🚨🇨🇴 Campoalto employee credentials and personal data allegedly leaked
⠀
A forum actor claims to have breached Campoalto, a Colombian education and vocational training institution, and published data taken from its internal systems.
⠀
The post allegedly includes:
⠀
• Employee usernames and passwords
• A file containing names and surnames
• Group or organizational information
• A screenshot presented as evidence of access
• Claims of additional compromised information
⠀
The actor says the intrusion was carried out in retaliation over the institution’s alleged treatment of employees.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
⠀
A forum actor claims to have breached Campoalto, a Colombian education and vocational training institution, and published data taken from its internal systems.
⠀
The post allegedly includes:
⠀
• Employee usernames and passwords
• A file containing names and surnames
• Group or organizational information
• A screenshot presented as evidence of access
• Claims of additional compromised information
⠀
The actor says the intrusion was carried out in retaliation over the institution’s alleged treatment of employees.
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
Going forward, I will delete any Free accounts that have not been accessed in 30 days. This helps keep things clean.
This does not apply to paid accounts. If your account is paid and has not been accessed for more than 30 days, it will still be there. 💙
You are free to sign up again at any point.
This does not apply to paid accounts. If your account is paid and has not been accessed for more than 30 days, it will still be there. 💙
You are free to sign up again at any point.
🔪 Slice For Life - Part 2 🔪
‼️ New Ransomware Group: L group Onion: http://4zrjdyuq4sjogm2epwwoleegquavhwo3o7fakstnlgox6guqt3qpe4qd[.]onion
Apache Server Status for L group Ransomware
/server-status
/server-status
🚨🇮🇳 Pulse Secure VPN access to major Indian financial services company allegedly offered for sale
⠀
A forum actor claims to be selling VPN access to an unidentified financial services organization in India with estimated annual revenue between $1 billion and $5 billion.
⠀
The advertised access allegedly includes:
⠀
• Pulse Secure VPN access
• Local administrator privileges
• Access to a network containing approximately 10,000+ hosts
• Carbon Black deployed as the organization’s AV/EDR solution
⠀
The seller did not publicly identify the affected company or disclose a sale price.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to be selling VPN access to an unidentified financial services organization in India with estimated annual revenue between $1 billion and $5 billion.
⠀
The advertised access allegedly includes:
⠀
• Pulse Secure VPN access
• Local administrator privileges
• Access to a network containing approximately 10,000+ hosts
• Carbon Black deployed as the organization’s AV/EDR solution
⠀
The seller did not publicly identify the affected company or disclose a sale price.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: ACRE Africa Breach Allegedly Exposes 14,300 Smallholder Farmers Alongside Source Code and Private Keys
Link: https://darkwebinformer.com/acre-africa-breach-allegedly-exposes-14-300-smallholder-farmers-alongside-source-code-and-private-keys/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: ACRE Africa Breach Allegedly Exposes 14,300 Smallholder Farmers Alongside Source Code and Private Keys
Link: https://darkwebinformer.com/acre-africa-breach-allegedly-exposes-14-300-smallholder-farmers-alongside-source-code-and-private-keys/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
ACRE Africa Breach Allegedly Exposes 14,300 Smallholder Farmers Alongside Source Code and Private Keys
A forum user posting as 888 has published what they describe as a breach of ACRE Africa, an authorised insurance intermediary providing agricultural and climate risk cover to smallholder farmers across the continent.
‼️ New Dark Web Informer Blog Post!
Title: Bloctel Do-Not-Call Register Allegedly Leaked, 3 Million French Phone Numbers Published Free
Link: https://darkwebinformer.com/bloctel-do-not-call-register-allegedly-leaked-3-million-french-phone-numbers-published-free/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Bloctel Do-Not-Call Register Allegedly Leaked, 3 Million French Phone Numbers Published Free
Link: https://darkwebinformer.com/bloctel-do-not-call-register-allegedly-leaked-3-million-french-phone-numbers-published-free/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Bloctel Do-Not-Call Register Allegedly Leaked, 3 Million French Phone Numbers Published Free
An actor posting as Cybernox has published what they describe as user data from Bloctel, the French government's official register allowing consumers to opt out of unsolicited telephone marketing.
‼️ New Dark Web Informer Blog Post!
Title: Mexican Presidency's Citizen Petition System Allegedly Breached, 400,000 Citizens and 59 Federal Agencies Exposed
Link: https://darkwebinformer.com/mexican-presidencys-citizen-petition-system-allegedly-breached-400-000-citizens-and-59-federal-agencies-exposed/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Mexican Presidency's Citizen Petition System Allegedly Breached, 400,000 Citizens and 59 Federal Agencies Exposed
Link: https://darkwebinformer.com/mexican-presidencys-citizen-petition-system-allegedly-breached-400-000-citizens-and-59-federal-agencies-exposed/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Mexican Presidency's Citizen Petition System Allegedly Breached, 400,000 Citizens and 59 Federal Agencies Exposed
An actor posting as cenfecracked claims to have obtained the database behind the Sistema de Atención Ciudadana, the platform through which members of the public submit petitions and requests for assistance to the Mexican Presidency.
🚨🇲🇽 Mérida military service applicant database allegedly leaked
⠀
A forum actor claims to have leaked a database containing applicants for Mexico’s Cartilla del Servicio Militar Nacional in Mérida, Yucatán, covering records from 2020 through 2026.
⠀
The exposed data allegedly includes:
⠀
• Full names and email addresses
• Parents’ and guardians’ names
• Nationality and naturalization information
• Dates and places of birth
• CURP identifiers
• Phone numbers
• Home addresses and postal codes
• Education, school and grade information
• Occupation and employment details
• Marital status
• Blood type
• Disability information
• Military service application and processing details
• Application status and issuance dates
⠀
A sample containing personal information was published alongside the post, with the full CSV reportedly distributed through Telegram.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
A forum actor claims to have leaked a database containing applicants for Mexico’s Cartilla del Servicio Militar Nacional in Mérida, Yucatán, covering records from 2020 through 2026.
⠀
The exposed data allegedly includes:
⠀
• Full names and email addresses
• Parents’ and guardians’ names
• Nationality and naturalization information
• Dates and places of birth
• CURP identifiers
• Phone numbers
• Home addresses and postal codes
• Education, school and grade information
• Occupation and employment details
• Marital status
• Blood type
• Disability information
• Military service application and processing details
• Application status and issuance dates
⠀
A sample containing personal information was published alongside the post, with the full CSV reportedly distributed through Telegram.
⠀
This claim is currently unverified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Framework customer data exposed after Metabase zero-day breach
Computer maker Framework says all customers were affected after attackers compromised its cloud instance at business intelligence provider Metabase.
Exposed information includes:
• Names
• Email addresses
• Phone numbers
• Physical addresses
Framework says order and payment information was not included.
Metabase says attackers exploited an unknown zero-day affecting versions 1.58 and later, which could allow access to customer instances and connected data.
The vulnerability has been patched, and Metabase Cloud instances have been updated.
Framework has not disclosed the total number of affected customers.
Source: https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/
Image: Reddit
Computer maker Framework says all customers were affected after attackers compromised its cloud instance at business intelligence provider Metabase.
Exposed information includes:
• Names
• Email addresses
• Phone numbers
• Physical addresses
Framework says order and payment information was not included.
Metabase says attackers exploited an unknown zero-day affecting versions 1.58 and later, which could allow access to customer instances and connected data.
The vulnerability has been patched, and Metabase Cloud instances have been updated.
Framework has not disclosed the total number of affected customers.
Source: https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/
Image: Reddit
‼️ New Dark Web Informer Blog Post!
Title: LEVI STRAUSS & CO. has Filed Form 8-K Due to a Cybersecurity Incident
Link: https://darkwebinformer.com/levi-strauss-co-has-filed-form-8-k-due-to-a-cybersecurity-incident/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: LEVI STRAUSS & CO. has Filed Form 8-K Due to a Cybersecurity Incident
Link: https://darkwebinformer.com/levi-strauss-co-has-filed-form-8-k-due-to-a-cybersecurity-incident/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
LEVI STRAUSS & CO. has Filed Form 8-K Due to a Cybersecurity Incident
Levi Strauss & Co. (the “Company”) recently detected that the Company experienced a cybersecurity incident in which an unauthorized third party gained access to Company files through social engineering techniques
‼️ New Dark Web Informer Blog Post!
Title: DepEd Schools Division of Iloilo Allegedly Breached, Records on Staff, Students and Families With Fingerprint Templates Leaked
Link: https://darkwebinformer.com/deped-schools-division-of-iloilo-allegedly-breached-records-on-staff-students-and-families-with-fingerprint-templates-leaked/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: DepEd Schools Division of Iloilo Allegedly Breached, Records on Staff, Students and Families With Fingerprint Templates Leaked
Link: https://darkwebinformer.com/deped-schools-division-of-iloilo-allegedly-breached-records-on-staff-students-and-families-with-fingerprint-templates-leaked/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
DepEd Schools Division of Iloilo Allegedly Breached, Records on Staff, Students and Families With Fingerprint Templates Leaked
An actor posting as citizengod has published what they describe as the database and source code of the Schools Division of Iloilo, the local office of the Philippines' Department of Education, which administers schooling from kindergarten to senior high school.
❤1
🚨 WordPress patches XSS2Shell flaw that could lead to server code execution
CVE-2026-64638 is a CVSS 8.9 pre-authentication XSS vulnerability in the WordPress login screen.
The XSS itself requires no account. Researchers at pwn.ai demonstrated how it can be chained against a logged-in administrator to reach PHP code execution after social engineering the admin into interacting with an attacker-controlled page.
A successful chain could potentially allow attackers to:
• Create API credentials
• Gain authenticated REST access
• Upload malicious plugin files
• Execute PHP on the server
• Access WordPress secrets and database credentials
WordPress 7.0.3 fixes the flaw, with patches backported through the 4.7 branch.
NHS England says exploitation is likely following the release of technical details and a PoC.
WordPress has not reported confirmed exploitation in the wild as of August 7.
Update immediately.
CVE-2026-64638 is a CVSS 8.9 pre-authentication XSS vulnerability in the WordPress login screen.
The XSS itself requires no account. Researchers at pwn.ai demonstrated how it can be chained against a logged-in administrator to reach PHP code execution after social engineering the admin into interacting with an attacker-controlled page.
A successful chain could potentially allow attackers to:
• Create API credentials
• Gain authenticated REST access
• Upload malicious plugin files
• Execute PHP on the server
• Access WordPress secrets and database credentials
WordPress 7.0.3 fixes the flaw, with patches backported through the 4.7 branch.
NHS England says exploitation is likely following the release of technical details and a PoC.
WordPress has not reported confirmed exploitation in the wild as of August 7.
Update immediately.
I have added 8 forums to the Forums Status Monitoring section on the threat feed, that are currently being onboarded. Almost all of them are of the carding variety. CTRL+SHIFT+R to refresh the page. No dates as to completion, but you will know once done.
🔥1
🚨‼️🚨 URGENT 🚨‼️🚨
BTCPay Server disclosed Friday that a critical vulnerability is being actively exploited and urged users to update their servers to version 2.4.2 immediately, according to the project’s official X account.
The team warned that user funds could be at risk, although it remains unclear how many servers have been compromised or whether any funds have been stolen.
Users who cannot update immediately were advised to shut down their BTCPay Server instances to prevent potential unauthorized access until the patch can be applied.
Details about the vulnerability and the ongoing exploitation remain limited. The Block said it contacted BTCPay Server for additional information.
Source: https://x.com/BtcpayServer/status/2085755643659522240
BTCPay Server disclosed Friday that a critical vulnerability is being actively exploited and urged users to update their servers to version 2.4.2 immediately, according to the project’s official X account.
The team warned that user funds could be at risk, although it remains unclear how many servers have been compromised or whether any funds have been stolen.
Users who cannot update immediately were advised to shut down their BTCPay Server instances to prevent potential unauthorized access until the patch can be applied.
Details about the vulnerability and the ongoing exploitation remain limited. The Block said it contacted BTCPay Server for additional information.
Source: https://x.com/BtcpayServer/status/2085755643659522240
X (formerly Twitter)
BTCPay Server (@BtcpayServer) on X
There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.
Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Serve
Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Serve
🚨🇫🇷 AFPABox user data and administrator access allegedly leaked
⠀
A forum actor claims to have leaked data associated with AFPABox, a platform connected to AFPA, France’s national adult vocational training organization. The post also claims administrator access to the platform.
⠀
The leak allegedly includes 101 user records containing:
⠀
• First and last names
• Positions and account statuses
• User messages
• Ages and gender information
• Registration dates
• Local time and language settings
• Last-visit timestamps
• User identifiers
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
⠀
A forum actor claims to have leaked data associated with AFPABox, a platform connected to AFPA, France’s national adult vocational training organization. The post also claims administrator access to the platform.
⠀
The leak allegedly includes 101 user records containing:
⠀
• First and last names
• Positions and account statuses
• User messages
• Ages and gender information
• Registration dates
• Local time and language settings
• Last-visit timestamps
• User identifiers
⠀
This claim is currently unverified.
⠀
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing