πŸ”ͺ Slice For Life - Part 2 πŸ”ͺ
4.7K subscribers
1.09K photos
59 videos
973 links
Download Telegram
β€ΌοΈπŸ‡ΏπŸ‡¦ RansomHouse names 1 new victim

πŸ‡ΏπŸ‡¦ Fidelity Services Group - South African integrated security provider offering guarding, cash management, fire protection, and related services.
This media is not supported in your browser
VIEW IN TELEGRAM
Microsoft fixed an Age of Empires RCE from yesterday’s Patch Tuesday (CVE-2026-50663). Here is an example of how it was done.

Credit: https://x.com/rdjgr/status/2077331427549421918
πŸ”₯2
πŸš¨πŸ‡«πŸ‡· DELKO customer dataset allegedly compromised

A forum actor claims to have compromised an internal appointment-booking tool belonging to DELKO, a French vehicle repair and maintenance chain operating more than 160 garages across France.

The actor says information belonging to 450,092 customers was scraped from the system. A sample containing customer and vehicle records was published with the post.

The allegedly exposed information includes customer IDs, names, email addresses, phone numbers, vehicle registration numbers, account creation dates, appointment dates, service types, transaction amounts, and detailed descriptions of vehicle repairs or maintenance.

This claim is currently unverified.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
πŸš¨πŸ‡¦πŸ‡· Argentine government portal credentials allegedly listed for sale

A forum actor claims to be selling a bundle of working login credentials for 21 government platforms across Argentina.

The seller describes the accounts as active and verified, claiming they provide access to restricted dashboards, administrative panels, internal communications, documents, notifications, workflows, and record-management functions. The credentials are said to have remained active for at least 30 days.

The advertised platforms include judicial, tax, vehicle registration, municipal, human resources, social security, and other government services.

This claim is currently unverified.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨 DarkMatter ransomware operation advertises affiliate program

A forum actor is advertising DarkMatter (not to be confused with one of the world's largest darknet markets), a newly introduced ransomware operation targeting small, medium, and large enterprises while claiming to exclude healthcare organizations and entities located in the CIS region.

The listing says CIS-based affiliates must pay a $250 entry fee, while non-CIS affiliates are charged $500 in Bitcoin or Monero. The operators are seeking a limited number of Russian-speaking partners and claim average affiliate payouts of approximately $70,000.

The advertised Windows ransomware supports multithreaded encryption, Active Directory integration, network propagation, credential dumping, security-tool disruption, event-log clearing, virtual machine detection, ESXi targeting, encrypted TOR-based victim portals, and configurable ransom notes. The operators also claim to provide custom builds, dedicated infrastructure, encrypted communications, and real-time reporting.

This claim is currently unverified.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
πŸš¨πŸ‡«πŸ‡· Actiale dataset allegedly leaked

A forum actor claims to have leaked data allegedly obtained from Actiale, a French company specializing in quality management, food safety, regulatory compliance, merchandising, and operational support services.

The listing advertises a 59MB JSON archive containing 229,978 records tied to 12,203 individuals. The files reportedly include approximately 206,000 service records and 23,000 mission records, with multiple public download links posted alongside the claim.

The allegedly exposed information includes names, dates of birth, home addresses, phone numbers, client and store details, employee roles, regional assignments, product information, service dates, mission records, and contact details for managers and field personnel.

This claim is currently unverified.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
The DOJ alerts and SEC alerts and whatever else was recently running in here, is running in my private channel. If anything cyber related happens I will forward here to reduce noise.
πŸ’₯ Forgejo: Forgejo is a self-hosted, open-source Git software forge for managing repositories, issues, pull requests, CI/CD, and software projects.

https://forgejo.org
πŸ’₯ VidBee is a modern, open-source video downloader that lets you download videos and audios from 1000+ websites worldwide.

GitHub: https://github.com/nexmoe/VidBee/
πŸš¨πŸ‡«πŸ‡· Croq’Vacances data allegedly leaked

A forum actor claims to have breached Croq’Vacances, a French organization that operates holiday camps, and obtained information tied to 72,916 unique individuals.

The listing advertises 72,639 user accounts, 71,181 contact records, 9,021 job applications, and 17,356 uploaded documents totaling approximately 24GB. The actor claims the account data includes 69,477 bcrypt password hashes and 25 administrator accounts.

The allegedly exposed information includes names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, national identity card and passport numbers, driver’s licenses, CVs, diplomas, identity scans, photographs, vaccination records, and medical information such as allergies, medications, and asthma conditions.

This claim is currently unverified.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
Media is too big
VIEW IN TELEGRAM
‼️ Scattered Spider members Owen Flowers, 18, from Walsall, and Thalha Jubair, 20, from east London have both been sentenced to 5 years and 6 months in prison.

The video is from when both Bomb and Earth2Star/Autism were arrested.

Source: https://www.bbc.com/news/articles/c4gyg0y6yg2o
πŸ”₯2❀1
πŸš¨πŸ‡«πŸ‡· RezoFed data allegedly leaked

A forum actor claims to have compromised RezoFed, the internal IT platform used by the French Federation of Social and Sociocultural Centres and its regional organizations across France.

The actor says an exposed web shell provided access to an Apache account with broad read and write permissions, allowing 29 database tables to be exported to CSV. The listing includes 118 user records containing alleged plaintext passwords, 5,146 contact records, and 30,228 financial contribution records.

The allegedly exposed information includes names, email addresses, phone numbers, job titles, associated organizations, account credentials, administrative roles, membership information, and financial contribution data. The actor also claims to have deleted source code, databases, and configuration files from the platform.

This claim is currently unverified.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
πŸš¨πŸ‡ΊπŸ‡Έ Seeking user dataset allegedly listed for sale

A forum actor claims to be selling a dataset containing 56 million records allegedly obtained from Seeking, an online dating platform.

The listing asks $400 for the dataset and includes a sample containing detailed user and account information.

The allegedly exposed fields include names, email addresses, password hashes, genders, birth dates, ages, locations, languages, relationship preferences, children, interests, occupations, education, income, net worth, lifestyle details, membership tiers, profile photographs, verification status, registration dates, login activity, and IP addresses.

This claim is currently unverified. Infostealer data courtesy of @whiteintel_io in the 2nd screenshot.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
πŸš¨πŸ‡²πŸ‡½ QuerΓ©taro Secretariat of Education certificates allegedly leaked

A forum actor claims to have leaked educational certificate data tied to the Secretariat of Education of QuerΓ©taro, Mexico.

The listing advertises more than 60,000 exposed certificates.

The exposed information allegedly includes full names, CURP identity numbers, educational institution details, certificate issuance data, and electronic signatures.

This claim is currently unverified.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
πŸš¨πŸ‡«πŸ‡· EVA user and booking data allegedly leaked

A forum actor claims to have breached EVA, a French gaming venue and reservation platform, and released data allegedly obtained through the company’s GraphQL API.

The listing advertises approximately 70,400 user accounts and 119,000 booking records. The actor also claims to have accessed information covering 63 locations in France, 99 vendors, 764 products, 10 games, store collections, playing fields, seasons, scores, and internal CSV exports.

The allegedly exposed information includes names, usernames, email addresses, phone numbers, birth dates, genders, home addresses, account roles, language preferences, battle pass details, booking dates, venue information, reservation statuses, order references, and session data.

This claim is currently unverified. Infostealer data courtesy of @whiteintel_io in the 2nd screenshot.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing