A threat actor using the alias Sensitive2025 is advertising a database they claim to have stolen from Loja Negócios Digital (lojanegociosdigital.com.br), a Brazilian online store.
A threat actor using the alias ChimeraZ claims to be leaking a database from the French Firefighters Federation (Fédération nationale des sapeurs-pompiers de France), specifically its official online membership platform (pompiers.fr).
A threat actor using the alias iProfessor claims to have breached NEBBIA (nebbia.fitness), a premium fitness-apparel and activewear brand headquartered in Žilina, Slovakia, that sells internationally through its online store.
Security researchers have disclosed an unpatched Cursor vulnerability that can allow a malicious Git repository to execute attacker-controlled code automatically when opened on a Windows system.
A threat actor using the alias bytetobreach is advertising the sale of data they claim to have stolen from ANCPI, Romania's National Agency for Cadastre and Land Registration, which maintains the country's land-registry and property records.
The U.S. Justice Department has unsealed an indictment charging three Russian nationals and two St. Petersburg-based companies over an alleged bulletproof hosting operation that caused more than $62 million in losses to cybercrime victims.
A threat actor using the alias 888 claims to have leaked a database from Conasems, the National Council of Municipal Health Secretariats of Brazil (Conselho Nacional de Secretarias Municipais de Saúde).
A Welsh man identified as an administrator of the dark web doxing platform Doxbin has been sentenced to prison for encouraging and assisting swatting attacks targeting people and organizations in the United Kingdom, United States, and Canada.
SAP has released its July 2026 security updates, addressing three new critical vulnerabilities affecting NetWeaver Application Server ABAP, AppRouter, and Commerce Cloud.
The United States has sanctioned a virtual private network provider, its administrator, and a malware obfuscation specialist for allegedly supplying services and tools used by ransomware groups targeting American organizations.
The U.S. Cybersecurity and Infrastructure Security Agency has added an 18-year-old Cisco IOS vulnerability to its Known Exploited Vulnerabilities catalog following confirmation that the flaw has been exploited in real-world attacks.
A joint cybersecurity advisory warns that cyber actors linked to the Russian Federal Security Service’s Center 16 continue to compromise poorly configured and vulnerable networking devices worldwide.
A threat actor using the alias NightBroker claims to have breached Suitable AI (suitable.ai), an AI-powered recruitment platform based in India and the United States that helps STEM professionals find jobs.
Two threat actors using the aliases misere and ChimeraZ claim to have breached Litige.fr, a French online legal-services and debt-recovery platform, and are leaking data they say covers 595,024 users.
Dutch police say they have uncovered strong indications that local criminals were involved in the cyberattack against telecommunications provider Odido, which exposed personal information belonging to millions of customers.
A threat actor using the alias ChimeraZ claims to be leaking a database from the seller portal of Bebeboutik (sales.bebeboutik.fr), a French private-sales marketplace for baby and children's products.
A threat actor using the alias 84City has posted an SQL dump they attribute to PPA Business School, described as one of the largest private higher-education groups in France, offering preparatory programs and bachelor's degrees across art, design, digital, communication, and business.
Dark Web Informer
Checked
8 hours 32 minutes ago
A real-time cyber threat intelligence platform that monitors the dark web and clearnet for data breaches, ransomware campaigns, darknet market activity, leaked databases, and active threat actors.