A threat actor posting as konata_izumi_shell claims to have breached a system belonging to Bolivia's Ministry of Health and Sports and extracted the complete database behind the Servicio Social de Salud Rural Obligatorio, the programme under which health sciences students and graduates carry out mandatory placements in rural and understaffed facilities.
A forum user posting as riche has published what they describe as a database from Bnine.com, the platform operated by B9, a US neobank offering checking accounts, debit cards, and early direct deposit.
A forum user posting as kitta has published what they describe as the database of Bebunk.com, a digital financial service offering current accounts and payment cards.
A forum user posting as kitta has published what they describe as the full database of RevolutionParts.com, the e-commerce platform used by automotive dealerships to sell parts online.
A threat actor posting as xpl0itrs is advertising the sale of data they claim to have taken from RapidFort, a US container hardening and software supply chain security vendor.
Dutch police have seized servers belonging to the pornographic content-sharing platform Motherless as part of an international investigation into suspected child sexual abuse material and videos allegedly depicting drug-facilitated sexual abuse.
CVE-2026-50522 is a critical remote code execution vulnerability in on-premises Microsoft SharePoint Server, caused by deserialization of untrusted data (CWE-502).
Hugging Face has disclosed a security breach in which an autonomous AI agent system compromised part of its production infrastructure and gained access to internal datasets and service credentials.
A threat actor posting under the alias PescobarLegado, working with a group identified in the post as NyxarGroup, claims to have obtained internal data from the Secretaría Distrital de Movilidad de Bogotá, the mobility authority under the Bogotá Mayor's Office in Colombia.
A threat actor using the alias bytetobreach is advertising the sale of data they claim to have taken from Georgia's court systems and the High Council of Justice of Georgia.
A newly disclosed OpenSSL flaw named HollowByte allows an unauthenticated attacker to exhaust server memory using specially crafted TLS requests containing as little as 11 bytes of data.
A threat actor using the alias doommageddon claims to have breached Hospital Di Camp, a healthcare facility in Campo Grande, Brazil, that has provided medical services for more than 20 years across fields including cardiology, gastroenterology, and orthopedics.
A threat actor using the alias Sensitive2025 is advertising a database they claim to have stolen from Loja Negócios Digital (lojanegociosdigital.com.br), a Brazilian online store.
A threat actor using the alias ChimeraZ claims to be leaking a database from the French Firefighters Federation (Fédération nationale des sapeurs-pompiers de France), specifically its official online membership platform (pompiers.fr).
A threat actor using the alias iProfessor claims to have breached NEBBIA (nebbia.fitness), a premium fitness-apparel and activewear brand headquartered in Žilina, Slovakia, that sells internationally through its online store.
Security researchers have disclosed an unpatched Cursor vulnerability that can allow a malicious Git repository to execute attacker-controlled code automatically when opened on a Windows system.
Dark Web Informer
Checked
2 hours 19 minutes ago
A real-time cyber threat intelligence platform that monitors the dark web and clearnet for data breaches, ransomware campaigns, darknet market activity, leaked databases, and active threat actors.