โ—๏ธ๐Ÿ‡ซ๐Ÿ‡ท Data from "Choisir le service public," the French government's official public sector job portal, is allegedly being sold. The listing claims to contain records of 377,418 job seekers, with proof screenshots showing candidate profiles including personal details, emails, phone numbers, and application history. image
OSINT-D2 ingests usernames and/or emails, aggregates public evidence from multiple OSINT sources, and enriches the dataset with targeted scrapers. GitHub:
โ€ผ๏ธ CISA has added 4 vulnerabilities to the KEV Catalog CVE-2025-40551: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability CVE-2019-19006: Sangoma FreePBX Improper Authentication Vulnerability CVE-2025-64328: Sangoma FreePBX OS Command Injection Vulnerability CVE-2021-39935: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability
โ€ผ๏ธ๐Ÿ‡บ๐Ÿ‡ธ USA - Bank Firewall & Network Admin Panel access listed for sale ($300) ๐Ÿ‡บ๐Ÿ‡ธ USA - College Software Suite (SaaS) Firewall & Network Admin Panel access listed for sale ($200) ๐ŸŒ Asia - Largest Real Estate Developer Firewall & Network Admin Panel access listed for sale ($300) ๐Ÿ‡บ๐Ÿ‡ฆ Ukraine - Accounting & Finance Company Firewall & Network Admin Panel access listed for sale ($200) ๐Ÿ‡บ๐Ÿ‡ธ USA - Electronic Device Manufacturer Firewall & Network Admin Panel access listed for sale ($200) ๐Ÿ‡จ๐Ÿ‡ณ China - Luxury Jewelry Company Firewall & Network Admin Panel access listed for sale ($200)
โ—๏ธ๐Ÿ‡จ๐Ÿ‡ณ Firewall and network admin panel access to a Chinese finance organization is being sold for $300. The listing claims root RCE plus shell access on a Linux-based firewall device. The seller, a known initial access broker, is accepting contact through Session. image
โ€ผ๏ธ๐Ÿ‡บ๐Ÿ‡ธ IT access to a U.S. company with $20M+ in revenue is being auctioned, with proof showing a remote monitoring and management (RMM) panel connected to multiple endpoints. The listing claims access to over 8,040 networks with daily updates. The auction starts at $2,000 with a blitz price of $3,500. Note: The green bars are not done by me. image
โ€ผ๏ธ๐Ÿ‡ฎ๐Ÿ‡ท A data set from the Islamic Azad University in Iran has allegedly been leaked, exposing multiple tables of sensitive records. The data includes user credentials with national IDs and passwords, student personal information, faculty payment records, and administrative department structures. The leak also contains detailed student registration data with extensive academic and personal fields.
โ€ผ๏ธ Reuters reports that French prosecutors raided Xโ€™s Paris offices on Tuesday as part of a criminal investigation originally opened in January 2025 over alleged algorithm manipulation. The probe has since expanded to include charges of complicity in distributing child sexual abuse material, generating sexually explicit deepfakes via the Grok AI chatbot, and Holocaust denial, which is a crime under French law. The raid was carried out by the Paris prosecutorโ€™s cybercrime unit with support from Europol and French police. Voluntary interview summonses for April 20 have been issued to both Elon Musk and former X CEO Linda Yaccarino. X has previously denied wrongdoing and characterized the French investigation as politically motivated.
โ—๏ธ๐Ÿ‡ฒ๐Ÿ‡น Gozo Channel, the ferry operator connecting Malta's islands, confirmed it was targeted in a cyberattack on Tuesday. The company said the incident impacted certain internal IT systems but was quickly contained thanks to existing infrastructure safeguards and contingency protocols. Ferry services were not disrupted. The company emphasized that all vessels continue to run on their normal schedule and that operations remain fully unaffected. Technical teams are currently working to restore the administrative systems that were impacted, and the company plans to bring in specialist cybersecurity forensic experts to support the investigation and recovery effort. image
โ—๏ธ๐Ÿ‡ต๐Ÿ‡ฐ Internal documents from the Pakistan Institute of Education (PIE) have allegedly been leaked, including strategic planning documents, budget breakdowns, and organizational charts. The threat actor claims the leak focuses on institutional operations and priorities rather than personal data, and has teased additional leaks to follow. image