U.S. insurance provider AssuranceAmerica has confirmed a data breach affecting nearly 7 million people, exposing personal information and driver’s license numbers.
A remote code execution vulnerability in Foxit PDF Reader, tracked as CVE-2024-30326, highlights the continued risk of malicious PDF files being used as an initial access vector.
Noma Labs has disclosed GitLost, a prompt injection vulnerability that showed how GitHub’s AI-powered Agentic Workflows could be tricked into leaking private repository data through a public GitHub issue.
A threat actor using the alias Saturne is selling a database from Follow, a French Ségur-certified medical software and patient-record platform used by specialist doctors and surgeons.
A threat actor using the alias TheSyndicate claims to have fully compromised Nayax, an Israeli global payments and fintech company (NASDAQ: NYAX, TASE: NYAX.TA), stating they have been inside its systems for almost a year.
A threat actor using the alias derm0nix (Hackero$ Crew) claims to have breached the Portal de Salud de Culiacán, the official digital health system of the Culiacán municipal government in Mexico, and has leaked the data for free.
Tokyo police have arrested a 15-year-old student over an alleged cyberattack targeting Bandai Channel, the anime and tokusatsu streaming service operated by Bandai Namco Filmworks.
CVE-2026-40138 is a critical pre-authentication vulnerability in the authentication subsystem of BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA).
A threat actor using the alias dezetat is advertising a database from Malaysia's Inland Revenue Board (LHDN / IRBM), taken from the MyTax portal, for $20,000.
A threat actor using the alias EvaN47 claims to have breached the Libyan Ministry of Education (moe.gov.ly) and is threatening to publish a 287GB dataset of students' data if the ministry does not make contact.
How a coordinated strike against a 2-million-device botnet exposes the hidden economy of residential proxies, and what it means for anyone with a connected device at home.
A threat actor using the alias Straightonumberone is selling what they describe as data stolen from Grupo ATC, a Mexican logistics conglomerate (comprising TLE, TLEA, and PHES), for $1,000 after a ransom negotiation reportedly failed.
A threat actor using the alias EvaN47 has posted what they describe as a breach of the Libyan Civil Aviation Authority (caa.gov.ly), advertising a roughly 300GB dataset spanning 2015 to 2026 with a contact for acquisition.
A threat actor using the alias lucy is advertising a private, one-time sale of what they describe as comprehensive data from Netim.com, a French domain registrar and hosting provider, for $5,000 in cryptocurrency.
CVE-2026-33017 is a critical unauthenticated remote code execution flaw in Langflow, the popular open-source visual framework for building AI agents and RAG pipelines.
A threat actor using the alias misere, crediting collaborators (ChimeraZ and NightBroker), has posted what they describe as a complete database breach of Pachatours (pachatours.fr / pachatours.pro), a French tour operator specializing in Hajj packages and Tunisian beach holidays.
Dark Web Informer
Checked
6 hours 17 minutes ago
A real-time cyber threat intelligence platform that monitors the dark web and clearnet for data breaches, ransomware campaigns, darknet market activity, leaked databases, and active threat actors.