πŸ”ͺ That Dark Web Guy - Part 3 πŸ”ͺ
4.96K subscribers
1.23K photos
68 videos
1.09K links
Download Telegram
🚨 TerraMaster pre-auth RCE 0-day exploit allegedly offered on a cybercrime forum
β €
TerraMaster is a network-attached storage (NAS) vendor that develops storage appliances and operating systems for home, business, and enterprise environments.
β €
A cybercrime forum actor using the handle LazaKNOXGroup claims to be selling an exclusive, unpatched pre-authentication remote code execution exploit affecting TerraMaster systems.
β €
Claimed exploit details include:
β €
β€’ Affects TerraMaster V4 and V5
β€’ Pre-authentication RCE
β€’ Claimed code execution as root
β€’ Described as a logical vulnerability
β€’ Actor claims 100% reliability in testing
β€’ Single-buyer exclusivity
β€’ Full rights reportedly transferred to the buyer
β €
The actor states that Deal Over Escrow is accepted and is marketing the exploit as an exclusive sale.
β €
The vulnerability, affected versions, exploit reliability, and 0-day status have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡§πŸ‡· FUSVE and Medgrupo confidential data allegedly offered on a cybercrime forum

Hi Jack!
β €
Medgrupo is a Brazilian medical education company, while FUSVE operates educational and healthcare institutions in Rio de Janeiro state, including Vassouras University Hospital.
β €
A cybercrime forum actor using the handle jackswastedlife claims to possess hundreds of thousands of sensitive and financial records associated with Medgrupo clients and students, along with 70,963 PDF medical imaging reports tied to patients of Vassouras University Hospital.
β €
Claimed exposed data includes:
β €
β€’ Client and student financial records
β€’ Patient names
β€’ Patient ages
β€’ Referring physician information
β€’ Medical imaging reports
β€’ Examination dates
β€’ Clinical indications
β€’ Other sensitive medical information
β €
The actor also published several files as purported samples and is directing interested parties to contact them through Tox or email.
β €
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ A threat actor claims to be selling a Remote Code Execution (RCE) and Blind SQL Injection vulnerability affecting an undisclosed Moroccan government university website.

πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
😭2
β€ΌοΈπŸ‡ΉπŸ‡­ An actor on a forum is offering webmail access allegedly belonging to Police Thailand, claiming it provides access to law enforcement portals and the ability to retrieve documents and legal information about individuals.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
They won’t backtrack. They’ll just delete posts, change accounts, and pretend they never said any of it. The internet has a much better memory than people do. πŸ€·β€β™€οΈ
😭1
β€ΌοΈπŸ‡¦πŸ‡· A seller is offering root-level database access to an unnamed Argentine university for $200 in XMR/BTC, claiming the database includes user records with emails, passwords, full names, city, and state information.

πŸ’₯ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
πŸš¨πŸ‡ΊπŸ‡Έ Phoenix woman pleads guilty to running dark web drug operation

Brejea Wrigley, 30, pleaded guilty to two federal counts of distributing methamphetamine after prosecutors say she took over the dark web vendor account β€œBlackCoconut” in August 2025.
β €
The operation offered methamphetamine, fentanyl marketed as β€œChina White,” pressed oxycodone pills, and mushrooms, with drugs shipped to customers nationwide through USPS.
β €
Undercover investigators placed two orders that were shipped from Phoenix to a law enforcement-controlled P.O. Box in New Hampshire.

The shipments contained nearly 450 grams and more than 800 grams of methamphetamine.
β €
Investigators later identified Wrigley as the person operating the account following additional investigation and search warrants.
β €
She faces up to life in federal prison, at least five years of supervised release, and a fine of up to $10 million.

Sentencing is scheduled for December 17.

Source: https://www.azfamily.com/2026/09/09/phoenix-woman-who-sold-meth-dark-web-could-face-up-life-prison/
β€ΌοΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡ΊπŸ‡ΈπŸ‡¨πŸ‡¦ Cl0p Ransomware claims and leaks 4 victims

πŸ‡ΊπŸ‡Έ Harley-Davidson - A U.S.-based motorcycle manufacturer known for heavyweight motorcycles, parts, accessories, apparel, and related financial services.

πŸ‡ΊπŸ‡Έ Henry Pratt Company - A U.S.-based manufacturer of valves and flow-control products used in water, wastewater, power, and industrial infrastructure.

πŸ‡ΊπŸ‡Έ GE - A U.S.-based industrial and aerospace company with major operations in aircraft engines, aviation systems, and related technologies.

πŸ‡¨πŸ‡¦ ALDO Group - A Canadian footwear and accessories company operating the ALDO brand and other retail businesses internationally.
Media is too big
VIEW IN TELEGRAM
Another good banger.

KSHMR - House Of Cards (feat. Sidnie Tipton)
πŸ”₯1
Forwarded from Dark Web Informer - Private
‼️ DOJ Press Release
━━━━━━━━━━━━━━━━━━━━━

Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomware

Full Press Release β†’ justice.gov

━━━━━━━━━━━━━━━━━━━━━
πŸ•΅οΈ Dark Web Informer β€’ DOJ Monitor

Note: DOJ articles that are not Cyber related will be removed manually.
❀1
β€ΌοΈπŸ‡ΊπŸ‡ΈπŸ‡΅πŸ‡­ Rhysida Ransomware claims a retail services company and a hospital

πŸ‡ΊπŸ‡Έ Professional Retail Services - A U.S.-based retail services company providing facilities maintenance, construction, project management, and related support for commercial and retail clients.

The listing claims employee evaluations, salary and bonus information, job offers, family documents, client credit reports, bankruptcy and tax records, medical records, corporate financial documents, tax returns, credit applications, signed checks, corporate credit card information, drug tests, and employee health insurance data. The dataset is being offered for 8 BTC.

πŸ‡΅πŸ‡­ General Santos Doctors Hospital - A Philippine hospital providing medical, surgical, diagnostic, and specialist healthcare services.

The listing claims approximately 3.5 million files totaling 2.44 TB, including patient PHI, pathology and hemodialysis records, admission records, cancer-treatment files, laboratory data, PhilHealth information, neonatal/NICU data, physician records, payroll workbooks, HR files, passport scans, drug-test records, audited financial statements, banking information, internal audit documents, payroll batches, and leadership contact information. The dataset is being offered for 8 BTC.
Media is too big
VIEW IN TELEGRAM
The Dark Web’s New Deadliest Drug

These are Nitazenes. Nitazenes are a highly potent and still relatively little-known class of synthetic opioids that are increasingly making their way into Europe’s illicit drug supply.

Video Credit: youtube.com/@fern-tv
β€ΌοΈπŸ‡ΊπŸ‡ΈπŸ”’ RansomHouse Ransomware claims California School Employees Association (CSEA)

πŸ‡ΊπŸ‡Έ California School Employees Association (CSEA) - A California-based labor organization representing classified public school employees and advocating for employee rights, benefits, and public education.

The listing claims the organization’s systems were encrypted on August 21, 2026 and references 35 evidence items, with the actor threatening to leak confidential data, project documents, and other internal information.
🚨 Surfshark discloses security incident after internal test server was exposed to the internet

Surfshark says human error resulted in an internal engineering test server being misconfigured and publicly reachable, allowing an unauthorized third party to gain access.
β €
The exposed environment contained limited internal engineering material, including parts of system binaries and configurations for certain services. Some build-related credentials had also previously been committed to the company’s code history.
β €
Surfshark says:

β€’ No customer data was accessed
β€’ No VPN traffic or browsing activity was exposed
β€’ No production systems were compromised
β€’ No encryption keys or user IP addresses were accessible
β€’ Apps and browser extensions were not altered
β €
Access was also gained to an isolated content accessibility optimization server, but Surfshark says it had no access to user identities, browsing traffic, encryption keys, or IP addresses.
β €
The first suspicious activity was detected on August 31. The incident was confirmed and contained on September 2, with additional remediation completed by September 5.
β €
Surfshark rotated or retired potentially affected internal credentials and says it found no malicious activity in the available access logs.

The company is now strengthening security around test environments and plans to conduct an additional independent security audit.

Source: https://surfshark.com/blog/security-update-september-2026-incident-report
Hot take, imagine SH releasing a dataset tomorrow related to NYπŸ‡ΊπŸ‡Έ licenses. It's a hot take chat.
πŸ”₯3
‼️ CVE-2026-11387: A critical improper-authentication flaw in the WordPress plugin SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery.

GitHub: https://github.com/abraxas/CVE-2026-11387-WooCommerce-SMS-OTP
πŸš¨πŸ‡ΉπŸ‡· Threat actor seeks partner after claiming access to a Turkish company’s SMTP credentials
β €
The targeted organization is described only as a medium-sized Turkish company, with its name and industry not disclosed in the forum post.
β €
An actor claims to possess the company’s SMTP credentials and is seeking a partner to help operationalize the access.
β €
The actor claims experience obtaining access through:
β €
β€’ RDP
β€’ Fortinet infrastructure
β€’ VPN services
β€’ Other remote-access environments
β €
The actor states that developing or configuring command-and-control infrastructure to evade detection is outside their area of expertise and says they are looking for someone to work with.
β €
The access claim, affected company, and validity of the credentials have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing