Dark Web Informer's banner
Dark Web Informer's profile picture

Dark Web Informer

@DarkWebInformer214,668 subscribers

One guy. Global cybercrime. Tracked so you don't have to. Ransomware, data breaches, dark web activity, darknet markets, IOCs & emerging threats. Stay informed!

Shorts

‼️Copy Fail (CVE-2026-31431) is a Linux privilege escalation bug that lets any local user get root using a 732-byte Python script, and itworks on basically every major Linux distro shipped since 2017. Website: Write-up: GitHub: It's a logic flaw in the kernel's crypto code (authencesn via AF_ALG and splice()) that allows a small write into the page cache, which can be used to tamper with a setuid binary like /usr/bin/su. Think how bad this is going to be for shared environments like Kubernetes, CI runners, and cloud sandboxes, where it enables container escape and tenant-to-host compromise. Found by Theori's Xint Code scanner, patched in the mainline kernel, and publicly disclosed on April 29, 2026; if you can't patch right away, the recommended workaround is to disable the algif_aead module.

‼️Copy Fail (CVE-2026-31431) is a Linux privilege escalation bug that lets any local user get root using a 732-byte Python script, and itworks on basically every major Linux distro shipped since 2017. Website: Write-up: GitHub: It's a logic flaw in the kernel's crypto code (authencesn via AF_ALG and splice()) that allows a small write into the page cache, which can be used to tamper with a setuid binary like /usr/bin/su. Think how bad this is going to be for shared environments like Kubernetes, CI runners, and cloud sandboxes, where it enables container escape and tenant-to-host compromise. Found by Theori's Xint Code scanner, patched in the mainline kernel, and publicly disclosed on April 29, 2026; if you can't patch right away, the recommended workaround is to disable the algif_aead module.

402,241 views

Must be nice to have that dirty money. I prefer my activity tracker watch tbh. 🤷‍♀️

Must be nice to have that dirty money. I prefer my activity tracker watch tbh. 🤷‍♀️

55,864 views

‼️ A threat actor is selling a NFCRipper tool which allegedly enables NFC relay, card capture, session cloning, and POS/ATM CVM bypass functionalities. They claim it can capture, replay, and manage card data through a centralized web panel for research and testing purposes. nfcripper[.]su

‼️ A threat actor is selling a NFCRipper tool which allegedly enables NFC relay, card capture, session cloning, and POS/ATM CVM bypass functionalities. They claim it can capture, replay, and manage card data through a centralized web panel for research and testing purposes. nfcripper[.]su

43,506 views

A XSS vulnerability took control of BreachForums about an hour and a half ago. It has since been fixed. Credit: Nicotine

A XSS vulnerability took control of BreachForums about an hour and a half ago. It has since been fixed. Credit: Nicotine

48,922 views

Lol, truth!

Lol, truth!

35,343 views

Shannon: Fully autonomous AI hacker to find actual exploits in your web apps. Shannon has achieved a 96.15% success rate on the hint-free, source-aware XBOW Benchmark. GitHub: Features: ▪️Fully Autonomous Operation ▪️Pentester-Grade Reports with Reproducible Exploits ▪️Critical OWASP Vulnerability Coverage ▪️Code-Aware Dynamic Testing ▪️Powered by Integrated Security Tools ▪️Parallel Processing for Faster Results

Shannon: Fully autonomous AI hacker to find actual exploits in your web apps. Shannon has achieved a 96.15% success rate on the hint-free, source-aware XBOW Benchmark. GitHub: Features: ▪️Fully Autonomous Operation ▪️Pentester-Grade Reports with Reproducible Exploits ▪️Critical OWASP Vulnerability Coverage ▪️Code-Aware Dynamic Testing ▪️Powered by Integrated Security Tools ▪️Parallel Processing for Faster Results

48,656 views

DDoS attack... wait for it.

DDoS attack... wait for it.

100,397 views

🚨Darcula Phishing-as-a-Service (PhaaS) Platform Integrates Generative AI, Lowering the Barrier for Threat Actors

🚨Darcula Phishing-as-a-Service (PhaaS) Platform Integrates Generative AI, Lowering the Barrier for Threat Actors

61,932 views

‼️ .cz BreachForums was briefly defaced by what looks like a XSS vuln in XenForo. XenForo is a popular forum platform that I have seen used by a lot of actors, most of which I have identified in my Threat-Surface repo on GitHub. Credit to antisocial for sending the video.

‼️ .cz BreachForums was briefly defaced by what looks like a XSS vuln in XenForo. XenForo is a popular forum platform that I have seen used by a lot of actors, most of which I have identified in my Threat-Surface repo on GitHub. Credit to antisocial for sending the video.

17,158 views

Wait for it...🤣

Wait for it...🤣

44,100 views

The proper way to apply thermal paste

The proper way to apply thermal paste

15,756 views

You probably know a co-worker who does this. 😂

You probably know a co-worker who does this. 😂

19,791 views

🚨PoC for CVE-2024-51378; CyberPanel Command Injection Vulnerability

🚨PoC for CVE-2024-51378; CyberPanel Command Injection Vulnerability

14,834 views

Videos

DarkWebInformer's profile picture

⚠️ A defense evasion tool called ExEngine is being sold as a service, marketed as an AV/EDR killer that disables mainstream consumer security software including Windows Defender, Malwarebytes, Bitdefender, and Avast. The tool combines AV termination with a Ring-3 rootkit, UAC bypass, and decoy payload delivery to support stealthy initial access operations. ⠀ ‣ Threat Actor: ryewx1 ‣ Category: Defense Evasion Tool / Killer ‣ Offering: ExEngine AV/EDR Killer ‣ Industry: Malware Tooling ⠀ The seller claims ExEngine actively terminates security software rather than only obfuscating payloads, granting attackers a longer window of undetected operation. The tool supports Windows 10 and 11 builds and is sold per-build at $150 to $250. ⠀ Advertised capabilities: ⠀ ▪️ AV/EDR termination with primary and fallback techniques ▪️ UAC bypass with automatic privilege escalation ▪️ Ring-3 rootkit functionality to hide files, processes, registry keys, and network connections ▪️ Discord webhook logging for victim machine info and execution status ▪️ Secondary decoy payload (game/document/installer) to keep targets unaware ▪️ Persistence across reboots and logouts ▪️ Anti-VM and anti-debug detection with fake error message exit ▪️ Universal Windows 10/11 support, all payload types ⠀ Risk to defenders: ⠀ ▪️ Active termination of consumer AV products including Windows Defender means traditional endpoint protections cannot be relied on once ExEngine executes successfully ▪️ Decoy payload pattern is designed to delay user-driven incident reporting, lengthening attacker dwell time ▪️ Ring-3 rootkit hiding of files, processes, and network connections complicates incident response triage on compromised hosts ▪️ Discord webhook telemetry indicates the operator is targeting consumer and SMB victims at scale rather than running individual targeted campaigns ▪️ Sold per-build at low cost ($150 to $250), making it accessible to low-skill operators who can pair it with commodity stealers, RATs, or loaders

Dark Web Informer

22,768 views • 1 month ago