πŸ”ͺ That Dark Web Guy - Part 3 πŸ”ͺ
4.97K subscribers
1.23K photos
68 videos
1.09K links
Download Telegram
πŸš¨πŸ‡ΊπŸ‡Έ SteelSeries TeamCity environment allegedly breached, employee data and credentials claimed exposed
β €
A cybercrime forum user claims to have breached the SteelSeries TeamCity environment and obtained access to internal project-related data. The post claims the database contains information belonging to 35 users with employee accounts.
β €
The advertised data includes:
β €
β€’ Employee account information
β€’ User IDs
β€’ Names
β€’ Email addresses
β€’ Last login details
β€’ User roles
β€’ Azure signing keys
β€’ VCS credentials
β€’ SSH keys
β€’ SVN-related credentials
β €
The forum post includes a sample of the allegedly exposed user records and claims additional data is available for download.
β €
SteelSeries is a gaming peripherals company known for products including gaming mice, keyboards, headsets and accessories.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ CVE PoC Published: CVE-2026-76565 - Reflected XSS in PhocaCart

GitHub: https://github.com/toanln-cov/CVE-2026-76565

A proof-of-concept has been released for CVE-2026-76565, a reflected cross-site scripting (XSS) vulnerability affecting PhocaCart ≀ 6.1.7 for Joomla.

The vulnerability exists in the price_from and price_to filter parameters within the mod_phocacart_filter module. Due to improper output encoding, unauthenticated attackers can craft a malicious URL that injects JavaScript into the page when viewed by a victim.

The PoC demonstrates:

β€’ Reflected XSS through crafted GET parameters
β€’ Exploitation of vulnerable price filter inputs
β€’ Attribute-context injection caused by missing htmlspecialchars() encoding
β€’ No authentication requirement for exploitation
β€’ Affected versions: PhocaCart ≀ 6.1.7
β€’ Fixed version: PhocaCart 6.1.8

πŸ’₯ No delays. No guessing. No redactions. Get the intel before everyone else with Dark Web Informer.
❀1
πŸš¨πŸ‡ΊπŸ‡Έ Access to major US technology company infrastructure allegedly offered for sale on cybercrime forum
β €
A cybercrime forum user is advertising what they claim is access to the infrastructure of a major American technology company operating in cloud technologies and artificial intelligence. The seller claims the access provides visibility into internal systems and enterprise resources.
β €
The advertised access includes:
β €
β€’ Corporate Git hosting with organization administrator rights
β€’ Claimed persistence access within company infrastructure
β€’ Private container registry credentials
β€’ Internal communication channels and webhooks
β€’ API keys for internal services
β€’ Access to a claimed vulnerability allowing credential retrieval
β €
The seller is asking $10,000 and states the access will be sold to a single buyer through escrow.
β €
The seller's claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀2
πŸš¨πŸ‡ΈπŸ‡¦ STC TV user database allegedly leaked on a cybercrime forum, 3M+ records claimed
β €
An actor claims to have obtained a database belonging to STC TV, a Saudi Arabia-based streaming service. The seller claims the dataset contains information belonging to more than 3 million users.
β €
The advertised data includes:
β €
β€’ Full names
β€’ User points
β€’ Gender information
β€’ Mobile numbers
β€’ Email addresses
β€’ Dates of birth
β€’ Nationality information
β€’ Barcode-related data
β €
The seller is advertising the alleged dataset for $2,000 and has included a sample of records as proof of the claimed data.
β €
STC TV is a digital entertainment platform operated by Saudi Telecom Company (stc), offering streaming content and subscription-based services.
β €
The seller's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Hono: A small, simple, and ultrafast web framework built on Web Standards

