βΌοΈ CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation
PoC: https://github.com/DavidCarliez/CVE-2026-58635-PoC
PoC: https://github.com/DavidCarliez/CVE-2026-58635-PoC
β€1
πͺ Slice For Life - Part 2 πͺ
βΌοΈ New Forum: IOC: leaked[.]at ns: norah.ns.cloudflare.com ns: pedro.ns.cloudflare.com
Thread announcement on another forum:
πͺ Slice For Life - Part 2 πͺ
βΌοΈ Looks like OGU lost their main domain completely.
They own the domain again.
Forwarded from FBI Watchdog Alerts by Dark Web Informer
β οΈ FBI Watchdog - WHOIS Change β οΈ
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: oguser.com
Record Type: WHOIS Change
Time Detected: 2026-07-17 01:18:14 UTC
Previous Records:
New Records:
π DarkWebInformer.com - Cyber Threat Intelligence
Domain: oguser.com
Record Type: WHOIS Change
Time Detected: 2026-07-17 01:18:14 UTC
Previous Records:
status: ['clienttransferprohibited']
New Records:
status: ['clienttransferprohibited'] β ['ok']
β€1
π¨π²π½ Baja California Sur transit police driverβs license dataset allegedly listed for sale
A forum actor claims to be selling a searchable program and driverβs license dataset allegedly tied to the Baja California Sur transit police in Mexico.
The listing advertises information belonging to approximately 325,000 individuals and asks 1,000 Mexican pesos for access. Screenshots posted as proof show a license search interface and detailed individual records.
The allegedly exposed information includes license types and numbers, full names, RFC and CURP identifiers, issuance dates, license status, pension status, Social Security numbers, home addresses, mobile, residential and work phone numbers, and personal and alternative email addresses.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to be selling a searchable program and driverβs license dataset allegedly tied to the Baja California Sur transit police in Mexico.
The listing advertises information belonging to approximately 325,000 individuals and asks 1,000 Mexican pesos for access. Screenshots posted as proof show a license search interface and detailed individual records.
The allegedly exposed information includes license types and numbers, full names, RFC and CURP identifiers, issuance dates, license status, pension status, Social Security numbers, home addresses, mobile, residential and work phone numbers, and personal and alternative email addresses.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
π¨π§π· Brazilian national health registry administrator access allegedly listed for sale
A forum actor claims to be selling live administrator access to a Brazilian national health and medical registry containing more than 300 million records.
The listing says the access allows users to search individuals by name, CPF number, state, and other identifiers. The seller claims the administrator account can view, edit, and modify records in real time.
The allegedly accessible information includes full personal profiles, residential addresses, maternal and paternal relationships, and complete historical vaccination records.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to be selling live administrator access to a Brazilian national health and medical registry containing more than 300 million records.
The listing says the access allows users to search individuals by name, CPF number, state, and other identifiers. The seller claims the administrator account can view, edit, and modify records in real time.
The allegedly accessible information includes full personal profiles, residential addresses, maternal and paternal relationships, and complete historical vaccination records.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
βΌοΈ New Dark Web Informer Blog Post!
Title: Brazilian Online Store Loja NegΓ³cios Digital Allegedly Breached, 20,000 Customer Records Exposed
Link: https://darkwebinformer.com/brazilian-online-store-loja-negocios-digital-allegedly-breached-20-000-customer-records-exposed/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Brazilian Online Store Loja NegΓ³cios Digital Allegedly Breached, 20,000 Customer Records Exposed
Link: https://darkwebinformer.com/brazilian-online-store-loja-negocios-digital-allegedly-breached-20-000-customer-records-exposed/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Brazilian Online Store Loja NegΓ³cios Digital Allegedly Breached, 20,000 Customer Records Exposed
A threat actor using the alias Sensitive2025 is advertising a database they claim to have stolen from Loja NegΓ³cios Digital (lojanegociosdigital.com.br), a Brazilian online store.
π¨π²π½ Villahermosa Integrated Citizen Service System dataset allegedly leaked
A forum actor claims to have leaked data allegedly obtained from the Integrated Citizen Service System, known as SIAC, used in Villahermosa, Tabasco.
The post includes a sample record and directs users to a Telegram channel to download the allegedly compromised material. No record count or archive size was disclosed.
The allegedly exposed information includes full names, CURP identifiers, email addresses, mobile and residential phone numbers, street addresses, municipalities, postal codes, birthplaces, dates of birth, genders, occupations, and professions.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have leaked data allegedly obtained from the Integrated Citizen Service System, known as SIAC, used in Villahermosa, Tabasco.
The post includes a sample record and directs users to a Telegram channel to download the allegedly compromised material. No record count or archive size was disclosed.
The allegedly exposed information includes full names, CURP identifiers, email addresses, mobile and residential phone numbers, street addresses, municipalities, postal codes, birthplaces, dates of birth, genders, occupations, and professions.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
π¨πΊπΈ FBI arrests Florida man accused of using malware-laced Steam games to drain crypto wallets
Federal authorities arrested 21-year-old Zyaire Wilkins over an alleged scheme that distributed eight malware-infected video games between May 2024 and February 2026.
The games allegedly infected around 8,000 devices, compromised approximately 80 cryptocurrency wallets, and stole at least $220,000.
Titles linked to the investigation include BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi, and Tokenova.
Prosecutors say the games were promoted through Discord, Telegram, X, LinkedIn, and targeted messages sent to people believed to hold large amounts of cryptocurrency.
Investigators allegedly identified Wilkins by tracing Bitcoin spent on more than 150 gift cards, including Uber Eats cards connected to deliveries made to his addresses.
Wilkins is charged with conspiracy to obtain information by computer for private financial gain.
Complaint: https://www.documentcloud.org/documents/28492703-us-v-wilkins-steam-malware/
Federal authorities arrested 21-year-old Zyaire Wilkins over an alleged scheme that distributed eight malware-infected video games between May 2024 and February 2026.
The games allegedly infected around 8,000 devices, compromised approximately 80 cryptocurrency wallets, and stole at least $220,000.
Titles linked to the investigation include BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi, and Tokenova.
Prosecutors say the games were promoted through Discord, Telegram, X, LinkedIn, and targeted messages sent to people believed to hold large amounts of cryptocurrency.
Investigators allegedly identified Wilkins by tracing Bitcoin spent on more than 150 gift cards, including Uber Eats cards connected to deliveries made to his addresses.
Wilkins is charged with conspiracy to obtain information by computer for private financial gain.
Complaint: https://www.documentcloud.org/documents/28492703-us-v-wilkins-steam-malware/
π₯3
Forwarded from Dark Web Informer - Private
Cybersecurity Incident Disclosure
Fri, 17 Jul 2026 12:20:02 EDT
A cybersecurity incident has been disclosed by River Financial Corp, Inc CIK: 0001641601, Ticker: $RVRF.
View SEC Filing
Fri, 17 Jul 2026 12:20:02 EDT
A cybersecurity incident has been disclosed by River Financial Corp, Inc CIK: 0001641601, Ticker: $RVRF.
View SEC Filing
βΌοΈ New Dark Web Informer Blog Post!
Title: One Namespace String to kube-system: Cross-Namespace Privilege Escalation in Kyverno (CVE-2026-54523)
Link: https://darkwebinformer.com/one-namespace-string-to-kube-system-cross-namespace-privilege-escalation-in-kyverno-cve-2026-54523/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: One Namespace String to kube-system: Cross-Namespace Privilege Escalation in Kyverno (CVE-2026-54523)
Link: https://darkwebinformer.com/one-namespace-string-to-kube-system-cross-namespace-privilege-escalation-in-kyverno-cve-2026-54523/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
One Namespace String to kube-system: Cross-Namespace Privilege Escalation in Kyverno (CVE-2026-54523)
CVE-2026-54523 (GHSA-79gf-7frw-68m9) is a critical privilege escalation in Kyverno, the CNCF Kubernetes policy engine.
π₯ I have migrated all of my repositories to my site. You can download and modify as needed. I am no longer sharing my repositories on GitHub. If it's not on my site, it's not mine.
https://git.darkwebinformer.com/
Edit: The link can also be found under "DWI Tools" at the navigation header of the website and an icon on the footer of the website.
https://git.darkwebinformer.com/
Edit: The link can also be found under "DWI Tools" at the navigation header of the website and an icon on the footer of the website.
β€2
This media is not supported in your browser
VIEW IN TELEGRAM
Just some guy playing Doom on a pregnancy test. π
βΌοΈπ²πΎπΊπΈ The Gentlemen ransomware claims 3 victims
π²πΎ Sunway Scientific - Malaysian supplier of scientific and laboratory equipment for research, biotechnology, and chemical industries.
πΊπΈ Advantage Home Health Care - Indiana-based provider of in-home care, post-procedure recovery, and long-term assistance services.
πΊπΈ Military Sealift Command - U.S. Navy organization providing ocean transportation and logistical support for military operations.
π²πΎ Sunway Scientific - Malaysian supplier of scientific and laboratory equipment for research, biotechnology, and chemical industries.
πΊπΈ Advantage Home Health Care - Indiana-based provider of in-home care, post-procedure recovery, and long-term assistance services.
πΊπΈ Military Sealift Command - U.S. Navy organization providing ocean transportation and logistical support for military operations.
βΌοΈ New Dark Web Informer Blog Post!
Title: Brazilian Hospital Hospital Di Camp Allegedly Breached, Patient Medical Data Leaked in Staged Release
Link: https://darkwebinformer.com/brazilian-hospital-hospital-di-camp-allegedly-breached-patient-medical-data-leaked-in-staged-release/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Brazilian Hospital Hospital Di Camp Allegedly Breached, Patient Medical Data Leaked in Staged Release
Link: https://darkwebinformer.com/brazilian-hospital-hospital-di-camp-allegedly-breached-patient-medical-data-leaked-in-staged-release/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Brazilian Hospital Hospital Di Camp Allegedly Breached, Patient Medical Data Leaked in Staged Release
A threat actor using the alias doommageddon claims to have breached Hospital Di Camp, a healthcare facility in Campo Grande, Brazil, that has provided medical services for more than 20 years across fields including cardiology, gastroenterology, and orthopedics.
βΌοΈ New Dark Web Informer Blog Post!
Title: OpenSSL HollowByte Flaw Lets 11-Byte TLS Requests Exhaust Server Memory
Link: https://darkwebinformer.com/openssl-hollowbyte-flaw-lets-11-byte-tls-requests-exhaust-server-memory/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: OpenSSL HollowByte Flaw Lets 11-Byte TLS Requests Exhaust Server Memory
Link: https://darkwebinformer.com/openssl-hollowbyte-flaw-lets-11-byte-tls-requests-exhaust-server-memory/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
OpenSSL HollowByte Flaw Lets 11-Byte TLS Requests Exhaust Server Memory
A newly disclosed OpenSSL flaw named HollowByte allows an unauthenticated attacker to exhaust server memory using specially crafted TLS requests containing as little as 11 bytes of data.