🇨🇱 [INITIAL ACCESS SALE] ISP Control Panel + API Access (Chile)
A threat actor is advertising access to an ISP environment allegedly based in Chile, including control panel, network API, and WordPress configs.
Claimed access:
• Provider control panel access
• Network management API
• WordPress configuration files
• Payment gateway endpoints
• Admin-related data (email/phone/login references)
Data exposure:
• “Thousands” of customer records
– Names, contacts, addresses
– Billing and payment history
• Additional sensitive elements:
– JWT tokens
– Webhooks
– Database configuration (localhost scope)
💰 Sale details:
• Starting bid: $3,000
• Blitz price: $15,000
• Claimed business turnover: $150K/month
⚠️ Initial assessment:
• This is not just a data leak — this is ACTIVE ACCESS being sold
• Presence of:
– API access
– Control panel
– Payment integrations
→ indicates high-impact compromise potential
• JWT + webhook exposure suggests:
– Possible session/token abuse
– API abuse / service impersonation
🎯 Risk perspective:
• Immediate threats:
• Customer data exfiltration
• Service disruption
• Financial fraud via payment systems
• Full infrastructure takeover
• Long-term risk:
• Persistent access / backdoor retention
• Supply chain impact (if ISP clients affected)
🔐 Recommended actions:
• Treat as critical incident if confirmed
• Immediate:
• Revoke API tokens / JWT secrets
• Rotate all credentials
• Audit control panel access logs
• Investigate:
• Unauthorized API usage
• Webhook abuse patterns
• Segment and isolate affected systems
Current status: Unverified but HIGH RISK due to nature of access being sold
#DDW #Intelligence #CyberThreat #InitialAccess #DarkWeb #OSINT
La situación en Medio Oriente ha dado un giro sísmico. Se reportan segundas oleadas de ataques coordinados del ejército iraní contra puntos estratégicos en Dubái, Kuwait y Arabia Saudita.
Lo que marca la diferencia en esta ofensiva:
Asistencia Estratégica: Se confirma que los ataques han contado con apoyo técnico y logístico de China, elevando la tensión a un nivel de confrontación de potencias.
Breaking
Palantir was allegedly hacked. An AI agent was used to gain super-user access and here”s what the hackers allegedly found:
Peter Thiel and Alex Karp commit mass surveillance of world leaders and titans of industry on a massive scale.
They have thousands of hours of transcribed and searchable conversations of Donald Trump, JD Vance and Elon Musk.
They have backdoored the devices, cars and jets of world leaders and accumulated the biggest archive of blackmail material.
Palantir is creating nuclear and bio weapon capabilities for Ukraine and is working closely with the CIA to defeat Russia. They believe they are one year away. They plan to achieve this by keeping Russia busy with meaningless peace negotiations.
Palantir is responsible of the majority of Palestinian deaths in Gaza. They have developed the AI targeting for Israel.
Palantir is an arm of the CIA and all data from international clients is copied into a CIA spy cloud.
Palantir has become the most dangerous company in the world. If you work there you have the right to know that this is what Palentir AI is used for, without your knowledge.
The Palentir data the hackers allegedly gathered will be given to Russia and/or China. I was chosen as a trusted partner for this publication. I’m not involved in the Palentir hack and I don’t know the hackers. But I do know that the hack happened.
@GullitDelBulla Ahi estas equivocado, el loco antes hacia lives de sitios de tor, le daban de baja el live o videos de youtube, entonces al final dejo de hacerlo por que le bajaron varios videos etc. unica evidencia nisiquiera tiene una base tecnica de que haciaxd
Puertas abiertas para la última noche junto a @badbunnypr y el DeBÍ TiRAR MáS FOToS World Tour. 📸 Hoy se vuelve a gozar en el Estadio Nacional 🏟️🔥
#BizarroCL#BadBunny#DTMFSantiago
An important victory – but we still need to stop Chat Control.
The Council of Ministers in the EU has, after three years, now reached a common position on Chat Control. The requirement for mandatory scanning (including end-to-end encrypted messaging services) has been removed, which is a major victory. The EU Council failed to implement mandatory mass surveillance. However, in its proposal, they are laying the groundwork for mass surveillance in the future.
What happens now?
The Council will now enter negotiations with the European Parliament, led by the European Commission. We urge the Parliament to stand firm in the trilogue negotiations and not deviate an inch from its previous position, demanding: no mass surveillance whatsoever without suspicion and a court order, no ID-verification requirements, and no censorship of legal content.
The EU Council is preparing for mandatory mass surveillance and censorship
The Council’s version of Chat Control includes voluntary scanning, vaguely worded legislation that may entail requirements for age verification and mandatory ID checks (even for end-to-end encrypted services), and an article stating that the requirement for mandatory scanning shall be reconsidered every three years. They also introduce a new infrastructure for blocking material, where it is up to each member state to block what they consider illegal. At the same time, a massive EU center is being established to work exclusively on this. All in all, this indicates that the EU Council is aiming to build an infrastructure for mass surveillance, and the legislative proposal is written in a way that opens the door to it.
The EU Council’s Chat Control version
- The EU Council’s Chat Control version introduces a new type of scanning for so-called new material and grooming. This means that AI will scan people’s conversations, photos and videos, in search of criminal content. This will result in enormous numbers of false positives, and people’s private lives will move from an AI detection to being examined by employees at a new EU center. This is mass surveillance and people’s private lives will be scanned without any suspicion and without a court order. This scanning is carried out in cooperation with American companies and can at any time be used to scan for virtually anything; Europol has already requested broader scanning and wants access to material that is not illegal.
- Every three years, the European Commission will challenge the law and attempt to force mandatory scanning (even for end-to-end-encrypted services). Messaging services (including end-to-end encrypted) must take “all reasonable measures” to reduce the risk of their services being misused, including implementation of age verification. This means that the EU may require ID checks and ban anonymous use of messaging services and social media. This poses problems for people who criticize those in power in authoritarian countries, for whistleblowers who want to leak documents, and for sources who wish to speak anonymously with journalists.
- A new infrastructure for blocking material is introduced, where it’s up to each of the member states to issue blocking orders for what they consider illegal. This implies that content that is illegal in one country will also be blocked in a country where it is legal. Once this infrastructure is in place, it also opens the door to a slippery slope when it comes to censorship.
Stop Chat Control
From the outset, Chat Control was a proposal that aimed to introduce mass surveillance. That ambition is clearly still present within the Commission and among many of the member states in the Council. The Council failed to introduce mass surveillance but has succeeded in paving the way for new attempts. This applies not only to future proposals for mandatory chat control scanning every three years. This is part of a broader development in which private and secure communication is being challenged by forces seeking to introduce mass surveillance. ProtectEU is a rebranded Chat Control, aimed at banning encryption. National laws are trying to do the same. We need to put a stop to these attempts here and now.