Kicksecure: Kicksecure is a hardened Linux operating system designed for security-sensitive computing. It includes protections against malware and exploits, stronger system isolation, hardened defaults, and physical-security features such as a panic-key emergency shutdown that can quickly power off the system if it is at risk of being physically compromised.
Link: https://www.kicksecure.com/
Link: https://www.kicksecure.com/
โค2
โผ๏ธ New Dark Web Informer Blog Post!
Title: Metropolis Technologies Source Code Allegedly Stolen and Leaked
Link: https://darkwebinformer.com/metropolis-technologies-source-code-allegedly-stolen-and-leaked/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Metropolis Technologies Source Code Allegedly Stolen and Leaked
Link: https://darkwebinformer.com/metropolis-technologies-source-code-allegedly-stolen-and-leaked/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Metropolis Technologies Source Code Allegedly Stolen and Leaked
A forum moderator posting as 888 claims to have breached Metropolis Technologies and uploaded stolen company source code for other forum members to download.
โผ๏ธ New Dark Web Informer Blog Post!
Title: Generali Insurance Bulgaria Dataset Claim Covers 1,241,432 Personal Records
Link: https://darkwebinformer.com/generali-insurance-bulgaria-dataset-claim-covers-1-241-432-personal-records/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Generali Insurance Bulgaria Dataset Claim Covers 1,241,432 Personal Records
Link: https://darkwebinformer.com/generali-insurance-bulgaria-dataset-claim-covers-1-241-432-personal-records/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Generali Insurance Bulgaria Dataset Claim Covers 1,241,432 Personal Records
A forum actor posting as Intelligence is offering what they claim is a dataset containing 1,241,432 personal-data records belonging to customers of Generali Insurance Bulgaria (Generali Insurance AD), a licensed Bulgarian insurer that operates as part ofโฆ
This media is not supported in your browser
VIEW IN TELEGRAM
The Prodigy - One Love (Hackers Soundtrack)
โค1
๐จ๐ฎ๐ฉ Universitas Andalas dataset containing 118K+ accounts allegedly leaked
โ
Universitas Andalas is a public university in Padang, West Sumatra, Indonesia, operating academic, administrative, and research systems including numerous online journal platforms.
โ
A forum actor using the handle Koyot claims to have obtained data covering 118,289 user accounts across 40 academic journal instances, along with administrative accounts tied to the universityโs main Joomla portal and journal systems.
โ
Claimed exposed data includes:
โ
โข Usernames and display names
โข Institutional email addresses
โข bcrypt and MD5 password hashes
โข Registration and last-login timestamps
โข TOTP 2FA seeds and emergency recovery codes
โข Active session IDs and remember-me tokens
โข Names, dates of birth, phone numbers, and addresses
โข Academic affiliations and ORCID identifiers
โข Biographies and CV information
โข Manuscript and peer-review working files
โข Reviewer assignments
โข Publication-fee payment records
โข Institutional subscriber IP ranges
โข Administrative and CMS records
โ
The actor claims the dump was extracted in September 2026 and includes data from the universityโs main portal and 40 Open Journal Systems instances. A sample of the purported records was published with the listing.
โ
The dataset is being offered as a single sale for $200 in XMR, with escrow reportedly accepted.
โ
The breach claim, record count, authenticity of the data, and claimed exposure of 2FA material have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
Universitas Andalas is a public university in Padang, West Sumatra, Indonesia, operating academic, administrative, and research systems including numerous online journal platforms.
โ
A forum actor using the handle Koyot claims to have obtained data covering 118,289 user accounts across 40 academic journal instances, along with administrative accounts tied to the universityโs main Joomla portal and journal systems.
โ
Claimed exposed data includes:
โ
โข Usernames and display names
โข Institutional email addresses
โข bcrypt and MD5 password hashes
โข Registration and last-login timestamps
โข TOTP 2FA seeds and emergency recovery codes
โข Active session IDs and remember-me tokens
โข Names, dates of birth, phone numbers, and addresses
โข Academic affiliations and ORCID identifiers
โข Biographies and CV information
โข Manuscript and peer-review working files
โข Reviewer assignments
โข Publication-fee payment records
โข Institutional subscriber IP ranges
โข Administrative and CMS records
โ
The actor claims the dump was extracted in September 2026 and includes data from the universityโs main portal and 40 Open Journal Systems instances. A sample of the purported records was published with the listing.
โ
The dataset is being offered as a single sale for $200 in XMR, with escrow reportedly accepted.
โ
The breach claim, record count, authenticity of the data, and claimed exposure of 2FA material have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โค1
๐จ Two VLC Media Player flaws can allow code execution and leak sensitive memory
Security researchers have disclosed two vulnerabilities affecting VLC Media Player versions 3.0.0 through 3.0.23.
โ
CVE-2026-56711, rated 8.6, is a heap out-of-bounds write caused by an integer overflow in VLC's picture buffer allocation.
An attacker can craft a malicious PNG with manipulated dimensions that causes VLC to allocate an undersized memory buffer before writing beyond its boundaries.
The flaw can potentially lead to arbitrary code execution when the malicious image is opened directly or loaded through a playlist.
โ
CVE-2026-73324, rated 6.9, affects VLC's RealRTSP handling.
A malicious RTSP server can send an oversized response that causes VLC to read beyond an allocated buffer and return adjacent heap memory to the attacker, potentially exposing sensitive information.
โ
The vulnerable RealRTSP component is enabled in official VideoLAN builds, although some Linux distribution packages may compile VLC without it.
โ
As of September 11, VLC 3.0.23 remains the current stable desktop release listed by VideoLAN and is affected by both vulnerabilities.
Users should avoid opening untrusted image files or RealRTSP playlist links until an updated release addressing the flaws becomes available.
Source: https://securityonline.info/vlc-media-player-vulnerabilities/
Security researchers have disclosed two vulnerabilities affecting VLC Media Player versions 3.0.0 through 3.0.23.
โ
CVE-2026-56711, rated 8.6, is a heap out-of-bounds write caused by an integer overflow in VLC's picture buffer allocation.
An attacker can craft a malicious PNG with manipulated dimensions that causes VLC to allocate an undersized memory buffer before writing beyond its boundaries.
The flaw can potentially lead to arbitrary code execution when the malicious image is opened directly or loaded through a playlist.
โ
CVE-2026-73324, rated 6.9, affects VLC's RealRTSP handling.
A malicious RTSP server can send an oversized response that causes VLC to read beyond an allocated buffer and return adjacent heap memory to the attacker, potentially exposing sensitive information.
โ
The vulnerable RealRTSP component is enabled in official VideoLAN builds, although some Linux distribution packages may compile VLC without it.
โ
As of September 11, VLC 3.0.23 remains the current stable desktop release listed by VideoLAN and is affected by both vulnerabilities.
Users should avoid opening untrusted image files or RealRTSP playlist links until an updated release addressing the flaws becomes available.
Source: https://securityonline.info/vlc-media-player-vulnerabilities/
โค3
โผ๏ธ New Dark Web Informer Blog Post!
Title: Boulanger Dataset Claim Covers 132,230 Customer and Service Records
Link: https://darkwebinformer.com/boulanger-dataset-claim-covers-132-230-customer-and-service-records/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Boulanger Dataset Claim Covers 132,230 Customer and Service Records
Link: https://darkwebinformer.com/boulanger-dataset-claim-covers-132-230-customer-and-service-records/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Boulanger Dataset Claim Covers 132,230 Customer and Service Records
A forum actor posting as fuie has uploaded what they claim is a database belonging to Boulanger, a French consumer electronics and home-appliance retailer.
๐จ GitLab CVSS 10 vulnerability exploited just one day after disclosure
Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances.
โ
The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request.
Affected versions include:
โข GitLab 18.7 through versions before 19.1.8
โข GitLab 19.2 through versions before 19.2.6
โข GitLab 19.3 through versions before 19.3.2
โ
GitLab disclosed and patched the vulnerability on September 10.
Just one day later, watchTowr began observing in-the-wild exploitation attempts and warns that mass exploitation is likely to follow.
โ
Administrators should upgrade immediately to GitLab 19.1.8, 19.2.6, 19.3.2, or a newer supported release.
GitLab.com is already patched.
Source: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances.
โ
The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request.
Affected versions include:
โข GitLab 18.7 through versions before 19.1.8
โข GitLab 19.2 through versions before 19.2.6
โข GitLab 19.3 through versions before 19.3.2
โ
GitLab disclosed and patched the vulnerability on September 10.
Just one day later, watchTowr began observing in-the-wild exploitation attempts and warns that mass exploitation is likely to follow.
โ
Administrators should upgrade immediately to GitLab 19.1.8, 19.2.6, 19.3.2, or a newer supported release.
GitLab.com is already patched.
Source: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
๐ช That Dark Web Guy - Part 3 ๐ช
๐จ GitLab CVSS 10 vulnerability exploited just one day after disclosure Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances. โ The flaw allows anโฆ
๐จ CVE-2026-85706: An unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7โ19.1.7; 19.2.0โ19.2.5; 19.3.0โ19.3.1
PoC: https://github.com/guneykabel/cve-2026-85706
PoC: https://github.com/guneykabel/cve-2026-85706
GitHub
GitHub - guneykabel/cve-2026-85706: Exploit poc for CVE-2026-85706 an unauthenticated arbitrary file read on Gitlab CE-EE affectingโฆ
Exploit poc for CVE-2026-85706 an unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7โ19.1.7; 19.2.0โ19.2.5; 19.3.0โ19.3.1 - guneykabel/cve-2026-85706
โผ๏ธ Darknet Markets Timeline was updated to show that DarkMattter Market is exit scamming. I'm in the process of updating the timeline to look and feel better as well as provide more information.
https://darkwebinformer.com/darknet-markets-timeline/
https://darkwebinformer.com/darknet-markets-timeline/
Dark Web Informer
Darknet Markets Timeline
โผ๏ธ New Dark Web Informer Blog Post!
Title: Citya Immobilier Dataset Claim Covers 2.2M+ Records and ~50K Digicodes
Link: https://darkwebinformer.com/citya-immobilier-dataset-claim-covers-2-2m-records-and-50k-digicodes/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Title: Citya Immobilier Dataset Claim Covers 2.2M+ Records and ~50K Digicodes
Link: https://darkwebinformer.com/citya-immobilier-dataset-claim-covers-2-2m-records-and-50k-digicodes/
๐ฅ Get early visibility into underground claims, including unblurred screenshots, before they turn into headlines: https://darkwebinformer.com/pricing
Dark Web Informer
Citya Immobilier Dataset Claim Covers 2.2M+ Records and ~50K Digicodes
A forum actor posting as ChimeraZ is selling what they claim is a database belonging to Citya Immobilier, a French real estate company providing property management, rental, sales and co-ownership services.
๐จ๐ฆ๐ช ECC Group database containing 52K+ records allegedly leaked by AnkaTeam
โ
ECC Group is a Dubai-based group of companies operating across construction, engineering, fit-out, manufacturing, building materials, facilities, and real estate development.
โ
An actor using the handle SALDIRGAN, identifying with AnkaTeam, claims to have leaked a database associated with ECC Groupโs official website.
โ
Claimed exposed data includes:
โ
โข 52,444 database records
โข WordPress user accounts
โข Usernames and display names
โข Email addresses
โข Password hashes
โข User registration dates
โข Account activation data
โข Other WordPress database records
โ
The actor identifies the backend as MariaDB and the affected CMS as WordPress, describing the incident as a database dump exposure. A sample administrator record was published alongside the claim.
โ
The breach claim, record count, and full scope of the exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
โ
ECC Group is a Dubai-based group of companies operating across construction, engineering, fit-out, manufacturing, building materials, facilities, and real estate development.
โ
An actor using the handle SALDIRGAN, identifying with AnkaTeam, claims to have leaked a database associated with ECC Groupโs official website.
โ
Claimed exposed data includes:
โ
โข 52,444 database records
โข WordPress user accounts
โข Usernames and display names
โข Email addresses
โข Password hashes
โข User registration dates
โข Account activation data
โข Other WordPress database records
โ
The actor identifies the backend as MariaDB and the affected CMS as WordPress, describing the incident as a database dump exposure. A sample administrator record was published alongside the claim.
โ
The breach claim, record count, and full scope of the exposed data have not been independently verified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Media is too big
VIEW IN TELEGRAM
Dangerous apps - In the web of data brokers
What many smartphone users know: the apps on their phones collect detailed location data. What few people know: the information often ends up with a global network of data brokers and advertising companies.
Video Credit: youtube.com/@DWDocumentary
What many smartphone users know: the apps on their phones collect detailed location data. What few people know: the information often ends up with a global network of data brokers and advertising companies.
Video Credit: youtube.com/@DWDocumentary
Forwarded from Dark Web Informer - Private
โผ๏ธ DOJ Press Release
โโโโโโโโโโโโโโโโโโโโโ
California Man Sentenced to Over 12 Years in Prison for Distributing Sadistic Child Sexual Abuse Material Over the Dark Web
Full Press Release โ justice.gov
โโโโโโโโโโโโโโโโโโโโโ
๐ต๏ธ Dark Web Informer โข DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
โโโโโโโโโโโโโโโโโโโโโ
California Man Sentenced to Over 12 Years in Prison for Distributing Sadistic Child Sexual Abuse Material Over the Dark Web
Full Press Release โ justice.gov
โโโโโโโโโโโโโโโโโโโโโ
๐ต๏ธ Dark Web Informer โข DOJ Monitor
Note: DOJ articles that are not Cyber related will be removed manually.
Department of Justice
California Man Sentenced to Over 12 Years in Prison for Distributing Sadistic Child Sexual Abuse Material Over the Dark Web
James David Johnson, 58, of Santee, California, was sentenced today to 151 months in prison and 10 years of supervised release for distributing images and videos over the dark web that depicted the sexual abuse of children.
โค1
๐จ ๐ช๐ธ Initial Access: Spanish Government Entity
A threat actor is advertising RDP access to an unnamed Spanish government entity with approximately 150 hosts and reported revenue of 20M.
The advertised access includes Local Admin privileges, Dell Unisphere, and several NAS servers containing more than 500TB of data. Kaspersky is reportedly installed but disabled.
This claim is currently unverified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
A threat actor is advertising RDP access to an unnamed Spanish government entity with approximately 150 hosts and reported revenue of 20M.
The advertised access includes Local Admin privileges, Dell Unisphere, and several NAS servers containing more than 500TB of data. Kaspersky is reportedly installed but disabled.
This claim is currently unverified.
โ
๐ฅ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
๐จ CVE-2026-89094: Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.
CVSS: 9.9
Foregejo Update/Notes: https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/16.0.4.md
CVSS: 9.9
Foregejo Update/Notes: https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/16.0.4.md