βΌοΈ New Dark Web Informer Blog Post!
Title: ACRE Africa Breach Allegedly Exposes 14,300 Smallholder Farmers Alongside Source Code and Private Keys
Link: https://darkwebinformer.com/acre-africa-breach-allegedly-exposes-14-300-smallholder-farmers-alongside-source-code-and-private-keys/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: ACRE Africa Breach Allegedly Exposes 14,300 Smallholder Farmers Alongside Source Code and Private Keys
Link: https://darkwebinformer.com/acre-africa-breach-allegedly-exposes-14-300-smallholder-farmers-alongside-source-code-and-private-keys/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
ACRE Africa Breach Allegedly Exposes 14,300 Smallholder Farmers Alongside Source Code and Private Keys
A forum user posting as 888 has published what they describe as a breach of ACRE Africa, an authorised insurance intermediary providing agricultural and climate risk cover to smallholder farmers across the continent.
βΌοΈ New Dark Web Informer Blog Post!
Title: Bloctel Do-Not-Call Register Allegedly Leaked, 3 Million French Phone Numbers Published Free
Link: https://darkwebinformer.com/bloctel-do-not-call-register-allegedly-leaked-3-million-french-phone-numbers-published-free/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Bloctel Do-Not-Call Register Allegedly Leaked, 3 Million French Phone Numbers Published Free
Link: https://darkwebinformer.com/bloctel-do-not-call-register-allegedly-leaked-3-million-french-phone-numbers-published-free/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Bloctel Do-Not-Call Register Allegedly Leaked, 3 Million French Phone Numbers Published Free
An actor posting as Cybernox has published what they describe as user data from Bloctel, the French government's official register allowing consumers to opt out of unsolicited telephone marketing.
βΌοΈ New Dark Web Informer Blog Post!
Title: Mexican Presidency's Citizen Petition System Allegedly Breached, 400,000 Citizens and 59 Federal Agencies Exposed
Link: https://darkwebinformer.com/mexican-presidencys-citizen-petition-system-allegedly-breached-400-000-citizens-and-59-federal-agencies-exposed/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Mexican Presidency's Citizen Petition System Allegedly Breached, 400,000 Citizens and 59 Federal Agencies Exposed
Link: https://darkwebinformer.com/mexican-presidencys-citizen-petition-system-allegedly-breached-400-000-citizens-and-59-federal-agencies-exposed/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Mexican Presidency's Citizen Petition System Allegedly Breached, 400,000 Citizens and 59 Federal Agencies Exposed
An actor posting as cenfecracked claims to have obtained the database behind the Sistema de AtenciΓ³n Ciudadana, the platform through which members of the public submit petitions and requests for assistance to the Mexican Presidency.
π¨π²π½ MΓ©rida military service applicant database allegedly leaked
β
A forum actor claims to have leaked a database containing applicants for Mexicoβs Cartilla del Servicio Militar Nacional in MΓ©rida, YucatΓ‘n, covering records from 2020 through 2026.
β
The exposed data allegedly includes:
β
β’ Full names and email addresses
β’ Parentsβ and guardiansβ names
β’ Nationality and naturalization information
β’ Dates and places of birth
β’ CURP identifiers
β’ Phone numbers
β’ Home addresses and postal codes
β’ Education, school and grade information
β’ Occupation and employment details
β’ Marital status
β’ Blood type
β’ Disability information
β’ Military service application and processing details
β’ Application status and issuance dates
β
A sample containing personal information was published alongside the post, with the full CSV reportedly distributed through Telegram.
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
A forum actor claims to have leaked a database containing applicants for Mexicoβs Cartilla del Servicio Militar Nacional in MΓ©rida, YucatΓ‘n, covering records from 2020 through 2026.
β
The exposed data allegedly includes:
β
β’ Full names and email addresses
β’ Parentsβ and guardiansβ names
β’ Nationality and naturalization information
β’ Dates and places of birth
β’ CURP identifiers
β’ Phone numbers
β’ Home addresses and postal codes
β’ Education, school and grade information
β’ Occupation and employment details
β’ Marital status
β’ Blood type
β’ Disability information
β’ Military service application and processing details
β’ Application status and issuance dates
β
A sample containing personal information was published alongside the post, with the full CSV reportedly distributed through Telegram.
β
This claim is currently unverified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨ Framework customer data exposed after Metabase zero-day breach
Computer maker Framework says all customers were affected after attackers compromised its cloud instance at business intelligence provider Metabase.
Exposed information includes:
β’ Names
β’ Email addresses
β’ Phone numbers
β’ Physical addresses
Framework says order and payment information was not included.
Metabase says attackers exploited an unknown zero-day affecting versions 1.58 and later, which could allow access to customer instances and connected data.
The vulnerability has been patched, and Metabase Cloud instances have been updated.
Framework has not disclosed the total number of affected customers.
Source: https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/
Image: Reddit
Computer maker Framework says all customers were affected after attackers compromised its cloud instance at business intelligence provider Metabase.
Exposed information includes:
β’ Names
β’ Email addresses
β’ Phone numbers
β’ Physical addresses
Framework says order and payment information was not included.
Metabase says attackers exploited an unknown zero-day affecting versions 1.58 and later, which could allow access to customer instances and connected data.
The vulnerability has been patched, and Metabase Cloud instances have been updated.
Framework has not disclosed the total number of affected customers.
Source: https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/
Image: Reddit
βΌοΈ New Dark Web Informer Blog Post!
Title: LEVI STRAUSS & CO. has Filed Form 8-K Due to a Cybersecurity Incident
Link: https://darkwebinformer.com/levi-strauss-co-has-filed-form-8-k-due-to-a-cybersecurity-incident/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: LEVI STRAUSS & CO. has Filed Form 8-K Due to a Cybersecurity Incident
Link: https://darkwebinformer.com/levi-strauss-co-has-filed-form-8-k-due-to-a-cybersecurity-incident/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
LEVI STRAUSS & CO. has Filed Form 8-K Due to a Cybersecurity Incident
Levi Strauss & Co. (the βCompanyβ) recently detected that the Company experienced a cybersecurity incident in which an unauthorized third party gained access to Company files through social engineering techniques
βΌοΈ New Dark Web Informer Blog Post!
Title: DepEd Schools Division of Iloilo Allegedly Breached, Records on Staff, Students and Families With Fingerprint Templates Leaked
Link: https://darkwebinformer.com/deped-schools-division-of-iloilo-allegedly-breached-records-on-staff-students-and-families-with-fingerprint-templates-leaked/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: DepEd Schools Division of Iloilo Allegedly Breached, Records on Staff, Students and Families With Fingerprint Templates Leaked
Link: https://darkwebinformer.com/deped-schools-division-of-iloilo-allegedly-breached-records-on-staff-students-and-families-with-fingerprint-templates-leaked/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
DepEd Schools Division of Iloilo Allegedly Breached, Records on Staff, Students and Families With Fingerprint Templates Leaked
An actor posting as citizengod has published what they describe as the database and source code of the Schools Division of Iloilo, the local office of the Philippines' Department of Education, which administers schooling from kindergarten to senior high school.
β€1
π¨ WordPress patches XSS2Shell flaw that could lead to server code execution
CVE-2026-64638 is a CVSS 8.9 pre-authentication XSS vulnerability in the WordPress login screen.
The XSS itself requires no account. Researchers at pwn.ai demonstrated how it can be chained against a logged-in administrator to reach PHP code execution after social engineering the admin into interacting with an attacker-controlled page.
A successful chain could potentially allow attackers to:
β’ Create API credentials
β’ Gain authenticated REST access
β’ Upload malicious plugin files
β’ Execute PHP on the server
β’ Access WordPress secrets and database credentials
WordPress 7.0.3 fixes the flaw, with patches backported through the 4.7 branch.
NHS England says exploitation is likely following the release of technical details and a PoC.
WordPress has not reported confirmed exploitation in the wild as of August 7.
Update immediately.
CVE-2026-64638 is a CVSS 8.9 pre-authentication XSS vulnerability in the WordPress login screen.
The XSS itself requires no account. Researchers at pwn.ai demonstrated how it can be chained against a logged-in administrator to reach PHP code execution after social engineering the admin into interacting with an attacker-controlled page.
A successful chain could potentially allow attackers to:
β’ Create API credentials
β’ Gain authenticated REST access
β’ Upload malicious plugin files
β’ Execute PHP on the server
β’ Access WordPress secrets and database credentials
WordPress 7.0.3 fixes the flaw, with patches backported through the 4.7 branch.
NHS England says exploitation is likely following the release of technical details and a PoC.
WordPress has not reported confirmed exploitation in the wild as of August 7.
Update immediately.
I have added 8 forums to the Forums Status Monitoring section on the threat feed, that are currently being onboarded. Almost all of them are of the carding variety. CTRL+SHIFT+R to refresh the page. No dates as to completion, but you will know once done.
π₯1
π¨βΌοΈπ¨ URGENT π¨βΌοΈπ¨
BTCPay Server disclosed Friday that a critical vulnerability is being actively exploited and urged users to update their servers to version 2.4.2 immediately, according to the projectβs official X account.
The team warned that user funds could be at risk, although it remains unclear how many servers have been compromised or whether any funds have been stolen.
Users who cannot update immediately were advised to shut down their BTCPay Server instances to prevent potential unauthorized access until the patch can be applied.
Details about the vulnerability and the ongoing exploitation remain limited. The Block said it contacted BTCPay Server for additional information.
Source: https://x.com/BtcpayServer/status/2085755643659522240
BTCPay Server disclosed Friday that a critical vulnerability is being actively exploited and urged users to update their servers to version 2.4.2 immediately, according to the projectβs official X account.
The team warned that user funds could be at risk, although it remains unclear how many servers have been compromised or whether any funds have been stolen.
Users who cannot update immediately were advised to shut down their BTCPay Server instances to prevent potential unauthorized access until the patch can be applied.
Details about the vulnerability and the ongoing exploitation remain limited. The Block said it contacted BTCPay Server for additional information.
Source: https://x.com/BtcpayServer/status/2085755643659522240
X (formerly Twitter)
BTCPay Server (@BtcpayServer) on X
There is a critical vulnerability being actively exploited on BTCPay Server, which can result in the loss of funds.
Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Serve
Please update your BTCPayServer to 2.4.2 by going to Admin Dashboard -> Serve
π¨π«π· AFPABox user data and administrator access allegedly leaked
β
A forum actor claims to have leaked data associated with AFPABox, a platform connected to AFPA, Franceβs national adult vocational training organization. The post also claims administrator access to the platform.
β
The leak allegedly includes 101 user records containing:
β
β’ First and last names
β’ Positions and account statuses
β’ User messages
β’ Ages and gender information
β’ Registration dates
β’ Local time and language settings
β’ Last-visit timestamps
β’ User identifiers
β
This claim is currently unverified.
β
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
β
A forum actor claims to have leaked data associated with AFPABox, a platform connected to AFPA, Franceβs national adult vocational training organization. The post also claims administrator access to the platform.
β
The leak allegedly includes 101 user records containing:
β
β’ First and last names
β’ Positions and account statuses
β’ User messages
β’ Ages and gender information
β’ Registration dates
β’ Local time and language settings
β’ Last-visit timestamps
β’ User identifiers
β
This claim is currently unverified.
β
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: http://darkwebinformer.com/pricing
βΌοΈ Exploit Forum:
Exploit[.]in:
198[.]144[.]121[.]93
π³π± ASN: 206264
Organization: Amarutu Technology Ltd
send[.]exploit[.]in:
195[.]206[.]181[.]20
π¬π§ ASN: 25369
Organization: Hydra Communications Ltd
notes[.]exploit[.]in
31[.]220[.]0[.]206
π§πΏ ASN: 206264
Organization: Amarutu Technology Ltd
Exploit[.]in:
198[.]144[.]121[.]93
π³π± ASN: 206264
Organization: Amarutu Technology Ltd
send[.]exploit[.]in:
195[.]206[.]181[.]20
π¬π§ ASN: 25369
Organization: Hydra Communications Ltd
notes[.]exploit[.]in
31[.]220[.]0[.]206
π§πΏ ASN: 206264
Organization: Amarutu Technology Ltd
π3β€1
IP Information for 89.39.149.156
ASN: 19624
ISP / Org: SERVERROOM - Data Room, Inc, US
Country: RO
Network Range: 89.39.149.0/24
ASN: 19624
ISP / Org: SERVERROOM - Data Room, Inc, US
Country: RO
Network Range: 89.39.149.0/24
β€1
πͺ Slice For Life - Part 2 πͺ
βΌοΈ Exploit Forum: Exploit[.]in: 198[.]144[.]121[.]93 π³π± ASN: 206264 Organization: Amarutu Technology Ltd send[.]exploit[.]in: 195[.]206[.]181[.]20 π¬π§ ASN: 25369 Organization: Hydra Communications Ltd notes[.]exploit[.]in 31[.]220[.]0[.]206 π§πΏ ASN: 206264β¦
forum[.]exploit[.]in
89[.]39[.]149[.]156
π·π΄ ASN: 19624
Organization: Data Room, Inc
89[.]39[.]149[.]156
π·π΄ ASN: 19624
Organization: Data Room, Inc
β€1
If you support this forum... go fuck yourself. Amarutu Technology Ltd, which operates the DDoS protection and hosting provider KoDDOS, has been identified in European parliamentary and academic monitoring reports as infrastructure associated with significant levels of online abuse. Research examining network abuse has also flagged its autonomous system as a notable hosting provider linked to the distribution of child sexual abuse material (CSAM).
β€4
1/2π¨ Cl0p Ransomware claims 44 victims
π¨π³ Mindray - A global medical technology manufacturer. The listing claims 50 GB of databases and project files, with listed revenue of $5 billion.
πΊπΈ Continental Aerospace Technologies - A U.S. aerospace manufacturer specializing in aircraft engines and components. The listing claims 347 GB of databases and project files, with listed revenue of $91 million.
net****** - Redacted organization. The listing claims 230 GB of projects, CAD files, backups, and Windchill files, with listed revenue of $370.9 million.
sh****** - Redacted organization. The listing claims 89 GB of engineering drawings, facility photographs, facility testing reports, and project plans, with listed revenue of $2.673 trillion.
g****** - Redacted organization. The listing claims 391 GB of software backups, system files, and projects, with listed revenue of $113 billion.
fis****** - Redacted organization. The listing claims 874 GB of projects, CAD files, Windchill files, and software, with listed revenue of $21.2 billion.
phi****** - Redacted organization. The listing claims 13.5 GB of PDF drawings, diagrams, and blueprints, with listed revenue of $20.7 billion.
ald****** - Redacted organization. The listing claims 424 GB of TSV files, software, projects, and CAD files, with listed revenue of $14.8 billion.
jr**** - Redacted organization. The listing claims 556.4 GB of CAD files, PDF drawings, diagrams, product presentations, specifications, manuals, and instructions, with listed revenue of $7.8 billion.
toa****** - Redacted organization. The listing claims 215 GB of project data, database backups, and logs, with listed revenue of $6.4 billion.
lar****** - Redacted organization. The listing claims 56 GB of project files and software, with listed revenue of $1.7 billion.
sta****** - Redacted organization. The listing claims 3,030 GB of databases and project data, with listed revenue of $939.2 million.
par****** - Redacted organization. The listing claims 24 GB of databases, projects, CAD files, and backups, with listed revenue of $475.7 million.
mam****** - Redacted organization. The listing claims 136 GB of PNG and Windchill files, with listed revenue of $281 million.
cor****** - Redacted organization. The listing claims 3,684 GB of databases, projects, PDFs, TXT files, and DOC files, with listed revenue of $269.8 million.
mam****** - Redacted organization. The listing claims 1.18 GB of databases and project files, with listed revenue of $131 million.
tri****** - Redacted organization. The listing claims 1,579.9 GB of databases and project files, with listed revenue of $1 billion.
sma****** - Redacted organization. The listing claims 6.08 GB of databases and project files, with listed revenue of $113 million.
suu****** - Redacted organization. The listing claims 1,470 GB of databases and project files, with listed revenue of $111 million.
bri****** - Redacted organization. The listing claims 22.4 GB of databases and project files, with listed revenue of $100 million.
jpm****** - Redacted organization. The listing claims 75.4 GB of databases and project files, with listed revenue of $400 million.
clo****** - Redacted organization. The listing claims 651 GB of databases and project files, with listed revenue of $400 million.