GitHub: https://github.com/honojs/hono
πŸ”₯1
🚨 Desktop RAT with reverse shell and file management features advertised on a cybercrime forum
β €
An actor is advertising what they describe as a desktop remote access trojan (RAT) featuring remote control capabilities, reverse shell functionality and an integrated file explorer. The seller is offering a free trial period to selected forum members.
β €
The advertised features include:
β €
β€’ Desktop remote access capabilities
β€’ Reverse shell functionality
β€’ Interactive remote control
β€’ Screen streaming using H.264 encoding
β€’ Low-level screenshot capture methods
β€’ Multi-monitor support
β€’ Automatic quality adjustment based on network conditions
β€’ Bot information storage
β€’ System information tracking
β€’ Online/offline status monitoring
β€’ Privilege level detection
β€’ Remote file management
β€’ File upload and download capabilities
β€’ File search, deletion, renaming and creation
β€’ Customizable options and future feature additions
β €
The seller claims the tool was written in C++ and includes mechanisms intended to reduce detection. The listing advertises the software for $100 per week.
β €
The seller's claims and the capabilities, effectiveness and detection resistance of the advertised tool have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ A new clearnet/darknet dr*g shop being advertised.

My comment: Site is very buggy. Stay smart.

mydrugs[.]top - Name is based off the tv series: "How to Sell Drugs Online (Fast)" Good show btw.

Dark Web Onion: http://6phcw63ywvjbw27qzmt3ic5fvzntsipdqsg5naxwh2vzyogmv5ki56yd[.]onion/

Lite version:
http://6phcw63ywvjbw27qzmt3ic5fvzntsipdqsg5naxwh2vzyogmv5ki56yd[.]onion/lite/index.php

Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/d593c18aefe1dcd0b2b6
😭1
πŸš¨πŸ‡ΊπŸ‡Έ Cybercrime forum user seeks US-based mules for KYC-related activity, $40K-$50K budget claimed
β €
An actor is seeking workers or mules from the United States for what they describe as KYC-related activity. The user claims they are looking for individuals who can provide access to KYC websites, obtain company documents, or create documents for account-related operations.
β €
The advertised request includes:
β €
β€’ US-based mules or workers
β€’ KYC platform accounts
β€’ Company documents or document creation
β€’ More than 50 accounts
β€’ Cryptocurrency payments
β €
The user claims they are willing to pay $40,000-$50,000 for the requested services and states they are only dealing through a middleman.
β €
The claims and the purpose, authenticity and scope of the requested activity have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡«πŸ‡· Banque Alimentaire du Bas-Rhin allegedly leaked on a cybercrime forum
β €
A threat actor claims to have leaked data belonging to Banque Alimentaire du Bas-Rhin, a French food bank organization based in Strasbourg. The post claims the leaked dataset contains approximately 10,073 lines in JSON format with a total size of 4.3 MB.
β €
The advertised data includes:
β €
β€’ Structured JSON records
β€’ Personal and organizational information
β€’ Internal database entries
β€’ Additional records from the claimed dataset
β €
The post includes sample data and a claimed proof of access, along with download links for the full dataset.
β €
Banque Alimentaire du Bas-Rhin is a nonprofit organization that supports food assistance programs and partner associations throughout the region.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❀2
Lul

Edit: Context,,, At some point the FBI lost the fbi_breachforums Telegram name.
😭4😁1
πŸš¨πŸ‡ΊπŸ‡Έ Cornerstone Residential allegedly breached, SQL dump advertised on cybercrime forum
β €
Cornerstone Residential, a Texas-based property management company, is allegedly the target of a claimed breach after a threat actor advertised what they describe as a full SQL database dump from the company.
β €
The threat actor claims the leaked data includes:
β €
β€’ User preferences
β€’ User roles
β€’ Elementor API access tokens and secrets
β€’ Administrator IP location information
β€’ Additional database records
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 D*xbin source code allegedly offered for sale on a cybercrime forum
β €
DF owner is advertising what they claim is the complete source code for D*xbin, a platform associated with the publication of personal information. The actor claims the code can be used to build a D*xbin/Vilebin-style platform or operate a similar paste site.
β €
The advertised offering includes:
β €
β€’ Complete platform source code
β€’ Updated version of the claimed Doxbin codebase
β€’ Ability to create a clone-style platform
β€’ Existing forum infrastructure components
β€’ Custom deployment capabilities
β €
The actor claims the source code is the same version currently used by D*xbin and states that some clone paste sites are already operating using the code.
β €
The seller's claims and the authenticity, ownership and functionality of the advertised source code have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing