Torrent sites are notorious for leaking IPs and shitty security.
‼️ Security researcher Nightmare Eclipse has released a new zero-day called FalconFlank, a CrowdStrike Falcon local privilege escalation (LPE) vulnerability.
GitHub: https://github.com/MSNightmare/FalconFlank
GitHub: https://github.com/MSNightmare/FalconFlank
🚨 Four French organizations allegedly targeted in data leaks, including Tisséo, CRMA Occitanie, BCTI and Charbonneaux-Brabant
⠀
Threat actor ChimeraZ has published four separate datasets allegedly obtained from French organizations, exposing personnel, business, operational and identity-related information.
⠀
The affected organizations and claimed data include:
⠀
• CRMA Occitanie: 1,029 records in a 60 KB CSV dataset, including names, email addresses and regional/organizational information
• BCTI / partenaires.bcti.fr: 12 MB partial dataset in JSON/PDF format containing business mission, appointment, property and billing-related records, along with a folder allegedly containing 21 French identity cards
• Charbonneaux-Brabant: 2,863 records in a 660 KB JSON dataset containing names, email addresses, usernames, language, job functions, customer profiles and other account-related fields
• Tisséo: 13,446 records associated with 2,877 people in a 1.22 GB JSON dataset, including employee names, email addresses, personnel IDs, departments, services, job roles, work locations and additional internal workforce information
⠀
Tisséo operates Toulouse’s public transport network, while CRMA Occitanie supports businesses and artisans across the Occitanie region. Charbonneaux-Brabant specializes in packaging and household products, and the BCTI portal serves professional partners and organizations.
⠀
Samples were published for each alleged dataset, with the actor also providing download links for the material.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Threat actor ChimeraZ has published four separate datasets allegedly obtained from French organizations, exposing personnel, business, operational and identity-related information.
⠀
The affected organizations and claimed data include:
⠀
• CRMA Occitanie: 1,029 records in a 60 KB CSV dataset, including names, email addresses and regional/organizational information
• BCTI / partenaires.bcti.fr: 12 MB partial dataset in JSON/PDF format containing business mission, appointment, property and billing-related records, along with a folder allegedly containing 21 French identity cards
• Charbonneaux-Brabant: 2,863 records in a 660 KB JSON dataset containing names, email addresses, usernames, language, job functions, customer profiles and other account-related fields
• Tisséo: 13,446 records associated with 2,877 people in a 1.22 GB JSON dataset, including employee names, email addresses, personnel IDs, departments, services, job roles, work locations and additional internal workforce information
⠀
Tisséo operates Toulouse’s public transport network, while CRMA Occitanie supports businesses and artisans across the Occitanie region. Charbonneaux-Brabant specializes in packaging and household products, and the BCTI portal serves professional partners and organizations.
⠀
Samples were published for each alleged dataset, with the actor also providing download links for the material.
⠀
The claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🔪 Slice For Life - Part 2 🔪
‼️ New Ransomware Group: Vexy Dark Web Onion: http://vexytsr3chimdz6siwaqi2lvxxwfkxvffkpwyanr2llequ2hkm56jvqd[.]onion
‼️ Vexy Ransomware Affiliate Program
‼️ New Dark Web Informer Blog Post!
Title: ZeroGaspi Customer Records for 89,281 French Shoppers Sold for 70 Dollars
Link: https://darkwebinformer.com/zerogaspi-customer-records-for-89-281-french-shoppers-sold-for-70-dollars/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: ZeroGaspi Customer Records for 89,281 French Shoppers Sold for 70 Dollars
Link: https://darkwebinformer.com/zerogaspi-customer-records-for-89-281-french-shoppers-sold-for-70-dollars/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
ZeroGaspi Customer Records for 89,281 French Shoppers Sold for 70 Dollars
A forum actor posting as ksye is selling what they describe as the customer database of zerogaspi.fr, a French retailer selling surplus and short dated groceries.
❤1
‼️ New Dark Web Informer Blog Post!
Title: 3.1 Million DZI Records Offered With National ID and Passport Numbers
Link: https://darkwebinformer.com/3-1-million-dzi-records-offered-with-national-id-and-passport-numbers/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: 3.1 Million DZI Records Offered With National ID and Passport Numbers
Link: https://darkwebinformer.com/3-1-million-dzi-records-offered-with-national-id-and-passport-numbers/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
3.1 Million DZI Records Offered With National ID and Passport Numbers
A forum actor posting as Intelligence is selling what they describe as 3,134,269 full personal data records belonging to customers of DZI Insurance, Bulgaria's oldest insurer and a subsidiary of Belgium's KBC Group.
🚨🇮🇳 FortiGate appliance credentials tied to multiple Indian IT companies allegedly offered for sale on a cybercrime forum
⠀
Multiple small and medium-sized IT and consulting companies in India are allegedly affected after a threat actor advertised credentials associated with their FortiGate appliances.
⠀
The seller describes the affected organizations as primarily providing IT support and consulting services, with claimed annual revenues ranging from approximately $300,000 to $1.5 million.
⠀
The advertised access includes:
⠀
• FortiGate appliance credentials
• IP addresses
• Usernames
• Passwords
• FortiGate identifiers
• Access associated with IT and consulting environments
⠀
The number of affected users or appliances is not specified in the listing.
⠀
The actor is asking $5,000 or a higher offer for the alleged access and is offering proof privately to prospective buyers.
⠀
The claims and the authenticity, scope and current validity of the allegedly compromised credentials have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Multiple small and medium-sized IT and consulting companies in India are allegedly affected after a threat actor advertised credentials associated with their FortiGate appliances.
⠀
The seller describes the affected organizations as primarily providing IT support and consulting services, with claimed annual revenues ranging from approximately $300,000 to $1.5 million.
⠀
The advertised access includes:
⠀
• FortiGate appliance credentials
• IP addresses
• Usernames
• Passwords
• FortiGate identifiers
• Access associated with IT and consulting environments
⠀
The number of affected users or appliances is not specified in the listing.
⠀
The actor is asking $5,000 or a higher offer for the alleged access and is offering proof privately to prospective buyers.
⠀
The claims and the authenticity, scope and current validity of the allegedly compromised credentials have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ A forum actor is offering edge device access to three American organizations, including two with over 5 million in revenue/size and one multi-billion revenue entity, claiming the access allows reaching Domain Admin.
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇺🇸 Motorola internal AI and GenAI infrastructure access allegedly offered for sale on a cybercrime forum
⠀
Motorola, a U.S.-based telecommunications and technology company, is allegedly affected by a significant security compromise after a threat actor claimed to have accessed internal environments supporting the company’s GenAI and AI engineering infrastructure.
⠀
The actor claims the compromised environment includes:
⠀
• Internal repositories and source code
• GenAI modules, proxies and custom agents
• Model Context Protocol (MCP) servers
• Jira MCP infrastructure
• Frog MCP infrastructure
• Bitbucket MCP infrastructure
• Enterprise integration systems
• CI/CD pipelines
• Salesforce-related pipelines
• ServiceNow-related pipelines
• Azure RAG infrastructure
• Internal documentation
• Chat transcripts
• Monitoring and reporting systems
• Additional AI engineering assets
⠀
The actor published multiple screenshots presented as proof of access and states that the compromised environment and associated assets are now being offered for sale.
⠀
No public asking price is provided, with prospective buyers directed to contact the actor privately for verification, additional details and pricing.
⠀
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Motorola, a U.S.-based telecommunications and technology company, is allegedly affected by a significant security compromise after a threat actor claimed to have accessed internal environments supporting the company’s GenAI and AI engineering infrastructure.
⠀
The actor claims the compromised environment includes:
⠀
• Internal repositories and source code
• GenAI modules, proxies and custom agents
• Model Context Protocol (MCP) servers
• Jira MCP infrastructure
• Frog MCP infrastructure
• Bitbucket MCP infrastructure
• Enterprise integration systems
• CI/CD pipelines
• Salesforce-related pipelines
• ServiceNow-related pipelines
• Azure RAG infrastructure
• Internal documentation
• Chat transcripts
• Monitoring and reporting systems
• Additional AI engineering assets
⠀
The actor published multiple screenshots presented as proof of access and states that the compromised environment and associated assets are now being offered for sale.
⠀
No public asking price is provided, with prospective buyers directed to contact the actor privately for verification, additional details and pricing.
⠀
The claims and the authenticity, scope and current validity of the allegedly compromised access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New Dark Web Informer Blog Post!
Title: More Than a Million Salt Mobile Records Offered for Sale
Link: https://darkwebinformer.com/more-than-a-million-salt-mobile-records-offered-for-sale/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: More Than a Million Salt Mobile Records Offered for Sale
Link: https://darkwebinformer.com/more-than-a-million-salt-mobile-records-offered-for-sale/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
More Than a Million Salt Mobile Records Offered for Sale
A forum actor posting as SaltMobile1 is selling what they describe as a database of Salt, a Swiss mobile operator, containing more than 1,090,000 records.
‼️ New Dark Web Informer Blog Post!
Title: HopCharge Analytics Export Published With Names, Phones and Coordinates
Link: https://darkwebinformer.com/hopcharge-analytics-export-published-with-names-phones-and-coordinates/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: HopCharge Analytics Export Published With Names, Phones and Coordinates
Link: https://darkwebinformer.com/hopcharge-analytics-export-published-with-names-phones-and-coordinates/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
HopCharge Analytics Export Published With Names, Phones and Coordinates
A forum actor posting as GoreTerminal has published what they describe as the database of hopcharge.com, an on demand doorstep electric vehicle charging service operating in India through mobile vans.
‼️ New Dark Web Informer Blog Post!
Title: Réso Files Totalling 675 GB Offered for Sale After a Silent Period Ends
Link: https://darkwebinformer.com/reso-files-totalling-675-gb-offered-for-sale-after-a-silent-period-ends/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Réso Files Totalling 675 GB Offered for Sale After a Silent Period Ends
Link: https://darkwebinformer.com/reso-files-totalling-675-gb-offered-for-sale-after-a-silent-period-ends/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Réso Files Totalling 675 GB Offered for Sale After a Silent Period Ends
A forum actor posting as caustic claims to hold 675 GB taken from the network of Réso, a French supplier of construction products including ceilings, partitions, floors and facades, with agencies across the country.