi-jurisdictional courthouse complex serving Bendigo and the Loddon-Mallee region in Victoria, Australia.
The dataset is described as containing court booking and hearing information across the Magistratesβ Court, Childrenβs Court, County Court, Supreme Court, Victorian Civil and Administrative Tribunal, and federal courts.
The allegedly exposed information includes case titles and numbers, hearing dates and times, courtrooms, divisions, participant names and email addresses, dates of birth, custody locations, agency details, notes, Webex meeting links, meeting numbers, passwords, host information, and PINs.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
πͺ Slice For Life - Part 2 πͺ
FBI Watchdog alerts are moving back to: https://t.me/FBI_Watchdog
CVEs is back online to: https://t.me/DWI_CVE_Alerts
Telegram
Dark Web Informer - CVE Alerts
Website: darkwebinformer.com
Website Pricing (Includes Crypto): darkwebinformer.com/pricing
Socials: darkwebinformer.com/socials
API: https://darkwebinformer.com/api-details
Main: https://t.me/SliceForLifeee
Website Pricing (Includes Crypto): darkwebinformer.com/pricing
Socials: darkwebinformer.com/socials
API: https://darkwebinformer.com/api-details
Main: https://t.me/SliceForLifeee
π₯ Discordo: A lightweight, secure, and feature-rich Discord terminal (TUI) client made in Go.
GitHub: https://github.com/ayn2op/discordo/
GitHub: https://github.com/ayn2op/discordo/
π₯2
π¨πͺπΈ Spanish Football Federation coaching academy data allegedly exposed
A forum actor claims to have accessed data tied to the Royal Spanish Football Federationβs coaching academy after discovering an allegedly misconfigured Firebase Storage bucket and Realtime Database.
The listing says 504 files totaling 182MB were publicly downloadable without authentication, while 113,681 authentication user IDs could be enumerated from the database. The actor says exposed files were linked to 16 users.
The allegedly exposed material includes front and back scans of Spanish DNI identity cards, profile photographs, invoices, personal images, course materials, administrative documents, training slides, screenshots, and a video.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have accessed data tied to the Royal Spanish Football Federationβs coaching academy after discovering an allegedly misconfigured Firebase Storage bucket and Realtime Database.
The listing says 504 files totaling 182MB were publicly downloadable without authentication, while 113,681 authentication user IDs could be enumerated from the database. The actor says exposed files were linked to 16 users.
The allegedly exposed material includes front and back scans of Spanish DNI identity cards, profile photographs, invoices, personal images, course materials, administrative documents, training slides, screenshots, and a video.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
π2π₯1
βΌοΈ CVE-2026-23744: MCPJam Inspector RCE Exploit
GitHub: https://github.com/CerberusMrXi/CVE-2026-23744-MCPJam-Exploit
Features:
βͺοΈMulti-payload Support: Includes Bash, Python, Netcat, Perl, PHP, and Base64 payloads.
βͺοΈCommand Execution: Execute commands on the target system with output capture.
βͺοΈTarget Scanning: Scan multiple targets with configurable rate limiting.
βͺοΈSession Management: Persistent session management for ongoing testing.
βͺοΈProxy Support: Integrate with proxies for anonymous or routed traffic.
βͺοΈTarget Fingerprinting: Identify target system characteristics.
βͺοΈAuto-listener Setup: Automatically configure listeners for reverse shells.
GitHub: https://github.com/CerberusMrXi/CVE-2026-23744-MCPJam-Exploit
Features:
βͺοΈMulti-payload Support: Includes Bash, Python, Netcat, Perl, PHP, and Base64 payloads.
βͺοΈCommand Execution: Execute commands on the target system with output capture.
βͺοΈTarget Scanning: Scan multiple targets with configurable rate limiting.
βͺοΈSession Management: Persistent session management for ongoing testing.
βͺοΈProxy Support: Integrate with proxies for anonymous or routed traffic.
βͺοΈTarget Fingerprinting: Identify target system characteristics.
βͺοΈAuto-listener Setup: Automatically configure listeners for reverse shells.
βΌοΈπΊπΈ DragonForce Ransomware names 4 victims
πΊπΈ Heritage Mechanical LLC - Maryland-based mechanical contractor providing commercial plumbing, HVAC, and steamfitting services.
πΊπΈ Stephens Precision - Vermont-based precision manufacturer specializing in machined assemblies, components, and tooling.
πΊπΈ Shillen MacKall & Seldon - Law firm representing personal injury clients across Vermont, New Hampshire, and Florida.
πΊπΈ Hughes Atwood & Mullaly PLLC - New Hampshire-based full-service law firm serving individuals, businesses, and institutions.
πΊπΈ Heritage Mechanical LLC - Maryland-based mechanical contractor providing commercial plumbing, HVAC, and steamfitting services.
πΊπΈ Stephens Precision - Vermont-based precision manufacturer specializing in machined assemblies, components, and tooling.
πΊπΈ Shillen MacKall & Seldon - Law firm representing personal injury clients across Vermont, New Hampshire, and Florida.
πΊπΈ Hughes Atwood & Mullaly PLLC - New Hampshire-based full-service law firm serving individuals, businesses, and institutions.
To those asking what happened to my GitHub... I simply just made everything private over a week ago. I'm no longer interested in using the application in general.
However, I will be using a different tool so you can still enjoy everything I've come out with. Probably will be done this weekend, I just need to find time.
Attaching a screenshot just to show nothing is gone.
However, I will be using a different tool so you can still enjoy everything I've come out with. Probably will be done this weekend, I just need to find time.
Attaching a screenshot just to show nothing is gone.
β€3
This media is not supported in your browser
VIEW IN TELEGRAM
Microsoft fixed an Age of Empires RCE from yesterdayβs Patch Tuesday (CVE-2026-50663). Here is an example of how it was done.
Credit: https://x.com/rdjgr/status/2077331427549421918
Credit: https://x.com/rdjgr/status/2077331427549421918
π₯2
π¨π«π· DELKO customer dataset allegedly compromised
A forum actor claims to have compromised an internal appointment-booking tool belonging to DELKO, a French vehicle repair and maintenance chain operating more than 160 garages across France.
The actor says information belonging to 450,092 customers was scraped from the system. A sample containing customer and vehicle records was published with the post.
The allegedly exposed information includes customer IDs, names, email addresses, phone numbers, vehicle registration numbers, account creation dates, appointment dates, service types, transaction amounts, and detailed descriptions of vehicle repairs or maintenance.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have compromised an internal appointment-booking tool belonging to DELKO, a French vehicle repair and maintenance chain operating more than 160 garages across France.
The actor says information belonging to 450,092 customers was scraped from the system. A sample containing customer and vehicle records was published with the post.
The allegedly exposed information includes customer IDs, names, email addresses, phone numbers, vehicle registration numbers, account creation dates, appointment dates, service types, transaction amounts, and detailed descriptions of vehicle repairs or maintenance.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
π¨π¦π· Argentine government portal credentials allegedly listed for sale
A forum actor claims to be selling a bundle of working login credentials for 21 government platforms across Argentina.
The seller describes the accounts as active and verified, claiming they provide access to restricted dashboards, administrative panels, internal communications, documents, notifications, workflows, and record-management functions. The credentials are said to have remained active for at least 30 days.
The advertised platforms include judicial, tax, vehicle registration, municipal, human resources, social security, and other government services.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to be selling a bundle of working login credentials for 21 government platforms across Argentina.
The seller describes the accounts as active and verified, claiming they provide access to restricted dashboards, administrative panels, internal communications, documents, notifications, workflows, and record-management functions. The credentials are said to have remained active for at least 30 days.
The advertised platforms include judicial, tax, vehicle registration, municipal, human resources, social security, and other government services.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
π¨ DarkMatter ransomware operation advertises affiliate program
A forum actor is advertising DarkMatter (not to be confused with one of the world's largest darknet markets), a newly introduced ransomware operation targeting small, medium, and large enterprises while claiming to exclude healthcare organizations and entities located in the CIS region.
The listing says CIS-based affiliates must pay a $250 entry fee, while non-CIS affiliates are charged $500 in Bitcoin or Monero. The operators are seeking a limited number of Russian-speaking partners and claim average affiliate payouts of approximately $70,000.
The advertised Windows ransomware supports multithreaded encryption, Active Directory integration, network propagation, credential dumping, security-tool disruption, event-log clearing, virtual machine detection, ESXi targeting, encrypted TOR-based victim portals, and configurable ransom notes. The operators also claim to provide custom builds, dedicated infrastructure, encrypted communications, and real-time reporting.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor is advertising DarkMatter (not to be confused with one of the world's largest darknet markets), a newly introduced ransomware operation targeting small, medium, and large enterprises while claiming to exclude healthcare organizations and entities located in the CIS region.
The listing says CIS-based affiliates must pay a $250 entry fee, while non-CIS affiliates are charged $500 in Bitcoin or Monero. The operators are seeking a limited number of Russian-speaking partners and claim average affiliate payouts of approximately $70,000.
The advertised Windows ransomware supports multithreaded encryption, Active Directory integration, network propagation, credential dumping, security-tool disruption, event-log clearing, virtual machine detection, ESXi targeting, encrypted TOR-based victim portals, and configurable ransom notes. The operators also claim to provide custom builds, dedicated infrastructure, encrypted communications, and real-time reporting.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
π¨π«π· Actiale dataset allegedly leaked
A forum actor claims to have leaked data allegedly obtained from Actiale, a French company specializing in quality management, food safety, regulatory compliance, merchandising, and operational support services.
The listing advertises a 59MB JSON archive containing 229,978 records tied to 12,203 individuals. The files reportedly include approximately 206,000 service records and 23,000 mission records, with multiple public download links posted alongside the claim.
The allegedly exposed information includes names, dates of birth, home addresses, phone numbers, client and store details, employee roles, regional assignments, product information, service dates, mission records, and contact details for managers and field personnel.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have leaked data allegedly obtained from Actiale, a French company specializing in quality management, food safety, regulatory compliance, merchandising, and operational support services.
The listing advertises a 59MB JSON archive containing 229,978 records tied to 12,203 individuals. The files reportedly include approximately 206,000 service records and 23,000 mission records, with multiple public download links posted alongside the claim.
The allegedly exposed information includes names, dates of birth, home addresses, phone numbers, client and store details, employee roles, regional assignments, product information, service dates, mission records, and contact details for managers and field personnel.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
The DOJ alerts and SEC alerts and whatever else was recently running in here, is running in my private channel. If anything cyber related happens I will forward here to reduce noise.