Torrent sites are notorious for leaking IPs and shitty security.
‼️ Security researcher Nightmare Eclipse has released a new zero-day called FalconFlank, a CrowdStrike Falcon local privilege escalation (LPE) vulnerability.
GitHub: https://github.com/MSNightmare/FalconFlank
GitHub: https://github.com/MSNightmare/FalconFlank
🚨 Four French organizations allegedly targeted in data leaks, including Tisséo, CRMA Occitanie, BCTI and Charbonneaux-Brabant
⠀
Threat actor ChimeraZ has published four separate datasets allegedly obtained from French organizations, exposing personnel, business, operational and identity-related information.
⠀
The affected organizations and claimed data include:
⠀
• CRMA Occitanie: 1,029 records in a 60 KB CSV dataset, including names, email addresses and regional/organizational information
• BCTI / partenaires.bcti.fr: 12 MB partial dataset in JSON/PDF format containing business mission, appointment, property and billing-related records, along with a folder allegedly containing 21 French identity cards
• Charbonneaux-Brabant: 2,863 records in a 660 KB JSON dataset containing names, email addresses, usernames, language, job functions, customer profiles and other account-related fields
• Tisséo: 13,446 records associated with 2,877 people in a 1.22 GB JSON dataset, including employee names, email addresses, personnel IDs, departments, services, job roles, work locations and additional internal workforce information
⠀
Tisséo operates Toulouse’s public transport network, while CRMA Occitanie supports businesses and artisans across the Occitanie region. Charbonneaux-Brabant specializes in packaging and household products, and the BCTI portal serves professional partners and organizations.
⠀
Samples were published for each alleged dataset, with the actor also providing download links for the material.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Threat actor ChimeraZ has published four separate datasets allegedly obtained from French organizations, exposing personnel, business, operational and identity-related information.
⠀
The affected organizations and claimed data include:
⠀
• CRMA Occitanie: 1,029 records in a 60 KB CSV dataset, including names, email addresses and regional/organizational information
• BCTI / partenaires.bcti.fr: 12 MB partial dataset in JSON/PDF format containing business mission, appointment, property and billing-related records, along with a folder allegedly containing 21 French identity cards
• Charbonneaux-Brabant: 2,863 records in a 660 KB JSON dataset containing names, email addresses, usernames, language, job functions, customer profiles and other account-related fields
• Tisséo: 13,446 records associated with 2,877 people in a 1.22 GB JSON dataset, including employee names, email addresses, personnel IDs, departments, services, job roles, work locations and additional internal workforce information
⠀
Tisséo operates Toulouse’s public transport network, while CRMA Occitanie supports businesses and artisans across the Occitanie region. Charbonneaux-Brabant specializes in packaging and household products, and the BCTI portal serves professional partners and organizations.
⠀
Samples were published for each alleged dataset, with the actor also providing download links for the material.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🔪 Slice For Life - Part 2 🔪
‼️ New Ransomware Group: Vexy Dark Web Onion: http://vexytsr3chimdz6siwaqi2lvxxwfkxvffkpwyanr2llequ2hkm56jvqd[.]onion
‼️ Vexy Ransomware Affiliate Program
‼️ New Dark Web Informer Blog Post!
Title: ZeroGaspi Customer Records for 89,281 French Shoppers Sold for 70 Dollars
Link: https://darkwebinformer.com/zerogaspi-customer-records-for-89-281-french-shoppers-sold-for-70-dollars/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: ZeroGaspi Customer Records for 89,281 French Shoppers Sold for 70 Dollars
Link: https://darkwebinformer.com/zerogaspi-customer-records-for-89-281-french-shoppers-sold-for-70-dollars/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
ZeroGaspi Customer Records for 89,281 French Shoppers Sold for 70 Dollars
A forum actor posting as ksye is selling what they describe as the customer database of zerogaspi.fr, a French retailer selling surplus and short dated groceries.
❤1
‼️ New Dark Web Informer Blog Post!
Title: 3.1 Million DZI Records Offered With National ID and Passport Numbers
Link: https://darkwebinformer.com/3-1-million-dzi-records-offered-with-national-id-and-passport-numbers/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: 3.1 Million DZI Records Offered With National ID and Passport Numbers
Link: https://darkwebinformer.com/3-1-million-dzi-records-offered-with-national-id-and-passport-numbers/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
3.1 Million DZI Records Offered With National ID and Passport Numbers
A forum actor posting as Intelligence is selling what they describe as 3,134,269 full personal data records belonging to customers of DZI Insurance, Bulgaria's oldest insurer and a subsidiary of Belgium's KBC Group.
🚨🇮🇳 FortiGate appliance credentials tied to multiple Indian IT companies allegedly offered for sale on a cybercrime forum
⠀
Multiple small and medium-sized IT and consulting companies in India are allegedly affected after a threat actor advertised credentials associated with their FortiGate appliances.
⠀
The seller describes the affected organizations as primarily providing IT support and consulting services, with claimed annual revenues ranging from approximately $300,000 to $1.5 million.
⠀
The advertised access includes:
⠀
• FortiGate appliance credentials
• IP addresses
• Usernames
• Passwords
• FortiGate identifiers
• Access associated with IT and consulting environments
⠀
The number of affected users or appliances is not specified in the listing.
⠀
The actor is asking $5,000 or a higher offer for the alleged access and is offering proof privately to prospective buyers.
⠀
The claims and the authenticity, scope and current validity of the allegedly compromised credentials have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Multiple small and medium-sized IT and consulting companies in India are allegedly affected after a threat actor advertised credentials associated with their FortiGate appliances.
⠀
The seller describes the affected organizations as primarily providing IT support and consulting services, with claimed annual revenues ranging from approximately $300,000 to $1.5 million.
⠀
The advertised access includes:
⠀
• FortiGate appliance credentials
• IP addresses
• Usernames
• Passwords
• FortiGate identifiers
• Access associated with IT and consulting environments
⠀
The number of affected users or appliances is not specified in the listing.
⠀
The actor is asking $5,000 or a higher offer for the alleged access and is offering proof privately to prospective buyers.
⠀
The claims and the authenticity, scope and current validity of the allegedly compromised credentials have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ A forum actor is offering edge device access to three American organizations, including two with over 5 million in revenue/size and one multi-billion revenue entity, claiming the access allows reaching Domain Admin.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇺🇸 Motorola internal AI and GenAI infrastructure access allegedly offered for sale on a cybercrime forum
⠀
Motorola, a U.S.-based telecommunications and technology company, is allegedly affected by a significant security compromise after a threat actor claimed to have accessed internal environments supporting the company’s GenAI and AI engineering infrastructure.
⠀
The actor claims the compromised environment includes:
⠀
• Internal repositories and source code
• GenAI modules, proxies and custom agents
• Model Context Protocol (MCP) servers
• Jira MCP infrastructure
• Frog MCP infrastructure
• Bitbucket MCP infrastructure
• Enterprise integration systems
• CI/CD pipelines
• Salesforce-related pipelines
• ServiceNow-related pipelines
• Azure RAG infrastructure
• Internal documentation
• Chat transcripts
• Monitoring and reporting systems
• Additional AI engineering assets
⠀
The actor published multiple screenshots presented as proof of access and states that the compromised environment and associated assets are now being offered for sale.
⠀
No public asking price is provided, with prospective buyers directed to contact the actor privately for verification, additional details and pricing.
⠀
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Motorola, a U.S.-based telecommunications and technology company, is allegedly affected by a significant security compromise after a threat actor claimed to have accessed internal environments supporting the company’s GenAI and AI engineering infrastructure.
⠀
The actor claims the compromised environment includes:
⠀
• Internal repositories and source code
• GenAI modules, proxies and custom agents
• Model Context Protocol (MCP) servers
• Jira MCP infrastructure
• Frog MCP infrastructure
• Bitbucket MCP infrastructure
• Enterprise integration systems
• CI/CD pipelines
• Salesforce-related pipelines
• ServiceNow-related pipelines
• Azure RAG infrastructure
• Internal documentation
• Chat transcripts
• Monitoring and reporting systems
• Additional AI engineering assets
⠀
The actor published multiple screenshots presented as proof of access and states that the compromised environment and associated assets are now being offered for sale.
⠀
No public asking price is provided, with prospective buyers directed to contact the actor privately for verification, additional details and pricing.
⠀
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: More Than a Million Salt Mobile Records Offered for Sale
Link: https://darkwebinformer.com/more-than-a-million-salt-mobile-records-offered-for-sale/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: More Than a Million Salt Mobile Records Offered for Sale
Link: https://darkwebinformer.com/more-than-a-million-salt-mobile-records-offered-for-sale/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
More Than a Million Salt Mobile Records Offered for Sale
A forum actor posting as SaltMobile1 is selling what they describe as a database of Salt, a Swiss mobile operator, containing more than 1,090,000 records.
‼️ New Dark Web Informer Blog Post!
Title: HopCharge Analytics Export Published With Names, Phones and Coordinates
Link: https://darkwebinformer.com/hopcharge-analytics-export-published-with-names-phones-and-coordinates/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: HopCharge Analytics Export Published With Names, Phones and Coordinates
Link: https://darkwebinformer.com/hopcharge-analytics-export-published-with-names-phones-and-coordinates/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
HopCharge Analytics Export Published With Names, Phones and Coordinates
A forum actor posting as GoreTerminal has published what they describe as the database of hopcharge.com, an on demand doorstep electric vehicle charging service operating in India through mobile vans.