{"generated_at": "2026-08-16T16:14:42.115924+00:00", "period_from": "2026-08-16T16:14:09.824501+00:00", "period_to": "2026-08-16T04:11:09.824501+00:00", "posts": [{"id": "2088996308031787413", "post_type": "Normal", "created_at": "2026-08-16T14:28:26+00:00", "created_at_datetime": [2026, 8, 16, 14, 28, 26], "author": "@DailyDarkWeb", "post_text": "<p>🇯🇴 Abwaab Educational Platform Database Allegedly Offered for Sale<br />\n<br />\nA newly registered threat actor on an underground forum claims to be selling a database belonging to Abwaab, an educational platform operating in Jordan and other Arab markets.<br />\n<br />\n* Approximately 4.78 GB of data allegedly included<br />\n* Seller claims the database contains millions of student IDs<br />\n* Millions of messages are allegedly exposed<br />\n* Student interactions with platform assistants are claimed to be included<br />\n* Communications between users may also be present<br />\n* The actor describes the listing as the platform's \"complete database\"<br />\n* Seller account was created in August 2026, has only one post and currently has zero reputation<br />\n<br />\nAnalyst Note: The potential exposure of student identifiers and private communications makes this claim particularly sensitive, especially if records involve minors. However, the seller provides no visible samples or other substantive proof in the listing. The provenance, record count, completeness and authenticity of the alleged database remain unverified, and the post alone does not establish that Abwaab was breached.<br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DarkWeb\">#DarkWeb</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Abwaab\">#Abwaab</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Jordan\">#Jordan</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Education\">#Education</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DataBreach\">#DataBreach</a></p>\n<img src=\"https://x.com/pic/media%2FHP2bERTWsAA40A6.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088996308031787413"}, {"id": "2088994681107386724", "post_type": "Normal", "created_at": "2026-08-16T14:21:58+00:00", "created_at_datetime": [2026, 8, 16, 14, 21, 58], "author": "@DailyDarkWeb", "post_text": "<p>🇺🇸 South Plains Rural Health Services Allegedly Hit — 1.4 TB of Data Advertised<br />\n<br />\nA threat actor on an underground forum claims to have obtained approximately 1.4 TB of data belonging to South Plains Rural Health Services (SPRHS), a U.S. healthcare provider.<br />\n<br />\n* 1.4 TB of data allegedly compromised<br />\n* Thousands of patient PII and PHI records claimed<br />\n* Financial and HR records allegedly included<br />\n* Provider and vendor information<br />\n* Mailboxes and email correspondence<br />\n* Database exports and other internal files<br />\n* Seller published screenshots presented as samples of the allegedly stolen material<br />\n* Forum account joined in May 2026 and currently shows 52 posts, 50 threads and a reputation score of 10<br />\n<br />\nAnalyst Note: The alleged presence of both PII and protected health information (PHI) makes this a potentially significant healthcare-sector incident. The screenshots provide some supporting material for the actor's claim, but they do not independently establish the provenance, completeness, or claimed 1.4 TB volume. No victim confirmation should be inferred from the underground listing alone.<br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DarkWeb\">#DarkWeb</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Healthcare\">#Healthcare</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DataBreach\">#DataBreach</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23PHI\">#PHI</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23CyberThreatIntelligence\">#CyberThreatIntelligence</a></p>\n<img src=\"https://x.com/pic/media%2FHP2Zlp6WQAEfNiC.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088994681107386724"}, {"id": "2088969839645725175", "post_type": "Normal", "created_at": "2026-08-16T12:43:15+00:00", "created_at_datetime": [2026, 8, 16, 12, 43, 15], "author": "@DailyDarkWeb", "post_text": "<p>🚨 Clop Claims 8 TB Data Theft From Zebra Technologies<br />\n<br />\nThe Clop ransomware group has claimed a major cyberattack involving Zebra Technologies, with the alleged theft of approximately 8 TB of corporate data.<br />\n<br />\n* According to DeXpose, Clop reported the victim on August 13, 2026<br />\n<br />\n* The threat actor claims the stolen material includes databases, project files and CAD files<br />\n<br />\n* Clop claims the total volume of exfiltrated information is approximately 8 TB<br />\n<br />\n* Zebra Technologies is a major U.S.-based enterprise technology company providing barcode scanners, RFID systems, mobile computers, printers and other technologies used across manufacturing, logistics, retail and healthcare environments<br />\n<br />\n* The threat actor specifically referenced approximately $5.6 billion in company revenue in its leak-site statement<br />\n<br />\n* The 8 TB figure and descriptions of the allegedly stolen files originate from the threat actor and should not currently be treated as independently verified facts<br />\n<br />\n⚠️ Analyst Note: Zebra's position within enterprise supply chains makes this claim noteworthy beyond the alleged volume of stolen information. CAD files, project documentation and internal databases could potentially contain commercially sensitive or customer-related information. However, the actual scope and impact cannot be established until Zebra or another authoritative source confirms the incident.<br />\n<br />\nSource: DeXpose / Clop leak-site monitoring<br />\nAugust 13, 2026<br />\n<br />\n<a href=\"https://www.dexpose.io/clop-ransomware-targets-zebra-com-in-major-data-breach/\">dexpose.io/clop-ransomware-t…</a><br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Ransomware\">#Ransomware</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Clop\">#Clop</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Zebra\">#Zebra</a></p>\n<img src=\"https://x.com/pic/media%2FHP2C_0TXgAA0Ki0.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088969839645725175"}, {"id": "2088968776720978224", "post_type": "Normal", "created_at": "2026-08-16T12:39:02+00:00", "created_at_datetime": [2026, 8, 16, 12, 39, 2], "author": "@DailyDarkWeb", "post_text": "<p>🇲🇽 Alleged Mexican Banking Database Leak Shared on Underground Forum<br />\n<br />\nA threat actor has published what they claim is a database containing information associated with customers of multiple Mexican banks.<br />\n<br />\n* The actor explicitly states that the leaked information is not recent, describing it as “not recent, but not too old either”<br />\n<br />\n* According to the post, exposed information allegedly includes full names, bank account numbers and other data<br />\n<br />\n* The accompanying screenshot shows numerous XLSX, XLS and ODS files, including datasets labeled with Mexican locations such as Veracruz and Sonora<br />\n<br />\n* The material appears to consist of multiple separate datasets rather than a clearly identified breach of a single Mexican financial institution<br />\n<br />\n* The threat actor provided a download location for the alleged data<br />\n<br />\n⚠️ Analyst Note: At this stage, the provenance, authenticity, number of affected individuals and specific financial institutions represented in the dataset have not been independently verified. The actor's own statement also indicates that the information is not newly obtained, raising the possibility that this is a compilation or redistribution of previously exposed datasets.<br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Intelligence\">#Intelligence</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DarkWeb\">#DarkWeb</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Mexico\">#Mexico</a></p>\n<img src=\"https://x.com/pic/media%2FHP2CB8VWgAAyhNd.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088968776720978224"}, {"id": "2088967382517575842", "post_type": "Normal", "created_at": "2026-08-16T12:33:29+00:00", "created_at_datetime": [2026, 8, 16, 12, 33, 29], "author": "@DailyDarkWeb", "post_text": "<p>🚨 New Linux Botnet “Evooo1Bot” Turns Compromised Devices Into DDoS Bots, Proxies and Internal Network Pivot Points<br />\n<br />\nFortiGuard Labs has uncovered a previously undocumented Linux botnet dubbed Evooo1Bot, which has been actively targeting internet-facing devices since July 2026.<br />\n<br />\n* Evooo1Bot reuses the leaked Mirai DDoS engine but significantly expands its capabilities<br />\n<br />\n* Fortinet observed active exploitation involving vulnerabilities affecting D-Link, NETGEAR, Tenda, Mitsubishi Electric, Telesquare and Alcatel devices<br />\n<br />\n* The malware supports 12 CPU architectures, allowing it to infect a broad range of Linux-based edge and IoT systems<br />\n<br />\n* It contains a 28-command remote administration interface supporting interactive shell access, file transfers, persistence and self-updates<br />\n<br />\n* A built-in SSH brute-force module contains more than 150 credentials, including enterprise-oriented accounts such as jenkins, postgres, oracle, nagios and deploy<br />\n<br />\n* Evooo1Bot actively checks for honeypots, sandboxes, debuggers, VMs and security-analysis tools before proceeding<br />\n<br />\n* Its DDoS component provides 16 different flooding methods<br />\n<br />\n* An integrated CVE exploitation engine targets vulnerabilities across routers, firewalls, IP cameras, Confluence, Kubernetes ingress-nginx, WSO2 and other technologies, although Fortinet notes that some exploit implementations do not work as shipped<br />\n<br />\n* The malware also includes credential sniffing capable of intercepting HTTP Basic Authorization and Cookie headers<br />\n<br />\n* One of its most significant capabilities is a SOCKS5 relay module that converts compromised devices into attacker-controlled proxy infrastructure<br />\n<br />\n* This means an infected router, firewall, camera or other edge device can potentially be used to hide attacker origins, relay malicious traffic and pivot toward internal networks<br />\n<br />\n⚠️ Analyst Note: Evooo1Bot demonstrates how modern Mirai descendants are evolving beyond simple DDoS botnets. Compromised edge devices increasingly provide something potentially more valuable than raw attack bandwidth: trusted network positioning. Turning thousands of routers and other internet-facing devices into distributed proxy and pivot infrastructure can provide threat actors with both anonymity and pathways into otherwise inaccessible networks.<br />\n<br />\nSource: FortiGuard Labs<br />\nAugust 13, 2026<br />\n<br />\n<a href=\"https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot\">fortinet.com/blog/threat-res…</a><br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Botnet\">#Botnet</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Linux\">#Linux</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23ThreatIntelligence\">#ThreatIntelligence</a></p>\n<img src=\"https://x.com/pic/media%2FHP2AwxsWkAADPIr.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088967382517575842"}, {"id": "2088966744207446314", "post_type": "Normal", "created_at": "2026-08-16T12:30:57+00:00", "created_at_datetime": [2026, 8, 16, 12, 30, 57], "author": "@DailyDarkWeb", "post_text": "<p>🇫🇷 Cyberattack on French Tax Agency Exposes Data of 678,000 Users<br />\n<br />\nFrance’s Finance Ministry has confirmed that taxpayer data was stolen in a cyberattack targeting the country’s General Directorate of Public Finances (DGFiP).<br />\n<br />\n* A malicious actor claimed on August 12 to have compromised the French tax authority in late June.<br />\n<br />\n* An investigation subsequently confirmed unauthorized access and the consultation and extraction of taxpayer information.<br />\n<br />\n* France’s Finance Ministry later confirmed that data belonging to approximately **678,000 users** was stolen.<br />\n<br />\n* The affected population includes both individual taxpayers and professionals.<br />\n<br />\n* Authorities are still investigating exactly which categories of information were accessed or extracted.<br />\n<br />\n* Affected taxpayers will be individually notified about the information potentially compromised and any precautionary measures they should take.<br />\n<br />\n* The ministry has not publicly attributed the attack to a specific threat actor in the information released so far.<br />\n<br />\n⚠️ Analyst Note: The confirmation materially changes the assessment from an unverified threat-actor claim to a government-confirmed data breach. With 678,000 affected users, follow-on phishing, impersonation and tax-related fraud should be considered potential downstream risks, particularly if the compromised records contain sufficient identity or financial context.<br />\n<br />\nSource: Reuters / French Finance Ministry<br />\nAugust 14, 2026<br />\n<br />\n<a href=\"https://www.reuters.com/legal/litigation/french-taxpayers-data-stolen-cyber-attack-french-finance-ministry-says-2026-08-14/\">reuters.com/legal/litigation…</a><br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23CyberSecurity\">#CyberSecurity</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DataBreach\">#DataBreach</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23France\">#France</a></p>\n<img src=\"https://x.com/pic/media%2FHP2ALmJWwAABsoH.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088966744207446314"}, {"id": "2088965941329543196", "post_type": "Normal", "created_at": "2026-08-16T12:27:46+00:00", "created_at_datetime": [2026, 8, 16, 12, 27, 46], "author": "@DailyDarkWeb", "post_text": "<p>🇰🇷 South Korea’s National Health Insurance Service Data Allegedly Offered for Sale — 48M Records Claimed<br />\n<br />\nA threat actor on an underground forum is advertising what they claim to be a dataset originating from South Korea’s National Health Insurance Service (NHIS), containing approximately 48 million records.<br />\n<br />\n* Seller claims the dataset contains personal information belonging to Korean citizens<br />\n* 48 million records allegedly included<br />\n* Sample fields shown include names, resident registration numbers (RRNs), gender and dates of birth<br />\n* Insurance type and subscriber classification data<br />\n* Employer and household information<br />\n* Monthly income and insurance-premium information<br />\n* Dependents and regional information<br />\n* Medical checkup-related dates and long-term-care grades<br />\n* Dataset is advertised for $450<br />\n* Seller account has VIP status, joined in October 2024 and currently shows 92 posts and a reputation score of 21<br />\n<br />\nAnalyst Note: If authentic, the combination of national identifiers, financial/insurance information and health-related metadata would make this a potentially high-impact exposure affecting a substantial portion of South Korea’s population. However, the forum listing alone does not establish that NHIS was breached or that the advertised data originated directly from its systems. The 48M-record claim and dataset provenance remain unverified.<br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DarkWeb\">#DarkWeb</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23SouthKorea\">#SouthKorea</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DataBreach\">#DataBreach</a></p>\n<img src=\"https://x.com/pic/media%2FHP1_c6wWEAA5An8.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088965941329543196"}, {"id": "2088963799076233647", "post_type": "Normal", "created_at": "2026-08-16T12:19:15+00:00", "created_at_datetime": [2026, 8, 16, 12, 19, 15], "author": "@DailyDarkWeb", "post_text": "<p>🇺🇸⚠️ McDonald’s 1.7M+ Employee Records Allegedly Offered for Sale<br />\n<br />\nA threat actor on an underground forum claims to be selling an internal McDonald’s dataset allegedly obtained directly from an Azure tenant using compromised credentials.<br />\n<br />\n* More than 1.7 million records claimed<br />\n* Alleged fields include full names, employee IDs, email addresses, job titles, departments, phone numbers and addresses<br />\n* Seller claims the dataset includes employee accounts, service accounts and other tenant account records<br />\n* An 8,000-record sample is advertised as proof<br />\n* Seller account joined the forum in March 2026 and currently shows 9 posts, 9 threads and zero reputation<br />\n<br />\nAnalyst Note: The claim is particularly notable because it appears consistent with the broader Azure credential-compromise/exfiltration activity recently reported by Hudson Rock, which specifically named McDonald’s among the allegedly affected organizations. However, this individual forum listing and its claimed 1.7M+ records have not been independently verified. The listing should therefore be treated as an allegation rather than confirmation of a new McDonald’s breach.<br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DarkWeb\">#DarkWeb</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23McDonalds\">#McDonalds</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DataBreach\">#DataBreach</a></p>\n<img src=\"https://x.com/pic/media%2FHP19gKuXUAA_jNR.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088963799076233647"}, {"id": "2088956982275240221", "post_type": "Normal", "created_at": "2026-08-16T11:52:10+00:00", "created_at_datetime": [2026, 8, 16, 11, 52, 10], "author": "@DailyDarkWeb", "post_text": "<p>🚨 12 KB Windows Backdoor Hid Its C2 Address in `desktop.ini` Whitespace<br />\n<br />\nGen Digital researchers have documented an unusual custom Windows backdoor discovered on a single corporate workstation, using an uncommon technique to conceal its command-and-control infrastructure.<br />\n<br />\n* The implant is only **12,288 bytes** and was disguised using the legitimate-looking Realtek filename `RtkNGUI64.exe`.<br />\n<br />\n* Researchers found the malware on exactly **one domain-joined Windows 7 SP1 workstation**, suggesting the possibility of a deliberately targeted operation rather than a mass campaign.<br />\n<br />\n* Persistence was achieved through a **WMI event subscription** configured to trigger at 19:50 rather than immediately at system startup.<br />\n<br />\n* Most notably, the malware stored its C2 domain inside a seemingly ordinary Windows `desktop.ini` file.<br />\n<br />\n* Instead of storing the domain as plaintext or encrypted data, each character was represented by the **number of trailing spaces on individual lines**.<br />\n<br />\n* Decoding those whitespace counts revealed the C2 domain `diagrtrack[.]com`, a typosquat referencing Windows' DiagTrack telemetry service.<br />\n<br />\n* The backdoor first sends an **ICMP echo request** containing an eight-character victim identifier before initiating HTTP communications.<br />\n<br />\n* Its C2 supports only three commands: `system` for executing shell commands, `put` for writing files and `time` for modifying the polling interval.<br />\n<br />\n* Researchers found no related samples in their corpus or VirusTotal and did not attribute the implant to any known threat actor or campaign.<br />\n<br />\nThe most interesting aspect is not the malware's size or capabilities but its operational subtlety. Encoding infrastructure through whitespace in a legitimate Windows configuration file illustrates how highly targeted implants can deliberately optimize for low prevalence and weak static indicators. A binary appearing on only one endpoint should not automatically receive lower investigative priority.<br />\n<br />\nSource: Gen Digital Threat Research<br />\n<br />\n<a href=\"https://www.gendigital.com/blog/insights/research/kb-backdoor\">gendigital.com/blog/insights…</a><br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Malware\">#Malware</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23ThreatIntelligence\">#ThreatIntelligence</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23CyberSecurity\">#CyberSecurity</a></p>\n<img src=\"https://x.com/pic/media%2FHP13TbkXQAEIgo6.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088956982275240221"}, {"id": "2088955954314297553", "post_type": "Normal", "created_at": "2026-08-16T11:48:05+00:00", "created_at_datetime": [2026, 8, 16, 11, 48, 5], "author": "@DailyDarkWeb", "post_text": "<p>⚠️ Notion User Database Allegedly Offered for Sale — 150M+ Records Claimed<br />\n<br />\nA threat actor on an underground forum is advertising what they claim is a database containing more than 150 million unique Notion user records.<br />\n<br />\n* Dataset allegedly contains user email addresses<br />\n* Hashed passwords are claimed to be included<br />\n* Registration and account activity dates<br />\n* Signup and last-login IP addresses<br />\n* Locale, timezone and country information<br />\n* Workspace-related metadata<br />\n* Seller provides what appears to be a sample of the alleged dataset<br />\n* The forum account dates to July 2023 and currently shows VIP status, 41 posts and a reputation score of 17<br />\n<br />\n⚠️ Important: There is currently no evidence in the forum post establishing that Notion itself was breached. The provenance, authenticity, freshness and claimed 150M+ record count have not been independently verified. The dataset could potentially originate from another source, aggregation, or previously exposed information.<br />\n<br />\nAnalyst Note: The inclusion of alleged hashed passwords and account metadata would substantially increase the potential impact if the dataset is authentic. Organizations should avoid treating the listing as a confirmed Notion breach until the source of the records is independently established.<br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DarkWeb\">#DarkWeb</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Notion\">#Notion</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DataBreach\">#DataBreach</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23CyberThreatIntelligence\">#CyberThreatIntelligence</a></p>\n<img src=\"https://x.com/pic/media%2FHP12XlVWIAAGNID.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088955954314297553"}, {"id": "2088954766650925336", "post_type": "Normal", "created_at": "2026-08-16T11:43:21+00:00", "created_at_datetime": [2026, 8, 16, 11, 43, 21], "author": "@DailyDarkWeb", "post_text": "<p>⚠️ GitHub Access to Fortune 100 Tech Company Allegedly Offered for Supply-Chain Attack<br />\n<br />\nA newly registered threat actor on an underground forum claims to be selling privileged GitHub access to an unidentified Fortune 100 technology company with reported revenue exceeding $20 billion.<br />\n<br />\n* Seller claims access to private GitHub repositories<br />\n* Claims ability to modify source code<br />\n* Claims access across the company's GitHub organizations<br />\n* CI/CD access is allegedly available<br />\n* Actor specifically advertises the ability to push code to a container registry<br />\n* Listing explicitly markets the access for a \"supply chain attack\"<br />\n* Escrow is reportedly accepted<br />\n* Seller account joined the forum in August 2026 and currently shows only 2 posts, 2 threads and zero reputation<br />\n<br />\nAnalyst Note: If authentic, the combination of source-code modification, CI/CD access and container-registry publishing privileges could create significant software supply-chain risk, potentially extending exposure beyond the unnamed company to downstream customers. However, the seller provides no visible technical proof in the listing, and the account has virtually no established reputation. The claims should therefore be treated as unverified intelligence until independently corroborated.<br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DarkWeb\">#DarkWeb</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23SupplyChain\">#SupplyChain</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23GitHub\">#GitHub</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23CyberThreatIntelligence\">#CyberThreatIntelligence</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DevSecOps\">#DevSecOps</a></p>\n<img src=\"https://x.com/pic/media%2FHP11SerXMAAL6-c.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088954766650925336"}, {"id": "2088953793194889287", "post_type": "Normal", "created_at": "2026-08-16T11:39:29+00:00", "created_at_datetime": [2026, 8, 16, 11, 39, 29], "author": "@DailyDarkWeb", "post_text": "<p>🇺🇸🌊 U.S. Navy Confirms Unique Seabed Warfare Virginia-Class Submarine<br />\n<br />\nThe U.S. Navy has confirmed plans for a one-of-a-kind Block V Virginia-class nuclear-powered submarine designed specifically for Subsea and Seabed Warfare (SSW).<br />\n<br />\n* Unlike most Block V boats, the submarine will NOT carry the standard Virginia Payload Module configuration.<br />\n<br />\n* A Navy spokesperson confirmed that the vessel will instead be built as an SSW-focused platform.<br />\n<br />\n* General Dynamics Electric Boat previously described the planned variant as a submarine designed to \"interact with the seafloor.\"<br />\n<br />\n* The specialized platform is expected to support highly sensitive undersea missions involving intelligence collection and operations around seabed infrastructure.<br />\n<br />\n* Its mission is broadly comparable to USS Jimmy Carter, the heavily modified Seawolf-class submarine associated with some of America's most sensitive underwater intelligence missions.<br />\n<br />\n* Publicly known capabilities associated with this mission area include deployment of remotely operated vehicles, unmanned underwater vehicles and specialized seabed payloads.<br />\n<br />\n* The Navy has NOT revealed which future Block V submarine will receive the SSW configuration.<br />\n<br />\n🔎 Analyst Note: Seabed warfare is becoming increasingly strategically important as subsea fiber-optic cables, sensors, energy infrastructure and military systems become critical elements of national security.<br />\n<br />\nA purpose-built Virginia-class SSW platform suggests the U.S. intends to preserve and modernize its highly specialized deep-ocean intelligence capability as USS Jimmy Carter ages.<br />\n<br />\nOriginal report:<br />\n<a href=\"https://www.twz.com/sea/navy-is-getting-a-unique-virginia-class-seabed-espionage-submarine\">twz.com/sea/navy-is-getting-…</a><br />\n<br />\nOfficial U.S. Navy Virginia-class information:<br />\n<a href=\"https://www.navy.mil/Resources/Fact-Files/Display-FactFiles/Article/2169558/attack-submarines-ssn/\">navy.mil/Resources/Fact-File…</a><br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Intelligence\">#Intelligence</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23USNavy\">#USNavy</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Submarine\">#Submarine</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Espionage\">#Espionage</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23OSINT\">#OSINT</a></p>\n<img src=\"https://x.com/pic/media%2FHP10ZyoWAAAZf5C.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088953793194889287"}, {"id": "2088952554617033047", "post_type": "Normal", "created_at": "2026-08-16T11:34:34+00:00", "created_at_datetime": [2026, 8, 16, 11, 34, 34], "author": "@DailyDarkWeb", "post_text": "<p>🇺🇸 BullyPedex Database Allegedly Offered for Sale — 280K+ Records<br />\n<br />\nA threat actor on an underground forum is advertising a database allegedly associated with <a href=\"http://BullyPedex.com\">BullyPedex.com</a>.<br />\n<br />\n* The seller claims the database contains more than 280,000 rows<br />\n* The dataset is labeled \"July 2026\"<br />\n* A substantial sample is included in the forum post<br />\n* Visible fields appear consistent with customer and billing-platform records, including names, email addresses, phone numbers, addresses, account metadata, subscriptions, tax IDs, invoice settings and shipping information<br />\n* The structure shown in the sample appears to contain Stripe-style customer objects and API paths<br />\n* The seller's forum account was created in May 2026 and currently shows a reputation score of 40<br />\n<br />\nAnalyst Note: The provided sample gives the claim more substance than a listing without evidence, but it does not independently establish how the records were obtained or whether BullyPedex itself was directly compromised. The claimed 280K+ record count, provenance and freshness remain unverified.<br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DarkWeb\">#DarkWeb</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23BullyPedex\">#BullyPedex</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DataLeak\">#DataLeak</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DataBreach\">#DataBreach</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23CyberThreatIntelligence\">#CyberThreatIntelligence</a></p>\n<img src=\"https://x.com/pic/media%2FHP1zRpSWAAA96Uu.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088952554617033047"}, {"id": "2088951360892834150", "post_type": "Normal", "created_at": "2026-08-16T11:29:49+00:00", "created_at_datetime": [2026, 8, 16, 11, 29, 49], "author": "@DailyDarkWeb", "post_text": "<p>⚠️ Milk Road Newsletter Database Allegedly Offered for Sale<br />\n<br />\nA threat actor on an underground forum is advertising a database allegedly associated with Milk Road, a cryptocurrency-focused newsletter and media platform.<br />\n<br />\n* The seller claims the dataset contains approximately 535,000 lines<br />\n* The listing describes it as a \"crypto newsletter DB\"<br />\n* Full samples are reportedly available to prospective buyers upon request<br />\n* The seller allows escrow or a forum middleman for the transaction<br />\n* The forum account currently shows only 5 posts and zero reputation<br />\n* No data fields, breach method or evidence establishing how the information was obtained are visible in the listing<br />\n<br />\nAnalyst Note: The advertisement alone does not establish that Milk Road was compromised. No sample is visible in the provided post, and the seller provides no technical evidence demonstrating provenance. The claimed 535K-line dataset should therefore be treated as an unverified underground-market claim pending validation or acknowledgment from Milk Road.<br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DarkWeb\">#DarkWeb</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23MilkRoad\">#MilkRoad</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Crypto\">#Crypto</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DataLeak\">#DataLeak</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23ThreatIntelligence\">#ThreatIntelligence</a></p>\n<img src=\"https://x.com/pic/media%2FHP1yMQOWwAA7esL.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088951360892834150"}, {"id": "2088950084218036532", "post_type": "Normal", "created_at": "2026-08-16T11:24:45+00:00", "created_at_datetime": [2026, 8, 16, 11, 24, 45], "author": "@DailyDarkWeb", "post_text": "<p>🚨 TensorFlow Lite Micro Integer-Overflow Exploit Offered for $1,500 — But It Is Not a True Zero-Day<br />\n<br />\nA threat actor is advertising an exploit targeting TensorFlow Lite Micro (tflite-micro), claiming an integer overflow can lead to heap corruption and ultimately remote code execution.<br />\n<br />\n* The seller targets the ElementCount() function in TensorFlow Lite Micro<br />\n* The claimed issue involves a 32-bit integer overflow while calculating tensor dimensions<br />\n* The seller claims exploitation can result in undersized memory allocation, heap corruption and potentially RCE<br />\n* A malicious .tflite model is advertised as the attack vector<br />\n* IoT, embedded devices and mobile applications are listed as potential targets<br />\n* Asking price: $1,500<br />\n* The seller describes the vulnerability as unpatched and without a CVE<br />\n<br />\nHowever, DDW identified a public TensorFlow Lite Micro pull request filed on August 12, 2026 describing the same ElementCount() integer-overflow condition and proposed overflow checks<br />\n<br />\nThe underground advertisement is dated August 14, meaning the technical issue was already publicly disclosed before it was offered as a supposed \"0-day\"<br />\n<br />\nThe TensorFlow Lite Micro maintainers closed the proposed fix, noting that the type change would first need to be adopted by upstream LiteRT<br />\n<br />\nAnalyst Note: The underlying integer-overflow condition appears technically plausible and is publicly documented, but the seller's claim of reliable remote code execution has NOT been independently demonstrated. More importantly, describing this as a zero-day is misleading because the vulnerability details were publicly available before the underground listing appeared.<br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23TensorFlow\">#TensorFlow</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23TensorFlowLite\">#TensorFlowLite</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23ZeroDay\">#ZeroDay</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Exploit\">#Exploit</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23AI\">#AI</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23CyberSecurity\">#CyberSecurity</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23ThreatIntelligence\">#ThreatIntelligence</a></p>\n<img src=\"https://x.com/pic/media%2FHP1xB6FXwAALnQI.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088950084218036532"}, {"id": "2088947117532291259", "post_type": "R to @DailyDarkWeb", "created_at": "2026-08-16T11:12:58+00:00", "created_at_datetime": [2026, 8, 16, 11, 12, 58], "author": "@DailyDarkWeb", "post_text": "<img src=\"https://x.com/pic/media%2FHP1uVVGXcAAz205.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088947117532291259"}, {"id": "2088946126783185365", "post_type": "Normal", "created_at": "2026-08-16T11:09:02+00:00", "created_at_datetime": [2026, 8, 16, 11, 9, 2], "author": "@DailyDarkWeb", "post_text": "<p>Long before biometric databases went digital, state surveillance relied on physical, physical-world identifiers.<br />\n<br />\nDuring the Cold War, East Germany’s secret police, the Stasi (Ministerium für Staatssicherheit), pioneered \"Geruchsspuren\" (Scent Samples) to track dissidents and political opponents.<br />\n<br />\nHow the Stasi Built Their Scent Archive:<br />\n<br />\n*Collection Methods: During interrogations, agents forced suspects to sit on sterile yellow cloths (Geruchstuch) to absorb sweat. They also conducted covert break-ins to steal worn socks and underwear.<br />\n<br />\n*Storage Protocols: Samples were sealed in airtight glass jars, cataloged with metadata (donor ID, collection date, responsible unit), and stored in climate-controlled archives.<br />\n<br />\n*Deployment: Specially trained sniffer dogs were used to match scents from crime scenes or illegal leaflet distributions against the archive to track targets anywhere in the city.<br />\n<br />\nPhysical data collection has always been about total domain awareness, the techniques have just evolved from glass jars to digital intelligence.<br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23OSINT\">#OSINT</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23DarkWeb\">#DarkWeb</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23SurveillanceHistory\">#SurveillanceHistory</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Stasi\">#Stasi</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23CyberIntelligence\">#CyberIntelligence</a></p>\n<a href=\"https://x.com/DailyDarkWeb/status/2088946126783185365#m\">\n<br />Video<br />\n  <img src=\"https://x.com/pic/amplify_video_thumb%2F2088946093144911872%2Fimg%2Fs0VV1H7f2BNwX5vY.jpg\" />\n</a>", "post_url": "https://x.com/DailyDarkWeb/status/2088946126783185365"}, {"id": "2088945005435977916", "post_type": "Normal", "created_at": "2026-08-16T11:04:34+00:00", "created_at_datetime": [2026, 8, 16, 11, 4, 34], "author": "@DailyDarkWeb", "post_text": "<p>🇺🇦 Ukraine Says Nvidia Jetson Orin Module Found Inside New Russian S-71 Monochrome Cruise Missile<br />\n<br />\nUkraine’s military intelligence agency, HUR, says its specialists identified an **Nvidia Jetson Orin computing module** among the components recovered from Russia’s new **S-71 Monochrome cruise missile**.<br />\n<br />\n* According to HUR, the Jetson Orin module was found inside the missile’s onboard electronics.<br />\n<br />\n* The Jetson Orin family is designed for high-performance edge AI workloads, including computer vision, autonomous systems and real-time sensor processing.<br />\n<br />\n* HUR also reported identifying **35 foreign-made electronic components** across Russian weapons examined by Ukrainian specialists.<br />\n<br />\n* The finding raises further questions about how advanced Western-origin commercial technology continues to reach Russian military supply chains despite export controls and sanctions.<br />\n<br />\n⚠️ Analyst Note: The presence of an AI-capable commercial computing module inside a modern cruise missile is significant, but the exact role of the Jetson Orin in the S-71 system has not been publicly established from the material shown. It could potentially support navigation, sensor processing, target recognition or other onboard computation, but those functions should not be treated as confirmed without additional technical evidence.<br />\n<br />\nSource: Kyiv Post / Ukraine’s HUR<br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Intelligence\">#Intelligence</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Ukraine\">#Ukraine</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Russia\">#Russia</a></p>\n<img src=\"https://x.com/pic/media%2FHP1saP6WQAAgOdu.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088945005435977916"}, {"id": "2088944684823347346", "post_type": "Normal", "created_at": "2026-08-16T11:03:18+00:00", "created_at_datetime": [2026, 8, 16, 11, 3, 18], "author": "@DailyDarkWeb", "post_text": "<p>🚨 Massive Azure Data Exfiltration Campaign Allegedly Hits McDonald’s, Vodafone, Kyndryl and Other Enterprises<br />\n<br />\nHudson Rock says it has uncovered a large-scale campaign in which threat actors are using compromised credentials to access Microsoft Azure environments and exfiltrate substantial volumes of enterprise data.<br />\n<br />\n* According to Hudson Rock, the campaign relies heavily on credentials harvested by information-stealing malware rather than exploitation of a new Azure vulnerability.<br />\n<br />\n* The researchers report that attackers are using compromised identities to authenticate to enterprise Microsoft cloud environments and access organizational data.<br />\n<br />\n* Hudson Rock says millions of records have been exfiltrated across affected environments.<br />\n<br />\n* Organizations referenced in the investigation include McDonald’s, Vodafone, Kyndryl and others.<br />\n<br />\n* The campaign highlights the continued value of infostealer logs to threat actors: credentials stolen from an endpoint can potentially provide access to cloud services long after the original device compromise.<br />\n<br />\n* The incident also demonstrates why password resets alone may be insufficient when session tokens, authentication artifacts or other credentials have been exposed.<br />\n<br />\n⚠️ Analyst Note: This should currently be treated as a researcher-reported campaign rather than confirmation that every named organization suffered a separately verified corporate breach. The important intelligence finding is the attack path: infostealer compromise → stolen enterprise credentials → legitimate cloud authentication → Azure data access and exfiltration. Organizations should correlate infostealer exposure with Entra ID sign-in telemetry, revoke active sessions and tokens, rotate affected credentials, and investigate abnormal cloud access rather than treating an infected endpoint as an isolated incident.<br />\n<br />\nSource: Hudson Rock<br />\n<br />\n<a href=\"https://www.hudsonrock.com/blog/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others\">hudsonrock.com/blog/massive-…</a><br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23DDW\">#DDW</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Intelligence\">#Intelligence</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Azure\">#Azure</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23Infostealer\">#Infostealer</a></p>\n<img src=\"https://x.com/pic/media%2FHP1sHlMWIAA9iNO.jpg\" />\n\n<img src=\"https://x.com/pic/media%2FHP1sHlYWIAAMYOr.jpg\" />", "post_url": "https://x.com/DailyDarkWeb/status/2088944684823347346"}, {"id": "2089021157076865181", "post_type": "Normal", "created_at": "2026-08-16T16:07:10+00:00", "created_at_datetime": [2026, 8, 16, 16, 7, 10], "author": "@DarkWebInformer", "post_text": "<p>🚨🇫🇷 Cravero Motoculture dataset allegedly leaked on a cybercrime forum<br />\n⠀<br />\nA forum user claims to have leaked a database allegedly belonging to Cravero Motoculture, a French agricultural and outdoor equipment business. The post is labeled as part of the actor's \"BlgCloud Leak\" series.<br />\n⠀<br />\nThe advertised leak reportedly contains approximately 3.7 GB of data across 49,168 files.<br />\n⠀<br />\nThe exposed data shown in the samples includes:<br />\n⠀<br />\n• Customer and CRM records<br />\n• Contact names<br />\n• Email addresses<br />\n• Phone numbers<br />\n• Physical addresses<br />\n• Company and account information<br />\n• Customer and supplier references<br />\n• Billing and invoicing fields<br />\n• Commercial document metadata<br />\n• PDF sales proposals and other documents<br />\n• File names, hashes and storage paths<br />\n• Internal record and attachment identifiers<br />\n⠀<br />\nThe poster's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.<br />\n⠀<br />\n💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. <a href=\"http://darkwebinformer.com/pricing\">darkwebinformer.com/pricing</a></p>\n<img src=\"https://x.com/pic/media%2FHP2xmEeXoAEEPTo.jpg\" />", "post_url": "https://x.com/DarkWebInformer/status/2089021157076865181"}, {"id": "2089019076932682065", "post_type": "Normal", "created_at": "2026-08-16T15:58:54+00:00", "created_at_datetime": [2026, 8, 16, 15, 58, 54], "author": "@DarkWebInformer", "post_text": "<p>🚨🇫🇷 FranceCasse customer and order dataset allegedly scraped and leaked on a cybercrime forum<br />\n⠀<br />\nA forum user claims to have released a newly obtained dataset from FranceCasse, a French automotive parts platform. The poster says the data was scraped during August 2026 and published samples from multiple files containing customer, address, order and product information.<br />\n⠀<br />\nThe advertised data includes:<br />\n⠀<br />\n• Customer names and usernames<br />\n• Email addresses<br />\n• Physical addresses and postal codes<br />\n• Customer account information<br />\n• Hashed passwords<br />\n• Order and cart identifiers<br />\n• Invoice and delivery information<br />\n• Payment method fields<br />\n• Order totals and shipping costs<br />\n• Product IDs and descriptions<br />\n• Product pricing and inventory information<br />\n• Vehicle and automotive part information<br />\n• Manufacturer and supplier fields<br />\n• Customer and delivery address records<br />\n⠀<br />\nThe forum post includes samples from files identified as addresses.csv, customers.csv, orders.jsonl and products.jsonl, with the full FranceCasse dataset placed behind hidden forum content.<br />\n⠀<br />\nThe poster's claims and the authenticity, source and scope of the allegedly exposed data have not been independently verified.<br />\n⠀<br />\n💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. <a href=\"http://darkwebinformer.com/pricing\">darkwebinformer.com/pricing</a></p>\n<img src=\"https://x.com/pic/media%2FHP2vsvvXEAAfow0.jpg\" />\n\n<img src=\"https://x.com/pic/media%2FHP2vswrWkAA4KT4.jpg\" />", "post_url": "https://x.com/DarkWebInformer/status/2089019076932682065"}, {"id": "2089012403942170927", "post_type": "Normal", "created_at": "2026-08-16T15:32:23+00:00", "created_at_datetime": [2026, 8, 16, 15, 32, 23], "author": "@FalconFeedsio", "post_text": "<p>🚨 Ransomware Alert 🚨<br />\n<br />\nQilin ransomware group has added 2 new victims to their dark web portal.<br />\n<br />\n* Mulino Padano S.p.A. 🇮🇹<br />\n* WEBA 🇧🇪</p>\n<img src=\"https://x.com/pic/media%2FHP2ptByaIAEAP1W.jpg\" />", "post_url": "https://x.com/FalconFeedsio/status/2089012403942170927"}, {"id": "2088998981007532353", "post_type": "Normal", "created_at": "2026-08-16T14:39:03+00:00", "created_at_datetime": [2026, 8, 16, 14, 39, 3], "author": "@FalconFeedsio", "post_text": "<p>🚨Alert: New Hacktivist Alliance🚨<br />\n<br />\nBABAYO EROR SYSTEM and BNCT_1360 have officially announced a new alliance.</p>\n<img src=\"https://x.com/pic/media%2FHP2df1raIAAnb_3.jpg\" />", "post_url": "https://x.com/FalconFeedsio/status/2088998981007532353"}, {"id": "2088998352180728198", "post_type": "Normal", "created_at": "2026-08-16T14:36:33+00:00", "created_at_datetime": [2026, 8, 16, 14, 36, 33], "author": "@FalconFeedsio", "post_text": "<p>🚨DDoS Alert 🇮🇱<br />\n<br />\nYEMEN CYBER GROUP claims to have targeted the website of Prima Hotels Israel (<a href=\"https://prima-hotels-israel.com\">prima-hotels-israel.com</a>)</p>\n<img src=\"https://x.com/pic/media%2FHP2c6-8aYAAOstq.jpg\" />", "post_url": "https://x.com/FalconFeedsio/status/2088998352180728198"}, {"id": "2088997856921391218", "post_type": "Normal", "created_at": "2026-08-16T14:34:35+00:00", "created_at_datetime": [2026, 8, 16, 14, 34, 35], "author": "@FalconFeedsio", "post_text": "<p>🚨 Ransomware Alert: 🇲🇦<br />\n<br />\nINFOSAT (<a href=\"http://infosat.ma\">infosat.ma</a>), a Morocco-based IT services and technology solutions company, has reportedly fallen victim to PANZER ransomware.<br />\n<br />\nNB: They intend to publish the data within 20–21 days.<br />\n<br />\n🔍 Key Details:<br />\n<br />\n🛡️ Threat Actor: PANZER<br />\n📅 Reported on: 16/08/26<br />\n⚠️ Data Compromised: 35 GB</p>\n<img src=\"https://x.com/pic/media%2FHP2ceQhboAAml-E.jpg\" />", "post_url": "https://x.com/FalconFeedsio/status/2088997856921391218"}, {"id": "2088997499688333331", "post_type": "Normal", "created_at": "2026-08-16T14:33:10+00:00", "created_at_datetime": [2026, 8, 16, 14, 33, 10], "author": "@FalconFeedsio", "post_text": "<p>🚨 Ransomware Alert: 🇨🇦<br />\n<br />\nMOSAID Technologies  (<a href=\"https://mosaid.com\">mosaid.com</a>), a Canada-based Semiconductor Manufacturing company, has reportedly fallen victim to Qilin ransomware.<br />\n<br />\n🔍 Key Details:<br />\n<br />\n🛡️ Threat Actor: Qilin<br />\n📅 Reported on: 14/08/26</p>\n<img src=\"https://x.com/pic/media%2FHP2cJbTbAAA9x19.jpg\" />", "post_url": "https://x.com/FalconFeedsio/status/2088997499688333331"}, {"id": "2088997324790063577", "post_type": "Normal", "created_at": "2026-08-16T14:32:28+00:00", "created_at_datetime": [2026, 8, 16, 14, 32, 28], "author": "@FalconFeedsio", "post_text": "<p>🚨 Ransomware Alert: 🇨🇦<br />\n<br />\nMOSAID Technologies  (<a href=\"https://mosaid.com\">mosaid.com</a>), a Canada-based Semiconductor Manufacturing company, has reportedly fallen victim to Qilin ransomware.<br />\n<br />\n🔍 Key Details:<br />\n<br />\n🛡️ Threat Actor: Qilin<br />\n📅 Reported on: 14/08/26</p>\n<img src=\"https://x.com/pic/media%2FHP2b_RtbYAAS9Ah.jpg\" />", "post_url": "https://x.com/FalconFeedsio/status/2088997324790063577"}, {"id": "2088978253537231205", "post_type": "Normal", "created_at": "2026-08-16T13:16:41+00:00", "created_at_datetime": [2026, 8, 16, 13, 16, 41], "author": "@FalconFeedsio", "post_text": "<p>🚨DDoS Alert 🇮🇱<br />\n<br />\nBD Anonymous claims to have targeted the website of Israel Defense and Security Forum (<a href=\"https://idsf.org.il\">idsf.org.il</a>)</p>\n<img src=\"https://x.com/pic/media%2FHP2Knwja0AATo7K.jpg\" />", "post_url": "https://x.com/FalconFeedsio/status/2088978253537231205"}, {"id": "2088974163180732648", "post_type": "Normal", "created_at": "2026-08-16T13:00:26+00:00", "created_at_datetime": [2026, 8, 16, 13, 0, 26], "author": "@FalconFeedsio", "post_text": "<p>🚨 Ransomware Alert 🚨<br />\n<br />\nThe Qilin ransomware group has added 6 new victims to its dark web portal:<br />\n<br />\n• Desatera Sdn Bhd 🇲🇾<br />\n• Loescher Editore 🇮🇹<br />\n• BOTEK Präzisionsbohrtechnik GmbH 🇩🇪<br />\n• Zanichelli Editore S.p.A. 🇮🇹<br />\n• INVENSITY 🇩🇪<br />\n• Megawide Construction Corporation 🇵🇭</p>\n<img src=\"https://x.com/pic/media%2FHP2G7LQaAAAuubl.jpg\" />", "post_url": "https://x.com/FalconFeedsio/status/2088974163180732648"}, {"id": "2088974003318952072", "post_type": "Normal", "created_at": "2026-08-16T12:59:48+00:00", "created_at_datetime": [2026, 8, 16, 12, 59, 48], "author": "@FalconFeedsio", "post_text": "<p>🚨DDoS Alert 🇮🇱<br />\n<br />\nYEMEN CYBER GROUP claims to have targeted the website of Brown Hotels (<a href=\"https://brownhotels.co.il\">brownhotels.co.il</a>).</p>\n<img src=\"https://x.com/pic/media%2FHP2GxvRbgAAJWJB.jpg\" />", "post_url": "https://x.com/FalconFeedsio/status/2088974003318952072"}, {"id": "2088973635214254355", "post_type": "Normal", "created_at": "2026-08-16T12:58:20+00:00", "created_at_datetime": [2026, 8, 16, 12, 58, 20], "author": "@FalconFeedsio", "post_text": "<p>🚨 Ransomware Alert 🚨<br />\n<br />\nThe LockBit 5.0 ransomware group has added 5 new victims to its dark web portal:<br />\n<br />\n• Verbandsgemeinde Rhein-Nahe 🇩🇪<br />\n• Agricola Galbusera 🇮🇹<br />\n• Crowe Dupouy 🇫🇷<br />\n• ACTUA Agences d'emploi 🇫🇷<br />\n• TECOSIM Group 🇩🇪</p>\n<img src=\"https://x.com/pic/media%2FHP2Gb0bbkAAh37o.jpg\" />", "post_url": "https://x.com/FalconFeedsio/status/2088973635214254355"}, {"id": "2088942612329968004", "post_type": "Normal", "created_at": "2026-08-16T10:55:04+00:00", "created_at_datetime": [2026, 8, 16, 10, 55, 4], "author": "@FalconFeedsio", "post_text": "<p>🚨DDoS Alert 🇮🇱<br />\n<br />\nYEMEN CYBER GROUP claims to have targeted the website of Asden Israel (<a href=\"https://asden.co.il\">asden.co.il</a>).</p>\n<img src=\"https://x.com/pic/media%2FHP1qOFga8AAwaJQ.jpg\" />", "post_url": "https://x.com/FalconFeedsio/status/2088942612329968004"}, {"id": "2088931809354793141", "post_type": "Normal", "created_at": "2026-08-16T10:12:08+00:00", "created_at_datetime": [2026, 8, 16, 10, 12, 8], "author": "@FalconFeedsio", "post_text": "<p>🚨 Ransomware Alert 🚨<br />\n<br />\nQilin ransomware group has added 6 new victims to its dark web portal.<br />\n<br />\n* Double H Equipment 🇺🇸<br />\n* Motorenmaier GmbH 🇩🇪<br />\n* DELTA WAYS 🇩🇪<br />\n* Ascii Group, LLC 🇺🇸<br />\n* Arnall Golden Gregory LLP 🇺🇸<br />\n* Jone Precision 🇫🇷</p>\n<img src=\"https://x.com/pic/media%2FHP1gY5ta4AAcGIa.jpg\" />", "post_url": "https://x.com/FalconFeedsio/status/2088931809354793141"}, {"id": "2088911481274519602", "post_type": "Normal", "created_at": "2026-08-16T08:51:21+00:00", "created_at_datetime": [2026, 8, 16, 8, 51, 21], "author": "@FalconFeedsio", "post_text": "<p>🚨DDoS Alert: 🇩🇪<br />\nNoName claims to have targeted Multiple websites in Germany.<br />\n<br />\n- Maritimes Cluster Norddeutschland e. V.<br />\n- Menzell Döhle Group<br />\n- ESWE Versorgungs AG</p>\n<img src=\"https://x.com/pic/media%2FHP1NxG4a0AEQ5oU.png\" />\n\n<img src=\"https://x.com/pic/media%2FHP1N6bQaUAAHqEk.png\" />", "post_url": "https://x.com/FalconFeedsio/status/2088911481274519602"}, {"id": "2088908968915853331", "post_type": "Normal", "created_at": "2026-08-16T08:41:22+00:00", "created_at_datetime": [2026, 8, 16, 8, 41, 22], "author": "@FalconFeedsio", "post_text": "<p>🚨 Ransomware Alert: 🇹🇼<br />\n<br />\nSmartSoft Technology Co., Ltd. (<a href=\"https://smartsoft.com.tw\">smartsoft.com.tw</a>), a Taiwan-based software development company, has reportedly fallen victim to Orova ransomware.<br />\n<br />\n🔍 Key Details:<br />\n<br />\n🛡️ Threat Actor: Orova<br />\n📅 Reported on: 16/08/26<br />\n⚠️ Data Compromised: 14.90 GB</p>\n<img src=\"https://x.com/pic/media%2FHP1LmoGbsAA6dId.jpg\" />", "post_url": "https://x.com/FalconFeedsio/status/2088908968915853331"}, {"id": "2088900616139760053", "post_type": "Normal", "created_at": "2026-08-16T08:08:11+00:00", "created_at_datetime": [2026, 8, 16, 8, 8, 11], "author": "@FalconFeedsio", "post_text": "<p>🚨DDoS Alert: 🇩🇪<br />\n<br />\nNoName claims to have targeted Two websites in Germany.<br />\n<br />\n- Rhein-Main-Verkehrsverbund GmbH<br />\n- ⁠Landeshauptstadt Wiesbaden</p>\n<img src=\"https://x.com/pic/media%2FHP1D3VMbkAAWRS_.png\" />", "post_url": "https://x.com/FalconFeedsio/status/2088900616139760053"}, {"id": "2088881455648919916", "post_type": "Normal", "created_at": "2026-08-16T06:52:03+00:00", "created_at_datetime": [2026, 8, 16, 6, 52, 3], "author": "@FalconFeedsio", "post_text": "<p>🚨DDoS Alert 🇩🇪<br />\n<br />\nBD Anonymous claims to have targeted the website of Bundeskriminalamt(<a href=\"https://bewerbung.bka.de\">bewerbung.bka.de</a>)</p>\n<img src=\"https://x.com/pic/media%2FHP0ylHYbsAAmZPs.jpg\" />", "post_url": "https://x.com/FalconFeedsio/status/2088881455648919916"}, {"id": "2088866105196675235", "post_type": "Normal", "created_at": "2026-08-16T05:51:03+00:00", "created_at_datetime": [2026, 8, 16, 5, 51, 3], "author": "@FalconFeedsio", "post_text": "<p>🚨Alert: New Hacktivist Alliance🚨<br />\n<br />\nCYBER TEAM INDONESIA and Dark Storm Team have officially announced a new alliance.</p>\n<img src=\"https://x.com/pic/media%2FHP0kpUbbYAAlBZ7.jpg\" />", "post_url": "https://x.com/FalconFeedsio/status/2088866105196675235"}, {"id": "2088997599529324641", "post_type": "Normal", "created_at": "2026-08-16T14:33:34+00:00", "created_at_datetime": [2026, 8, 16, 14, 33, 34], "author": "@IntCyberDigest", "post_text": "<p>Epic Games has confirmed a native Linux client for the Epic Games Store. Staffer onepercentnachos told an August 13 Discord AMA it's coming \"soon,\" but not in the next preview build. Epic says the job is bigger than a launcher binary that runs on Linux.<br />\n<br />\nCurrent Linux and Steam Deck players still need non-native Heroic and Proton for now.</p>\n<img src=\"https://x.com/pic/media%2FHP2b_FEWEAAfgZ0.png\" />", "post_url": "https://x.com/IntCyberDigest/status/2088997599529324641"}, {"id": "2088921737735868599", "post_type": "Normal", "created_at": "2026-08-16T09:32:07+00:00", "created_at_datetime": [2026, 8, 16, 9, 32, 7], "author": "@IntCyberDigest", "post_text": "<p>North Korean threat actor says he got COVID-19 in 2018 during a job interview, then quickly corrects it to 2019, and says it took him two years to recover after being asked about the gap in his resume.</p>\n<a href=\"https://x.com/IntCyberDigest/status/2088921737735868599#m\">\n<br />Video<br />\n  <img src=\"https://x.com/pic/media%2FHP1XN8gWgAA88sj.jpg\" />\n</a>\n\n<hr />\n<blockquote>\n<b>tanuki42 (@tanuki42_)</b>\n<p>\n<p>1/ I think I found patient zero for COVID-19.<br />\n<br />\nMeet my latest North Korean applicant <a href=\"https://x.com/hodlwarden\" title=\"Hodlwarden\">@hodlwarden</a> (\"Ming Cheng\"). Ming had a mysterious 3 year employment gap on his resume from 2018-2021 which initially raised some concerns, but then he explained he was receiving COVID treatment.</p>\n<img src=\"https://x.com/pic/media%2FHPsLvxiacAEqNJ-.png\" />\n\n<a href=\"https://x.com/tanuki42_/status/2088278343653413254#m\">\n<br />Video<br />\n  <img src=\"https://x.com/pic/amplify_video_thumb%2F2088275808750284800%2Fimg%2F0tAbhrDwCDBFvMGI.jpg\" />\n</a>\n\n\n</p>\n<footer>\n— <cite><a href=\"https://x.com/tanuki42_/status/2088278343653413254#m\">https://x.com/tanuki42_/status/2088278343653413254#m</a>\n</footer>\n</blockquote>", "post_url": "https://x.com/IntCyberDigest/status/2088921737735868599"}, {"id": "2088848597299404955", "post_type": "Normal", "created_at": "2026-08-16T04:41:29+00:00", "created_at_datetime": [2026, 8, 16, 4, 41, 29], "author": "@RaidForumsHub", "post_text": "<p>RaidBin is now LIVE!<br />\n<br />\nRaidBin — a fast, modern paste-sharing platform built for speed, simplicity, and reliability.<br />\n<br />\nVisit: <a href=\"https://raidbin.st\">raidbin.st</a><br />\nOnion: <a href=\"https://raidbinahr33urj6dcnuphimsnnxkvryvomimphp5wsfa5x3gkm2jsqd.onion/\">raidbinahr33urj6dcnuphimsnnx…</a><br />\n<br />\nFor Update Join : <a href=\"https://t.me/RaidBin\">t.me/RaidBin</a><br />\n<br />\n<a href=\"https://x.com/search?f=tweets&amp;q=%23RaidBin\">#RaidBin</a> <a href=\"https://x.com/search?f=tweets&amp;q=%23RaidForums\">#RaidForums</a></p>\n<img src=\"https://x.com/pic/media%2FHP0Um7Ta4AARWoF.png\" />", "post_url": "https://x.com/RaidForumsHub/status/2088848597299404955"}]}
