🔪 Slice For Life - Part 2 🔪
4.72K subscribers
1.1K photos
62 videos
979 links
Download Telegram
Torrent sites are notorious for leaking IPs and shitty security.
‼️ Security researcher Nightmare Eclipse has released a new zero-day called FalconFlank, a CrowdStrike Falcon local privilege escalation (LPE) vulnerability.

GitHub: https://github.com/MSNightmare/FalconFlank
‼️ New Ransomware Group: Vexy

Dark Web Onion: http://vexytsr3chimdz6siwaqi2lvxxwfkxvffkpwyanr2llequ2hkm56jvqd[.]onion
🚨 Four French organizations allegedly targeted in data leaks, including Tisséo, CRMA Occitanie, BCTI and Charbonneaux-Brabant

Threat actor ChimeraZ has published four separate datasets allegedly obtained from French organizations, exposing personnel, business, operational and identity-related information.

The affected organizations and claimed data include:

• CRMA Occitanie: 1,029 records in a 60 KB CSV dataset, including names, email addresses and regional/organizational information
• BCTI / partenaires.bcti.fr: 12 MB partial dataset in JSON/PDF format containing business mission, appointment, property and billing-related records, along with a folder allegedly containing 21 French identity cards
• Charbonneaux-Brabant: 2,863 records in a 660 KB JSON dataset containing names, email addresses, usernames, language, job functions, customer profiles and other account-related fields
• Tisséo: 13,446 records associated with 2,877 people in a 1.22 GB JSON dataset, including employee names, email addresses, personnel IDs, departments, services, job roles, work locations and additional internal workforce information

Tisséo operates Toulouse’s public transport network, while CRMA Occitanie supports businesses and artisans across the Occitanie region. Charbonneaux-Brabant specializes in packaging and household products, and the BCTI portal serves professional partners and organizations.

Samples were published for each alleged dataset, with the actor also providing download links for the material.

The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇮🇳 FortiGate appliance credentials tied to multiple Indian IT companies allegedly offered for sale on a cybercrime forum

Multiple small and medium-sized IT and consulting companies in India are allegedly affected after a threat actor advertised credentials associated with their FortiGate appliances.

The seller describes the affected organizations as primarily providing IT support and consulting services, with claimed annual revenues ranging from approximately $300,000 to $1.5 million.

The advertised access includes:

• FortiGate appliance credentials
• IP addresses
• Usernames
• Passwords
• FortiGate identifiers
• Access associated with IT and consulting environments

The number of affected users or appliances is not specified in the listing.

The actor is asking $5,000 or a higher offer for the alleged access and is offering proof privately to prospective buyers.

The claims and the authenticity, scope and current validity of the allegedly compromised credentials have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ A forum actor is offering edge device access to three American organizations, including two with over 5 million in revenue/size and one multi-billion revenue entity, claiming the access allows reaching Domain Admin.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇺🇸 Motorola internal AI and GenAI infrastructure access allegedly offered for sale on a cybercrime forum

Motorola, a U.S.-based telecommunications and technology company, is allegedly affected by a significant security compromise after a threat actor claimed to have accessed internal environments supporting the company’s GenAI and AI engineering infrastructure.

The actor claims the compromised environment includes:

• Internal repositories and source code
• GenAI modules, proxies and custom agents
• Model Context Protocol (MCP) servers
• Jira MCP infrastructure
• Frog MCP infrastructure
• Bitbucket MCP infrastructure
• Enterprise integration systems
• CI/CD pipelines
• Salesforce-related pipelines
• ServiceNow-related pipelines
• Azure RAG infrastructure
• Internal documentation
• Chat transcripts
• Monitoring and reporting systems
• Additional AI engineering assets

The actor published multiple screenshots presented as proof of access and states that the compromised environment and associated assets are now being offered for sale.

No public asking price is provided, with prospective buyers directed to contact the actor privately for verification, additional details and pricing.

The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ ShinyHunters has leaked the data of McKesson Corporation, NeoGen Corporation, Elekta AB, Jack Henry & Associates.