ato****** - Redacted organization. The listing claims 980 GB of databases and project files, with listed revenue of $68 million.
hon****** - Redacted organization. The listing claims 1,588 GB of databases and project files, with listed revenue of $470 million.
int****** - Redacted organization. The listing claims 261 GB of databases, projects, PDFs, XLSX, XLS, and DOCX files, with listed revenue of $31 million.
int****** - Redacted organization. The listing claims 271 GB of databases, projects, backups, software installers, updates, and XML files, with listed revenue of $27 million.
gal****** - Redacted organization. The listing claims 382 GB of databases, projects, project backups, and SQL database backups, with listed revenue of $15 million.
π¨π³ Mindray - A global medical technology manufacturer. The listing claims 50 GB of databases and project files, with listed revenue of $5 billion.
πΊπΈ Continental Aerospace Technologies - A U.S. aerospace manufacturer specializing in aircraft engines and components. The listing claims 347 GB of databases and project files, with listed revenue of $91 million.
net****** - Redacted organization. The listing claims 230 GB of projects, CAD files, backups, and Windchill files, with listed revenue of $370.9 million.
sh****** - Redacted organization. The listing claims 89 GB of engineering drawings, facility photographs, facility testing reports, and project plans, with listed revenue of $2.673 trillion.
g****** - Redacted organization. The listing claims 391 GB of software backups, system files, and projects, with listed revenue of $113 billion.
fis****** - Redacted organization. The listing claims 874 GB of projects, CAD files, Windchill files, and software, with listed revenue of $21.2 billion.
phi****** - Redacted organization. The listing claims 13.5 GB of PDF drawings, diagrams, and blueprints, with listed revenue of $20.7 billion.
ald****** - Redacted organization. The listing claims 424 GB of TSV files, software, projects, and CAD files, with listed revenue of $14.8 billion.
jr**** - Redacted organization. The listing claims 556.4 GB of CAD files, PDF drawings, diagrams, product presentations, specifications, manuals, and instructions, with listed revenue of $7.8 billion.
toa****** - Redacted organization. The listing claims 215 GB of project data, database backups, and logs, with listed revenue of $6.4 billion.
lar****** - Redacted organization. The listing claims 56 GB of project files and software, with listed revenue of $1.7 billion.
sta****** - Redacted organization. The listing claims 3,030 GB of databases and project data, with listed revenue of $939.2 million.
par****** - Redacted organization. The listing claims 24 GB of databases, projects, CAD files, and backups, with listed revenue of $475.7 million.
mam****** - Redacted organization. The listing claims 136 GB of PNG and Windchill files, with listed revenue of $281 million.
cor****** - Redacted organization. The listing claims 3,684 GB of databases, projects, PDFs, TXT files, and DOC files, with listed revenue of $269.8 million.
mam****** - Redacted organization. The listing claims 1.18 GB of databases and project files, with listed revenue of $131 million.
tri****** - Redacted organization. The listing claims 1,579.9 GB of databases and project files, with listed revenue of $1 billion.
sma****** - Redacted organization. The listing claims 6.08 GB of databases and project files, with listed revenue of $113 million.
suu****** - Redacted organization. The listing claims 1,470 GB of databases and project files, with listed revenue of $111 million.
bri****** - Redacted organization. The listing claims 22.4 GB of databases and project files, with listed revenue of $100 million.
jpm****** - Redacted organization. The listing claims 75.4 GB of databases and project files, with listed revenue of $400 million.
clo****** - Redacted organization. The listing claims 651 GB of databases and project files, with listed revenue of $400 million.
ato****** - Redacted organization. The listing claims 980 GB of databases and project files, with listed revenue of $68 million.
hon****** - Redacted organization. The listing claims 1,588 GB of databases and project files, with listed revenue of $470 million.
int****** - Redacted organization. The listing claims 261 GB of databases, projects, PDFs, XLSX, XLS, and DOCX files, with listed revenue of $31 million.
int****** - Redacted organization. The listing claims 271 GB of databases, projects, backups, software installers, updates, and XML files, with listed revenue of $27 million.
gal****** - Redacted organization. The listing claims 382 GB of databases, projects, project backups, and SQL database backups, with listed revenue of $15 million.
β€1