This media is not supported in your browser
VIEW IN TELEGRAM
Just some guy playing Doom on a pregnancy test. 😂
‼️🇲🇾🇺🇸 The Gentlemen ransomware claims 3 victims
🇲🇾 Sunway Scientific - Malaysian supplier of scientific and laboratory equipment for research, biotechnology, and chemical industries.
🇺🇸 Advantage Home Health Care - Indiana-based provider of in-home care, post-procedure recovery, and long-term assistance services.
🇺🇸 Military Sealift Command - U.S. Navy organization providing ocean transportation and logistical support for military operations.
🇲🇾 Sunway Scientific - Malaysian supplier of scientific and laboratory equipment for research, biotechnology, and chemical industries.
🇺🇸 Advantage Home Health Care - Indiana-based provider of in-home care, post-procedure recovery, and long-term assistance services.
🇺🇸 Military Sealift Command - U.S. Navy organization providing ocean transportation and logistical support for military operations.
‼️ New Dark Web Informer Blog Post!
Title: Brazilian Hospital Hospital Di Camp Allegedly Breached, Patient Medical Data Leaked in Staged Release
Link: https://darkwebinformer.com/brazilian-hospital-hospital-di-camp-allegedly-breached-patient-medical-data-leaked-in-staged-release/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Brazilian Hospital Hospital Di Camp Allegedly Breached, Patient Medical Data Leaked in Staged Release
Link: https://darkwebinformer.com/brazilian-hospital-hospital-di-camp-allegedly-breached-patient-medical-data-leaked-in-staged-release/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Brazilian Hospital Hospital Di Camp Allegedly Breached, Patient Medical Data Leaked in Staged Release
A threat actor using the alias doommageddon claims to have breached Hospital Di Camp, a healthcare facility in Campo Grande, Brazil, that has provided medical services for more than 20 years across fields including cardiology, gastroenterology, and orthopedics.
‼️ New Dark Web Informer Blog Post!
Title: OpenSSL HollowByte Flaw Lets 11-Byte TLS Requests Exhaust Server Memory
Link: https://darkwebinformer.com/openssl-hollowbyte-flaw-lets-11-byte-tls-requests-exhaust-server-memory/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: OpenSSL HollowByte Flaw Lets 11-Byte TLS Requests Exhaust Server Memory
Link: https://darkwebinformer.com/openssl-hollowbyte-flaw-lets-11-byte-tls-requests-exhaust-server-memory/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
OpenSSL HollowByte Flaw Lets 11-Byte TLS Requests Exhaust Server Memory
A newly disclosed OpenSSL flaw named HollowByte allows an unauthenticated attacker to exhaust server memory using specially crafted TLS requests containing as little as 11 bytes of data.
🔪 Slice For Life - Part 2 🔪
‼️🇺🇸 ShinyHunters names Abbott owned Exact Sciences Corporation Exact Sciences is a Madison, Wisconsin-based maker of cancer screening and diagnostic tests, best known for its flagship non-invasive colorectal cancer test, Cologuard, that became a wholly owned…
‼️🇺🇸 Abbott has released a statement regarding ShinyHunters claim on Abbott owned Exact Sciences Corporation:
"Abbott is investigating a cyber incident in which there was unauthorized access to a limited number of internal systems in our Cancer Diagnostics business only. This does not impact any business operations, product or product availability, manufacturing or lab operations, or our ability to serve patients.
There is no impact to any other Abbott businesses, sites or systems. The legacy Exact Sciences systems are separate from Abbott’s.
Upon learning this, we took immediate steps to address the situation. We have engaged leading third-party cybersecurity experts and law enforcement and are working diligently to further investigate the information accessed and resolve this issue.
Based on what we know at this time, we do not expect any material impact on the business or financial results. We take our responsibility to protect our systems and data very seriously and will continue to closely monitor our systems."
Source: https://www.abbott.com/en-us/corpnewsroom/diagnostics-testing/abbott-statement-on-cyber-incident-in-cancer-diagnostics-business
"Abbott is investigating a cyber incident in which there was unauthorized access to a limited number of internal systems in our Cancer Diagnostics business only. This does not impact any business operations, product or product availability, manufacturing or lab operations, or our ability to serve patients.
There is no impact to any other Abbott businesses, sites or systems. The legacy Exact Sciences systems are separate from Abbott’s.
Upon learning this, we took immediate steps to address the situation. We have engaged leading third-party cybersecurity experts and law enforcement and are working diligently to further investigate the information accessed and resolve this issue.
Based on what we know at this time, we do not expect any material impact on the business or financial results. We take our responsibility to protect our systems and data very seriously and will continue to closely monitor our systems."
Source: https://www.abbott.com/en-us/corpnewsroom/diagnostics-testing/abbott-statement-on-cyber-incident-in-cancer-diagnostics-business
Abbott
Abbott statement on cyber incident in Cancer Diagnostics business | Abbott Newsroom
❤2
‼️🚨 CVE-2026-63030 // wp2shell-poc: Proof-of-concept for an unauthenticated SQL injection in WordPress core that chains to remote code execution, via REST batch route confusion.
PoC: https://github.com/Icex0/wp2shell-poc
PoC: https://github.com/Icex0/wp2shell-poc
❤1
🔪 Slice For Life - Part 2 🔪
‼️🚨 CVE-2026-63030 // wp2shell-poc: Proof-of-concept for an unauthenticated SQL injection in WordPress core that chains to remote code execution, via REST batch route confusion. PoC: https://github.com/Icex0/wp2shell-poc
X (formerly Twitter)
WordPress (@WordPress) on X
WordPress 7.0.2 is now available. This security release addresses 1 critical and 1 high severity issue, including a REST API vulnerability that could lead to remote code execution. Update your sites now. https://t.co/YHLAOD0rxF
🔪 Slice For Life - Part 2 🔪
https://x.com/WordPress/status/2078191359307943981
Another PoC: https://github.com/sergiointel/wp2shell-poc
GitHub
GitHub - sergiointel/wp2shell-poc: Stock vulnerable wordpress RCE poc for wp2shell.
Stock vulnerable wordpress RCE poc for wp2shell. Contribute to sergiointel/wp2shell-poc development by creating an account on GitHub.
🚨🇧🇷 Receita Federal dataset containing 279 million CPF records allegedly listed for sale
A forum actor claims to have extracted a current dataset from systems tied to Brazil’s Receita Federal containing 279,008,638 records. The actor also claims to possess an older backup created in 2019 containing approximately 248 million CPF entries.
The newly advertised dataset is described as a 69.6GB file, with two samples containing 10,000 records each published as proof. The actor is asking $10,000 for the alleged 2026 dataset and $1,300 for the 2019 backup, payable in Bitcoin or Monero.
The allegedly exposed information includes CPF numbers, full names, dates of birth, email addresses, phone numbers, residential addresses, postal codes, municipalities, occupations, nationalities, parents’ names, sex, tax-registration dates, cadastral status, foreign residency indicators, and death-related records.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have extracted a current dataset from systems tied to Brazil’s Receita Federal containing 279,008,638 records. The actor also claims to possess an older backup created in 2019 containing approximately 248 million CPF entries.
The newly advertised dataset is described as a 69.6GB file, with two samples containing 10,000 records each published as proof. The actor is asking $10,000 for the alleged 2026 dataset and $1,300 for the 2019 backup, payable in Bitcoin or Monero.
The allegedly exposed information includes CPF numbers, full names, dates of birth, email addresses, phone numbers, residential addresses, postal codes, municipalities, occupations, nationalities, parents’ names, sex, tax-registration dates, cadastral status, foreign residency indicators, and death-related records.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇷🇴 Romanian government and commercial datasets allegedly bundled for sale
A forum actor claims to be selling a bundle described as six Romanian datasets containing property, aviation, education, court, and courier records.
The listing advertises 27,796,642 national property registration records, 437,809 court cases, more than 1.55 million courier delivery records, teacher salary data covering all 42 counties, and 94 files allegedly taken from the Bucharest Airports backend. The complete bundle is priced at $5,000.
The allegedly exposed information includes names, CNP identifiers, home and delivery addresses, property details, teacher positions and salaries, court parties, IBANs, phone numbers, email addresses, hearing dates, flight information, administrator accounts, password hashes, contact submissions, subscriber details, and login logs.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to be selling a bundle described as six Romanian datasets containing property, aviation, education, court, and courier records.
The listing advertises 27,796,642 national property registration records, 437,809 court cases, more than 1.55 million courier delivery records, teacher salary data covering all 42 counties, and 94 files allegedly taken from the Bucharest Airports backend. The complete bundle is priced at $5,000.
The allegedly exposed information includes names, CNP identifiers, home and delivery addresses, property details, teacher positions and salaries, court parties, IBANs, phone numbers, email addresses, hearing dates, flight information, administrator accounts, password hashes, contact submissions, subscriber details, and login logs.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇦🇷 Instituto Ferrero de Neurología y Sueño data allegedly being ransomed for $150,000
A forum actor claims to have breached Instituto Ferrero de Neurología y Sueño, an Argentine medical center specializing in neurological and sleep disorders.
The listing advertises 636GB of data containing approximately 474,826 files tied to 103,315 users. The actor is demanding $150,000 and threatens to sell the material if payment is not made by August 5, 2026.
The allegedly compromised material may include patient, clinical, administrative, and other internal records, although the post does not provide a detailed breakdown of the exposed fields. Samples were shared through the actor’s Telegram channel.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have breached Instituto Ferrero de Neurología y Sueño, an Argentine medical center specializing in neurological and sleep disorders.
The listing advertises 636GB of data containing approximately 474,826 files tied to 103,315 users. The actor is demanding $150,000 and threatens to sell the material if payment is not made by August 5, 2026.
The allegedly compromised material may include patient, clinical, administrative, and other internal records, although the post does not provide a detailed breakdown of the exposed fields. Samples were shared through the actor’s Telegram channel.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇦🇷 Aceitera General Deheza dataset allegedly listed for sale
A forum actor claims to be selling a dataset allegedly obtained from Aceitera General Deheza, an Argentine agribusiness company involved in agricultural production, processing, logistics, and exports.
The listing advertises approximately 8 million records totaling around 124GB for $300. The seller says individual datasets can also be requested separately and published a proof-of-concept containing sample records from multiple tables.
The allegedly exposed information includes names, addresses, phone numbers, email addresses, usernames, roles and permissions, authentication and device tokens, vendor records, business locations, machinery and IoT identifiers, SIM details, GPS coordinates, vehicle registration numbers, transaction histories, product and crop data, weights, humidity readings, timestamps, and synchronization metadata.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to be selling a dataset allegedly obtained from Aceitera General Deheza, an Argentine agribusiness company involved in agricultural production, processing, logistics, and exports.
The listing advertises approximately 8 million records totaling around 124GB for $300. The seller says individual datasets can also be requested separately and published a proof-of-concept containing sample records from multiple tables.
The allegedly exposed information includes names, addresses, phone numbers, email addresses, usernames, roles and permissions, authentication and device tokens, vendor records, business locations, machinery and IoT identifiers, SIM details, GPS coordinates, vehicle registration numbers, transaction histories, product and crop data, weights, humidity readings, timestamps, and synchronization metadata.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇵🇪 Instituto Sabio Nacional Antúnez de Mayolo student data allegedly leaked
A forum actor claims to have leaked personal and academic information belonging to students of the Instituto Sabio Nacional Antúnez de Mayolo, known as ISAM, a higher education institution in Peru.
The listing says the material contains the institution’s complete student dataset and includes samples.
The allegedly exposed information includes DNI numbers, full names, dates of birth, phone numbers, email addresses, home addresses, genders, ages, enrollment dates, academic status, study programs, campuses, class schedules, admission types, and academic periods.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have leaked personal and academic information belonging to students of the Instituto Sabio Nacional Antúnez de Mayolo, known as ISAM, a higher education institution in Peru.
The listing says the material contains the institution’s complete student dataset and includes samples.
The allegedly exposed information includes DNI numbers, full names, dates of birth, phone numbers, email addresses, home addresses, genders, ages, enrollment dates, academic status, study programs, campuses, class schedules, admission types, and academic periods.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇰🇷 Robot Global Team source code allegedly leaked
A forum actor claims to have breached Robot Global Team, known as RGT, a South Korean company that develops and manufactures autonomous service robots, including its SIRBOT product line.
The listing says the incident occurred in July 2026 and resulted in a collection of the company’s source code being stolen. A file-tree sample was posted as proof.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have breached Robot Global Team, known as RGT, a South Korean company that develops and manufactures autonomous service robots, including its SIRBOT product line.
The listing says the incident occurred in July 2026 and resulted in a collection of the company’s source code being stolen. A file-tree sample was posted as proof.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇮🇳 PappyJoe patient data allegedly stolen for a $250,000 ransom
A forum actor claims to have breached PappyJoe, an India-based healthcare technology company that provides cloud-based clinic and practice management software for appointments, electronic medical records, billing, prescriptions, patient communications, and administrative tasks.
The listing advertises 413GB of data allegedly containing personally identifiable information tied to 6,873,180 patients and 531,673 files. The actor is demanding $250,000 and threatens to sell the material if payment is not made by August 5, 2026.
The post does not provide a detailed breakdown of the allegedly compromised fields, but describes the material as patient PII and links to samples published.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have breached PappyJoe, an India-based healthcare technology company that provides cloud-based clinic and practice management software for appointments, electronic medical records, billing, prescriptions, patient communications, and administrative tasks.
The listing advertises 413GB of data allegedly containing personally identifiable information tied to 6,873,180 patients and 531,673 files. The actor is demanding $250,000 and threatens to sell the material if payment is not made by August 5, 2026.
The post does not provide a detailed breakdown of the allegedly compromised fields, but describes the material as patient PII and links to samples published.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
‼️🇺🇸 A known initial access broker is offering for sale alleged access to an unnamed large US casino and resort for $500.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
🚨🇵🇱 Wydawnictwo WAM customer dataset allegedly leaked
A forum actor claims to have breached Wydawnictwo WAM, a Polish publisher and online bookstore offering religious and spiritual books, audiobooks, and educational materials.
The listing says the incident exposed data tied to approximately 71,600 unique users.
The allegedly exposed information includes customer names, email addresses, phone numbers, billing and shipping addresses, postal codes, account details, order identifiers, product information, payment and delivery statuses, transaction records, timestamps, and other e-commerce data.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have breached Wydawnictwo WAM, a Polish publisher and online bookstore offering religious and spiritual books, audiobooks, and educational materials.
The listing says the incident exposed data tied to approximately 71,600 unique users.
The allegedly exposed information includes customer names, email addresses, phone numbers, billing and shipping addresses, postal codes, account details, order identifiers, product information, payment and delivery statuses, transaction records, timestamps, and other e-commerce data.
This claim is currently unverified.
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing