Brave added email aliases to their desktop browser
https://x.com/DarkWebInformer/status/2093129109106794603
https://x.com/DarkWebInformer/status/2093129109106794603
X (formerly Twitter)
Dark Web Informer (@DarkWebInformer) on X
Brave added email aliases to their desktop browser
Email Aliases lets you create unique email addresses that automatically forward messages to your primary inbox.
Email Aliases lets you create unique email addresses that automatically forward messages to your primary inbox.
Google Engineer Accused of Polymarket Insider Trading Says He Was Just Gambling
https://www.wired.com/story/google-engineer-accused-of-polymarket-insider-trading-says-he-was-just-gambling/
https://www.wired.com/story/google-engineer-accused-of-polymarket-insider-trading-says-he-was-just-gambling/
WIRED
Google Engineer Accused of Polymarket Insider Trading Says He Was Just Gambling
Michele Spagnuolo was arrested for alleged insider trading on Polymarket, but the Switzerland-based engineer says he was simply gamblingβactivity that is beyond the reach of US commodities law.
π1
Here is the Indictment against Ruben Ian Thomson
https://www.courtlistener.com/docket/74707103/united-states-v-thomson/
https://www.courtlistener.com/docket/74707103/united-states-v-thomson/
π¨π«π· Actis Location dataset allegedly leaked on a cybercrime forum, 464GB and 666K+ files claimed
β
Actis Location, a French company specializing in the rental of construction, industrial and professional equipment, is allegedly affected by a data exposure after a threat actor published what they claim is company data obtained as part of the BigCloud leak series.
β
The actor claims the exposed material totals approximately 464 GB and contains 666,155 files, with portions of the data converted to text for publication.
β
The advertised data includes:
β
β’ Email communications
β’ Employee and customer names
β’ Email addresses
β’ Phone numbers
β’ Physical addresses
β’ Cities, postal codes and countries
β’ CRM records
β’ Customer and company account information
β’ Internal reference numbers
β’ Rental and quotation documents
β’ Contract-related information
β’ Equipment and product details
β’ Pricing and payment-related information
β’ Rental dates and durations
β’ Additional internal business documents
β
The forum post includes samples of alleged email, CRM and document data, along with download links for the material. The actor describes Actis Location as BigCloud Leak #15.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Actis Location, a French company specializing in the rental of construction, industrial and professional equipment, is allegedly affected by a data exposure after a threat actor published what they claim is company data obtained as part of the BigCloud leak series.
β
The actor claims the exposed material totals approximately 464 GB and contains 666,155 files, with portions of the data converted to text for publication.
β
The advertised data includes:
β
β’ Email communications
β’ Employee and customer names
β’ Email addresses
β’ Phone numbers
β’ Physical addresses
β’ Cities, postal codes and countries
β’ CRM records
β’ Customer and company account information
β’ Internal reference numbers
β’ Rental and quotation documents
β’ Contract-related information
β’ Equipment and product details
β’ Pricing and payment-related information
β’ Rental dates and durations
β’ Additional internal business documents
β
The forum post includes samples of alleged email, CRM and document data, along with download links for the material. The actor describes Actis Location as BigCloud Leak #15.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨π©πͺ EggyWall advertises privacy-focused "bulletproof" VPS hosting with DDoS protection
EggyWall, a hosting provider advertising VPS infrastructure in Frankfurt, Germany, is promoting what it describes as privacy-focused hosting with built-in DDoS protection and minimal restrictions on customer content.
The advertised features include:
β’ VPS hosting in Frankfurt, Germany
β’ NVMe SSD storage
β’ High-speed uplinks
β’ Full root access
β’ Free DDoS protection
β’ Layer 7 WAF protection
β’ Filtering against malicious HTTP traffic
β’ Full server control
β’ Privacy-focused hosting
β’ "Bulletproof" hosting
β’ Responsive support
The provider states that DDoS protection is included with every server at no additional cost and advertises a policy summarized as "Your server, your content, your responsibility."
No public pricing is displayed in the forum advertisement, with prospective customers instead directed to contact the provider or initiate a contract.
The provider's claims and the effectiveness, scope and resilience of the advertised hosting and DDoS protections have not been independently verified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
EggyWall, a hosting provider advertising VPS infrastructure in Frankfurt, Germany, is promoting what it describes as privacy-focused hosting with built-in DDoS protection and minimal restrictions on customer content.
