πŸ”ͺ That Dark Web Guy - Part 3 πŸ”ͺ
4.88K subscribers
1.17K photos
66 videos
1.04K links
Download Telegram
‼️ Allure Darknet Market launches 1.5

Dark Web: http://allureg32wdtbv7yzcybds6iakavl3dd6z2aten3l26xpsmeo7dq47id[.]onion

Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/3e4cf9f309984f61f924
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API Access: https://darkwebinformer.com/api-details
Socials: https://darkwebinformer.com/socials
‼️ DarkForums is back up under the domain I discovered earlier today:

darkforums[.]as

https://x.com/DarkWebInformer/status/2093018895846162799?s=20
❀6πŸ”₯1😁1
πŸš¨πŸ‡«πŸ‡· Actis Location dataset allegedly leaked on a cybercrime forum, 464GB and 666K+ files claimed
β €
Actis Location, a French company specializing in the rental of construction, industrial and professional equipment, is allegedly affected by a data exposure after a threat actor published what they claim is company data obtained as part of the BigCloud leak series.
β €
The actor claims the exposed material totals approximately 464 GB and contains 666,155 files, with portions of the data converted to text for publication.
β €
The advertised data includes:
β €
β€’ Email communications
β€’ Employee and customer names
β€’ Email addresses
β€’ Phone numbers
β€’ Physical addresses
β€’ Cities, postal codes and countries
β€’ CRM records
β€’ Customer and company account information
β€’ Internal reference numbers
β€’ Rental and quotation documents
β€’ Contract-related information
β€’ Equipment and product details
β€’ Pricing and payment-related information
β€’ Rental dates and durations
β€’ Additional internal business documents
β €
The forum post includes samples of alleged email, CRM and document data, along with download links for the material. The actor describes Actis Location as BigCloud Leak #15.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡©πŸ‡ͺ EggyWall advertises privacy-focused "bulletproof" VPS hosting with DDoS protection

EggyWall, a hosting provider advertising VPS infrastructure in Frankfurt, Germany, is promoting what it describes as privacy-focused hosting with built-in DDoS protection and minimal restrictions on customer content.

The advertised features include:

β€’ VPS hosting in Frankfurt, Germany
β€’ NVMe SSD storage
β€’ High-speed uplinks
β€’ Full root access
β€’ Free DDoS protection
β€’ Layer 7 WAF protection
β€’ Filtering against malicious HTTP traffic
β€’ Full server control
β€’ Privacy-focused hosting
β€’ "Bulletproof" hosting
β€’ Responsive support

The provider states that DDoS protection is included with every server at no additional cost and advertises a policy summarized as "Your server, your content, your responsibility."

No public pricing is displayed in the forum advertisement, with prospective customers instead directed to contact the provider or initiate a contract.

The provider's claims and the effectiveness, scope and resilience of the advertised hosting and DDoS protections have not been independently verified.

πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡ΆπŸ‡¦ Qatar General Retirement & Social Insurance Authority allegedly breached, internal accounts and API tokens exposed

Qatar General Retirement & Social Insurance Authority (GRSIA) is allegedly affected by a breach after a threat actor published samples claiming to originate from systems associated with the authority.

The advertised data includes:

β€’ Internal and partner user accounts
β€’ First and last names
β€’ Email addresses
β€’ User and partner account types
β€’ Partner IDs
β€’ Store IDs
β€’ Account roles and permissions
β€’ Account status information
β€’ API names and environment identifiers
β€’ API authentication tokens
β€’ Token expiration dates
β€’ Record creation and update timestamps

The samples include entries labeled API Testing and GRSIA_PROD, along with records for internal users, partner administrators and store users. Several organizations and partner accounts also appear within the sample data.

The actor additionally published what they claim is a publicly reachable system endpoint and provided a download link containing the alleged material.

The claims and the authenticity, source and scope of the allegedly exposed data and credentials have not been independently verified.

πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨πŸ‡ͺπŸ‡Έ Dataset from unnamed Spanish company allegedly offered on a cybercrime forum, 7,222+ records claimed
β €
An unnamed company in Spain is allegedly affected by a data exposure after a threat actor advertised what they claim is a complete dataset containing more than 7,222 plaintext records across multiple tables.
β €
The advertised data includes:
β €
β€’ Full names
β€’ Email addresses
β€’ Phone numbers
β€’ Physical addresses
β€’ Postal codes
β€’ Cities and municipalities
β€’ Spanish identification numbers
β€’ Customer-related records
β€’ Contact information
β€’ Commercial and billing-related tables
β€’ Invoice-related records
β€’ Additional internal business data
β €
The actor published sample records from the alleged dataset along with a partial list of table names, including customer, contact, invoice and tax-related tables.
β €
The company is not identified in the listing, and no public asking price is provided.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡ΈπŸ‡ͺ VMware Horizon enterprise admin access to Swedish technology company allegedly offered for sale on a cybercrime forum
β €
An unnamed technology/SaaS company in Sweden, reportedly generating $100 million to $250 million in revenue, is allegedly compromised after a threat actor advertised access to its environment through an underground marketplace.
β €
The advertised access includes:
β €
β€’ VMware Horizon access
β€’ Enterprise Administrator privileges
β€’ Network of approximately 1,000 hosts
β€’ No AV/EDR detected by the seller
β€’ Technology/SaaS sector
β€’ Sweden-based organization
β €
The actor is asking for approximately 0.02254392 BTC, for the accesst.
β €
The seller's claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡ΊπŸ‡Έ Grindr (again?) dataset allegedly offered for sale on a cybercrime forum, 28M user records claimed
β €
Grindr, a location-based dating and social networking platform, is allegedly affected by a data exposure after a threat actor advertised what they claim is a dataset containing information on approximately 28 million registered users.
β €
The advertised data includes:
β €
β€’ Email addresses
β€’ Account and profile IDs
β€’ Dates of birth and ages
β€’ Gender and pronoun information
β€’ Cities, states and countries
β€’ Account and verification status
β€’ Device and app information
β€’ Profile creation and activity timestamps
β€’ Height, weight and body-type information
β€’ Relationship and dating preferences
β€’ Profile descriptions and interests
β€’ Social media account information
β€’ Subscription and account tier details
β€’ Profile views and engagement metrics
β€’ Health-related profile fields
β€’ Additional highly sensitive profile information
β €
The actor published sample records and a list of claimed dataset fields, and is offering the alleged material for $400.
β €
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
😭1
πŸš¨πŸ‡ΊπŸ‡Έ Dataset from unnamed US cryptocurrency exchange allegedly offered for sale, 817K records claimed
β €
An unnamed cryptocurrency exchange in the United States is allegedly affected by a data exposure after a threat actor advertised what they claim is a fresh private dataset containing approximately 817,000 records.
β €
The advertised data includes:
β €
β€’ Full names
β€’ Email addresses
β€’ Phone numbers
β€’ Countries
β€’ Physical addresses
β€’ Account balance information
β€’ Additional account-related data
β €
The actor describes the material as a fresh dump dated August 28, 2026 and states that only one copy of the alleged dataset will be sold.
β €
The listing is priced at $3,500, with the seller stating that escrow is accepted.
β €
The exchange is not identified in the listing, and the claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 Critical CVE-2026-73125 impacts Ebyte NE2-D11 devices

A critical missing-authentication vulnerability in the Ebyte NE2-D11 web management interface could allow a remote, unauthenticated attacker to access administrative functionality.

CVE-2026-73125 carries a CVSS 3.1 score of 9.8 and requires no privileges or user interaction. Successful exploitation could allow attackers to:

β€’ Access sensitive configuration data
β€’ Modify device settings
β€’ Disrupt device availability

Affected firmware: FW-9167-0-11

Ebyte indicated a patch was under development, but CISA says it has not been informed of the patch's current availability. No confirmed active exploitation has been reported at this time.

CISA: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
I'm thinking Darknet Market vendors have the most off the wall pseudonyms. 😭
😁2
This media is not supported in your browser
VIEW IN TELEGRAM
‼️ Unconfirmed reports that there is a new X account takeover exploit being used.
😈8😁3😭1
Someone asked why I'm sharing 480p video. Bro, tell them to stop recording at 480p... there is nothing I can do there. 😭
😭3