๐Ÿ”ช Slice For Life - Part 2 ๐Ÿ”ช
4.69K subscribers
1.07K photos
59 videos
964 links
Download Telegram
๐Ÿšจ AWS STS access tied to an unnamed telecommunications company allegedly listed for sale for $140,000.

A forum actor claims to be selling AWS Security Token Service access associated with an unidentified telecommunications company reporting approximately $9 billion in revenue.

The listing references 18 Amazon SQS queues, each allegedly processing or exposing up to 100,000 records per week. The seller also claims the access supports an โ€œSQS downgrade attackโ€ and set the asking price at $140,000.

No company name, sample data, proof of access, or additional technical details were publicly provided.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ’ฅ Cariddi: Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

GitHub: https://github.com/edoardottt/cariddi
โ€ผ๏ธ CVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

CVSS: 10

Details: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58630
โค1
โ€ผ๏ธ CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

CVSS: 9.1

Scanner: https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

Details and Mitigation: https://support.checkpoint.com/results/sk/sk185169/
โค1
โ€ผ๏ธ PoC released for CVE-2026-54121 codenamed Certighost

CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges.

GitHub: https://github.com/aniqfakhrul/cve-2026-54121
โค1๐Ÿ˜ญ1
๐Ÿšจ CVE-2026-62835: Microsoft Azure Portal Information Disclosure Vulnerability

CVE-2026-62835 involves a flaw in the authorization process of Online Services, enabling attackers to access restricted information. The vulnerability documented by this CVE requires no customer action to resolve.

CVSS: 9.3

More information: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62835
โค1
๐Ÿšจ๐Ÿ‡ฒ๐Ÿ‡ฝ Acomee customer dataset containing more than 17,000 records allegedly leaked

A forum actor claims to have leaked data tied to Acomee, a Mexican distributor of telecommunications, networking, surveillance, and electrical equipment.

The post advertises slightly more than 17,000 records.

The allegedly exposed information includes names, RFC identifiers, email addresses, usernames, password fields, registration dates, street addresses, phone numbers, cities, states, postal codes, account permissions, vendor details, purchasing preferences, marketplace settings, tax regimes, subscription validity dates, account statuses, and internal file references.

This claim is currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
๐Ÿšจ๐Ÿ‡ธ๐Ÿ‡ฆ GulfJobs[.]com recruitment dataset containing approximately 872,000 records allegedly listed for sale

A forum actor claims to be selling data tied to GulfJobs[.]com, a Saudi recruitment platform connecting employers with job candidates.

The listing advertises approximately 872,000 entity and metadata records covering candidate contacts, profiles, job applications, authentication logs, and third-party platform mappings.

The allegedly exposed information includes names, email addresses, phone numbers, dates of birth, genders, nationalities, home addresses, marital statuses, emergency contacts, passport details, employment histories, skills, salaries, police clearance certificates, rรฉsumรฉs, physical attributes, disability information, application statuses, interview results, background checks, visa statuses, and onboarding records.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ป๐Ÿ‡ช RDP access to unnamed Venezuelan equipment supplier allegedly listed for sale on a Russian speaking forum

A forum actor claims to be selling remote access to the network of a Venezuelan company that supplies industrial, agricultural, and household equipment.

The listing says the company has operated for more than 27 years, works with over 600 distributors, and maintains 20 authorized service centers. Its revenue is estimated at between 10 million and 25 million, although no currency was specified.

The advertised access allegedly includes an Active Directory user account on a Windows Server 2012 R2 system, Radmin VPN and AnyDesk connectivity, access to networked computers, and approximately 2TB of data. Bitdefender is reportedly installed on the environment.

This claim is currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________

Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
โค1
๐Ÿšจ๐ŸŒ Coinbase session cookie checker and account takeover service advertised on a cybercrime forum

A forum actor is advertising a bot that allegedly checks stolen Coinbase session cookies for account balances, provides access without valid email credentials, and supports rapid withdrawals using methods designed to evade antifraud systems. The listing also advertises 2FA removal for Coinbase, MEXC, Kraken, Bybit, and other cryptocurrency exchanges.

The seller says personally sourced material is required and prioritizes stealer logs, macOS logs, RDP access, hVNC, and botnet data. Accounts from the US and UK must reportedly hold at least $1,000, while accounts from Europe and other regions require balances of at least $8,000. Revenue-sharing terms of 60/40 and 50/50 are advertised depending on the account balance.

