‼️ New Dark Web Informer Blog Post!
Title: French Firefighters Federation Membership Platform Allegedly Breached, Data on Nearly 125,000 Members Leaked
Link: https://darkwebinformer.com/french-firefighters-federation-membership-platform-allegedly-breached-data-on-nearly-125-000-members-leaked/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: French Firefighters Federation Membership Platform Allegedly Breached, Data on Nearly 125,000 Members Leaked
Link: https://darkwebinformer.com/french-firefighters-federation-membership-platform-allegedly-breached-data-on-nearly-125-000-members-leaked/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
French Firefighters Federation Membership Platform Allegedly Breached, Data on Nearly 125,000 Members Leaked
A threat actor using the alias ChimeraZ claims to be leaking a database from the French Firefighters Federation (Fédération nationale des sapeurs-pompiers de France), specifically its official online membership platform (pompiers.fr).
🚨🇮🇩 VPN access to Indonesian technology company allegedly listed for sale
A forum actor claims to be selling OpenVPN access to an unidentified Indonesian technology and SaaS company.
The listing says the access includes local administrator privileges and identifies Carbon Black as the organization’s endpoint security platform.
The target is described as generating between $1 billion and $5 billion in revenue and operating a network of approximately 2,500 hosts.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to be selling OpenVPN access to an unidentified Indonesian technology and SaaS company.
The listing says the access includes local administrator privileges and identifies Carbon Black as the organization’s endpoint security platform.
The target is described as generating between $1 billion and $5 billion in revenue and operating a network of approximately 2,500 hosts.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
‼️ PLAY ransomware claims 5 victims
🇸🇪 Svensk Direktreklam - Swedish direct marketing company distributing advertising leaflets and local newspapers nationwide.
🇺🇸 Andorra Life - California-based health products company wholesaling and retailing nutritional supplements.
🇳🇱 A.G. Scholtes - Dutch meat wholesaler supplying beef products to butchers, hospitality businesses, supermarkets, and manufacturers.
🇬🇧 Wring Group - British contractor specializing in demolition, asbestos removal, environmental services, waste management, and recycling.
🇺🇸 Boston Electric and Telephone - Massachusetts-based contractor providing electrical, telecommunications, data networking, and security services.
🇸🇪 Svensk Direktreklam - Swedish direct marketing company distributing advertising leaflets and local newspapers nationwide.
🇺🇸 Andorra Life - California-based health products company wholesaling and retailing nutritional supplements.
🇳🇱 A.G. Scholtes - Dutch meat wholesaler supplying beef products to butchers, hospitality businesses, supermarkets, and manufacturers.
🇬🇧 Wring Group - British contractor specializing in demolition, asbestos removal, environmental services, waste management, and recycling.
🇺🇸 Boston Electric and Telephone - Massachusetts-based contractor providing electrical, telecommunications, data networking, and security services.
💥 I will be adding my repositories from GitHub to my own site this weekend. I've added Telegram Checker for now. You cannot register, only view... for the time being. I will update once everything has been migrated.
Link: https://git.darkwebinformer.com/
Link: https://git.darkwebinformer.com/
🚨🇺🇸 West Village Uptown Dallas WordPress dataset allegedly leaked
A forum actor claims to have released a complete WordPress dataset allegedly obtained from the West Village Uptown Dallas website.
The listing says the material includes the site’s complete WordPress data and provides a sample containing an administrator account record.
The allegedly exposed information includes usernames, password hashes, email addresses, display names, account registration dates, user status details, activation keys, and other WordPress site data.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have released a complete WordPress dataset allegedly obtained from the West Village Uptown Dallas website.
The listing says the material includes the site’s complete WordPress data and provides a sample containing an administrator account record.
The allegedly exposed information includes usernames, password hashes, email addresses, display names, account registration dates, user status details, activation keys, and other WordPress site data.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
❤1
‼️ CVE-2026-3891: A critical Unauthenticated Arbitrary File Upload vulnerability found in the Pix for WooCommerce WordPress plugin in versions up to and including 1.5.0.
PoC: https://github.com/m4sh-wacker/CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit
PoC: https://github.com/m4sh-wacker/CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit
🔥1
‼️ CVE-2026-15409: PoC exploit for CVE-2026-15409 that achieves non-root remote code execution on SonicWall SMA 1000 appliances.
GitHub: https://github.com/remmons-r7/rapid7-CVE-2026-15409
GitHub: https://github.com/remmons-r7/rapid7-CVE-2026-15409
‼️ The Coca-Cola Company has filed form 8-K due to a cybersecurity incident on behalf of fairlife, LLC.
"On July 16, 2026, The Coca-Cola Company (the “Company”) announced that fairlife, LLC (“fairlife”), a dairy company owned by the Company, identified unauthorized access by a third party to a portion of its systems, including its production-related systems, in connection with a ransomware event.
After detecting the issue, the Company promptly activated its incident response and business continuity protocols. The Company’s investigation and assessment of the impact of the incident is ongoing, with the assistance of outside advisors and cybersecurity experts. The Company has also notified law enforcement.
Product quality and safety have not been impacted. However, as a result of the incident, production operations at fairlife in the United States are temporarily suspended. fairlife’s Canada production operations are not currently impacted.
The Company is working diligently to complete the investigation and restore the systems and impacted operations. The full scope, nature and impacts of the incident are not yet known. Accordingly, the Company has not yet determined whether the incident is reasonably likely to materially affect the Company.
The information in this Form 8-K shall not be deemed “filed” for purposes of Section 18 of the Securities Exchange Act of 1934, nor shall it be deemed incorporated by reference in any filing under the Securities Act of 1933, except as shall be expressly set forth by specific reference in such filing."
Source: https://www.sec.gov/Archives/edgar/data/21344/000162828026048466/ko-20260716.htm
"On July 16, 2026, The Coca-Cola Company (the “Company”) announced that fairlife, LLC (“fairlife”), a dairy company owned by the Company, identified unauthorized access by a third party to a portion of its systems, including its production-related systems, in connection with a ransomware event.
After detecting the issue, the Company promptly activated its incident response and business continuity protocols. The Company’s investigation and assessment of the impact of the incident is ongoing, with the assistance of outside advisors and cybersecurity experts. The Company has also notified law enforcement.
Product quality and safety have not been impacted. However, as a result of the incident, production operations at fairlife in the United States are temporarily suspended. fairlife’s Canada production operations are not currently impacted.
The Company is working diligently to complete the investigation and restore the systems and impacted operations. The full scope, nature and impacts of the incident are not yet known. Accordingly, the Company has not yet determined whether the incident is reasonably likely to materially affect the Company.
The information in this Form 8-K shall not be deemed “filed” for purposes of Section 18 of the Securities Exchange Act of 1934, nor shall it be deemed incorporated by reference in any filing under the Securities Act of 1933, except as shall be expressly set forth by specific reference in such filing."
Source: https://www.sec.gov/Archives/edgar/data/21344/000162828026048466/ko-20260716.htm
😁1
Forwarded from Dark Web Informer - Private
Cybersecurity Incident Disclosure
Thu, 16 Jul 2026 16:20:56 EDT
A cybersecurity incident has been disclosed by COCA COLA CO, Inc CIK: 0000021344, Ticker: $KO.
View SEC Filing
Thu, 16 Jul 2026 16:20:56 EDT
A cybersecurity incident has been disclosed by COCA COLA CO, Inc CIK: 0000021344, Ticker: $KO.
View SEC Filing
‼️ CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation
PoC: https://github.com/DavidCarliez/CVE-2026-58635-PoC
PoC: https://github.com/DavidCarliez/CVE-2026-58635-PoC
❤1
🔪 Slice For Life - Part 2 🔪
‼️ New Forum: IOC: leaked[.]at ns: norah.ns.cloudflare.com ns: pedro.ns.cloudflare.com
Thread announcement on another forum:
🔪 Slice For Life - Part 2 🔪
‼️ Looks like OGU lost their main domain completely.
They own the domain again.
Forwarded from FBI Watchdog Alerts by Dark Web Informer
⚠️ FBI Watchdog - WHOIS Change ⚠️
🔗 DarkWebInformer.com - Cyber Threat Intelligence
Domain: oguser.com
Record Type: WHOIS Change
Time Detected: 2026-07-17 01:18:14 UTC
Previous Records:
New Records:
🔗 DarkWebInformer.com - Cyber Threat Intelligence
Domain: oguser.com
Record Type: WHOIS Change
Time Detected: 2026-07-17 01:18:14 UTC
Previous Records:
status: ['clienttransferprohibited']
New Records:
status: ['clienttransferprohibited'] → ['ok']
❤1
🚨🇲🇽 Baja California Sur transit police driver’s license dataset allegedly listed for sale
A forum actor claims to be selling a searchable program and driver’s license dataset allegedly tied to the Baja California Sur transit police in Mexico.
The listing advertises information belonging to approximately 325,000 individuals and asks 1,000 Mexican pesos for access. Screenshots posted as proof show a license search interface and detailed individual records.
The allegedly exposed information includes license types and numbers, full names, RFC and CURP identifiers, issuance dates, license status, pension status, Social Security numbers, home addresses, mobile, residential and work phone numbers, and personal and alternative email addresses.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to be selling a searchable program and driver’s license dataset allegedly tied to the Baja California Sur transit police in Mexico.
The listing advertises information belonging to approximately 325,000 individuals and asks 1,000 Mexican pesos for access. Screenshots posted as proof show a license search interface and detailed individual records.
The allegedly exposed information includes license types and numbers, full names, RFC and CURP identifiers, issuance dates, license status, pension status, Social Security numbers, home addresses, mobile, residential and work phone numbers, and personal and alternative email addresses.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇧🇷 Brazilian national health registry administrator access allegedly listed for sale
A forum actor claims to be selling live administrator access to a Brazilian national health and medical registry containing more than 300 million records.
The listing says the access allows users to search individuals by name, CPF number, state, and other identifiers. The seller claims the administrator account can view, edit, and modify records in real time.
The allegedly accessible information includes full personal profiles, residential addresses, maternal and paternal relationships, and complete historical vaccination records.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to be selling live administrator access to a Brazilian national health and medical registry containing more than 300 million records.
The listing says the access allows users to search individuals by name, CPF number, state, and other identifiers. The seller claims the administrator account can view, edit, and modify records in real time.
The allegedly accessible information includes full personal profiles, residential addresses, maternal and paternal relationships, and complete historical vaccination records.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: Brazilian Online Store Loja Negócios Digital Allegedly Breached, 20,000 Customer Records Exposed
Link: https://darkwebinformer.com/brazilian-online-store-loja-negocios-digital-allegedly-breached-20-000-customer-records-exposed/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Brazilian Online Store Loja Negócios Digital Allegedly Breached, 20,000 Customer Records Exposed
Link: https://darkwebinformer.com/brazilian-online-store-loja-negocios-digital-allegedly-breached-20-000-customer-records-exposed/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Brazilian Online Store Loja Negócios Digital Allegedly Breached, 20,000 Customer Records Exposed
A threat actor using the alias Sensitive2025 is advertising a database they claim to have stolen from Loja Negócios Digital (lojanegociosdigital.com.br), a Brazilian online store.
🚨🇲🇽 Villahermosa Integrated Citizen Service System dataset allegedly leaked
A forum actor claims to have leaked data allegedly obtained from the Integrated Citizen Service System, known as SIAC, used in Villahermosa, Tabasco.
The post includes a sample record and directs users to a Telegram channel to download the allegedly compromised material. No record count or archive size was disclosed.
The allegedly exposed information includes full names, CURP identifiers, email addresses, mobile and residential phone numbers, street addresses, municipalities, postal codes, birthplaces, dates of birth, genders, occupations, and professions.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have leaked data allegedly obtained from the Integrated Citizen Service System, known as SIAC, used in Villahermosa, Tabasco.
The post includes a sample record and directs users to a Telegram channel to download the allegedly compromised material. No record count or archive size was disclosed.
The allegedly exposed information includes full names, CURP identifiers, email addresses, mobile and residential phone numbers, street addresses, municipalities, postal codes, birthplaces, dates of birth, genders, occupations, and professions.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇺🇸 FBI arrests Florida man accused of using malware-laced Steam games to drain crypto wallets
Federal authorities arrested 21-year-old Zyaire Wilkins over an alleged scheme that distributed eight malware-infected video games between May 2024 and February 2026.
The games allegedly infected around 8,000 devices, compromised approximately 80 cryptocurrency wallets, and stole at least $220,000.
Titles linked to the investigation include BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi, and Tokenova.
Prosecutors say the games were promoted through Discord, Telegram, X, LinkedIn, and targeted messages sent to people believed to hold large amounts of cryptocurrency.
Investigators allegedly identified Wilkins by tracing Bitcoin spent on more than 150 gift cards, including Uber Eats cards connected to deliveries made to his addresses.
Wilkins is charged with conspiracy to obtain information by computer for private financial gain.
Complaint: https://www.documentcloud.org/documents/28492703-us-v-wilkins-steam-malware/
Federal authorities arrested 21-year-old Zyaire Wilkins over an alleged scheme that distributed eight malware-infected video games between May 2024 and February 2026.
The games allegedly infected around 8,000 devices, compromised approximately 80 cryptocurrency wallets, and stole at least $220,000.
Titles linked to the investigation include BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi, and Tokenova.
Prosecutors say the games were promoted through Discord, Telegram, X, LinkedIn, and targeted messages sent to people believed to hold large amounts of cryptocurrency.
Investigators allegedly identified Wilkins by tracing Bitcoin spent on more than 150 gift cards, including Uber Eats cards connected to deliveries made to his addresses.
Wilkins is charged with conspiracy to obtain information by computer for private financial gain.
Complaint: https://www.documentcloud.org/documents/28492703-us-v-wilkins-steam-malware/
🔥3