🚨🇹🇷 Threat actor seeks partner after claiming access to a Turkish company’s SMTP credentials
⠀
The targeted organization is described only as a medium-sized Turkish company, with its name and industry not disclosed in the forum post.
⠀
An actor claims to possess the company’s SMTP credentials and is seeking a partner to help operationalize the access.
⠀
The actor claims experience obtaining access through:
⠀
• RDP
• Fortinet infrastructure
• VPN services
• Other remote-access environments
⠀
The actor states that developing or configuring command-and-control infrastructure to evade detection is outside their area of expertise and says they are looking for someone to work with.
⠀
The access claim, affected company, and validity of the credentials have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
The targeted organization is described only as a medium-sized Turkish company, with its name and industry not disclosed in the forum post.
⠀
An actor claims to possess the company’s SMTP credentials and is seeking a partner to help operationalize the access.
⠀
The actor claims experience obtaining access through:
⠀
• RDP
• Fortinet infrastructure
• VPN services
• Other remote-access environments
⠀
The actor states that developing or configuring command-and-control infrastructure to evade detection is outside their area of expertise and says they are looking for someone to work with.
⠀
The access claim, affected company, and validity of the credentials have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ I have added 3 new incidents to the Physical Bitcoin Attacks page.
https://darkwebinformer.com/physical-bitcoin-attacks/
https://darkwebinformer.com/physical-bitcoin-attacks/
Dark Web Informer
Physical Bitcoin Attacks
A comprehensive database of known physical attacks against Bitcoin and crypto asset holders occurring in meatspace.
🚨🇫🇷 WiziShop and Dropizi dataset containing 511K+ records allegedly leaked on a cybercrime forum
⠀
WiziShop and Dropizi are French e-commerce platforms that help businesses create and manage online stores, with Dropizi focused on dropshipping.
⠀
A cybercrime forum actor using the handle ChimeraZ claims to have leaked a dataset associated with stores operating through WiziShop and Dropizi, containing 511,661 records across 21,402 stores.
⠀
Claimed exposed data includes:
⠀
• Invoice IDs and numbers
• Supplier information
• Customer identifiers
• Store names
• Billing and delivery addresses
• Cities and postal information
• Countries
• Transaction and invoice dates
• Other store and order-related records
⠀
The actor states the dataset is approximately 127 MB in JSON format and published multiple download mirrors along with a sample of the purported data.
⠀
The source, record count, and authenticity of the dataset have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
WiziShop and Dropizi are French e-commerce platforms that help businesses create and manage online stores, with Dropizi focused on dropshipping.
⠀
A cybercrime forum actor using the handle ChimeraZ claims to have leaked a dataset associated with stores operating through WiziShop and Dropizi, containing 511,661 records across 21,402 stores.
⠀
Claimed exposed data includes:
⠀
• Invoice IDs and numbers
• Supplier information
• Customer identifiers
• Store names
• Billing and delivery addresses
• Cities and postal information
• Countries
• Transaction and invoice dates
• Other store and order-related records
⠀
The actor states the dataset is approximately 127 MB in JSON format and published multiple download mirrors along with a sample of the purported data.
⠀
The source, record count, and authenticity of the dataset have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇰🇼 Jazeera Airways partial dataset containing 54K+ individuals allegedly leaked
⠀
Jazeera Airways is a Kuwait-based low-cost airline serving destinations across the Middle East, Asia, Europe, and Africa.
⠀
A forum actor using the handle ChimeraZ claims to have leaked a partial Jazeera Airways dataset containing information tied to 54,375 people, with approximately 154,310 lines of data.
⠀
Claimed exposed data includes:
⠀
• Customer names
• Email addresses
• Mobile numbers
• Insurance policy information
• Policy and insurance certificate numbers
• Coverage levels
• Policy issue, start, and end dates
• Insurer information
• Premium amounts
• Benefit schedules
• Policy notes
• Travel agency invoices
• Invoice and payment-related information
⠀
The actor states the leak is approximately 400 MB in JSON and PDF formats and includes 3,711 agency invoices totaling around 335 MB, along with tens of thousands of policy notes and insurance certificates.
⠀
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Jazeera Airways is a Kuwait-based low-cost airline serving destinations across the Middle East, Asia, Europe, and Africa.
⠀
A forum actor using the handle ChimeraZ claims to have leaked a partial Jazeera Airways dataset containing information tied to 54,375 people, with approximately 154,310 lines of data.
⠀
Claimed exposed data includes:
⠀
• Customer names
• Email addresses
• Mobile numbers
• Insurance policy information
• Policy and insurance certificate numbers
• Coverage levels
• Policy issue, start, and end dates
• Insurer information
• Premium amounts
• Benefit schedules
• Policy notes
• Travel agency invoices
• Invoice and payment-related information
⠀
The actor states the leak is approximately 400 MB in JSON and PDF formats and includes 3,711 agency invoices totaling around 335 MB, along with tens of thousands of policy notes and insurance certificates.
⠀
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨🇫🇷 Aqualter contact dataset containing 273K+ individuals allegedly leaked
⠀
Aqualter is a French water-management company providing services and infrastructure related to drinking water, wastewater treatment, and environmental management.
⠀
A forum actor using the handle ChimeraZ claims to have leaked contact information associated with 273,229 individuals, totaling more than 320,000 records.
⠀
Claimed exposed data includes:
⠀
• 187,073 phone numbers
• 86,156 email addresses
• Associated record identifiers
⠀
The actor states the dataset is approximately 7 MB in CSV format and published samples showing email addresses and phone numbers.
⠀
The source, record count, and authenticity of the dataset have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
⠀
Aqualter is a French water-management company providing services and infrastructure related to drinking water, wastewater treatment, and environmental management.
⠀
A forum actor using the handle ChimeraZ claims to have leaked contact information associated with 273,229 individuals, totaling more than 320,000 records.
⠀
Claimed exposed data includes:
⠀
• 187,073 phone numbers
• 86,156 email addresses
• Associated record identifiers
⠀
The actor states the dataset is approximately 7 MB in CSV format and published samples showing email addresses and phone numbers.
⠀
The source, record count, and authenticity of the dataset have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
🚨🇺🇸 Booking.com-linked payment card dataset containing 2.3K+ records allegedly offered for sale
⠀
Booking.com is a global online travel platform used to book accommodations, flights, car rentals, and other travel services.
⠀
A forum actor using the handle ChimeraZ claims to be selling a dataset containing 2,348 records allegedly associated with Booking.com customers.
⠀
Claimed exposed data includes:
⠀
• Customer names
• Street addresses
• ZIP/postal codes
• Payment card numbers
• Card expiration dates
• Record identifiers
⠀
The actor states the dataset is approximately 350 KB in JSON format and does not include CVV codes. Several sample records were published alongside the listing.
⠀
The dataset is being offered for $40 in XMR.
⠀
The source of the data, its connection to Booking.com, and the authenticity of the records have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Booking.com is a global online travel platform used to book accommodations, flights, car rentals, and other travel services.
⠀
A forum actor using the handle ChimeraZ claims to be selling a dataset containing 2,348 records allegedly associated with Booking.com customers.
⠀
Claimed exposed data includes:
⠀
• Customer names
• Street addresses
• ZIP/postal codes
• Payment card numbers
• Card expiration dates
• Record identifiers
⠀
The actor states the dataset is approximately 350 KB in JSON format and does not include CVV codes. Several sample records were published alongside the listing.
⠀
The dataset is being offered for $40 in XMR.
⠀
The source of the data, its connection to Booking.com, and the authenticity of the records have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❤2🔥1
🚨 DarkMatter Market is likely gone after exit scamming. That doesn't mean the feds stop chasing though. If admin got spooked on something, then things may just be heating up.
Name: DarkMatter Market
Launch Date: September 22nd, 2022
Exit Start: September 7th, 2026
Dread Superlist: September 24th, 2023
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
Name: DarkMatter Market
Launch Date: September 22nd, 2022
Exit Start: September 7th, 2026
Dread Superlist: September 24th, 2023
________________________________________
Main Channel: https://t.me/SliceForLifeee
Backup Channel: https://t.me/SliceForLifeeee
Telegram CVE Feed: https://t.me/DWI_CVE_Alerts
FBI Watchdog Alerts: https://t.me/FBI_Watchdog
Website: https://darkwebinformer.com
Pricing (Includes Crypto): https://darkwebinformer.com/pricing
API: https://darkwebinformer.com/api-details
Donations: https://darkwebinformer.com/donations
Socials: https://darkwebinformer.com/socials
🚨🇺🇸 Forum actor solicits U.S. tax forms for refund filing operation
⠀
U.S. tax forms such as 1040s, 1065s, 1099s, W-2s, and W-9s can contain sensitive taxpayer, income, employment, and business information used for federal tax reporting.
⠀
A forum actor using the handle Elkmann is seeking partners who can provide tax-form data from compromised targets, claiming they can process the information and file for refunds throughout the year.
⠀
Forms being requested include:
⠀
• Form 1040 individual tax returns
• Form 1065 partnership returns
• Form 1099 information returns
• W-2 wage and tax statements
• W-9 taxpayer identification forms
• W-9 records accompanied by email access
⠀
The actor states they can process as many forms as partners can provide and is actively seeking partnerships ahead of the next tax season.
⠀
Minimum quantities are reportedly discussed privately, with initial contact requested through forum messages.
⠀
The legitimacy, scale, and success of the claimed refund operation have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
U.S. tax forms such as 1040s, 1065s, 1099s, W-2s, and W-9s can contain sensitive taxpayer, income, employment, and business information used for federal tax reporting.
⠀
A forum actor using the handle Elkmann is seeking partners who can provide tax-form data from compromised targets, claiming they can process the information and file for refunds throughout the year.
⠀
Forms being requested include:
⠀
• Form 1040 individual tax returns
• Form 1065 partnership returns
• Form 1099 information returns
• W-2 wage and tax statements
• W-9 taxpayer identification forms
• W-9 records accompanied by email access
⠀
The actor states they can process as many forms as partners can provide and is actively seeking partnerships ahead of the next tax season.
⠀
Minimum quantities are reportedly discussed privately, with initial contact requested through forum messages.
⠀
The legitimacy, scale, and success of the claimed refund operation have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Kicksecure: Kicksecure is a hardened Linux operating system designed for security-sensitive computing. It includes protections against malware and exploits, stronger system isolation, hardened defaults, and physical-security features such as a panic-key emergency shutdown that can quickly power off the system if it is at risk of being physically compromised.
Link: https://www.kicksecure.com/
Link: https://www.kicksecure.com/
❤2
‼️ New Dark Web Informer Blog Post!
Title: Metropolis Technologies Source Code Allegedly Stolen and Leaked
Link: https://darkwebinformer.com/metropolis-technologies-source-code-allegedly-stolen-and-leaked/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Metropolis Technologies Source Code Allegedly Stolen and Leaked
Link: https://darkwebinformer.com/metropolis-technologies-source-code-allegedly-stolen-and-leaked/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Metropolis Technologies Source Code Allegedly Stolen and Leaked
A forum moderator posting as 888 claims to have breached Metropolis Technologies and uploaded stolen company source code for other forum members to download.
‼️ New Dark Web Informer Blog Post!
Title: Generali Insurance Bulgaria Dataset Claim Covers 1,241,432 Personal Records
Link: https://darkwebinformer.com/generali-insurance-bulgaria-dataset-claim-covers-1-241-432-personal-records/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Generali Insurance Bulgaria Dataset Claim Covers 1,241,432 Personal Records
Link: https://darkwebinformer.com/generali-insurance-bulgaria-dataset-claim-covers-1-241-432-personal-records/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Generali Insurance Bulgaria Dataset Claim Covers 1,241,432 Personal Records
A forum actor posting as Intelligence is offering what they claim is a dataset containing 1,241,432 personal-data records belonging to customers of Generali Insurance Bulgaria (Generali Insurance AD), a licensed Bulgarian insurer that operates as part of…
This media is not supported in your browser
VIEW IN TELEGRAM
The Prodigy - One Love (Hackers Soundtrack)
❤1
🚨🇮🇩 Universitas Andalas dataset containing 118K+ accounts allegedly leaked
⠀
Universitas Andalas is a public university in Padang, West Sumatra, Indonesia, operating academic, administrative, and research systems including numerous online journal platforms.
⠀
A forum actor using the handle Koyot claims to have obtained data covering 118,289 user accounts across 40 academic journal instances, along with administrative accounts tied to the university’s main Joomla portal and journal systems.
⠀
Claimed exposed data includes:
⠀
• Usernames and display names
• Institutional email addresses
• bcrypt and MD5 password hashes
• Registration and last-login timestamps
• TOTP 2FA seeds and emergency recovery codes
• Active session IDs and remember-me tokens
• Names, dates of birth, phone numbers, and addresses
• Academic affiliations and ORCID identifiers
• Biographies and CV information
• Manuscript and peer-review working files
• Reviewer assignments
• Publication-fee payment records
• Institutional subscriber IP ranges
• Administrative and CMS records
⠀
The actor claims the dump was extracted in September 2026 and includes data from the university’s main portal and 40 Open Journal Systems instances. A sample of the purported records was published with the listing.
⠀
The dataset is being offered as a single sale for $200 in XMR, with escrow reportedly accepted.
⠀
The breach claim, record count, authenticity of the data, and claimed exposure of 2FA material have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
⠀
Universitas Andalas is a public university in Padang, West Sumatra, Indonesia, operating academic, administrative, and research systems including numerous online journal platforms.
⠀
A forum actor using the handle Koyot claims to have obtained data covering 118,289 user accounts across 40 academic journal instances, along with administrative accounts tied to the university’s main Joomla portal and journal systems.
⠀
Claimed exposed data includes:
⠀
• Usernames and display names
• Institutional email addresses
• bcrypt and MD5 password hashes
• Registration and last-login timestamps
• TOTP 2FA seeds and emergency recovery codes
• Active session IDs and remember-me tokens
• Names, dates of birth, phone numbers, and addresses
• Academic affiliations and ORCID identifiers
• Biographies and CV information
• Manuscript and peer-review working files
• Reviewer assignments
• Publication-fee payment records
• Institutional subscriber IP ranges
• Administrative and CMS records
⠀
The actor claims the dump was extracted in September 2026 and includes data from the university’s main portal and 40 Open Journal Systems instances. A sample of the purported records was published with the listing.
⠀
The dataset is being offered as a single sale for $200 in XMR, with escrow reportedly accepted.
⠀
The breach claim, record count, authenticity of the data, and claimed exposure of 2FA material have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
❤1
🚨 Two VLC Media Player flaws can allow code execution and leak sensitive memory
Security researchers have disclosed two vulnerabilities affecting VLC Media Player versions 3.0.0 through 3.0.23.
⠀
CVE-2026-56711, rated 8.6, is a heap out-of-bounds write caused by an integer overflow in VLC's picture buffer allocation.
An attacker can craft a malicious PNG with manipulated dimensions that causes VLC to allocate an undersized memory buffer before writing beyond its boundaries.
The flaw can potentially lead to arbitrary code execution when the malicious image is opened directly or loaded through a playlist.
⠀
CVE-2026-73324, rated 6.9, affects VLC's RealRTSP handling.
A malicious RTSP server can send an oversized response that causes VLC to read beyond an allocated buffer and return adjacent heap memory to the attacker, potentially exposing sensitive information.
⠀
The vulnerable RealRTSP component is enabled in official VideoLAN builds, although some Linux distribution packages may compile VLC without it.
⠀
As of September 11, VLC 3.0.23 remains the current stable desktop release listed by VideoLAN and is affected by both vulnerabilities.
Users should avoid opening untrusted image files or RealRTSP playlist links until an updated release addressing the flaws becomes available.
Source: https://securityonline.info/vlc-media-player-vulnerabilities/
Security researchers have disclosed two vulnerabilities affecting VLC Media Player versions 3.0.0 through 3.0.23.
⠀
CVE-2026-56711, rated 8.6, is a heap out-of-bounds write caused by an integer overflow in VLC's picture buffer allocation.
An attacker can craft a malicious PNG with manipulated dimensions that causes VLC to allocate an undersized memory buffer before writing beyond its boundaries.
The flaw can potentially lead to arbitrary code execution when the malicious image is opened directly or loaded through a playlist.
⠀
CVE-2026-73324, rated 6.9, affects VLC's RealRTSP handling.
A malicious RTSP server can send an oversized response that causes VLC to read beyond an allocated buffer and return adjacent heap memory to the attacker, potentially exposing sensitive information.
⠀
The vulnerable RealRTSP component is enabled in official VideoLAN builds, although some Linux distribution packages may compile VLC without it.
⠀
As of September 11, VLC 3.0.23 remains the current stable desktop release listed by VideoLAN and is affected by both vulnerabilities.
Users should avoid opening untrusted image files or RealRTSP playlist links until an updated release addressing the flaws becomes available.
Source: https://securityonline.info/vlc-media-player-vulnerabilities/
❤3
‼️ New Dark Web Informer Blog Post!
Title: Boulanger Dataset Claim Covers 132,230 Customer and Service Records
Link: https://darkwebinformer.com/boulanger-dataset-claim-covers-132-230-customer-and-service-records/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Boulanger Dataset Claim Covers 132,230 Customer and Service Records
Link: https://darkwebinformer.com/boulanger-dataset-claim-covers-132-230-customer-and-service-records/
💥 Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Boulanger Dataset Claim Covers 132,230 Customer and Service Records
A forum actor posting as fuie has uploaded what they claim is a database belonging to Boulanger, a French consumer electronics and home-appliance retailer.
🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure
Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances.
⠀
The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request.
Affected versions include:
• GitLab 18.7 through versions before 19.1.8
• GitLab 19.2 through versions before 19.2.6
• GitLab 19.3 through versions before 19.3.2
⠀
GitLab disclosed and patched the vulnerability on September 10.
Just one day later, watchTowr began observing in-the-wild exploitation attempts and warns that mass exploitation is likely to follow.
⠀
Administrators should upgrade immediately to GitLab 19.1.8, 19.2.6, 19.3.2, or a newer supported release.
GitLab.com is already patched.
Source: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances.
⠀
The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request.
Affected versions include:
• GitLab 18.7 through versions before 19.1.8
• GitLab 19.2 through versions before 19.2.6
• GitLab 19.3 through versions before 19.3.2
⠀
GitLab disclosed and patched the vulnerability on September 10.
Just one day later, watchTowr began observing in-the-wild exploitation attempts and warns that mass exploitation is likely to follow.
⠀
Administrators should upgrade immediately to GitLab 19.1.8, 19.2.6, 19.3.2, or a newer supported release.
GitLab.com is already patched.
Source: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
🔪 That Dark Web Guy - Part 3 🔪
🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances. ⠀ The flaw allows an…
🚨 CVE-2026-85706: An unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7–19.1.7; 19.2.0–19.2.5; 19.3.0–19.3.1
PoC: https://github.com/guneykabel/cve-2026-85706
PoC: https://github.com/guneykabel/cve-2026-85706
GitHub
GitHub - guneykabel/cve-2026-85706: Exploit poc for CVE-2026-85706 an unauthenticated arbitrary file read on Gitlab CE-EE affecting…
Exploit poc for CVE-2026-85706 an unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7–19.1.7; 19.2.0–19.2.5; 19.3.0–19.3.1 - guneykabel/cve-2026-85706