βΌοΈ A forum actor is offering for sale a private Windows local privilege escalation exploit claimed to work on versions since 2016 and unaffected by the recent Patch Tuesday update, priced at $145,000 non-negotiable.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
β€2
βΌοΈ A forum actor claims to be selling a private 0day exploit that bypasses Google Chromes Safe Browsing/malware download alert on macOS, reportedly functional from macOS Monterey through version 27. The exploit is offered for sale at a non-negotiable price of $13,000.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
β€1
π¨πͺπΈ Spanish Social Security pensioner records allegedly offered for sale
A forum actor claims to have breached Spainβs National Social Security Institute after an unsuccessful extortion attempt. The listing advertises 3,184,288 records allegedly covering pensioners across Spain.
The actor claims the data is stored in JSON format and that the broader collection also contains PDF files and images. A sample was published to support the claim, while the full dataset is being offered for β¬5,000.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to have breached Spainβs National Social Security Institute after an unsuccessful extortion attempt. The listing advertises 3,184,288 records allegedly covering pensioners across Spain.
The actor claims the data is stored in JSON format and that the broader collection also contains PDF files and images. A sample was published to support the claim, while the full dataset is being offered for β¬5,000.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
This media is not supported in your browser
VIEW IN TELEGRAM
βΌοΈ CVE-2026-43503: DirtyClone is a Linux kernel local privilege escalation (LPE) vulnerability caused by page-cache corruption.
PoC: https://github.com/entra1337/DirtyClone
PoC: https://github.com/entra1337/DirtyClone
β€1
βΌοΈ New Dark Web Informer Blog Post!
Title: Mercor Breached, Biometric Face and Voice Data on Every Registered User Offered for Sale
Link: https://darkwebinformer.com/mercor-breached-biometric-face-and-voice-data-on-every-registered-user-offered-for-sale/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Mercor Breached, Biometric Face and Voice Data on Every Registered User Offered for Sale
Link: https://darkwebinformer.com/mercor-breached-biometric-face-and-voice-data-on-every-registered-user-offered-for-sale/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Mercor Breached, Biometric Face and Voice Data on Every Registered User Offered for Sale
A seller posting as Resolute, claiming to have acted alongside a group using the Lapsus$ name, is advertising data from a complete compromise of Mercor, the US platform that recruits domain experts to produce training data for AI laboratories.
π₯1
πͺ Slice For Life - Part 2 πͺ
βΌοΈ New Dark Web Informer Blog Post! Title: Mercor Breached, Biometric Face and Voice Data on Every Registered User Offered for Sale Link: https://darkwebinformer.com/mercor-breached-biometric-face-and-voice-data-on-every-registered-user-offered-for-sale/β¦
Read the details from Mercor: https://www.mercor.com/blog/update-on-mercor-security-incident/?matchtype=e
Mercor
Mercor Data Breach: Investigation Findings and Updates
Official update on Mercorβs March 2026 data breach: a LiteLLM supply chain attack, what our investigation found, who was affected, and security changes.
βΌοΈ Analog Devices, Inc. has filed form 8-K due to a Cybersecurity incident
https://www.sec.gov/Archives/edgar/data/6281/000119312526324223/d158253d8k.htm
"On June 23, 2026, Analog Devices, Inc. (the βCompanyβ) identified unauthorized access to certain Company systems. Following detection of the unauthorized access, the Company immediately activated its incident response protocols and engaged external cybersecurity experts to assist with containment and investigation activities. The Company has also notified and is coordinating with law enforcement authorities. The Companyβs operations were not interrupted throughout the duration of the incident.
The Companyβs investigation has found that certain files were exfiltrated from the affected systems. The Companyβs investigation into the nature and scope of the exfiltrated information remains ongoing. To the Companyβs knowledge, the data has not been publicly released or used for fraudulent purposes. The Company will continue to monitor for any indication of misuse and will take appropriate action if warranted. The Company will provide notifications to affected parties and applicable regulators as appropriate and in accordance with applicable law.
While the Companyβs investigation continues, based on information currently known, and the containment and mitigation measures taken, the Company does not believe the June 23, 2026 incident is reasonably likely to materially impact its business, operations, or financial condition.
Separately and unrelated, on July 26, 2026, the Company was made aware of public reports regarding a disparate cybersecurity matter and is currently assessing its validity, scope, and any potential impact."
https://www.sec.gov/Archives/edgar/data/6281/000119312526324223/d158253d8k.htm
"On June 23, 2026, Analog Devices, Inc. (the βCompanyβ) identified unauthorized access to certain Company systems. Following detection of the unauthorized access, the Company immediately activated its incident response protocols and engaged external cybersecurity experts to assist with containment and investigation activities. The Company has also notified and is coordinating with law enforcement authorities. The Companyβs operations were not interrupted throughout the duration of the incident.
The Companyβs investigation has found that certain files were exfiltrated from the affected systems. The Companyβs investigation into the nature and scope of the exfiltrated information remains ongoing. To the Companyβs knowledge, the data has not been publicly released or used for fraudulent purposes. The Company will continue to monitor for any indication of misuse and will take appropriate action if warranted. The Company will provide notifications to affected parties and applicable regulators as appropriate and in accordance with applicable law.
While the Companyβs investigation continues, based on information currently known, and the containment and mitigation measures taken, the Company does not believe the June 23, 2026 incident is reasonably likely to materially impact its business, operations, or financial condition.
Separately and unrelated, on July 26, 2026, the Company was made aware of public reports regarding a disparate cybersecurity matter and is currently assessing its validity, scope, and any potential impact."
β€1
Forwarded from Dark Web Informer - Private
Cybersecurity Incident Disclosure
Wed, 29 Jul 2026 17:15:35 EDT
A cybersecurity incident has been disclosed by ANALOG DEVICES INC, Inc CIK: 0000006281, Ticker: $ADI.
View SEC Filing
Wed, 29 Jul 2026 17:15:35 EDT
A cybersecurity incident has been disclosed by ANALOG DEVICES INC, Inc CIK: 0000006281, Ticker: $ADI.
View SEC Filing
β€1
π¨ OpenMonero posted an update on the Monero drain they recently went through of approximately 399 XMR. Claiming it was due to a zero-day vulnerability that "had been hiding since the start of the project."
Dread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/0641ad60e064a450aa8a
Dread: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/0641ad60e064a450aa8a
β€2π2
π¨π΅πΉ CUF customer and contact data allegedly offered for sale
A forum actor claims to be selling approximately 263,000 records belonging to CUF, a private healthcare network in Portugal. The advertised dataset is divided into contact records, sample collection instructions, and customer unit information.
The data allegedly includes names, Portuguese tax identification numbers, email addresses, phone and fax numbers, physical addresses, dates of birth, gender, customer and unit codes, account details, marketing preferences, assigned representatives, payment methods, collection instructions, timestamps, and internal record identifiers.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to be selling approximately 263,000 records belonging to CUF, a private healthcare network in Portugal. The advertised dataset is divided into contact records, sample collection instructions, and customer unit information.
The data allegedly includes names, Portuguese tax identification numbers, email addresses, phone and fax numbers, physical addresses, dates of birth, gender, customer and unit codes, account details, marketing preferences, assigned representatives, payment methods, collection instructions, timestamps, and internal record identifiers.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¨π²π½ Locatel citizen records allegedly leaked
A forum actor claims to have leaked a dataset belonging to Locatel, a public information and assistance service operating in Mexico. The listing advertises 363,954 citizen records.
Published samples allegedly contain names, paternal and maternal surnames, RFC tax identifiers, street addresses, neighborhoods, municipalities, postal codes, phone numbers, gender, email addresses, and internal classification fields.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to have leaked a dataset belonging to Locatel, a public information and assistance service operating in Mexico. The listing advertises 363,954 citizen records.
Published samples allegedly contain names, paternal and maternal surnames, RFC tax identifiers, street addresses, neighborhoods, municipalities, postal codes, phone numbers, gender, email addresses, and internal classification fields.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨ pCloud password manager credential checker allegedly offered for sale
A forum seller is advertising βpCloud Pass,β a Python-based credential-checking tool designed to validate pCloud accounts through proxy networks and extract data stored inside password vaults.
The listing claims the tool can download saved usernames and passwords, notes, cryptocurrency seed phrases in multiple languages, and private keys in HEX, WIF, and EVM formats.
It reportedly supports HTTP, SOCKS4, and SOCKS5 proxies and can process approximately 2,500 accounts per minute using 100 threads. Compiled and source-code versions are advertised separately.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum seller is advertising βpCloud Pass,β a Python-based credential-checking tool designed to validate pCloud accounts through proxy networks and extract data stored inside password vaults.
The listing claims the tool can download saved usernames and passwords, notes, cryptocurrency seed phrases in multiple languages, and private keys in HEX, WIF, and EVM formats.
It reportedly supports HTTP, SOCKS4, and SOCKS5 proxies and can process approximately 2,500 accounts per minute using 100 threads. Compiled and source-code versions are advertised separately.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π1
π¨π«π· ENGIE Green customer data allegedly compromised
A forum actor claims to have compromised ENGIE Green, a French renewable energy company, through an SQL injection vulnerability. The actor is demanding contact from the company and threatening to release customer data, internal documents, and a complete SQL dump.
The post claims 621,019 customer records were obtained and includes samples from the companyβs WordPress user database. The exposed information allegedly includes employee names, corporate email addresses, usernames, password hashes, account registration dates, activation keys, and administrative account details.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to have compromised ENGIE Green, a French renewable energy company, through an SQL injection vulnerability. The actor is demanding contact from the company and threatening to release customer data, internal documents, and a complete SQL dump.
The post claims 621,019 customer records were obtained and includes samples from the companyβs WordPress user database. The exposed information allegedly includes employee names, corporate email addresses, usernames, password hashes, account registration dates, activation keys, and administrative account details.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¨π―π΅ Mama Works user database allegedly offered for sale
A forum actor claims to be selling a database belonging to Mama Works, a Japanese employment platform focused on connecting homemakers with flexible work opportunities. The listing advertises 322,537 user records in CSV format for $7,000.
Published samples allegedly contain names, names written in kana, email addresses, passwords, gender, dates of birth, ages, postal codes, prefectures, districts, house numbers, residential details, phone numbers, university information, account creation dates, and last login timestamps.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A forum actor claims to be selling a database belonging to Mama Works, a Japanese employment platform focused on connecting homemakers with flexible work opportunities. The listing advertises 322,537 user records in CSV format for $7,000.
Published samples allegedly contain names, names written in kana, email addresses, passwords, gender, dates of birth, ages, postal codes, prefectures, districts, house numbers, residential details, phone numbers, university information, account creation dates, and last login timestamps.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π²π½ Nayarit State Health System patient database allegedly leaked
A forum actor claims to have leaked a database belonging to the Sistema de Salud del Estado de Nayarit, the public healthcare system serving the Mexican state of Nayarit.
The post advertises 60,184 patient records in CSV and JSON formats. The data allegedly includes patient identifiers, names, paternal and maternal surnames, sex, CURP identifiers, home addresses, dates of birth, medical record numbers, healthcare services, and affiliation numbers.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum actor claims to have leaked a database belonging to the Sistema de Salud del Estado de Nayarit, the public healthcare system serving the Mexican state of Nayarit.
The post advertises 60,184 patient records in CSV and JSON formats. The data allegedly includes patient identifiers, names, paternal and maternal surnames, sex, CURP identifiers, home addresses, dates of birth, medical record numbers, healthcare services, and affiliation numbers.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
π¨ Ling App user database allegedly leaked
A forum actor claims to have leaked a complete export belonging to Ling App, a gamified language-learning platform. The listing advertises 5,970,006 deduplicated user profiles spanning 2022 through November 2025, including 2,377,076 profiles with unique email addresses and 166,446 paying subscribers across 238 countries.
The data allegedly includes names, email and IP addresses, location details, device identifiers, operating system information, authentication methods, subscription and payment status, transaction identifiers, purchase timestamps, and hundreds of account activity fields covering language progress, study time, streaks, fluency, and onboarding.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to have leaked a complete export belonging to Ling App, a gamified language-learning platform. The listing advertises 5,970,006 deduplicated user profiles spanning 2022 through November 2025, including 2,377,076 profiles with unique email addresses and 166,446 paying subscribers across 238 countries.
The data allegedly includes names, email and IP addresses, location details, device identifiers, operating system information, authentication methods, subscription and payment status, transaction identifiers, purchase timestamps, and hundreds of account activity fields covering language progress, study time, streaks, fluency, and onboarding.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
π¨ Business and individual lead databases allegedly offered for sale
A forum seller is advertising email and contact databases containing records associated with businesses and individuals. The actor claims the information was gathered from credible sources, regularly updated, and can be purchased for randomly selected or specific countries.
The advertised records allegedly include email addresses, full names, first and last names, mobile numbers, telecommunications providers, and countries of origin. Pricing starts at $29 for 10,000 records, with 100,000 records offered for $149 and one million records for $500.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
A forum seller is advertising email and contact databases containing records associated with businesses and individuals. The actor claims the information was gathered from credible sources, regularly updated, and can be purchased for randomly selected or specific countries.
The advertised records allegedly include email addresses, full names, first and last names, mobile numbers, telecommunications providers, and countries of origin. Pricing starts at $29 for 10,000 records, with 100,000 records offered for $149 and one million records for $500.
This claim is currently unverified.
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
π¨π«π· Two million French personal records allegedly offered for sale
A forum actor claims to be selling a 2026 dataset containing approximately two million records associated with individuals in France. The full collection is priced at $2,000.
Published samples allegedly contain names, email addresses, phone numbers, street addresses, house numbers, cities, postal codes, and dates of birth.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
A forum actor claims to be selling a 2026 dataset containing approximately two million records associated with individuals in France. The full collection is priced at $2,000.
Published samples allegedly contain names, email addresses, phone numbers, street addresses, house numbers, cities, postal codes, and dates of birth.
This claim is currently unverified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials