🔪 Slice For Life - Part 2 🔪
4.3K subscribers
804 photos
37 videos
743 links
Download Telegram
‼️ New Ransomware Group: L group

Onion: http://4zrjdyuq4sjogm2epwwoleegquavhwo3o7fakstnlgox6guqt3qpe4qd[.]onion
2
🚨🇨🇴 Campoalto employee credentials and personal data allegedly leaked

A forum actor claims to have breached Campoalto, a Colombian education and vocational training institution, and published data taken from its internal systems.

The post allegedly includes:

• Employee usernames and passwords
• A file containing names and surnames
• Group or organizational information
• A screenshot presented as evidence of access
• Claims of additional compromised information

The actor says the intrusion was carried out in retaliation over the institution’s alleged treatment of employees.

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
Going forward, I will delete any Free accounts that have not been accessed in 30 days. This helps keep things clean.

This does not apply to paid accounts. If your account is paid and has not been accessed for more than 30 days, it will still be there. 💙

You are free to sign up again at any point.
‼️ Helix leak site

Onion IOC: http://helixr2sncrd3ndsz5oho6mzqw3x5u7mvox5zcsngc5wm7v4l5k7oryd[.]onion
😁5
🚨🇮🇳 Pulse Secure VPN access to major Indian financial services company allegedly offered for sale

A forum actor claims to be selling VPN access to an unidentified financial services organization in India with estimated annual revenue between $1 billion and $5 billion.

The advertised access allegedly includes:

• Pulse Secure VPN access
• Local administrator privileges
• Access to a network containing approximately 10,000+ hosts
• Carbon Black deployed as the organization’s AV/EDR solution

The seller did not publicly identify the affected company or disclose a sale price.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇲🇽 Mérida military service applicant database allegedly leaked

A forum actor claims to have leaked a database containing applicants for Mexico’s Cartilla del Servicio Militar Nacional in Mérida, Yucatán, covering records from 2020 through 2026.

The exposed data allegedly includes:

• Full names and email addresses
• Parents’ and guardians’ names
• Nationality and naturalization information
• Dates and places of birth
• CURP identifiers
• Phone numbers
• Home addresses and postal codes
• Education, school and grade information
• Occupation and employment details
• Marital status
• Blood type
• Disability information
• Military service application and processing details
• Application status and issuance dates

A sample containing personal information was published alongside the post, with the full CSV reportedly distributed through Telegram.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Framework customer data exposed after Metabase zero-day breach

Computer maker Framework says all customers were affected after attackers compromised its cloud instance at business intelligence provider Metabase.

Exposed information includes:

• Names
• Email addresses
• Phone numbers
• Physical addresses

Framework says order and payment information was not included.

Metabase says attackers exploited an unknown zero-day affecting versions 1.58 and later, which could allow access to customer instances and connected data.

The vulnerability has been patched, and Metabase Cloud instances have been updated.

Framework has not disclosed the total number of affected customers.

Source: https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/

Image: Reddit
🚨 WordPress patches XSS2Shell flaw that could lead to server code execution

CVE-2026-64638 is a CVSS 8.9 pre-authentication XSS vulnerability in the WordPress login screen.

The XSS itself requires no account. Researchers at pwn.ai demonstrated how it can be chained against a logged-in administrator to reach PHP code execution after social engineering the admin into interacting with an attacker-controlled page.

A successful chain could potentially allow attackers to:

• Create API credentials
• Gain authenticated REST access
• Upload malicious plugin files
• Execute PHP on the server
• Access WordPress secrets and database credentials

WordPress 7.0.3 fixes the flaw, with patches backported through the 4.7 branch.

NHS England says exploitation is likely following the release of technical details and a PoC.

WordPress has not reported confirmed exploitation in the wild as of August 7.

Update immediately.
Media is too big
VIEW IN TELEGRAM
The Secret Market for Zero Day Exploits

Video Credit: youtube.com/Vice
3
I have added 8 forums to the Forums Status Monitoring section on the threat feed, that are currently being onboarded. Almost all of them are of the carding variety. CTRL+SHIFT+R to refresh the page. No dates as to completion, but you will know once done.
🔥1
🚨‼️🚨 URGENT 🚨‼️🚨

BTCPay Server disclosed Friday that a critical vulnerability is being actively exploited and urged users to update their servers to version 2.4.2 immediately, according to the project’s official X account.

The team warned that user funds could be at risk, although it remains unclear how many servers have been compromised or whether any funds have been stolen.

Users who cannot update immediately were advised to shut down their BTCPay Server instances to prevent potential unauthorized access until the patch can be applied.

Details about the vulnerability and the ongoing exploitation remain limited. The Block said it contacted BTCPay Server for additional information.

Source: https://x.com/BtcpayServer/status/2085755643659522240
🚨🇫🇷 AFPABox user data and administrator access allegedly leaked

A forum actor claims to have leaked data associated with AFPABox, a platform connected to AFPA, France’s national adult vocational training organization. The post also claims administrator access to the platform.

The leak allegedly includes 101 user records containing:

• First and last names
• Positions and account statuses
• User messages
• Ages and gender information
• Registration dates
• Local time and language settings
• Last-visit timestamps
• User identifiers

This claim is currently unverified.

💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
‼️ Exploit Forum:

Exploit[.]in:

198[.]144[.]121[.]93
🇳🇱 ASN: 206264
Organization: Amarutu Technology Ltd

send[.]exploit[.]in:

195[.]206[.]181[.]20
🇬🇧 ASN: 25369
Organization: Hydra Communications Ltd

notes[.]exploit[.]in

31[.]220[.]0[.]206
🇧🇿 ASN: 206264
Organization: Amarutu Technology Ltd
😭31