🔎 OSINT-driven cybersecurity intelligence Breaches | Threat Actors | Malware | Phishing | CVEs | Dark Web Monitoring

South Asia
‼️DATA SALE ALERT — COINBASE 🇺🇸 A threat actor Jerryalex claims to be selling a newly compiled database allegedly associated with Coinbase. Claimed dataset: • 2.1M records dated August 2026 • Emails, full names & phone numbers • Residential addresses, ZIP codes & cities • Advertised as “valid” and recently verified • Full dataset reportedly offered for $10,000+ ⚠️ The Coinbase attribution, dataset size, source, validity and authenticity of the records have not been independently verified. Sample personal information and transaction/contact details have been omitted to avoid exposing PII. #CyberSecurity #DataLeak #DataSale #Coinbase #ThreatIntel #OSINT
23
‼️CYBER ATTACK ALERT — HIGHSPEEDRURAL.US 🇺🇸 Yemen Cyber Group claims to have disrupted highspeedrural.us, a U.S.-based commercial service offering portable 4G LTE Wi-Fi routers and cellular data plans. Claimed impact: • Website returned 503 Service Unavailable • Check-host report cited by the group as evidence • Claimed as part of #OpUSA ⚠️ The group’s attribution and claim of responsibility have not been independently verified. The reported service disruption may have other causes. #CyberSecurity #DDoS #USA #ThreatIntel #OSINT
39
‼️CYBER ATTACK ALERT — COUPONS.CO.IL 🇮🇱 Yemen Cyber Group claims to have disrupted coupons.co.il, an Israeli daily-deals and social-commerce website, under #OpIsrael Claimed impact: • Website reported as unavailable • “Bad Gateway” error observed • Check-host report cited as evidence ⚠️ The group’s attribution and claim of responsibility have not been independently verified. The reported outage may have other causes. #CyberSecurity #DDoS #Israel #ThreatIntel #OSINT
42
‼️CYBER THREAT ALERT — US AUTOMOTIVE PARTS COMPANY 🇺🇸 A threat actor NTDS. is advertising access to an unnamed U.S.-based organization in the automotive parts & engineering sector. Claimed access/details: • Revenue: $30M+ • SonicWall VPN access • Domain-user privileges + local administrator access • Claimed access to 136 hosts • Auction starting at $1,000 ⚠️ The access claim, organization identity, revenue figures, host count and level of access have not been independently verified. #CyberSecurity #ThreatIntel #InitialAccess #SonicWall #Automotive #OSINT
57
‼️DATABASE BREACH ALERT — UNIVERSIDAD TECNOLÓGICA DE ESCUINAPA 🇲🇽 A threat actor Belial01bit claims to have compromised the database of Universidad Tecnológica de Escuinapa, Sinaloa, Mexico. Claimed data: • Records of ~1,140 students • Birth certificates • CURP-related information • Proof of address • High-school certificates ⚠️ The breach claim, dataset size, samples and authenticity of the alleged records have not been independently verified. Sensitive personal documents and the threat actor’s channel have been omitted. #CyberSecurity #DataBreach #DataLeak #Mexico #Education #ThreatIntel
57
‼️DATABASE BREACH ALERT — ORAIT.IT 🇮🇹 A threat actor Sophia01 claims to have compromised orait.it, an Italy-based website, and is offering the database for free. Claimed exposed data includes: • Customer IDs and account details • Names, emails & dates of birth • Phone/mobile numbers • Addresses, cities & postal codes • Company, VAT/SIRET/DNI-related fields • IP registration and account metadata • Password hashes and security-related fields ⚠️ The breach claim, dataset contents and authenticity of the exposed records have not been independently verified. Passwords, personal records and threat-actor access/session details are omitted to avoid amplifying sensitive information. #CyberSecurity #DataBreach #DataLeak #Italy #ThreatIntel #OSINT
58
‼️MALWARE / CYBERCRIME TOOLING ALERT — CHAMPO A threat actor NOW is advertising CHAMPO, a multi-chain cryptocurrency wallet-poisoning and automated transaction platform offered as source code for $2,000. Claimed capabilities: • Scans Ethereum, BSC, Polygon, Solana & Bitcoin • Identifies high-value wallets and transaction patterns • Generates matching/vanity wallet addresses • Filters bots, exchanges, contracts and inactive wallets • Automates wallet funding and transactions • Mass mode: 5–1,000 transactions per target • Turbo mode: claimed 30–40 transactions/minute • Stealth features including randomized delays/gas settings • Supports ERC-20 assets including USDT/USDC/DAI • SQLite-based wallet/transaction intelligence Technical stack: TypeScript/Node.js, ethers.js, @solana/web3.js, bitcoinjs-lib and SQLite3. The seller claims live testing identified 11,655 addresses from 100 scanned blocks and targeted wallets holding $1.2M+ in assets, with 27 transactions reportedly executed. These performance and transaction claims have not been independently verified. 💰 Price: $2,000 📦 Availability: Claimed 20 copies 📅 Posted: September 27, 2026 ⚠️ CHAMPO is explicitly marketed for wallet-poisoning and automated blockchain operations. The advertised capabilities, performance metrics and claimed successful transactions have not been independently verified. Source code, installation commands and operational details are not reproduced to avoid facilitating financial abuse. #CyberSecurity #CryptoSecurity #Blockchain #WalletPoisoning #CyberCrime #ThreatIntel #OSINT
71
‼️DATABASE LEAK ALERT — E-OFFICE SUMEDANG 🇮🇩 Threat actor LIVOR claims to have leaked data allegedly associated with an E-Office village/go.id system in Sumedang, Indonesia. Claimed exposed data: • 35 UMKM records • 1,474 PJS participation records • 1,500 Ritulahu submission records • Data reportedly packaged as a downloadable archive 📅 Posted: September 27, 2026 ⚠️ The alleged compromise, record counts, source and authenticity of the leaked data have not been independently verified. The download link and any potentially sensitive personal information are omitted to avoid amplifying exposed data. #CyberSecurity #DataBreach #DataLeak #Indonesia #Sumedang #GovernmentSecurity #ThreatIntel #OSINT
174
‼️DATABASE BREACH ALERT — Adobe for Business 🇺🇸 Threat actor Mr_Raccoonn claims to have obtained 832 GB of data allegedly associated with business.adobe.com and organizations using Adobe’s enterprise platforms. Claimed dataset: • 13 million records • ~3 million support tickets • Data involving ~15,000 employees • Internal documents and business records • Customer/CRM information • Magento-related datasets • Corporate emails & phone numbers • Support cases and troubleshooting records • Employee accounts and access-rights information • Creative assets, PDFs, contracts & document archives • HackerOne bug-bounty report archive, allegedly containing security findings and technical information The post includes samples allegedly associated with multiple organizations and enterprise customers. 📦 Claimed size: 832 GB 📅 Posted: September 27, 2026 ⚠️ The alleged breach, 13-million-record count, 832 GB size, affected organizations and authenticity of the samples have not been independently verified. Sensitive personal data, credentials, security findings and threat-actor contact details are omitted to avoid amplifying potentially exposed information. #CyberSecurity #DataBreach #DataLeak #Adobe #EnterpriseSecurity #CRM #BugBounty #ThreatIntel #OSINT
152
‼️DATABASE LEAK ALERT — AGEFIPH 🇫🇷 Threat actor Syrv4x claims to have released a database allegedly linked to AGEFIPH (agefiph.fr), the French organization supporting employment access for people with disabilities. Claimed dataset: • 3,736 records • 4 MB in size • Names, dates of birth & contact details • Addresses and postal/city information • Employment status & contract details • Education/training and qualification levels • Employer/SIRET/URSSAF information • Disability-related information and beneficiary status • Public-policy and social-benefit information • Working hours, occupation & socioeconomic category 📅 Posted: September 27, 2026 💰 Claimed: Shared for free ⚠️ The alleged breach, record count, source and authenticity of the database have not been independently verified. Sensitive personal and disability-related information from the sample is not reproduced to avoid amplifying highly sensitive data. #CyberSecurity #DataBreach #DataLeak #France #AGEFIPH #PII #Privacy #ThreatIntel #OSINT
142
‼️MALWARE ALERT – Mirai 🦠 Malware: Mirai 🔑 SHA-256: 0ac11d95a309589c35f6838e1e732e27ba0a27ecd46e33f6fd77ab8d3623083a 🌐 Source URL: hxxp://45.74.3.24/bot.aarch64 🇺🇸 Serving IP: 45.74.3.24 (United States) ⚠️ Detection: 13/93 security vendors flagged the URL as malicious 📡 Status: HTTP 200 🛡️ Do not access or execute the payload. Organizations should block the associated URL/IP and monitor systems for related indicators. #CyberSecurity #Mirai #Malware #IoT #ThreatIntel #IOC #InfoSec
167
‼️CRITICAL ANDROID SECURITY ALERT — OnePlus 15 A security research write-up published September 24, 2026 details a two-bug privilege-escalation chain that can reportedly take an ordinary Android app from untrusted_app → UID 0/root, without special permissions. Technical details: • Device tested: OnePlus 15 (CPH2747) • OS: OxygenOS 16 • Test firmware: 16.0.3.503(EX01) • Kernel: 6.12.23 • Patch level: 2026-02-01 • PoC built as a normal APK targeting API 35, requiring no special permissions. Bug #1 — AtlasService command injection • OxygenOS AtlasService runs as root and exposes Binder functionality. • setEvent() reportedly lacks an adequate caller permission check. • A multimedia audio debug event reaches audioDumpInfo. • Attacker-controlled data is subsequently passed into a shell command through system(). • This can reportedly provide command execution in the dumpstate SELinux domain with UID 0. Bug #2 — OplusLogCore HAL shell execution • Vendor HAL: vendor.oplus.hardware.olc2.IOplusLogCore/default • doShell() reportedly executes shell commands when the caller UID is 0. • A related blocking variant also exists. • The resulting process transitions into vendor_qti_init_shell, which the researcher reports has an extremely broad Linux capability set. 🔗 Attack chain: untrusted_app → AtlasService → audioDumpInfo → UID 0 / dumpstate → OLC2 Binder HAL → vendor_qti_init_shell The researcher reports that the same unmodified PoC APK also worked on the OnePlus 15, after development/testing on a OnePlus 12 Pro (CPH2581). OnePlus reportedly confirmed that the underlying issues affect multiple OnePlus/OPPO products and software versions, although a complete affected-device list was not provided. 🛡️ Mitigation: The researcher reports that the OnePlus 15 issues are fixed in OxygenOS 16.0.10.500(EX01). OnePlus community release information confirms rollout of that version for the OnePlus 15. Users should install the latest security/software update available for their device. ⚠️ The technical details above summarize the published research; exploit payloads and reproduction commands are intentionally omitted. blog.nns.ee/2026/09/24/onepl… #CyberSecurity #Android #OnePlus #OxygenOS #PrivilegeEscalation #RootExploit #MobileSecurity #InfoSec
207
‼️FAKE GOVERNMENT WEBSITE ALERT — Saudi Arabia 🇸🇦 Target: Balady / Saudi Municipal Services Type: Government Impersonation / Phishing Suspicious URL: hxxps://www[.]services-balady-gov-sa[.]cc/
1
2
494
‼️FAKE WEBSITE ALERT - Pakistan 🇵🇰 Target: NADRA Type: Government & Payment Brand Impersonation / Phishing Suspicious URL: hxxps://visagovpknadravisa[.]xevantor[.]online/
230
‼️MALWARE ALERT 🦠 Malware: Mirai 🔑 SHA-256: 9b4ecd66ff86da2b6d10ce18f40a81e7443102fa24ebc7d49fecf49b92415061 🌐 Source URL: hxxp://193.111.117.135/bins/mirai.sh4 🇵🇱 Serving IP: 193.111.117.135 (Poland) ⚠️ Detection: 8/92 security vendors flagged the URL as malicious 📡 Status: HTTP 200 🛡️ Do not access or execute the payload. Organizations should block the associated URL/IP and monitor exposed systems for related indicators. #CyberSecurity #Mirai #Malware #IoT #ThreatIntel #IOC #InfoSec
1
245
Another Detected: 🦠 Malware: Mirai 🔑 SHA-256: 9b4ecd66ff86da2b6d10ce18f40a81e7443102fa24ebc7d49fecf49b92415061 🌐 Source URL: hxxp://193.111.117.135/bins/mirai.m68k 🇵🇱 Serving IP: 193.111.117.135 (Poland) ⚠️ Detection: 8/92 security vendors flagged the URL as malicious 📡 Status: HTTP 200
1
147
‼️MALWARE ALERT – Malicious EXE File 🦠 File: file_018d7b156998810c.exe 🔑 SHA-256: 1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 🌐 Source URL: hxxp://91.92.242.236/files-129312398/files/file_018d7b156998810c.exe 🇳🇱 Serving IP: 91.92.242.236 (Netherlands) ⚠️ Detection: 22/93 security vendors flagged the URL as malicious 📡 Status: HTTP 200 🛡️ Do not download or execute the file. Block the URL/IP and monitor endpoints for related indicators. #CyberSecurity #Malware #ThreatIntel #IOC #Infosec #CyberAwareness
193
‼️WEBSITE DEFACEMENT ALERT 🇱🇾 Libya | Higher Education Organization: Elmergib University Affected URL: hxxps://mfe.elmergib.edu.ly/16ab8dacfebb95_cox.txt
204
‼️CYBER ATTACK ALERT — Ukraine 🇺🇦 The pro-Russian threat actor group NoName057(16) claims to have conducted attacks against multiple Ukrainian organizations under #OpUkraine. Claimed targets include: • TOR security agency • Vertol — aviation services company • Kryvyi Rih Thermal Power Plant — heat/energy infrastructure The actor appears to claim website/service disruption, with Check-Host reports cited as purported evidence. ⚠️ The attacks, duration, operational impact and attribution have not been independently verified. The cited check-report links are omitted. #CyberSecurity #DDoS #Ukraine #CriticalInfrastructure #ThreatIntel #OSINT #OpUkraine
195