We work in the dark to bring clarity to the light. Contact via 051068fee6cdbbdaf0d7bff81e8e90b073abfd04d5bc574ce0dd93a7a41fc8a773

Dark Web
🤝 Collaborate with Daily Dark Web For: Interviews Paid collaborations & sponsorship opportunities Cybersecurity tips & leads Threat intelligence sharing Research collaboration Media inquiries Exclusive stories Contact us securely via Session: 051068fee6cdbbdaf0d7bff81e8e90b073abfd04d5bc574ce0dd93a7a41fc8a773 #CyberSecurity #ThreatIntelligence #DarkWeb #OSINT #InfoSec
Made with AI
6
14,990
🇦🇪 🚨 369CINEMAS[.]AE (UAE) 12M+ RECORDS ALLEGEDLY OFFERED A threat actor on an underground forum claims to be selling or publishing data allegedly associated with 369 Cinemas / 369cinemas[.]ae (UAE cinema chain; managed by Truth Cinemas per listing graphic). The actor claims the dataset includes: * Emails / usernames (claimed) * Hashed passwords (claimed) * Names / DOB / phone / location fields (claimed) Claimed scope: 12M+ records; listed price ~5K (claimed). The claim has not been independently verified. ⚠️ Analyst Note: Named UAE cinema operator claim with large asserted PII volume and escrow-thread framing. Unverified TA claim — NOT confirmation 369cinemas systems were breached. #DDW #DarkWeb #UAE #Entertainment #ThreatIntelligence #CyberSecurity
2,123
🚨 CISA FLAGS NEW CITRIX NETSCALER ZERO-DAY AS ACTIVELY EXPLOITED Citrix has released emergency patches for a new vulnerability being exploited against NetScaler appliances: CVE-2026-88779 CVSS 4.0: 8.7 / HIGH The vulnerability is a memory overflow affecting: * NetScaler ADC * NetScaler Gateway But there is an important precondition: The appliance must be configured as either: * SAML Service Provider (SP) OR * SAML Identity Provider (IdP) The attack requires: * NO authentication * NO user interaction * Network access Citrix says it has already observed: TARGETED ATTACKS against unmitigated NetScaler deployments. Confirmed impact: MEMORY OVERFLOW ↓ NETSCALER SERVICE CRASH ↓ DENIAL OF SERVICE Repeated exploitation can potentially keep the service unavailable. CISA's vulnerability intelligence now classifies exploitation as: ACTIVE and the flaw has been added to the Known Exploited Vulnerabilities catalog. ⚠️ IMPORTANT: Some early reporting suggested this vulnerability could allow unauthenticated remote code execution. That is NOT currently confirmed. Citrix's official assessment lists the impact as denial of service, and Norway's NSM has now explicitly corrected its earlier RCE warning while noting that researchers continue investigating the discrepancy. Patch immediately to: * 14.1-73.41+ * 13.1-64.28+ * 14.1-73.41 FIPS+ * 13.1-37.282 FIPS/NDcPP+ Organizations that patched NetScaler recently should CHECK AGAIN. This is a newly disclosed vulnerability requiring another update. Citrix advisory: support.citrix.com/external/… #Citrix #NetScaler #ZeroDay #CVE202688779 #CISA #KEV #ThreatIntel #DDW
1
2
9
2,707
🤖🚨 CRITICAL CODE-INJECTION FLAW DISCLOSED IN OPEN-SOURCE AI AGENT FRAMEWORK A new critical vulnerability has been disclosed in: InternLM MindSearch CVE-2026-105135 CVSS v3.1: 10.0 / CRITICAL MindSearch is an open-source AI search/agent framework that uses multiple agents to plan searches, execute actions and synthesize answers. The vulnerability affects: MindSearch 0.1.0 and sits inside the: Planner Agent ↓ mindsearch/agent/graph.py ↓ ExecutionAction.run() According to the vulnerability disclosure, attacker-controlled manipulation of the: inputs argument can result in: CODE INJECTION ↓ ARBITRARY CODE EXECUTION The attack can reportedly be initiated REMOTELY. Security properties reported for the flaw: * Network reachable * Low attack complexity * No privileges required * No user interaction required * High confidentiality impact * High integrity impact * High availability impact An exploit has reportedly been disclosed alongside the vulnerability. However: * No confirmed exploitation in the wild has been identified * CVE-2026-105135 is NOT currently in CISA KEV * No fixed MindSearch release has been identified in the current CVE record * Vendor response/remediation remains unclear ⚠️ Analyst Note: This is exactly the security boundary AI-agent platforms need to get right. Agent frameworks increasingly take: UNTRUSTED INPUT ↓ LLM REASONING ↓ PLANNER ↓ EXECUTION ACTIONS ↓ HOST ENVIRONMENT If attacker-controlled content crosses from the reasoning layer into executable code without a hard security boundary, the AI agent itself can become the path to host compromise. This vulnerability was publicly disclosed: OCTOBER 4, 2026. Organizations experimenting with exposed MindSearch deployments should restrict access until the vendor provides definitive remediation guidance. Upstream vulnerability disclosure: vuldb.com/vuln/413352 InternLM MindSearch: github.com/InternLM/MindSear… #MindSearch #InternLM #AISecurity #AgenticAI #CVE2026105135 #RCE #CyberSecurity #DDW
1
2
12
3,025
🚨 CVSS 10 — UNAUTHENTICATED COMMAND INJECTION DISCLOSED IN AHSAY BACKUP SERVERS A critical vulnerability has just been disclosed in: AHSAYCBS CVE-2026-105134 CVSS v3.1: 10.0 / CRITICAL CVSS v4.0: 9.3 / CRITICAL AhsayCBS is centralized backup infrastructure used by enterprises and managed service providers. The vulnerability affects the: Replication Receiver specifically: /rps/api/json/UpdateReceivers.do Manipulation of the: random parameter can reportedly lead to: REMOTE REQUEST ↓ OS COMMAND INJECTION ↓ ARBITRARY COMMAND EXECUTION The published attack characteristics are particularly concerning: * Network reachable * Low attack complexity * No authentication required * No user interaction required Affected: * AhsayCBS 10.3.0 * AhsayCBS 10.3.1 * AhsayCBS 10.3.2 Fixed: * AhsayCBS 10.3.4 At this stage: * No confirmed mass exploitation has been identified * No working public PoC was found in major exploit repositories * CVE-2026-105134 is not currently listed in CISA KEV ⚠️ Analyst Note: Backup infrastructure is an exceptionally valuable target. Compromise of the backup control plane can potentially give an attacker access to: PRODUCTION BACKUPS + CREDENTIALS + REPLICATION INFRASTRUCTURE + DISASTER-RECOVERY DATA For ransomware operators, destroying or compromising recovery capability before encryption can dramatically increase leverage. Organizations and MSPs running AhsayCBS should inventory exposed instances and move to 10.3.4. Upstream vulnerability record: vuldb.com/vuln/413351 #Ahsay #AhsayCBS #CVE2026105134 #RCE #BackupSecurity #MSP #Ransomware #ThreatIntel #DDW
2
2
7
3,154
🇰🇷🚨 SOUTH KOREA INVESTIGATES AI-ASSISTED HACKING CAMPAIGN AGAINST 7 FINANCIAL INSTITUTIONS South Korean authorities are investigating what appears to be a coordinated cyber campaign targeting the country's financial sector. Confirmed affected organizations currently include: * Shinhan Bank * KB Kookmin Bank * Hana Bank * BNK Busan Bank * Hyundai Capital * Yegaram Savings Bank * Welcome Savings Bank Authorities say the SAME ATTACKER IP infrastructure was identified across multiple incidents. The attacker also repeatedly rotated IP addresses while continuing attacks. More unusually: Investigators found evidence suggesting AI tooling may have been used to automate attacks against multiple financial institutions at scale. According to Korean financial-sector investigators, traces associated with: ARTEX AI were found in infrastructure used against banks. ARTEX AI is described as an open-source LLM-based autonomous penetration-testing system. However: ⚠️ This DOES NOT establish who conducted the attacks. The tool is publicly available, attacker infrastructure spans multiple countries, and attribution remains under investigation. The compromises reportedly targeted comparatively overlooked external systems, including: * Employee support portals * Loan-agent systems * Internet-facing web services * Systems missing authentication controls * Web applications with access-control weaknesses * Servers affected by known vulnerabilities Attackers reportedly installed malware in at least some cases and stole log files containing customer information. Authorities say there is currently NO indication that internet/mobile banking systems were compromised or that direct financial losses occurred. South Korea has now escalated nationally. On October 4: * The Financial Services Commission convened an emergency sector-wide meeting * Attack IPs + defensive guidance were distributed to ~500 financial companies * Banks/card companies were ordered to complete emergency checks by October 6 * Securities, insurance, savings banks and electronic-finance companies must complete checks by October 8 * KISA activated an emergency response posture * President Lee Jae Myung ordered a thorough investigation and countermeasures ⚠️ Analyst Note: If investigators confirm substantial autonomous-AI involvement, this incident deserves close attention. The important evolution isn't simply: "hackers used AI." It is the possibility of an attacker using agentic tooling to repeatedly probe MANY organizations, discover weak peripheral systems and scale exploitation across an entire industry. AI could turn: ONE ATTACKER ↓ AUTOMATED RECON ↓ AUTOMATED VULNERABILITY DISCOVERY ↓ MASS TARGET SELECTION ↓ PARALLEL INTRUSION ATTEMPTS. The investigation is ongoing. Latest Korean investigation details: yna.co.kr/view/AKR2026100402… #SouthKorea #AISecurity #AgenticAI #Banking #CyberAttack #ThreatIntel #DDW
2
1
12
3,487
🇺🇸🚨 RANSOMWARE GROUP CLAIMS 344 GB STOLEN FROM FLORIDA HEALTHCARE PROVIDER The Booba Project ransomware operation has added: MORSELIFE HEALTH SYSTEM, INC. to its data-leak site. MorseLife is a major senior healthcare provider based in West Palm Beach, Florida, providing services including: * Skilled nursing * Assisted living * Memory care * Home healthcare * Hospice and palliative care * Rehabilitation * PACE services The threat actor claims it stole: 344 GB OF DATA The listing appeared today: OCTOBER 4, 2026. ⚠️ IMPORTANT: This is currently an UNVERIFIED THREAT-ACTOR CLAIM. * MorseLife has not publicly confirmed the incident * The claimed 344 GB exfiltration has not been independently verified * The specific contents of the allegedly stolen files are not yet established * There is currently no verified evidence showing whether patient medical records were included * Encryption or operational disruption has not been confirmed The listing has now been independently captured by multiple ransomware-monitoring platforms. Healthcare organizations are particularly high-impact extortion targets because compromised environments can contain combinations of: PATIENT DATA + IDENTITY INFORMATION + INSURANCE DATA + CLINICAL RECORDS + EMPLOYEE INFORMATION. We are monitoring for data samples, an official MorseLife response and any regulatory disclosure. Upstream ransomware monitor: ransomlook.io/recent #Ransomware #MorseLife #Healthcare #Florida #DataBreach #ThreatIntel #DDW
2
7
3,682
🇹🇭 🚨 THAI AIRWAYS 200M+ RECORDS ALLEGEDLY OFFERED A threat actor on an underground forum claims to be selling or publishing data allegedly associated with Thai Airways / thaiairways[.]com (national airline). The actor claims the dataset includes: * Booking / ticketing / baggage fields (claimed) * Loyalty program data (claimed) * Payment / customer-service / digital-log fields (claimed) * Operational data (claimed) Claimed scope: 200M+ records (2026 listing claim). The claim has not been independently verified. ⚠️ Analyst Note: Named national airline claim with very large asserted volume spanning booking/loyalty/payment categories. Unverified TA claim — NOT confirmation Thai Airways systems were breached. #DDW #DarkWeb #Thailand #Aviation #ThreatIntelligence #CyberSecurity
1
5
3,955
🇮🇱 🚨 ISRAELI MINISTRY OF DEFENSE (IMOD) 5TB DATA ALLEGEDLY OFFERED A threat actor on an underground forum claims to be selling or publishing data allegedly associated with the Israeli Ministry of Defense (IMOD) / mod[.]gov[.]il. The actor claims the dataset includes: * Employee and administration data (claimed) * Contract and procurement data (claimed) * Defense company / industry data (claimed) * Policy and regulatory documents (claimed) * Research and development data (claimed) * Veteran and certain service-recipient data (claimed) * Government archives and documents (claimed) Claimed volume: ~5TB (claimed). The claim has not been independently verified. ⚠️ Analyst Note: Named Israeli Ministry of Defense claim with large claimed volume. Screenshot shows meeting photo with faces already blurred in source. Unverified TA claim — NOT confirmation IMOD systems were breached. #DDW #DarkWeb #Israel #Defense #ThreatIntelligence #CyberSecurity
7
35
5,512
cmd.exe The investigation also identified related extensions including: * Coca-Cola Christmas * Aurora Borealis Studio Theme * Deep Focus * Theme Charcoal Mint Co. IMPORTANT: Socket did NOT find an active malicious payload in every related extension version. Some are classified as high-risk CLUSTER-LINKED extensions rather than confirmed malware. But several retained unnecessary executable functionality and trusted marketplace update channels that could potentially be weaponized later. One Coca-Cola Christmas listing on Open VSX had accumulated approximately: 39,000 DOWNLOADS. ⚠️ Analyst Note: The most important lesson isn't "don't install themes." It's that developer extensions execute with the developer's privileges. That potentially exposes: SOURCE CODE ↓ GITHUB/GITLAB TOKENS ↓ CLOUD CREDENTIALS ↓ SSH KEYS ↓ PACKAGE-REGISTRY TOKENS ↓ PRODUCTION ACCESS And blockchain-based dead drops make traditional domain takedowns significantly less effective. Developers and security teams should inventory extensions across VS Code, Cursor and other VS Code-compatible environments — including seemingly harmless themes. Original Socket investigation + IoCs: socket.dev/blog/glassworm-vs… #GlassWorm #VSCode #SupplyChain #Malware #OpenVSX #Solana #DeveloperSecurity #ThreatIntel #DDW
1
18
4,508
🚨 RANSOMWARE GROUP CLAIMS ST. FRANCIS HEALTHCARE SYSTEM OF HAWAIʻi The Wallstreet ransomware group has added: ST. FRANCIS HEALTHCARE SYSTEM OF HAWAIʻi to its data-leak site. The listing appeared on: OCTOBER 3, 2026. St. Francis is a nonprofit healthcare organization that has served Hawaiʻi families since 1927, providing hospice, home and community-based healthcare services. Wallstreet is threatening publication of allegedly stolen information if the organization does not engage with the group. ⚠️ IMPORTANT: This is currently an UNVERIFIED THREAT-ACTOR CLAIM. * The Wallstreet leak-site listing has been independently captured by multiple ransomware trackers. * No confirmed volume of stolen data has been established. * No independently authenticated data sample currently proves the claimed compromise. * DDW found no public confirmation from St. Francis establishing the scope of an incident. * No operational disruption has been confirmed. Because the alleged victim operates in healthcare, any verified exposure involving patient or healthcare information could carry significant privacy and regulatory consequences. We are monitoring for data samples, regulatory notifications and an official response from St. Francis. Upstream ransomware monitor: ransomlook.io/ #Ransomware #Healthcare #Hawaii #Wallstreet #DataBreach #ThreatIntel #DDW
2
2
12
4,712
🚨 RESEARCHER ACHIEVES FULL KVM VM ESCAPE → HOST ROOT A potentially major virtualization zero-day has just surfaced. Security researcher Paulos Yibelo says he achieved: GUEST VM ↓ KVM ESCAPE ↓ HOST ROOT in what he describes as a: "Full VM escape zeroday" Vercel CEO Guillermo Rauch has now publicly CONFIRMED that Vercel's Sandbox bounty program validated a: KVM 0DAY Rauch said the vulnerability affects what he called the industry's "gold standard" for Linux virtualization. The research emerged from Vercel's Sandbox security challenge, designed specifically to test the isolation boundary protecting environments that execute: * Untrusted code * AI-generated code * Agent workloads Yibelo reportedly received: $50,000 the maximum single-report bounty tier. Why this matters: Modern cloud and AI sandbox architectures increasingly depend on microVM isolation. The security assumption is: UNTRUSTED WORKLOAD ↓ GUEST ❌ HOST A genuine KVM guest-to-host ROOT escape breaks that boundary. However, several critical details are NOT PUBLIC yet: * No CVE * No affected kernel versions * No exploit chain * No public PoC * No confirmed exploitation in the wild * No evidence that every KVM/Firecracker deployment is vulnerable * No evidence of customer-data compromise Vercel says a full technical write-up is coming. ⚠️ Analyst Note: This could become particularly important for agentic AI security. Giving an AI agent a sandbox only works if the sandbox remains a reliable security boundary. Prompt injection → malicious code execution is one problem. Prompt injection → sandbox escape → HOST ROOT is an entirely different threat model. For now: DO NOT assume unrelated KVM patches mitigate this vulnerability. We are monitoring for the technical disclosure, CVE and Linux/vendor remediation guidance. Original researcher disclosure: x.lingyaoai.com/PaulosYibelo Vercel CEO confirmation: x.lingyaoai.com/rauchg #KVM #ZeroDay #VMEscape #Linux #AISecurity #AgenticAI #CloudSecurity #ThreatIntel #DDW
5
24
4,944
When AI reverse-engineering goes from "cool game mod" to full existential crisis in under two minutes 😂 It starts off innocent enough: an AI reverse-engineers a game to put Halo into Modern Warfare 2. But the realization quickly sets in, if AI models can reverse-engineer complex, undocumented software code, the implications go way beyond video games.  When millions of lines of encrypted, undocumented code are no longer a barrier, the foundation of software security changes:  Copyright & Software Security: Code obfuscation and complexity were long considered built-in forms of security and copyright protection.  Infrastructure Risks: Legacy banking software, government networks, telecom, and critical supply chains all rely on systems that are computationally difficult to breach or replace.  Systemic Disruption: If automated reverse-engineering scales, software-dependent industries, from finance to logistics, face a massive shift in how trust and security are maintained.  And just when you think you're staring down the collapse of global white-collar infrastructure... "Did you see they also put Minecraft in Skyrim?" 🎮  What aspect of AI code generation or reverse-engineering are you most interested in exploring further?
1
2
10
5,108
🇩 DENMARK'S TECHNICAL UNIVERSITY CONFIRMS MAJOR IDENTITY-SYSTEM BREACH The Technical University of Denmark (DTU) has confirmed a serious cyberattack against: DTUBasen its central identity and access-management system. Attackers compromised legitimate DTU profiles and used them to gain access to the identity database before downloading a LARGE AMOUNT OF DATA. Potentially affected: ~200,000 PEOPLE including: * ~40,000 active users * ~160,000 former users * Students * Employees * Guests * External partners The database contains personal information dating back to: 2003. For active users, potentially exposed information includes: * Danish CPR national ID numbers * Full names * Home addresses * Profile photographs * Work email addresses * Job titles * Office locations DTU says it currently CANNOT determine exactly what information was downloaded or precisely how many people were affected. The attack has been contained, but the investigation is continuing with external specialists and Danish authorities. DTU has reported the breach to Denmark's Data Protection Agency. ⚠️ Analyst Note: The important security lesson here is the target. The attackers didn't merely compromise individual university accounts. They reportedly leveraged compromised identities to reach the institution's centralized: IDENTITY + ACCESS MANAGEMENT SYSTEM. Once identity infrastructure becomes the attacker's pivot point, one compromised account can potentially become a gateway to decades of organizational data. DTU is now warning users to change passwords anywhere they reused their DTU password and consider placing a credit warning against their Danish CPR number. Original DTU disclosure: dtu.dk/english/newsarchive/2… #DTU #Denmark #DataBreach #IdentitySecurity #IAM #CyberSecurity #ThreatIntel #DDW
13
5,203
This one works well for LinkedIn too, especially for the “job titles have gone too far” angle. “Underwater Ceramic Technician.” Sounds impressive. Until you realize he means: dishwasher. Then the comeback: “I’m an overground concrete pilot.” Translation: I drive. We really have mastered the art of turning normal jobs into enterprise-grade job titles. 😂 Cybersecurity may be one of the worst offenders: Security Engineer Cyber Defense Specialist Threat Intelligence Analyst Digital Risk Protection Expert Adversary Simulation Engineer Sometimes I wonder what we’d call “the person who fixes the Wi-Fi” in 2026. Principal Wireless Availability Restoration Architect? #Cybersecurity #TechHumor #Leadership #DailyRedTeam #DRT
3
16
5,290
Fortinet warns that attackers are exploiting a critical FortiMail zero-day (CVE-2026-104286) to execute unauthorized code or commands on vulnerable devices. Review Fortinet’s advisory and assess exposed… Source: bleepingcomputer.com/news/se…
1
2
10
5,425
🇺🇸 🚨 BASEFEX CRYPTO INVESTOR LEADS ALLEGEDLY OFFERED FOR SALE A threat actor claims to be selling a 2026 “USA crypto” investor-leads database allegedly sourced from Basefex, citing about 90,000 lines. The actor claims fields such as name, email, phone, address, city, state, ZIP/IP, country, and source, and advertises samples/pricing via private contact. The claim has not been independently verified. ⚠️ Analyst Note: Lead-list sales are frequently aggregated or recycled marketing data rather than fresh breach dumps. Authenticity and exclusivity are unconfirmed. Unverified threat-actor claim — NOT confirmation of a compromise of Basefex. This is a US private company listing (not US government). No investor sample values appear in this capture. #DDW #DarkWeb #USA #Crypto #DataLeak #ThreatIntelligence #CyberSecurity
1
1
13
5,382