Ido Cohen: The attackers never rest... and neither do we. Meet RedAct, a newly tracked ransomware group. The group has already published 2 victims and states that it is driven purely by financial gain—not politics or hacktivism. According to its public message, organizations that refuse to negotiate or fail to meet ransom demands should expect their stolen data to be published. Another emerging threat worth keeping on your radar.2026-06-28
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Dark Web Informer: VRI Portal de Conteúdo dataset claim posted on a forum VRI Portal de Conteúdo is a Brazilian content portal focused on technical material in accounting, corporate, labor, and tax law areas. A forum user claims a dataset tied to VRI Portal de Conteúdo was exposed, allegedly containing 40K rows.2026-06-28
x-ctibreachBrazil
Dark web monitoring and threat intelligence feed on ransomware groups and data leak sites.
Daily Dark Web: Pinned: New Linux "pedit COW" Privilege Escalation Exploit Published Security researcher Massimiliano Oldani has released a public proof-of-concept (PoC) exploit, **packet_edit_meme**, for the Linux kernel vulnerability **CVE-2026-46331**, nicknamed **pedit COW**. * The flaw resides in Linux's **net/sched act_pedit** traffic control subsystem and allows an unprivileged local user to escalate privileges to **root** by corrupting shared page-cache memory.2026-06-28
x-ctivulnerabilityUnited States
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: Clearcover Customer Data Allegedly Offered for Sale A threat actor claims to be selling a database allegedly belonging to U.S. auto insurer Clearcover. * According to the forum post, the dataset is dated **25 June 2026** and allegedly contains **448,603** records.2026-06-28
x-ctibreachUnknownT1566
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: Alleged Compromise of Colima State Government Electronic Signature System A threat actor claims to have compromised the Advanced Electronic Signature (Firma Electrónica Avanzada) platform used by the Government of the State of Colima, Mexico. * According to the forum post, the actor alleges they: * Gained administrative access to the portal. * Deleted all user accounts except a single administrator account. * Retained control of the remaining administrative account.2026-06-28
x-cticampaignMexico
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: French Municipal Police Data Allegedly Leaked A threat actor claims to have leaked approximately 4,900 "mains courantes" (police incident reports/logs) belonging to the Municipal Police of Joinville-le-Pont, France. * According to the listing, the actor states the dataset was personally extracted and is offering access through a paid forum.2026-06-28
x-cticampaignFrance
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Daily Dark Web: French Hospital Patient Database Allegedly Repackaged and Shared A threat actor has published what they claim is a reformatted dataset originating from the 2024 Blackout ransomware leak targeting Centre Hospitalier d'Armentières in France. According to the post, the dataset contains information on approximately 203,928 patients, covering records from 2004 through March 2018.2026-06-28
x-ctiransomwareFranceT1566
Daily coverage of dark web activities, cybercrime forums and underground market intelligence.
Hackmanac: #PollResults Turns out what worries you most for H2 2026 is 𝐒𝐮𝐩𝐩𝐥𝐲 𝐂𝐡𝐚𝐢𝐧 𝐚𝐭𝐭𝐚𝐜𝐤𝐬 (𝟑𝟒%). Thanks to everyone who voted and see you at next #MondayPoll!2026-06-28
H4ckmanacransomwareUnknownT1566
Threat intelligence and cyber alert feed covering data breaches, ransomware incidents and vulnerability disclosures.
Ido Cohen: New Ransomware Group: Settra Settra has entered the ransomware landscape with 10+ published victims already listed on its leak site. Unlike groups that attempt to justify their actions, Settra openly states its motivation is simple: money. The group claims it does not target specific countries or industries—it targets organizations with exploitable security weaknesses.2026-06-27
ido_cohen2ransomwareUnknownT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
MalwareHunterTeam: RT by @malwrhunterteam: This is some kind of IT security related recruiting ad from the University of Criminal Investigation and Police Studies of Serbia... What are they "analysing"? Looks top or something like that... 2026-06-27
malwrhunterteamcampaignSerbia
Malware samples, IOCs and indicators of compromise distributed by the MalwareHunterTeam research group.