‼️🇸🇦 Thmanyah allegedly breached: 107,084 subscriber emails and a Bitmovin license key exposed from the leading Arabic podcast and media-tech platform
A threat actor is selling a database from Thmanyah, the Saudi media-tech company founded in 2016 in Riyadh and majority-owned by Saudi Research and Media Group (SRMG), which operates the largest Arabic podcast network in the Middle East and North Africa and holds the Guinness World Record for the most-viewed podcast episode on YouTube.
The actor states the breach exposed 107,084 subscriber emails along with a Bitmovin video-streaming LICENSE key embedded in the dump. The sample shows internal admin accounts on the thmanyah[.]com domain, user join dates from 2024, language and category preferences across Documentary, Science Fiction, True Crime, Food, and Relationships content, plus Apple Podcasts category mappings and translation metadata.
▸ Actor: lulzintel (GOD User)
▸ Sector: Media / Podcast Platform / Tech
▸ Type: Data Sale (paywalled, 6 forum points)
▸ Records: 107,084 subscriber emails + Bitmovin LICENSE key
▸ Country: Saudi Arabia
▸ Date: 14/05/2026
Compromised data:
▪ Subscriber email addresses (107,084 records)
▪ User ID
▪ Account approval flag (is_approved)
▪ Join date
▪ Language preference (lang, e.g., "en", "ar")
▪ Name
▪ Question fields (q7, q4_2, q5, q6, q1, q2_2, q8, q3, q3_str)
▪ Interests array (e.g., "google_podcast")
▪ VUE_APP_BITMOVIN_LICENSE_KEY (included in the file)
▪ Internal Thmanyah staff accounts visible in sample
▪ Waitlist IDs and category mappings to Apple Podcasts taxonomy (Documentary, Science Fiction, True Crime, Food, Relationships)
▪ Translation pairs (Arabic and English) for category names
▪ Listen/yes flags, device type (e.g., android), age ranges (e.g., 20+, 4_8)
Stop guessing what's redacted. Subscribers see everything → https://t.co/281Qjc6p2J
❗️🚨 Microsoft Edge keeps every saved password in process memory as cleartext from the moment it launches. Microsoft's responsed when reported: "by design."
All of them. Including credentials for sites you won't open this session.
Researcher @L1v1ng0ffTh3L4N tested every major Chromium browser. Edge is the only one that behaves this way.
Chrome decrypts credentials on demand, and App-Bound Encryption locks the keys to an authenticated Chrome process so other processes can't reuse them.
In Chrome, plaintext surfaces only during autofill or when a password is viewed, making memory scraping far less useful.
What makes this extra weird is that Edge still demands re-authentication before revealing those passwords in its Password Manager UI, while the same browser process already holds every one of them in plaintext.
In shared environments, this turns into a credential harvest. On a terminal server, an attacker with admin rights can read the memory of every logged-on user process. In the published PoC video, a compromised admin account lifts stored credentials from two other logged-on (and even disconnected) users with Edge running.
Microsoft's official response when notified: "by design."
The finding was disclosed April 29 at BigBiteOfTech by PaloAltoNtwks Norway, alongside a small educational tool that lets anyone verify the cleartext storage for themselves.
On Telegram, anyone can utilize AI bots to easily develop, launch and manage their own bot – with no coding required. #TelegramTips
More information for developers is available here:
https://t.co/xBsBGCc664
‼️ https://t.co/5Bh62HuixW has been breached — threat actors accessed customer data and reservations, and are actively abusing it.
A Reddit user says he reported the breach over two weeks ago after being phished with his own reservation details, but Booking said everything was fine on their end.
"Given how weak their security appears to be, I'm not surprised"
⚠️ ALERT - CPUID’s site was compromised for ~19 hours, serving trojanized CPU-Z and HWMonitor installers.
Attackers used DLL sideloading to pair legit apps with a malicious file, deploying STX RAT.
150+ victims reported before detection.
🔗 Read → https://t.co/3Oshrvbawo
⚠️ Attackers are hijacking exposed ComfyUI servers into crypto mining and proxy botnets.
Scanners exploit unauthenticated setups via custom nodes, run code, and install persistent malware. Infected systems mine crypto and resist removal.
🔗 Read → https://t.co/JliAjRpFz4
An image is made of many small parts. When each part is rotated in the same direction, their individual changes add together. If this is done recursively across all segments, the combined effect is the rotation of the whole image.