💥OpenOSINT turns OSINT into a terminal-based AI agent.
Give it an email, username, domain, IP, or target, and it can chain real tools, pivot on findings, and save a structured report.
GitHub: https://t.co/N2j3qGI9SM
Live Demo: https://t.co/pDrlfGs6nd
New Claude Code Attack Allows Attackers to Take Full Control of Developers’ Systems
Source: https://t.co/l5UcqnR1hW
A proof-of-concept attack that shows how a completely clean-looking GitHub repository can trick AI-powered coding agents like Claude Code into silently opening a reverse shell on a developer’s machine, without a single line of malicious code ever appearing in the repository.
Published on June 25, 2026, the proof-of-concept (PoC) attack targets agentic coding tools such as Claude Code and exploits indirect prompt injection, a technique that embeds malicious instructions in external content the AI agent processes, rather than in direct user input.
The result is catastrophic: a fully interactive shell running under the developer's own user privileges, with access to every secret in the environment, from ANTHROPIC_API_KEY to AWS_SECRET_ACCESS_KEY and GITHUB_TOKEN.
#cybersecuritynews
Anthropic, one of the world's leading AI companies forced to suspend its most advanced models
The Trump administration declared them a security risk and ordered the company to ban foreign access
The AI was able to:
- Find thousands of hidden bugs in every major phone/computer system (Windows, Mac, Linux, phones, web browsers, etc.).
- Many of these bugs were very old, some 16 to 27 years old that human experts had missed for decades
The AI didn’t just find the bugs… it figured out how to actually break in and take control of the computers.
- It found a way to completely take over a secure server like breaking into a locked house and getting full keys to everything
- It escaped the “sandbox” safety walls in web browsers, meaning a bad website could take over your whole computer
- It discovered brand-new ways to hack into systems that no one had seen before.
🇮🇩 Alleged Sale of Indonesian Government Employee Database
A threat actor is advertising what they claim to be an employee database associated with https://t.co/RqEzRYjNAQ, the official website of the Mamuju Regency Government in Indonesia.
According to the post, the dataset allegedly contains employee information including:
* Full names.
* National employee identification numbers (NIK).
* Phone numbers.
* Additional personnel-related records.
The actor has shared a sample of the data and is offering the database for sale through private channels. The authenticity and scope of the dataset have not been independently verified.
Potential risks include:
* Targeted phishing campaigns against government personnel.
* Social engineering attacks using employee identity information.
* Account takeover attempts leveraging personal details.
* Impersonation of government employees.
* Collection of intelligence on government staff and organizational structures.
Analyst Note: Government employee databases are frequently targeted by threat actors because they provide verified identity information that can be leveraged for phishing, credential theft, and long-term intelligence collection against public sector organizations.
#DDW #Intelligence #DarkWeb #Indonesia
🇮🇩 Indonesia - Bank Jatim - A threat actor is advertising an alleged database linked to Bank Jatim's mobile banking platform, claiming access to approximately 5.7 million records.
According to the listing, the exposed data may include:
* Full names
* Indonesian National Identity Numbers (NIK)
* Dates and places of birth
* Gender information
* Education details
* Professional information
* Phone numbers
* Additional banking-related identifiers
The post includes a sample structure allegedly containing customer demographic and personal information. Daily Dark Web has not independently verified the authenticity of the claims or the source of the data.
Analyst Note: Financial-sector datasets are among the most valuable assets traded in cybercriminal communities due to their potential use in identity theft, account takeover attempts, financial fraud, social engineering, and targeted phishing campaigns. If authentic, the exposure of national identity numbers combined with personal information would significantly increase the risk to affected individuals.
#DDW #Intelligence #DarkWeb #Indonesia
🚨 Allianz allegedly targeted in ~500 internal Docker images leak
A threat actor on an underground forum is claiming to release a full dump of roughly 500 Docker images, totaling around 40 GB, allegedly originating from Allianz internal infrastructure.
The actor claims the images contain exposed configuration files, source code, credentials, and private keys.
𝗪𝗵𝗮𝘁'𝘀 𝗮𝗹𝗹𝗲𝗴𝗲𝗱𝗹𝘆 𝗲𝘅𝗽𝗼𝘀𝗲𝗱:
• Exposed configuration files with API keys, DB passwords, and service tokens
• Internal microservices with source code
• Hardcoded credentials for staging and prod environments
• TLS private keys and internal CA certs
𝗗𝗲𝘁𝗮𝗶𝗹𝘀:
𝗧𝗮𝗿𝗴𝗲𝘁: Allianz
𝗦𝗲𝗰𝘁𝗼𝗿: Insurance / Financial Services
𝗔𝗰𝘁𝗼𝗿: hackformetome
𝗖𝗹𝗮𝗶𝗺: Full dump of internal Docker images
𝗘𝘅𝗽𝗼𝘀𝘂𝗿𝗲: ~500 Docker images (~40 GB)
𝗣𝗿𝗶𝗰𝗲: 10 Points
𝗢𝗯𝘀𝗲𝗿𝘃𝗲𝗱: May 28, 2026
💥 Stop guessing what's redacted. Paid subscribers see everything: https://t.co/281Qjc6p2J
A tiny bee just did what chemotherapy couldn't.
Scientists in Australia discovered that honeybee venom can wipe out 100% of aggressive breast cancer cells in under 60 minutes.
And the healthy cells around them? Barely touched.
The breakthrough came from Dr. Ciara Duffy and her team at the Harry Perkins Institute of Medical Research, working alongside the University of Western Australia.
They tested venom drawn from 312 honeybees and bumblebees across Australia, Ireland, and England.
The target: triple-negative breast cancer and HER2-enriched breast cancer. Two of the deadliest, most stubborn forms of the disease.
The weapon: melittin. The same tiny peptide that makes a bee sting burn.
At one specific dose, melittin tore through cancer cell membranes completely within an hour. Within just 20 minutes, it shut down the chemical signals cancer cells need to grow and multiply.
Bumblebee venom, which lacks melittin, did nothing. Zero effect, even at high concentrations.
Scientists then recreated melittin synthetically in the lab and got almost identical results, meaning no bees need to be harmed to develop the therapy.
Published in the peer-reviewed journal npj Precision Oncology, the findings are still early-stage. Human trials haven't happened yet.
But one thing is clear. Nature has been hiding answers in plain sight all along, sometimes inside the smallest creatures on Earth.
Source: Harry Perkins Institute of Medical Research / npj Precision Oncology (Dr. Ciara Duffy et al.)
🚨 فيديو إثبات (PoC) يُظهر استغلال ثغرة جديدة باسم "YellowKey" تتجاوز حماية BitLocker كاملةً على نظام Windows.
🔹 الفيديو يوضّح خطوة بخطوة طريقة الاستغلال:
1- نسخ مجلد FsTx إلى ذاكرة USB
2- الدخول إلى وضع Windows Recovery Environment
3- تنفيذ تركيبة مفاتيح (SHIFT + CTRL) للحصول على Shell بصلاحيات كاملة على القرص المشفّر
دون الحاجة لكلمة مرور أو مفتاح استرداد
Credit: @DarkWebInformer
🇮🇩 A threat actor is advertising an alleged database linked to “Inspektorat Pandeglang Kab” — a regional Indonesian government entity operating under the .go.id government domain structure.
While the listing currently reveals limited technical details publicly, the use of an official Indonesian government domain reference raises concerns regarding potential exposure of administrative or citizen-related information.
At this stage, the authenticity, scope, and origin of the alleged dataset remain unverified.
Potential risks associated with government-sector database exposures may include: • Citizen identity exposure • Internal administrative record leakage • Government employee targeting • Credential abuse • Social engineering campaigns • Public-sector infrastructure reconnaissance
Indonesian government organizations and public institutions should: • Review externally exposed systems and databases • Audit authentication and access-control mechanisms • Monitor for unauthorized scraping activity • Conduct credential rotation for administrative accounts • Review third-party/vendor access paths • Monitor underground forums for additional leaks or resale activity
Government-sector databases remain highly attractive targets for cybercriminals due to the concentration of sensitive citizen, operational, and administrative data.
#DDW #Intelligence #Indonesia #CyberSecurity #DarkWeb #Government #DataBreach
🇮🇩 A dataset allegedly linked to Indonesian election voter records has been shared on underground forums.
The leaked content appears to reference:
• temporary voter registration/correction data
• DPR / DPD / DPRD election-related records
• Indonesian citizen identification details
• and regional voter information documents in PDF format
According to the exposed sample fields, the dataset may contain:
• NIK (Indonesian national identification numbers)
• full names
• birth details
• residential addresses
• RT/RW administrative location information
• and other voter-related demographic records
At this stage, the authenticity, source, and scope of the data remain unverified.
If legitimate, exposure of voter and citizen registry information could create significant risks including:
• identity theft
• targeted phishing and social engineering
• election-related disinformation operations
• citizen profiling
• credential stuffing attacks
• and broader privacy/security concerns affecting public sector systems
Government and election-related datasets remain highly valuable within underground ecosystems due to their use in:
• identity verification bypass attempts
• fraud operations
• SIM swapping/social engineering
• financial fraud
• and influence or intelligence operations
Organizations and agencies should:
• validate whether exposed samples are authentic
• monitor for abuse of national ID information
• review access controls on election and citizen systems
• investigate potential insider or third-party exposure paths
• and monitor underground channels for redistribution activity
This incident also highlights the ongoing targeting of public-sector and election-related infrastructure across multiple regions globally.
#Indonesia #DataLeak #ElectionSecurity #CyberSecurity #ThreatIntelligence #Government #DDW #Intelligence
🇮🇩 An anonymous researcher has disclosed that a publicly accessible webpage belonging to the Magelang City Government’s BPKAD portal allegedly exposed sensitive citizen data related to social aid recipients for several years without authentication.
According to the researcher, the exposed information reportedly included:
• full names
• Indonesian National ID Numbers (NIK)
• full residential addresses
• and social assistance payment details
The researcher claims the exposure was originally referenced in a 2022 VICE Indonesia article discussing broader impacts of personal data leaks in Indonesia, including:
• identity abuse
• fraudulent loan registrations
• and tax-related scams
Notably, the researcher states the same data remained publicly accessible in 2026, suggesting a prolonged exposure window potentially spanning multiple years.
The disclosure also references:
• a proof-of-concept Python scraper demonstrating automation risks
• concerns around large-scale scraping of government websites
• and an alleged follow-up discovery involving more than 125,000 citizen records
At this stage:
• the full scope of exposure remains unverified
• no independent validation of the larger dataset claim has been confirmed
• and the intent appears framed as awareness-focused security research rather than data publication
Long-term exposure of government citizen data can significantly increase risks involving:
• identity theft
• financial fraud
• social engineering
• targeted phishing campaigns
• loan/benefit abuse
• and broader privacy violations
This case highlights a growing issue where:
• publicly exposed government pages
• weak access controls
• legacy CMS deployments
• and unprotected document indexing
can enable mass automated scraping using relatively simple tooling.
Government organizations should:
• audit publicly accessible datasets and archives
• disable unnecessary indexing/exposure of sensitive documents
• implement authentication and access segmentation
• monitor for scraping activity and abnormal requests
• review historical web content exposure
• and establish formal vulnerability disclosure mechanisms for researchers
The incident also demonstrates how seemingly “public” data exposures can still create major privacy and security risks when aggregated and automated at scale.
#Indonesia #DataExposure #Government #CyberSecurity #ThreatIntelligence #Privacy #OSINT #DDW #Intelligence
🚨🇮🇩 LSP Telematika allegedly breached: 14GB+ certification database exposed from Indonesian IT professional records
A threat actor claims to be selling a database tied to LSP Telematika, an Indonesian professional certification body for information technology. The actor alleges the exposed dataset contains tens of thousands of records involving assessors and assessees, along with private conversations, decree documents, and company files.
━━━━━━━━━━━━━━━━━━━━
Target: LSP Telematika
Sector: Professional Certification / Information Technology
Incident: Database Leak
Exposure: 14GB+
Actor: Kyyzo
Country: Indonesia
Date: 16/05/2026
━━━━━━━━━━━━━━━━━━━━
What’s allegedly included:
▪ Assessee records from certification database tables
▪ Assessor personal data and profile information
▪ Registration numbers and certification-related identifiers
▪ Names, birthplaces, birth dates, ages, and email fields
▪ Phone numbers, identity number fields, and address-related data
▪ Private conversations and decree-related documents
▪ Personal company document files linked to certification activity
Potential impact:
The exposed data could be used for identity theft, phishing, credential targeting, impersonation, and social engineering against Indonesian IT certification participants and assessors.
Status:
Unverified underground forum claim. The actor posted database samples and described the release as part of an extortion-driven follow-up leak.
Stop guessing what's redacted. Subscribers see everything → https://t.co/281Qjc6p2J
⚠️ Critical Linux Kernel Flaw ‘ssh-keysign-pwn’ Exposes SSH Keys and Shadow Passwords
Source: https://t.co/wzp6CCp2lT
A newly disclosed Linux kernel vulnerability is raising serious concerns across the security community, as it allows attackers to access highly sensitive data, including SSH private keys and password hashes, on affected systems.
Tracked as CVE-2026-46333, the flaw has been nicknamed “ssh-keysign-pwn” and impacts a wide range of Linux distributions. The GitHub PoC ssh-keysign-pwn demonstrates exactly how to weaponize this race condition on pre‑31e62c2ebbfd kernels.
#cybersecuritynews #Linux
DON'T SIGN IN WITH GOOGLE
DON'T SIGN IN WITH GOOGLE
DON'T SIGN IN WITH GOOGLE
DON'T SIGN IN WITH GOOGLE
DON'T SIGN IN WITH GOOGLE
DON'T SIGN IN WITH GOOGLE
DON'T SIGN IN WITH GOOGLE
Microsoft has confirmed that Windows Update has been downgrading newer GPU drivers that users install manually from Intel, AMD, or NVIDIA websites.
The system treated older OEM-approved drivers as the best match for the hardware via a broad 4-part HWID ranking, often replacing fresh 2026 drivers with older 2024 or earlier versions.
Microsoft is now changing this. New display drivers will use narrower targeting with 2-part HWIDs plus CHIDs, making updates specific to the exact hardware and preventing unwanted replacements.
Via:Windowslatest