This claim is currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
โค2
๐Ÿšจ๐Ÿ‡ซ๐Ÿ‡ท Alpissimo[.]fr user dataset containing approximately 600 records allegedly leaked

A forum actor claims to have breached alpissimo[.]fr and released data allegedly obtained from the website.

The listing advertises approximately 600 user records. A sample posted on the forum contains information submitted through the site, including names, email addresses, phone numbers, submission dates, and messages containing housing or travel requirements. The full download was placed behind the forumโ€™s reply requirement.

This claim is currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ซ๐Ÿ‡ท SDIS de la Marne personnel data and documents allegedly leaked

Forum actors ChimeraZ and Cybernox claim to have leaked a database and document archive tied to SDIS 51, the fire and rescue service for Franceโ€™s Marne department.

The post advertises 2,168 records covering 2,167 individuals, along with 1,021 files totaling approximately 700MB. The actors say the archive contains 1,020 documents related to firefighters and the organizationโ€™s website, provided in CSV and PDF formats.

The allegedly exposed information includes personnel names, work email addresses, phone numbers, job titles, departmental roles, and firefighter-related documents.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ซ๐Ÿ‡ท Three French fire and rescue services allegedly targeted in separate data leaks

Forum actors ChimeraZ and Cybernox claim to have leaked data tied to SDIS 06 in Alpes-Maritimes, SDIS 40 in Landes, and SDIS 04 in Alpes-de-Haute-Provence.

The SDIS 06 listing advertises 2,331 records covering 2,325 people and 15,833 files totaling 22.5GB. The SDIS 40 post references 241 records and 3,205 files totaling 11.8GB, while the SDIS 04 listing advertises 145 personnel records.

The allegedly exposed information includes firefightersโ€™ names, dates of birth, nationalities, ranks, assignments, email addresses, phone numbers, home addresses, biographies, internal operational material, and other private documents.

These claims are currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands contact dataset containing 14 million records allegedly listed for sale

A forum actor claims to be selling a 2026 dataset containing approximately 14 million records tied to individuals in the Netherlands.

The seller is asking 2,500 in an unspecified currency and says the dataset will be sold exclusively to one buyer.

The allegedly exposed information includes names, dates of birth, genders, identification numbers, email addresses, mobile and home phone numbers, job titles, departments, account details, record ownership and creation metadata, contact preferences, and linked social media identifiers.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿ‡ฉ๐Ÿ‡ช Root CMS access to three major companies allegedly listed for sale

A forum actor claims to be selling privileged CMS access tied to two unnamed US pharmaceutical and biotechnology companies and the German rail-freight division of a national railway.

The three organizations reportedly generate approximately $84.4 billion in combined annual revenue. The listings advertise root access to 18 CMS instances, including systems distributed across 10 countries.

The seller claims the access provides full read and write capabilities, including access to records, user account creation, file uploads, and email creation. Asking prices are listed at $16,000 for the biotechnology company, $40,000 for the pharmaceutical company, and $12,000 for the rail-freight operator.

This claim is currently unverified.

๐Ÿ’ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ฏ๐Ÿ‡ต๐Ÿ‡จ๐Ÿ‡ฆ๐Ÿ‡ฎ๐Ÿ‡ฑ Root CMS access to three government platforms allegedly listed for sale

A forum actor claims to be selling privileged CMS access tied to Nara Prefectureโ€™s Nara Super App in Japan, New Brunswickโ€™s MyHealthNB platform in Canada, and Israelโ€™s National Digital Agency.

The listings advertise prices of $2,000 for Nara Super App, $10,000 for MyHealthNB, and $5,000 for the Israeli government system. The seller claims the access provides full read and write capabilities, including control over user accounts, file uploads, and email creation.

The actor gave potential buyers 48 hours to purchase the access after publicly naming the affected platforms.

These claims are currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐Ÿšจ๐Ÿ‡ฌ๐Ÿ‡ง UK Department for Education contact records allegedly leaked

A forum actor claims to have breached systems tied to the UK Department for Education and obtained data from its Help Portal and Turing Portal.

The listing advertises approximately 600,000 parent and staff contact records from the Help Portal, along with around 7,000 additional records from the Turing Portal. Samples containing names, email addresses, phone numbers, job titles, and internal contact identifiers were posted on the forum.

This claim is currently unverified.

๐Ÿ’ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing