We work in the dark to bring clarity to the light.

Dark Web
🧰 10 GITHUB REPOSITORIES WORTH BOOKMARKING FOR CYBERSECURITY RESEARCH A strong security toolkit is not just about scanners and exploits. Sometimes the most useful resource is a well-maintained repository with payload references, wordlists, public reports, OSINT resources, training labs, and field-tested notes. Here are 10 worth keeping close: * swisskyrepo/PayloadsAllTheThings — payload encyclopedia and attack references * danielmiessler/SecLists — huge collection of wordlists and test data * HackTricks-wiki/hacktricks — practical pentesting and privilege-escalation field guide * jivoi/awesome-osint — curated OSINT tools and resources * edoardottt/awesome-hacker-search-engines — search engines useful for security research * reddelexc/hackerone-reports — collection of public HackerOne reports * edoardottt/awesome-hacking — broad hacking and security resource list * Orange-Cyberdefense/arsenal — security tools and research inventory * OWASP/Top10 — OWASP Top 10 project resources * OWASP/WebGoat — deliberately insecure application for hands-on security training Why these matter: * Better payload and testing references * Faster reconnaissance and enumeration * Stronger OSINT workflows * Real-world vulnerability writeups * Practical labs for continuous learning * Easier access to trusted community knowledge Analyst Note: The best repository is not always the one with the most stars. What matters is whether it is maintained, relevant, and useful to your workflow. Bookmark the good ones. Revisit them often. And always validate techniques in a legal, controlled environment. #DDW #CyberSecurity #GitHub #OSINT #Pentesting #RedTeam #SecurityResearch #OWASP #ThreatIntelligence
2
7
31
9,975
🧊 SAMSUNG PUSHED A TEST FIRMWARE TO SMART FRIDGES. THE ICE CREAM DID NOT SURVIVE 🍦💧 On Sep 22, Samsung mistakenly shipped internal test software via SmartThings to some Bespoke AI 4-door fridges in South Korea (mostly 2024+ models). Affected units lost power or cooling, screens froze mid-update, and the app showed them offline. SBS reports hundreds of cases. Samsung halted the update, sent technicians out over Chuseok and is covering repairs. Spoiled-food compensation is still under review. Patch management: now a fridge problem. arstechnica.com/gadgets/2026… #Samsung #IoT #SmartHome #FirmwareFail #CyberSecurity #DDW
3
2,992
🚨 THE COPILOT+ PC BRAND IS DEAD — MICROSOFT AND PC MAKERS QUIETLY DROP THE WINDOWS 11 AI PC LABEL Microsoft and its hardware partners are quietly retiring the "Copilot+ PC" marketing name, Windows Central reports. The features and the hardware bar are staying. • Surface CVP Brett Ostrum told Windows Central that the new Surface Pro 12-inch and Surface Laptop 13-inch (Snapdragon X2, announced Sep 23) "are not called Copilot+ PCs", but still meet all the Copilot+ requirements • Qualcomm SVP Kedar Kondap said the same NPU experiences will continue, "probably without" the Copilot+ PC terminology • None of Microsoft's 2026 Surface PCs carry the Copilot+ name, and more OEMs have dropped it from product names and marketing • The Copilot+ spec baseline (e.g. 45 TOPS NPU) still exists; only the label is going away • Other outlets corroborated the shift on Sep 25, noting Microsoft's Copilot+ landing page now redirects to a "performance PCs" page ⚠️ Analyst Note: This is a rebrand, not a rollback. Copilot+ features and hardware requirements remain in place. The label was badly damaged by Recall's 2024 launch, when security researchers showed the screenshot-everything feature stored user activity insecurely, which forced Microsoft to delay it. Dropping the name does not change what is on the device: organizations should still inventory NPU-equipped Windows 11 PCs and govern Recall and other on-device AI features by policy, whatever the machine is called. Source (Windows Central, Zac Bowden, Sep 24 2026): windowscentral.com/microsoft… #Microsoft #Windows11 #CopilotPlus #Recall #Privacy #CyberSecurity #DDW
8
2,960
🚨 UPDATE: BITGET REVISES WALLET INCIDENT LOSS TO ~$387.5M — ATTACK PATH FIXED, RECOVERY BOUNTY LAUNCHED Update to our earlier ~$351.6M report: Bitget has published a follow-up on its September 24 hot/warm wallet incident. This is a revised figure for the same incident, not a second breach. • Latest on-chain tracing: ~$387.5M in assets moved to attacker-controlled addresses, up from the initial ~$351.6M estimate • Bitget says the increase comes from a fuller count of Zcash and TRON transfers made during the incident, not from new unauthorized transfers • Attack path identified; underlying vulnerability "identified and remediated"; incident contained, with no further unauthorized transfers possible • Mandiant and SlowMist are assisting the investigation • Recovery Bounty: 5% of funds frozen, and 5% of funds recovered, go to whoever's voluntary efforts directly led to it (court-order/law-enforcement actions excluded; Bitget makes final eligibility calls) • Some affected funds already frozen with industry partners; Bybit's LazarusBounty named as a core channel for the effort • Live fund-tracing dashboard and attacker-address API published • Withdrawal status/timing to be announced by September 26, 4:00 AM UTC (12:00 AM ET) ⚠️ Analyst Note: The ~$36M jump is an accounting revision, not fresh theft. Bitget's notice does not attribute the attack to North Korea / Lazarus. That link remains unconfirmed, even though the bounty runs through Bybit's LazarusBounty platform. Figures may change as more transactions are traced. Source (Bitget official update): bitget.com/support/articles/… #Bitget #CryptoExchange #CyberSecurity #ThreatIntel #DDW nitter.net/DailyDarkWeb/status/21…
🚨 BITGET CONFIRMS ~$351.6M HOT/WARM WALLET INCIDENT (SEP 24) Crypto exchange Bitget published an official Security Notice stating that at 18:31 UTC on September 24, 2026 its security systems detected unauthorized transfers from some hot wallets. What Bitget confirmed: • Estimated funds affected: approximately $351.6 million • Breach contained to portions of the hot and warm wallet layers • Cold wallets remain fully secure (three-tier wallet architecture) • Loss covered by Bitget’s User Protection Fund (fund >$464 million) • Withdrawals temporarily suspended pending security review • Deposits and trading remain operational • Law enforcement and on-chain security firms notified ⚠️ Analyst Note: This is an official Bitget disclosure. Prefer the primary Security Notice over secondary media. Bitget’s notice explicitly says it will not speculate on the attack vector until the investigation is complete. Separate preliminary media / CEO remarks have discussed possible North Korea / Lazarus links (including on-chain XRP flow commentary) — treat those as unconfirmed attribution unless Bitget or a government agency formally confirms. Do not frame Lazarus (or any actor) as proven solely from secondary reporting. Official Bitget Security Notice: bitget.com/support/articles/… #DDW #DarkWeb #Bitget #Crypto #ExchangeSecurity #ThreatIntelligence #CyberSecurity
2
3,700
🚨 META ADDS STRONGER MUSE SAFETY WARNING AFTER NEW AI AGENT VULNERABILITY REPORT Meta Platforms is adding a clearer safety warning within its Muse AI agent after a security researcher found a vulnerability that could let an attacker access a user's sensitive personal information, Reuters reports, citing The Information. • The flaw was reported by an outside researcher through Meta's bug bounty program and had not previously been disclosed • Per an internal Meta incident report reviewed by The Information, it could have allowed an attacker to access a user's dedicated virtual machine — an individualized cloud-based account containing data including emails and files • Meta initially classified it as "SEV-2", its third-highest severity level on a five-point scale • Meta's reported response is a strengthened in-app warning, not a patch — the report does not say whether the underlying flaw has been fixed • Meta did not immediately respond to Reuters' request for comment • Muse, launched earlier this month, carries out tasks such as shopping, travel booking, emailing and payments on users' behalf ⚠️ Analyst Note: This follows the Muse macOS zero-day we covered on Sep 22 — Patrick Wardle's not-a-mused PoC, which abused an undocumented dictation-endpoint setting and required existing local code execution. The newly reported bug-bounty flaw concerns access to users' cloud virtual machines; the report does not link it to Wardle's bug, so treat them as separate issues. Two security problems in Muse's first month underline the risk of AI agents holding broad access to email, files and payments. Source (Reuters, citing The Information, 25 Sep 2026): tech.yahoo.com/ai/meta-ai/ar… Earlier zero-day PoC (Patrick Wardle): github.com/pwardle/not-a-mus… Our Sep 22 coverage: nitter.net/DailyDarkWeb/status/21… #DDW #Meta #Muse #AISecurity #AgenticAI #ThreatIntel #CyberSecurity #DarkWeb
🚨 META MUSE ZERO-DAY LETS LOCAL MALWARE HIJACK THE AI AGENT’S TRUST AND ACCESS macOS security researcher Patrick Wardle has released a public PoC for not-a-mused, a local zero-day affecting Meta’s Muse AI assistant for macOS. • Muse exposes an undocumented setting, endo_voyager_dictation_endpoint • An unprivileged local process can modify the endpoint without administrator privileges • Redirecting it can send dictated prompts to an attacker-controlled server • Wardle’s PoC shows potential capture of prompts, prompt injection, theft of Muse authentication material and abuse of access already granted to the agent • The attack requires existing local code execution — this is NOT a remote zero-click compromise • The security impact is amplified because an AI agent may hold substantially broader permissions than the malware that initially lands on the Mac • The researcher’s PoC implements a subset of more than 50 commands exposed by Muse • No confirmed in-the-wild exploitation has been identified • No public CVE or confirmed patched version was identified at the time of disclosure ⚠️ Analyst Note: This is a strong example of AI agents becoming privilege amplifiers. Traditional macOS controls may prevent ordinary malware from directly accessing sensitive resources, but if that malware can hijack a highly privileged agent already trusted by the user, the agent itself can become the attacker’s bridge into files, services and other authorized capabilities. Original researcher PoC: github.com/pwardle/not-a-mus… #Meta #Muse #AISecurity #AgenticAI #macOS #ZeroDay #ThreatIntel #CyberSecurity #DDW #DarkWeb
2
1
6
3,767
🚨 COMPROMISED GITHUB ACTIONS CAME BACK ONLINE — MINI SHAI-HULUD TAGS STILL LIVE Socket researchers report that two popular actions-cool GitHub Actions — issues-helper and maintain-one-comment — were re-enabled on September 16, 2026 with malicious release tags still intact from the May Mini Shai-Hulud campaign. • Both repos were originally compromised May 18 and disabled by GitHub security on May 19 • On re-enablement, mutable tags such as @v2.2.1 still resolved to the malicious payload • Any workflow referencing either action by tag (not a pinned commit SHA) resumed downloading and running the malware • Payload installs Bun, harvests CI/CD secrets from the runner, and exfiltrates them • GitHub’s dependency graph lists ~15,000 repositories depending on issues-helper alone • Socket update Sep 25: both repositories have been disabled on GitHub again — tag-based workflows now fail at job setup instead of executing the payload ⚠️ Analyst Note: This is Socket primary research (published Sep 24, updated Sep 25), not a dark-web claim. The material new fact is the Sep 16 re-enablement with unclean tags, plus today’s second disable. Treat prior May compromise details as background. Workflows pinned to a known-clean pre–May 18 commit SHA were not hit by the tag move. Primary (Socket, 24 Sep 2026; update 25 Sep 2026): socket.dev/blog/mini-shai-hu… #DDW #GitHubActions #SupplyChain #ShaiHulud #ThreatIntelligence #CyberSecurity #DarkWeb
2
3,922
🇵🇪 🚨 OSIPTEL PERU ~50K RECORDS ALLEGEDLY EXPOSED VIA IDOR A threat actor on an underground forum claims to have obtained personal data allegedly associated with Peruvian telecom regulator OSIPTEL (Organismo Supervisor de Inversión Privada en Telecomunicaciones). The actor claims the dataset includes: * About 50,000 alleged personal records (scraping claimed ongoing) * Field categories such as phone numbers, national ID (DNI) numbers, and full names (categories only — no sample values reproduced) * Alleged access via an IDOR in an administrative login interface The claim has not been independently verified. ⚠️ Analyst Note: Regulator identity datasets are high-signal if authentic, but IDOR claims are easy to exaggerate from limited samples. Freshness, completeness, and whether access was broadly exploitable remain unverified. Treat as an unverified threat-actor claim — NOT confirmation of an OSIPTEL systems compromise. No victim record samples are shown. #DDW #DarkWeb #Peru #Government #Telecom #PII #DataLeak #ThreatIntelligence #CyberSecurity
3
9
4,303
🇰🇷 🚨 HYUN LAW ~247GB EMAIL DATABASE ALLEGEDLY LEAKED A threat actor on an underground forum claims to have published an email database allegedly associated with South Korean law firm Hyun Law. The actor claims the dataset includes: * About 247GB alleged email database * Law-firm email archives that may contain privileged client communications if authentic (categories only) The claim has not been independently verified. ⚠️ Analyst Note: Email-archive size claims are often compressed mailbox stores and may include attachments rather than unique message counts. Privileged-content risk is high if authentic. Treat as an unverified threat-actor claim — NOT confirmation of a confirmed Hyun Law breach. No message samples or client records are shown. #DDW #DarkWeb #SouthKorea #Legal #DataLeak #ThreatIntelligence #CyberSecurity
1
6
4,031
🚨 $351.6M BITGET HACK — NORTH KOREAN ACTORS SUSPECTED Bitget has confirmed that approximately $351.6 million was stolen after attackers compromised a critical backend system supporting its wallet infrastructure. According to Bitget, the attackers were able to spoof transaction data and trigger the platform’s authorization process, resulting in unauthorized transfers from a portion of its hot and warm wallets. The company says its cold wallets were not affected. Bitget has temporarily suspended withdrawals while the incident is investigated. Deposits and trading remain operational, and the company says customer balances are accurate and the losses are covered by its User Protection Fund. Bitget CEO Gracy Chen said the attack pattern is highly consistent with known North Korean threat actor activity based on IP behavior and on-chain analysis. However, attribution to the Lazarus Group specifically has not yet been publicly confirmed. ⚠️ Analyst Note: The important detail here is the attack path. Bitget says the attackers did not need to steal private keys; instead, they compromised backend wallet infrastructure and manipulated transaction data before the authorization-signing process. That points to a broader crypto-exchange risk: compromising the systems around key management can be just as damaging as compromising the keys themselves. #Bitget #Lazarus #NorthKorea #CryptoHack #CyberSecurity #DarkWeb
1
14
4,743
🇮🇷 🚨 KAYA.IR ~1.14GB FREELANCING PLATFORM DATABASE ALLEGEDLY LEAKED A threat actor on an underground forum claims to have published data allegedly associated with Iranian freelancing platform Kaya.ir. The actor claims the dataset includes: * About 1.14GB / ~1.7 million records across dozens of collections * Claimed user accounts with phones and national ID numbers (categories only) * Claimed financial transaction and bank-account fields (categories only) * Claimed private chats, support tickets, and identity-verification records (categories only) * Claimed authentication material described as bcrypt password hashes (no samples) The claim has not been independently verified. ⚠️ Analyst Note: Freelancing-platform dumps that allege national IDs, bank details, and identity documents are high-sensitivity. Whether passwords are hashes vs reusable secrets, and whether any of this is fresh production data, remain unverified. Treat as an unverified threat-actor claim — NOT confirmation of a Kaya.ir systems compromise. Record samples and identity-document images are not shown. #DDW #DarkWeb #Iran #PII #DataLeak #ThreatIntelligence #CyberSecurity
3
4,035
🇲🇽 🚨 JUMAPA CELAYA ~153K UTILITY RECORDS ALLEGEDLY LEAKED A threat actor on an underground forum claims to have published data allegedly associated with Mexican municipal water utility JUMAPA Celaya (also referred to as SIGAA). The actor claims the dataset includes: * About 153,136 alleged individuals * Claimed names, addresses, emails, and property/account details (categories only) The claim has not been independently verified. ⚠️ Analyst Note: Municipal utility dumps are often billing/customer databases. Freshness and completeness are unverified. Local reporting notes the utility director has disputed a confirmed systems compromise — treat as an unverified threat-actor claim, NOT confirmation of a JUMAPA/SIGAA breach. Record samples are not shown. #DDW #DarkWeb #Mexico #Government #PII #DataLeak #ThreatIntelligence #CyberSecurity
5
14
4,367
🇫🇷 🚨 DOINSPORT ~6.9GB SPORTS-CLUB SaaS DATABASE ALLEGEDLY FOR SALE A threat actor on an underground forum claims to be selling data allegedly associated with French sports club management SaaS Doinsport. The actor claims the dataset includes: * About 6.9GB alleged JSONL export (~2.1M rows) * Claimed ~54.5k users, ~176k clients, ~1.75M bookings, and 863 clubs * Categories such as emails, phones, and club contact details (categories only) The claim has not been independently verified. ⚠️ Analyst Note: SaaS multi-tenant dumps can expose many clubs' members at once. Whether this is a full production export, staging data, or a partial snapshot — and tenant coverage — remain unverified. Treat as an unverified threat-actor claim — NOT confirmation of a Doinsport systems compromise. If authentic and non-public, such material could support identity fraud, phishing, profiling, or further targeting of related clubs — but those outcomes should not be treated as confirmed from a listing alone. #DDW #DarkWeb #France #SaaS #PII #DataLeak #ThreatIntelligence #CyberSecurity
1
6
4,211
🇰🇼 🚨 KUWAIT AIRWAYS ~1.2M CUSTOMER RECORDS ALLEGEDLY LEAKED A threat actor on an underground forum claims to have published data allegedly associated with Kuwait Airways. The actor claims the dataset includes: * About 1.2 million alleged customer / loyalty records * Field categories such as personal contact details, passport identifiers, and loyalty-program attributes (categories only) * Listing associates the material with 2021-origin data The claim has not been independently verified. ⚠️ Analyst Note: OLD NEWS: the listing itself ties the dump to 2021-origin data, so this may be recirculated rather than a fresh 2026 airline compromise. Volume, field completeness, authenticity, and whether any Kuwait Airways systems were involved remain unverified. Treat as an unverified threat-actor claim — NOT confirmation of a new airline systems breach. If authentic and non-public, such material could support identity fraud, phishing, profiling, or further targeting of related travelers — but those outcomes should not be treated as confirmed from a listing alone. #DDW #DarkWeb #Kuwait #Aviation #PII #DataLeak #ThreatIntelligence #CyberSecurity
1
2
6
4,597