The advertised features include:
β’ VPS hosting in Frankfurt, Germany
β’ NVMe SSD storage
β’ High-speed uplinks
β’ Full root access
β’ Free DDoS protection
β’ Layer 7 WAF protection
β’ Filtering against malicious HTTP traffic
β’ Full server control
β’ Privacy-focused hosting
β’ "Bulletproof" hosting
β’ Responsive support
The provider states that DDoS protection is included with every server at no additional cost and advertises a policy summarized as "Your server, your content, your responsibility."
No public pricing is displayed in the forum advertisement, with prospective customers instead directed to contact the provider or initiate a contract.
The provider's claims and the effectiveness, scope and resilience of the advertised hosting and DDoS protections have not been independently verified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΆπ¦ Qatar General Retirement & Social Insurance Authority allegedly breached, internal accounts and API tokens exposed
Qatar General Retirement & Social Insurance Authority (GRSIA) is allegedly affected by a breach after a threat actor published samples claiming to originate from systems associated with the authority.
The advertised data includes:
β’ Internal and partner user accounts
β’ First and last names
β’ Email addresses
β’ User and partner account types
β’ Partner IDs
β’ Store IDs
β’ Account roles and permissions
β’ Account status information
β’ API names and environment identifiers
β’ API authentication tokens
β’ Token expiration dates
β’ Record creation and update timestamps
The samples include entries labeled API Testing and GRSIA_PROD, along with records for internal users, partner administrators and store users. Several organizations and partner accounts also appear within the sample data.
The actor additionally published what they claim is a publicly reachable system endpoint and provided a download link containing the alleged material.
The claims and the authenticity, source and scope of the allegedly exposed data and credentials have not been independently verified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Qatar General Retirement & Social Insurance Authority (GRSIA) is allegedly affected by a breach after a threat actor published samples claiming to originate from systems associated with the authority.
The advertised data includes:
β’ Internal and partner user accounts
β’ First and last names
β’ Email addresses
β’ User and partner account types
β’ Partner IDs
β’ Store IDs
β’ Account roles and permissions
β’ Account status information
β’ API names and environment identifiers
β’ API authentication tokens
β’ Token expiration dates
β’ Record creation and update timestamps
The samples include entries labeled API Testing and GRSIA_PROD, along with records for internal users, partner administrators and store users. Several organizations and partner accounts also appear within the sample data.
The actor additionally published what they claim is a publicly reachable system endpoint and provided a download link containing the alleged material.
The claims and the authenticity, source and scope of the allegedly exposed data and credentials have not been independently verified.
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πͺπΈ Dataset from unnamed Spanish company allegedly offered on a cybercrime forum, 7,222+ records claimed
β
An unnamed company in Spain is allegedly affected by a data exposure after a threat actor advertised what they claim is a complete dataset containing more than 7,222 plaintext records across multiple tables.
β
The advertised data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ Physical addresses
β’ Postal codes
β’ Cities and municipalities
β’ Spanish identification numbers
β’ Customer-related records
β’ Contact information
β’ Commercial and billing-related tables
β’ Invoice-related records
β’ Additional internal business data
β
The actor published sample records from the alleged dataset along with a partial list of table names, including customer, contact, invoice and tax-related tables.
β
The company is not identified in the listing, and no public asking price is provided.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
An unnamed company in Spain is allegedly affected by a data exposure after a threat actor advertised what they claim is a complete dataset containing more than 7,222 plaintext records across multiple tables.
β
The advertised data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ Physical addresses
β’ Postal codes
β’ Cities and municipalities
β’ Spanish identification numbers
β’ Customer-related records
β’ Contact information
β’ Commercial and billing-related tables
β’ Invoice-related records
β’ Additional internal business data
β
The actor published sample records from the alleged dataset along with a partial list of table names, including customer, contact, invoice and tax-related tables.
β
The company is not identified in the listing, and no public asking price is provided.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΈπͺ VMware Horizon enterprise admin access to Swedish technology company allegedly offered for sale on a cybercrime forum
β
An unnamed technology/SaaS company in Sweden, reportedly generating $100 million to $250 million in revenue, is allegedly compromised after a threat actor advertised access to its environment through an underground marketplace.
β
The advertised access includes:
β
β’ VMware Horizon access
β’ Enterprise Administrator privileges
β’ Network of approximately 1,000 hosts
β’ No AV/EDR detected by the seller
β’ Technology/SaaS sector
β’ Sweden-based organization
β
The actor is asking for approximately 0.02254392 BTC, for the accesst.
β
The seller's claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
An unnamed technology/SaaS company in Sweden, reportedly generating $100 million to $250 million in revenue, is allegedly compromised after a threat actor advertised access to its environment through an underground marketplace.
β
The advertised access includes:
β
β’ VMware Horizon access
β’ Enterprise Administrator privileges
β’ Network of approximately 1,000 hosts
β’ No AV/EDR detected by the seller
β’ Technology/SaaS sector
β’ Sweden-based organization
β
The actor is asking for approximately 0.02254392 BTC, for the accesst.
β
The seller's claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨πΊπΈ Grindr (again?) dataset allegedly offered for sale on a cybercrime forum, 28M user records claimed
β
Grindr, a location-based dating and social networking platform, is allegedly affected by a data exposure after a threat actor advertised what they claim is a dataset containing information on approximately 28 million registered users.
β
The advertised data includes:
β
β’ Email addresses
β’ Account and profile IDs
β’ Dates of birth and ages
β’ Gender and pronoun information
β’ Cities, states and countries
β’ Account and verification status
β’ Device and app information
β’ Profile creation and activity timestamps
β’ Height, weight and body-type information
β’ Relationship and dating preferences
β’ Profile descriptions and interests
β’ Social media account information
β’ Subscription and account tier details
β’ Profile views and engagement metrics
β’ Health-related profile fields
β’ Additional highly sensitive profile information
β
The actor published sample records and a list of claimed dataset fields, and is offering the alleged material for $400.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
Grindr, a location-based dating and social networking platform, is allegedly affected by a data exposure after a threat actor advertised what they claim is a dataset containing information on approximately 28 million registered users.
β
The advertised data includes:
β
β’ Email addresses
β’ Account and profile IDs
β’ Dates of birth and ages
β’ Gender and pronoun information
β’ Cities, states and countries
β’ Account and verification status
β’ Device and app information
β’ Profile creation and activity timestamps
β’ Height, weight and body-type information
β’ Relationship and dating preferences
β’ Profile descriptions and interests
β’ Social media account information
β’ Subscription and account tier details
β’ Profile views and engagement metrics
β’ Health-related profile fields
β’ Additional highly sensitive profile information
β
The actor published sample records and a list of claimed dataset fields, and is offering the alleged material for $400.
β
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π1
βΌοΈ New Dark Web Informer Blog Post!
Title: ToxC2 Sells a Cross Platform Agent That Runs Its Command Channel Over Tox
Link: https://darkwebinformer.com/toxc2-sells-a-cross-platform-agent-that-runs-its-command-channel-over-tox/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: ToxC2 Sells a Cross Platform Agent That Runs Its Command Channel Over Tox
Link: https://darkwebinformer.com/toxc2-sells-a-cross-platform-agent-that-runs-its-command-channel-over-tox/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
ToxC2 Sells a Cross Platform Agent That Runs Its Command Channel Over Tox
A seller posting as Reze is advertising ToxC2, a command and control agent priced at 70 dollars for builds covering Windows, macOS and Linux.
βΌοΈ New Dark Web Informer Blog Post!
Title: A 500 Dollar Phishing Panel Built to Relay Card Details and One Time Codes
Link: https://darkwebinformer.com/a-500-dollar-phishing-panel-built-to-relay-card-details-and-one-time-codes/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: A 500 Dollar Phishing Panel Built to Relay Card Details and One Time Codes
Link: https://darkwebinformer.com/a-500-dollar-phishing-panel-built-to-relay-card-details-and-one-time-codes/
π₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
A 500 Dollar Phishing Panel Built to Relay Card Details and One Time Codes
A seller posting as PAL1T is advertising a live phishing panel at 500 dollars, presented as version 1.0 and aimed at capturing card data together with one time passcodes.
π¨πΊπΈ Dataset from unnamed US cryptocurrency exchange allegedly offered for sale, 817K records claimed
β
An unnamed cryptocurrency exchange in the United States is allegedly affected by a data exposure after a threat actor advertised what they claim is a fresh private dataset containing approximately 817,000 records.
β
The advertised data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ Countries
β’ Physical addresses
β’ Account balance information
β’ Additional account-related data
β
The actor describes the material as a fresh dump dated August 28, 2026 and states that only one copy of the alleged dataset will be sold.
β
The listing is priced at $3,500, with the seller stating that escrow is accepted.
β
The exchange is not identified in the listing, and the claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
β
An unnamed cryptocurrency exchange in the United States is allegedly affected by a data exposure after a threat actor advertised what they claim is a fresh private dataset containing approximately 817,000 records.
β
The advertised data includes:
β
β’ Full names
β’ Email addresses
β’ Phone numbers
β’ Countries
β’ Physical addresses
β’ Account balance information
β’ Additional account-related data
β
The actor describes the material as a fresh dump dated August 28, 2026 and states that only one copy of the alleged dataset will be sold.
β
The listing is priced at $3,500, with the seller stating that escrow is accepted.
β
The exchange is not identified in the listing, and the claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
β
π₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
π¨ Critical CVE-2026-73125 impacts Ebyte NE2-D11 devices
A critical missing-authentication vulnerability in the Ebyte NE2-D11 web management interface could allow a remote, unauthenticated attacker to access administrative functionality.
CVE-2026-73125 carries a CVSS 3.1 score of 9.8 and requires no privileges or user interaction. Successful exploitation could allow attackers to:
β’ Access sensitive configuration data
β’ Modify device settings
β’ Disrupt device availability
Affected firmware: FW-9167-0-11
Ebyte indicated a patch was under development, but CISA says it has not been informed of the patch's current availability. No confirmed active exploitation has been reported at this time.
CISA: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
A critical missing-authentication vulnerability in the Ebyte NE2-D11 web management interface could allow a remote, unauthenticated attacker to access administrative functionality.
CVE-2026-73125 carries a CVSS 3.1 score of 9.8 and requires no privileges or user interaction. Successful exploitation could allow attackers to:
β’ Access sensitive configuration data
β’ Modify device settings
β’ Disrupt device availability
Affected firmware: FW-9167-0-11
Ebyte indicated a patch was under development, but CISA says it has not been informed of the patch's current availability. No confirmed active exploitation has been reported at this time.
CISA: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
This media is not supported in your browser
VIEW IN TELEGRAM
βΌοΈ Unconfirmed reports that there is a new X account takeover exploit being used.
π8π3π1
Someone asked why I'm sharing 480p video. Bro, tell them to stop recording at 480p... there is nothing I can do there. π
π3
βΌοΈπΊπΈ McKesson Corporation has filed form 8-K due to a cybersecurity incident.
On August 25, 2026, McKesson Corporation discovered a cybersecurity incident affecting its information systems. An investigation of the incident is in its early stages. Information about the incident, including any updates, is available on the companyβs website at www.mckesson.com/cybersecurity.
As of the date of this filing, the company has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations.
PDF: https://d18rn0p25nwr6d.cloudfront.net/CIK-0000927653/5d76bf4d-9af6-40d2-89cc-6648aa9cbb59.pdf
On August 25, 2026, McKesson Corporation discovered a cybersecurity incident affecting its information systems. An investigation of the incident is in its early stages. Information about the incident, including any updates, is available on the companyβs website at www.mckesson.com/cybersecurity.
As of the date of this filing, the company has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations.
PDF: https://d18rn0p25nwr6d.cloudfront.net/CIK-0000927653/5d76bf4d-9af6-40d2-89cc-6648aa9cbb59.pdf
βΌοΈπ¨ Rhysida Ransomware claims a nonprofitt Federally Qualified Health Center for 37 BTC
πΊπΈ Valley Health Team - A California-based nonprofit Federally Qualified Health Center providing medical, dental, behavioral health, and other primary care services across the Central Valley.
The listing claims 3.28 TB across 9,056,196 files, including SQL databases containing information on 160,870 patients, 4.18 million diagnoses, 7.6 million unencrypted EHR scans, Social Security numbers, passports, other personal data, financial statements, salaries, and tax records.
The data is being offered for 37 BTC.
πΊπΈ Valley Health Team - A California-based nonprofit Federally Qualified Health Center providing medical, dental, behavioral health, and other primary care services across the Central Valley.
The listing claims 3.28 TB across 9,056,196 files, including SQL databases containing information on 160,870 patients, 4.18 million diagnoses, 7.6 million unencrypted EHR scans, Social Security numbers, passports, other personal data, financial statements, salaries, and tax records.
The data is being offered for 37 BTC.