πŸ”ͺ That Dark Web Guy - Part 3 πŸ”ͺ
4.99K subscribers
1.26K photos
70 videos
1.11K links
Download Telegram
🚨 CVE-2026-89094: Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

CVSS: 9.9

Foregejo Update/Notes: https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/16.0.4.md
XCancel is back online after Nitter seeked legal advice regarding X Corp.'s cease-and-desist order.

xcancel[.]com
❀4
πŸ”ͺ That Dark Web Guy - Part 3 πŸ”ͺ
I will do top 2 for now. Voting ends sometime in the next 24 hours. Yes I realize the telegram scraper is missing from my Git, I will add it back sometime later today. https://git.darkwebinformer.com
❀3
πŸš¨πŸ‡²πŸ‡½ YucatΓ‘n government documents allegedly leaked, 30 GB archive claimed
β €
The Government of YucatΓ‘n is the state administration responsible for public services, civil records, education, and other government functions across YucatΓ‘n, Mexico.
β €
A forum actor using the handle vansel claims to have obtained approximately 30 GB of documents, totaling around 50,000 files, from the state of YucatΓ‘n.
β €
Claimed exposed data includes:
β €
β€’ CURP identity records
β€’ Birth certificates
β€’ Official state documents
β€’ School-related records
β€’ Names and dates of birth
β€’ Civil registry information
β€’ Family and parental information
β€’ Government-issued identifiers
β€’ Other personal information contained in official documents
β €
The actor states that roughly 10% of the claimed archive has been released so far, consisting of approximately 5,000 PDF files totaling 2.91 GB.
β €
Sample documents published with the post appear to include Mexican birth certificates and CURP-related records.
β €
The breach claim, source of the documents, total file count, and full scope of the exposure have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡¦πŸ‡ͺ Initial Access to Dubai-based IT company allegedly offered for sale
β €
The affected organization is described only as an IT company in Dubai that works with Capgemini and Digital Dubai. Its identity was not disclosed in the listing.
β €
A forum actor using the handle jorisbernard77 claims to be selling access to the company’s environment, including remote desktop access and several internal business services.
β €
Claimed access includes:
β €
β€’ Full RDP access
β€’ Microsoft Teams
β€’ Microsoft Outlook
β€’ Password-protected company files
β€’ Tally Prime Gold accounting software
β€’ Bank account access
β€’ Other internal systems accessible through the compromised environment
β €
The access claim, affected company, and extent of the alleged compromise have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
πŸš¨πŸ‡ΊπŸ‡Έ Tiny Rituals dataset containing 227K+ records allegedly breached and sold
β €
Tiny Rituals is a U.S.-based jewelry retailer offering gemstone, crystal, spiritual, and wellness-focused jewelry and accessories.
β €
A forum actor using the handle JSON09 claims to have obtained a dataset containing 227,843 records associated with Tiny Rituals, with the breach reportedly occurring on September 10, 2026.
β €
Claimed exposed data includes:
β €
β€’ First and last names
β€’ Email addresses
β€’ Phone numbers
β€’ Street addresses
β€’ Cities
β€’ ZIP/postal codes
β€’ Countries
β €
The dataset was advertised for $250.
β €
The breach claim, record count, and authenticity of the dataset have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Please open Telegram to view this post
VIEW IN TELEGRAM
πŸš¨πŸ‡«πŸ‡· Ekolis data leak allegedly exposes driver, vehicle, and logistics information
β €
Ekolis is a French company specializing in telematics and connected-device solutions for the trucking and logistics industry.
β €
An underground forum member using the handle 4me44 claims to have leaked data associated with Ekolis following an alleged breach on September 5, 2026.
β €
Claimed exposed data includes:
β €
β€’ Driver information
β€’ Vehicle and trailer records
β€’ Fleet identifiers
β€’ Customer and company names
β€’ Phone numbers
β€’ Street and service addresses
β€’ Vehicle registration details
β€’ Equipment types
β€’ Location and logistics information
β€’ Operational timestamps
β€’ Additional telematics-related records
β €
The actor states the leak contains 8 separate files and published sample records showing vehicle, customer, and location-related information.
β €
The breach claim, source of the data, and full scope of the exposure have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
‼️ New Darknet Market: Sentinel Market

Stay vigilant!

Market: http://sentunywvqvyqj6kvnrw5uo6tszg74glp46fsdnjf345f37zbui56dyd[.]onion

Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/69690d62a6869eee6b57
😈1
🚨 πŸ‡ΉπŸ‡· Initial Access: Turkish Import & Export Company

A threat actor is advertising RDP access to an unnamed Turkish import and export company with reported revenue below 5M.

The advertised access includes two domain user accounts. The environment reportedly contains 33 domain users, four domain computers, and one domain controller, with Windows Defender and Wazuh XDR/EDR deployed.

This claim is currently unverified.

πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
🚨 πŸ‡΅πŸ‡­ Initial Access: Major Philippine Telecom Company

A threat actor is advertising firewall access to an unnamed major telecommunications company in the Philippines reportedly generating more than $1B in revenue.

The advertised access is described as Firewall/RCE access and is listed for $1,200, negotiable. Payment is requested in XMR or BTC.

This claim is currently unverified.

πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
At some point when I moved all my repositories from GitHub to my Git server, the Telegram Scraper script didn't get moved. Unfortunately, I can't sync the original repository from GitHub because it no longer exists on my GitHub account.

Anyway, I've added the script back to my Git server, and I'm in the process of adding an IOC extractor and a global database search feature to it. I will add an updated Readme at that time. Soonβ„’

https://git.darkwebinformer.com/DarkWebInformer/Telegram_Scraper
πŸš¨πŸ‡©πŸ‡ͺ LANXESS internal data allegedly leaked following failed negotiations
β €
LANXESS is a German specialty chemicals company headquartered in Cologne, producing chemical intermediates, additives, and specialty products for industries worldwide.
β €
A forum actor using the handle sta6 claims to have released internal LANXESS data after what they describe as weeks of unsuccessful negotiations with the company.
β €
Claimed exposed data includes:
β €
β€’ 14,658 user records
β€’ 11,860 MD5 password hashes
β€’ Corporate and external business email addresses
β€’ Names, phone numbers, addresses, and job information
β€’ Internal account and login information
β€’ TLS/SSL private keys and certificate archives
β€’ Application and database credentials
β€’ Oracle-related user data and password hashes
β€’ Internal LANXESS contact-routing information
β€’ 12,249 customer and business enquiry emails
β€’ Names, corporate emails, phone numbers, and message content from external contacts
β€’ Configuration files and other internal system data
β €
The actor also claims the material contains historical TLS/SSL keys dating from 2011 through 2025, cleartext credentials from several internal configuration files, and information tied to approximately 12,000 external customers and business contacts.
β €
A sample archive was published as purported proof of the compromise.
β €
The breach claim, authenticity of the material, and full scope of the exposed data have not been independently verified.
β €
πŸ’₯ No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing