🔪 Slice For Life - Part 2 🔪
4.76K subscribers
1.1K photos
62 videos
980 links
Download Telegram
🚨🇫🇷 Critical IsiGéo zero-day SQL injection vulnerability allegedly weaponized and offered for sale on a cybercrime forum

IsiGéo is the target of a newly advertised exploit after a threat actor claims to have discovered and weaponized a critical zero-day SQL injection vulnerability affecting the platform.

The actor claims the vulnerability enables:

• SQL injection exploitation
• Compromise of the underlying dataset
• Full data extraction
• Access to information stored within affected systems

The actor states that the exploit is now being offered for sale and is providing further technical details, proof of concept and pricing privately to prospective buyers.

No public price, technical indicators or vulnerability details were disclosed in the forum post.

The claims and the existence, severity, exploitability and current validity of the alleged zero-day vulnerability have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Media is too big
VIEW IN TELEGRAM
Blasterjaxx & Timmy Trumpet - Time To Say Goodbye
🔥2
🚨🇻🇪 Carnet de la Patria dataset allegedly leaked on a cybercrime forum, 30M+ citizen records claimed

Carnet de la Patria, Venezuela’s government-issued identification and social benefits system, is allegedly affected by a major data breach after a threat actor claimed to have obtained the platform’s complete dataset containing information on 30,045,854 citizens.

The actor claims the dataset identifies individuals who do and do not hold a Carnet de la Patria and includes:

• 30,045,854 citizen records
• More than 16 million phone numbers
• Approximately 11.5 million addresses
• Approximately 3.9 million email addresses
• Approximately 16.6 million Carnet de la Patria serial numbers
• Citizen identification information
• Cardholder status information
• Additional government-related personal data

The actor also claims the dataset contains approximately 2.3 million records associated with foreign nationals, including Venezuelan identification numbers beginning with the “E” prefix.

The complete dataset is claimed to be approximately 14.3 GB and provided in .DB format, with a proof of concept offered through the forum.

The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🔪 Slice For Life - Part 2 🔪 pinned «❗️I will randomly purge this channel. Over 27 forums monitored on the platform and still growing. X/Twitter: https://x.com/DarkWebInformer Main Channel: https://t.me/SliceForLifeee Backup Channel: https://t.me/SliceForLifeeee Telegram CVE Feed: https://…»
Torrent sites are notorious for leaking IPs and shitty security.
‼️ Security researcher Nightmare Eclipse has released a new zero-day called FalconFlank, a CrowdStrike Falcon local privilege escalation (LPE) vulnerability.

GitHub: https://github.com/MSNightmare/FalconFlank
‼️ New Ransomware Group: Vexy

Dark Web Onion: http://vexytsr3chimdz6siwaqi2lvxxwfkxvffkpwyanr2llequ2hkm56jvqd[.]onion
🚨 Four French organizations allegedly targeted in data leaks, including Tisséo, CRMA Occitanie, BCTI and Charbonneaux-Brabant

Threat actor ChimeraZ has published four separate datasets allegedly obtained from French organizations, exposing personnel, business, operational and identity-related information.

The affected organizations and claimed data include:

• CRMA Occitanie: 1,029 records in a 60 KB CSV dataset, including names, email addresses and regional/organizational information
• BCTI / partenaires.bcti.fr: 12 MB partial dataset in JSON/PDF format containing business mission, appointment, property and billing-related records, along with a folder allegedly containing 21 French identity cards
• Charbonneaux-Brabant: 2,863 records in a 660 KB JSON dataset containing names, email addresses, usernames, language, job functions, customer profiles and other account-related fields
• Tisséo: 13,446 records associated with 2,877 people in a 1.22 GB JSON dataset, including employee names, email addresses, personnel IDs, departments, services, job roles, work locations and additional internal workforce information

Tisséo operates Toulouse’s public transport network, while CRMA Occitanie supports businesses and artisans across the Occitanie region. Charbonneaux-Brabant specializes in packaging and household products, and the BCTI portal serves professional partners and organizations.

Samples were published for each alleged dataset, with the actor also providing download links for the material.

The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇮🇳 FortiGate appliance credentials tied to multiple Indian IT companies allegedly offered for sale on a cybercrime forum

Multiple small and medium-sized IT and consulting companies in India are allegedly affected after a threat actor advertised credentials associated with their FortiGate appliances.

The seller describes the affected organizations as primarily providing IT support and consulting services, with claimed annual revenues ranging from approximately $300,000 to $1.5 million.

The advertised access includes:

• FortiGate appliance credentials
• IP addresses
• Usernames
• Passwords
• FortiGate identifiers
• Access associated with IT and consulting environments

The number of affected users or appliances is not specified in the listing.

The actor is asking $5,000 or a higher offer for the alleged access and is offering proof privately to prospective buyers.

The claims and the authenticity, scope and current validity of the allegedly compromised credentials have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing