๐จ AWS STS access tied to an unnamed telecommunications company allegedly listed for sale for $140,000.
A forum actor claims to be selling AWS Security Token Service access associated with an unidentified telecommunications company reporting approximately $9 billion in revenue.
The listing references 18 Amazon SQS queues, each allegedly processing or exposing up to 100,000 records per week. The seller also claims the access supports an โSQS downgrade attackโ and set the asking price at $140,000.
No company name, sample data, proof of access, or additional technical details were publicly provided.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to be selling AWS Security Token Service access associated with an unidentified telecommunications company reporting approximately $9 billion in revenue.
The listing references 18 Amazon SQS queues, each allegedly processing or exposing up to 100,000 records per week. The seller also claims the access supports an โSQS downgrade attackโ and set the asking price at $140,000.
No company name, sample data, proof of access, or additional technical details were publicly provided.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
This media is not supported in your browser
VIEW IN TELEGRAM
๐ฅ Cariddi: Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more
GitHub: https://github.com/edoardottt/cariddi
GitHub: https://github.com/edoardottt/cariddi
โผ๏ธ CVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVSS: 10
Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58630
CVSS: 10
Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58630
โค1
โผ๏ธ CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
CVSS: 9.1
Scanner: https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
Details and Mitigation: https://support.checkpoint.com/results/sk/sk185169/
CVSS: 9.1
Scanner: https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
Details and Mitigation: https://support.checkpoint.com/results/sk/sk185169/
โค1
โผ๏ธ PoC released for CVE-2026-54121 codenamed Certighost
CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges.
GitHub: https://github.com/aniqfakhrul/cve-2026-54121
CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges.
GitHub: https://github.com/aniqfakhrul/cve-2026-54121
โค1๐ญ1
๐จ CVE-2026-62835: Microsoft Azure Portal Information Disclosure Vulnerability
CVE-2026-62835 involves a flaw in the authorization process of Online Services, enabling attackers to access restricted information. The vulnerability documented by this CVE requires no customer action to resolve.
CVSS: 9.3
More information: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62835
CVE-2026-62835 involves a flaw in the authorization process of Online Services, enabling attackers to access restricted information. The vulnerability documented by this CVE requires no customer action to resolve.
CVSS: 9.3
More information: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62835
โค1
๐จ๐ฒ๐ฝ Acomee customer dataset containing more than 17,000 records allegedly leaked
A forum actor claims to have leaked data tied to Acomee, a Mexican distributor of telecommunications, networking, surveillance, and electrical equipment.
The post advertises slightly more than 17,000 records.
The allegedly exposed information includes names, RFC identifiers, email addresses, usernames, password fields, registration dates, street addresses, phone numbers, cities, states, postal codes, account permissions, vendor details, purchasing preferences, marketplace settings, tax regimes, subscription validity dates, account statuses, and internal file references.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to have leaked data tied to Acomee, a Mexican distributor of telecommunications, networking, surveillance, and electrical equipment.
The post advertises slightly more than 17,000 records.
The allegedly exposed information includes names, RFC identifiers, email addresses, usernames, password fields, registration dates, street addresses, phone numbers, cities, states, postal codes, account permissions, vendor details, purchasing preferences, marketplace settings, tax regimes, subscription validity dates, account statuses, and internal file references.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
๐จ๐ธ๐ฆ GulfJobs[.]com recruitment dataset containing approximately 872,000 records allegedly listed for sale
A forum actor claims to be selling data tied to GulfJobs[.]com, a Saudi recruitment platform connecting employers with job candidates.
The listing advertises approximately 872,000 entity and metadata records covering candidate contacts, profiles, job applications, authentication logs, and third-party platform mappings.
The allegedly exposed information includes names, email addresses, phone numbers, dates of birth, genders, nationalities, home addresses, marital statuses, emergency contacts, passport details, employment histories, skills, salaries, police clearance certificates, rรฉsumรฉs, physical attributes, disability information, application statuses, interview results, background checks, visa statuses, and onboarding records.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to be selling data tied to GulfJobs[.]com, a Saudi recruitment platform connecting employers with job candidates.
The listing advertises approximately 872,000 entity and metadata records covering candidate contacts, profiles, job applications, authentication logs, and third-party platform mappings.
The allegedly exposed information includes names, email addresses, phone numbers, dates of birth, genders, nationalities, home addresses, marital statuses, emergency contacts, passport details, employment histories, skills, salaries, police clearance certificates, rรฉsumรฉs, physical attributes, disability information, application statuses, interview results, background checks, visa statuses, and onboarding records.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐ป๐ช RDP access to unnamed Venezuelan equipment supplier allegedly listed for sale on a Russian speaking forum
A forum actor claims to be selling remote access to the network of a Venezuelan company that supplies industrial, agricultural, and household equipment.
The listing says the company has operated for more than 27 years, works with over 600 distributors, and maintains 20 authorized service centers. Its revenue is estimated at between 10 million and 25 million, although no currency was specified.
The advertised access allegedly includes an Active Directory user account on a Windows Server 2012 R2 system, Radmin VPN and AnyDesk connectivity, access to networked computers, and approximately 2TB of data. Bitdefender is reportedly installed on the environment.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to be selling remote access to the network of a Venezuelan company that supplies industrial, agricultural, and household equipment.
The listing says the company has operated for more than 27 years, works with over 600 distributors, and maintains 20 authorized service centers. Its revenue is estimated at between 10 million and 25 million, although no currency was specified.
The advertised access allegedly includes an Active Directory user account on a Windows Server 2012 R2 system, Radmin VPN and AnyDesk connectivity, access to networked computers, and approximately 2TB of data. Bitdefender is reportedly installed on the environment.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
โค1
๐จ๐ Coinbase session cookie checker and account takeover service advertised on a cybercrime forum
A forum actor is advertising a bot that allegedly checks stolen Coinbase session cookies for account balances, provides access without valid email credentials, and supports rapid withdrawals using methods designed to evade antifraud systems. The listing also advertises 2FA removal for Coinbase, MEXC, Kraken, Bybit, and other cryptocurrency exchanges.
The seller says personally sourced material is required and prioritizes stealer logs, macOS logs, RDP access, hVNC, and botnet data. Accounts from the US and UK must reportedly hold at least $1,000, while accounts from Europe and other regions require balances of at least $8,000. Revenue-sharing terms of 60/40 and 50/50 are advertised depending on the account balance.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor is advertising a bot that allegedly checks stolen Coinbase session cookies for account balances, provides access without valid email credentials, and supports rapid withdrawals using methods designed to evade antifraud systems. The listing also advertises 2FA removal for Coinbase, MEXC, Kraken, Bybit, and other cryptocurrency exchanges.
The seller says personally sourced material is required and prioritizes stealer logs, macOS logs, RDP access, hVNC, and botnet data. Accounts from the US and UK must reportedly hold at least $1,000, while accounts from Europe and other regions require balances of at least $8,000. Revenue-sharing terms of 60/40 and 50/50 are advertised depending on the account balance.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
โค2
๐ช Slice For Life - Part 2 ๐ช
๐จ๐ Coinbase session cookie checker and account takeover service advertised on a cybercrime forum A forum actor is advertising a bot that allegedly checks stolen Coinbase session cookies for account balances, provides access without valid email credentialsโฆ
I'm onboarding to the feed. should be done sometime this weekend. I have plans so dont think its being done right away.
๐จ๐ซ๐ท Alpissimo[.]fr user dataset containing approximately 600 records allegedly leaked
A forum actor claims to have breached alpissimo[.]fr and released data allegedly obtained from the website.
The listing advertises approximately 600 user records. A sample posted on the forum contains information submitted through the site, including names, email addresses, phone numbers, submission dates, and messages containing housing or travel requirements. The full download was placed behind the forumโs reply requirement.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have breached alpissimo[.]fr and released data allegedly obtained from the website.
The listing advertises approximately 600 user records. A sample posted on the forum contains information submitted through the site, including names, email addresses, phone numbers, submission dates, and messages containing housing or travel requirements. The full download was placed behind the forumโs reply requirement.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐จ๐ซ๐ท SDIS de la Marne personnel data and documents allegedly leaked
Forum actors ChimeraZ and Cybernox claim to have leaked a database and document archive tied to SDIS 51, the fire and rescue service for Franceโs Marne department.
The post advertises 2,168 records covering 2,167 individuals, along with 1,021 files totaling approximately 700MB. The actors say the archive contains 1,020 documents related to firefighters and the organizationโs website, provided in CSV and PDF formats.
The allegedly exposed information includes personnel names, work email addresses, phone numbers, job titles, departmental roles, and firefighter-related documents.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Forum actors ChimeraZ and Cybernox claim to have leaked a database and document archive tied to SDIS 51, the fire and rescue service for Franceโs Marne department.
The post advertises 2,168 records covering 2,167 individuals, along with 1,021 files totaling approximately 700MB. The actors say the archive contains 1,020 documents related to firefighters and the organizationโs website, provided in CSV and PDF formats.
The allegedly exposed information includes personnel names, work email addresses, phone numbers, job titles, departmental roles, and firefighter-related documents.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐ซ๐ท Three French fire and rescue services allegedly targeted in separate data leaks
Forum actors ChimeraZ and Cybernox claim to have leaked data tied to SDIS 06 in Alpes-Maritimes, SDIS 40 in Landes, and SDIS 04 in Alpes-de-Haute-Provence.
The SDIS 06 listing advertises 2,331 records covering 2,325 people and 15,833 files totaling 22.5GB. The SDIS 40 post references 241 records and 3,205 files totaling 11.8GB, while the SDIS 04 listing advertises 145 personnel records.
The allegedly exposed information includes firefightersโ names, dates of birth, nationalities, ranks, assignments, email addresses, phone numbers, home addresses, biographies, internal operational material, and other private documents.
These claims are currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
Forum actors ChimeraZ and Cybernox claim to have leaked data tied to SDIS 06 in Alpes-Maritimes, SDIS 40 in Landes, and SDIS 04 in Alpes-de-Haute-Provence.
The SDIS 06 listing advertises 2,331 records covering 2,325 people and 15,833 files totaling 22.5GB. The SDIS 40 post references 241 records and 3,205 files totaling 11.8GB, while the SDIS 04 listing advertises 145 personnel records.
The allegedly exposed information includes firefightersโ names, dates of birth, nationalities, ranks, assignments, email addresses, phone numbers, home addresses, biographies, internal operational material, and other private documents.
These claims are currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐จ๐ณ๐ฑ Netherlands contact dataset containing 14 million records allegedly listed for sale
A forum actor claims to be selling a 2026 dataset containing approximately 14 million records tied to individuals in the Netherlands.
The seller is asking 2,500 in an unspecified currency and says the dataset will be sold exclusively to one buyer.
The allegedly exposed information includes names, dates of birth, genders, identification numbers, email addresses, mobile and home phone numbers, job titles, departments, account details, record ownership and creation metadata, contact preferences, and linked social media identifiers.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to be selling a 2026 dataset containing approximately 14 million records tied to individuals in the Netherlands.
The seller is asking 2,500 in an unspecified currency and says the dataset will be sold exclusively to one buyer.
The allegedly exposed information includes names, dates of birth, genders, identification numbers, email addresses, mobile and home phone numbers, job titles, departments, account details, record ownership and creation metadata, contact preferences, and linked social media identifiers.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐บ๐ธ๐บ๐ธ๐ฉ๐ช Root CMS access to three major companies allegedly listed for sale
A forum actor claims to be selling privileged CMS access tied to two unnamed US pharmaceutical and biotechnology companies and the German rail-freight division of a national railway.
The three organizations reportedly generate approximately $84.4 billion in combined annual revenue. The listings advertise root access to 18 CMS instances, including systems distributed across 10 countries.
The seller claims the access provides full read and write capabilities, including access to records, user account creation, file uploads, and email creation. Asking prices are listed at $16,000 for the biotechnology company, $40,000 for the pharmaceutical company, and $12,000 for the rail-freight operator.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to be selling privileged CMS access tied to two unnamed US pharmaceutical and biotechnology companies and the German rail-freight division of a national railway.
The three organizations reportedly generate approximately $84.4 billion in combined annual revenue. The listings advertise root access to 18 CMS instances, including systems distributed across 10 countries.
The seller claims the access provides full read and write capabilities, including access to records, user account creation, file uploads, and email creation. Asking prices are listed at $16,000 for the biotechnology company, $40,000 for the pharmaceutical company, and $12,000 for the rail-freight operator.
This claim is currently unverified.
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐จ๐ฏ๐ต๐จ๐ฆ๐ฎ๐ฑ Root CMS access to three government platforms allegedly listed for sale
A forum actor claims to be selling privileged CMS access tied to Nara Prefectureโs Nara Super App in Japan, New Brunswickโs MyHealthNB platform in Canada, and Israelโs National Digital Agency.
The listings advertise prices of $2,000 for Nara Super App, $10,000 for MyHealthNB, and $5,000 for the Israeli government system. The seller claims the access provides full read and write capabilities, including control over user accounts, file uploads, and email creation.
The actor gave potential buyers 48 hours to purchase the access after publicly naming the affected platforms.
These claims are currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to be selling privileged CMS access tied to Nara Prefectureโs Nara Super App in Japan, New Brunswickโs MyHealthNB platform in Canada, and Israelโs National Digital Agency.
The listings advertise prices of $2,000 for Nara Super App, $10,000 for MyHealthNB, and $5,000 for the Israeli government system. The seller claims the access provides full read and write capabilities, including control over user accounts, file uploads, and email creation.
The actor gave potential buyers 48 hours to purchase the access after publicly naming the affected platforms.
These claims are currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ๐ฌ๐ง UK Department for Education contact records allegedly leaked
A forum actor claims to have breached systems tied to the UK Department for Education and obtained data from its Help Portal and Turing Portal.
The listing advertises approximately 600,000 parent and staff contact records from the Help Portal, along with around 7,000 additional records from the Turing Portal. Samples containing names, email addresses, phone numbers, job titles, and internal contact identifiers were posted on the forum.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to have breached systems tied to the UK Department for Education and obtained data from its Help Portal and Turing Portal.
The listing advertises approximately 600,000 parent and staff contact records from the Help Portal, along with around 7,000 additional records from the Turing Portal. Samples containing names, email addresses, phone numbers, job titles, and internal contact identifiers were posted on the forum.
This claim is currently unverified.
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing