UPDATE: Microsoft has patched the actively exploited on-prem Exchange flaw (CVE-2026-42897).
Patch now, and keep the existing mitigation on for extra protection.
Affects Exchange Server 2016, 2019, and SE.
Details 👇 https://t.co/7CUgmom0Jh
🔴 Un cybercriminel revendique le piratage de Smartbox et publie les données de plus de 60 000 personnes.
Smartbox est un service spécialisé dans les coffrets cadeaux, séjours, activités de loisirs et expériences commercialisés dans plusieurs pays européens.
Les données publiées contiendraient notamment des noms, prénoms, adresses e-mail, numéros de téléphone, adresses postales et diverses informations associées à des comptes utilisateurs.
https://t.co/pOCzLRydqm
🔴 Toulouse Football Club : des données personnelles de supporters ont potentiellement été exposées après une cyberattaque ayant touché l’un des prestataires du club.
> https://t.co/Xk8ska0vRD
🚨 CYBER INTELLIGENCE ALERT: FEMBOYFORUM DRIVES ONE OF THE LARGEST LEAK LIBRARIES IN THE CRIMINAL ECOSYSTEM
🌐 Cybercriminal community announces massive expansion of leak repository
[STATUS: ACTIVE MONITORING]
The cybercriminal community known as "FemboyForum" has announced the launch and expansion of its central archive—a platform used to share illicitly obtained information, leaked databases, compromised credentials, infostealer logs, vulnerability references, and other resources linked to the criminal ecosystem.
Additionally, they announced the upcoming addition of approximately 100,000 new files.
📊 Repository Statistics
📂 Data breach sources (BS): 622,882
🔐 Compromised logs and credentials (ULP/Logs): 33,671
📑 Indexed posts: 656,553
🌐 Onion resources: 11,116
⚠️ CVE references: 240,332
📈 Intelligence Assessment
The observed volume of information suggests the existence of a major aggregation platform used by malicious actors to exchange leaked data, stolen credentials, infostealer malware logs, information derived from security breaches, and technical exploitation references.
The announced addition of over 100,000 files could significantly increase the availability of compromised information within criminal circles and facilitate reconnaissance activities, credential abuse, fraud, and unauthorized access. 🎯 Risk Level: HIGH
🏴 Category: Cybercriminal Community / Leak Repository
📈 Trend: Rapid expansion and growth
⚠️ Associated Vectors: Data leakage • Compromised credentials • Infostealers • Security breaches • Illicit information exchange
#CyberSecurity #ThreatIntelligence #Cybercrime #DataBreach #DataLeak #DarkWeb #CyberCrime #Infostealer #CredentialLeaks #ThreatActor #Hackers #CTI #CyberThreats #Darknet #CyberIntelligence #VECERT
🚨 Microsoft just dropped a record 206 security fixes.
Three bugs were already public. 39 are rated Critical. Some can let attackers run code over the network or bypass #BitLocker.
This is the Patch Tuesday list admins should not skim.
See what Microsoft fixed: https://t.co/cEQsEwOFoj
🚨 A serious flaw in Arista switches is being exploited right now — and Arista says it won't fix it.
It's one of 3 actively exploited bugs CISA just flagged, alongside Cisco and Google Chrome.
Federal agencies have until June 23 to act.
Read: https://t.co/8NVvsIqDDf
✨🇪🇺Vous voulez vraiment comprendre pourquoi Siri AI est bloqué en Europe ?
Je vous recommande vivement la dernière vidéo de @LelloucheNico de @Numerama , "J'ai demandé à Apple pourquoi l'Europe n'a rien (la réponse est dingue)", qui explique clairement et simplement la situation.
C’est probablement l’une des meilleures explications disponibles actuellement sur internet.
Si le sujet vous intéresse, prenez le temps de regarder cette vidéo.
https://t.co/IEb1GPRYiw
Trois pays bloquent les messages RCS chiffrés de façon globale avec iOS 27 : la Chine, la Corée du Sud… et la France https://t.co/J96luFdlvA #RCS#Chiffrement
🇫🇷 Alleged Nantes Metropolitan Administration Employee Directory Leak Advertised Online
A threat actor has posted what they claim is a database containing information on employees and agents associated with the Nantes metropolitan administration in France.
* According to the post:
* Target: https://t.co/C4mR1Ik03h
* Claimed records: 5,274
* Format: CSV
* Dataset name: annuaire_agents_nantes_v2.csv
* The actor states the dataset contains employee directory information, including:
* Full names
* Job functions and positions
* Organizations and departments
* Service information
* Email addresses
* Office phone numbers
* Mobile phone numbers
* Manager details
* Addresses
* URLs
* The post appears to reference municipal employees and administrative personnel connected to the Nantes metropolitan government.
* No evidence was provided indicating financial information, passwords, national identification numbers, or citizen records were included in the exposed sample.
* At the time of publication, Daily Dark Web could not independently verify:
* The authenticity of the dataset
* Whether the data originated from a compromise
* Whether the information was publicly accessible prior to publication
* Whether all claimed records belong to active municipal employees
Analyst Note:
Even when datasets contain only directory information, they can significantly increase the effectiveness of spear-phishing, business email compromise (BEC), social engineering, and physical security targeting. Government employee contact databases are frequently leveraged by threat actors to map organizational structures and identify high-value personnel for follow-on attacks.
#DDW #Intelligence #DarkWeb #France
🚨🇫🇷 Rennes, Nantes, Bordeaux, Saint-Étienne, Aix-Marseille... les métropoles françaises de plus en plus touchées par les fuites de données
Des dizaines de milliers de personnes concernant agents, administrés et utilisateurs de services publics auraient été exposés ces derniers mois.
Parmi les données sensibles revendiquées figurent notamment des noms, adresses e-mail professionnelles et numéros de téléphone.
Des fonctions, rattachements hiérarchiques et diverses informations internes aux collectivités apparaissent également dans les données exposées.
🔴 FUITES INFOS | SMARTBOX GROUP — Coffrets cadeaux et e-cartes cadeaux — 60 568 personnes concernées
📅 10 juin 2026
Base revendiquée le 10 juin 2026 concernant https://t.co/TwleMFq5lV, site du groupe Smartbox, spécialisé dans la vente de coffrets cadeaux, e-cartes cadeaux et expériences à réserver en Europe, notamment pour les séjours, restaurants, loisirs, bien-être et activités.
60 568 utilisateurs sont annoncés, avec un fichier User.csv de 60 569 lignes et un échantillon contenant notamment des données de comptes pouvant aller jusqu'au 5 juin 2026, ainsi qu'un fichier echosign_dev1__SIGN_Agreement__c.csv de 202 658 lignes semblant contenir des métadonnées d'accords ou documents e-signature.
• Identifiants internes • Nom • Prénom • Nom d'utilisateur • Adresse e-mail • Téléphone • Téléphone mobile • Statut du compte • Date de dernière connexion • Type d'utilisateur • Identifiant contact • Identifiant compte • Date de création • Date de modification • Surnom communautaire • Fuseau horaire • Langue • Indicateur portail • Indicateur partenaire • Identifiant de fédération • Société • Département • Fonction • Adresse postale • Ville • État • Code postal �� Pays • Identifiant manager • Alias • Division • Métadonnées de documents e-signature
Researchers just unveiled FROST (fingerprinting remotely using OPFS-based SSD timing), a technique that exploits your SSD's timing to silently detect every site and app you have open.
No clicks.
No interaction.
Just visit a page.
Let's have a look at how it works...
1/7
⚠️ ServiceNow Confirms Flaw Allowing Unauthorized Access to Customer Instance Tables
Source: https://t.co/FF1bEWofsy
ServiceNow has confirmed a security vulnerability that could allow unauthorized actors to query customer instance tables, raising concerns about potential data exposure across enterprise environments.
The issue, disclosed through threat intelligence channels, involves improper access controls that may enable attackers to execute queries against backend instance tables without proper authentication.
ServiceNow, widely used for IT service management (ITSM) and enterprise workflows, hosts sensitive operational and business data, making such vulnerabilities particularly critical.
#cybersecuritynews
‼️🚨 BREAKING: ServiceNow has been breached. Customers are reporting unauthorised access to their instances.
One customer states their security team reported this vulnerability to them, and they closed the case twice, saying they had already known since the 7th of April.
🚨 Fully patched Windows 10 and 11 are still at risk from a new Microsoft Defender zero-day.
The exploit, "RoguePlanet," can hand attackers full SYSTEM control when it works.
It's the latest public drop from a researcher feuding with Microsoft.
Read: https://t.co/RbALiW3Qvj
🔴 L’Académie de Lille visée par une fuite de données sur le dark web. Un pirate affirme avoir récupéré les informations de nombreux agents.
https://t.co/aiCSPQAN2v
🔴 L’Union européenne prépare une action en justice contre la France et l’Espagne pour leur retard dans l’adoption de nouvelles règles visant à mieux protéger les infrastructures contre les cyberattaques.
https://t.co/BRhJPqHL43
🛠️ Microsoft Patch Tuesday de juin 2026
📊 Le bilan:
→ 200 vulnérabilités corrigées (largement au-dessus de la moyenne)
→ 33 critiques
→ 3 zero-day déjà divulguées publiquement
Récap 👇
- https://t.co/B1OhT1UOFA
#PatchTuesday#Cybersécurité#Microsoft