Passive public-source aggregation

Darkweb news by category.

Current public reporting is grouped by reader-focused categories with source, source type, category, and claim-status labels on every item.

Source flow map showing allowlisted public feeds normalized into the Darkweb tab
Allowlisted public feeds only; Tor collection is off by default.
Items
32
Sources
4
Categories
5
Updated
2026-05-29 19:18 UTC

This feed publishes public metadata and summaries only. It does not authenticate to illicit services, execute exploits, collect credentials, download stolen data, index leaked datasets, submit forms, or run browser automation.

Category 1

Ransomware & Extortion OSINT

Public reporting and advisories about ransomware activity, extortion trends, and defensive context.

Items
8
Sources
1
Latest
2026-05-29 18:21 UTC

Ransomware & Extortion OSINT

ChatGPT share links abused to host fake outage pages to deliver malware

BleepingComputer | rss | established-security-journalism

Threat actors are abusing ChatGPT's content-sharing feature to display fake OpenAI outage pages that direct users to download malware disguised as the ChatGPT desktop application. [...]

Ransomware & Extortion OSINT

California AG sues 23andMe over 2023 breach exposing health data

BleepingComputer | rss | established-security-journalism

California Attorney General Rob Bonta filed a lawsuit against 23andMe, now Chrome Holding Co., over the company's failure to protect sensitive customer genetic and personal information. [...]

Ransomware & Extortion OSINT

From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market

BleepingComputer | rss | established-security-journalism

DDoS attacks are increasingly being sold like subscription services, complete with pricing tiers, support, and reseller programs. Flare explores how the DDoS-as-a-Service market has evolved from scattered tools into polished attack platforms. [...]

Ransomware & Extortion OSINT

Dutch govt disrupts malware botnet with 17 million infected devices

BleepingComputer | rss | established-security-journalism

Dutch authorities have taken offline a massive botnet of 17 million devices and seized more than 200 servers at a local provider that supported the operation. [...]

Ransomware & Extortion OSINT

Google Chrome adds session cookie theft protection for all users

BleepingComputer | rss | established-security-journalism

Google says the Chrome Device Bound Session Credentials (DBSC) security feature is now generally available and is rolling out to all users to prevent account takeovers. [...]

Ransomware & Extortion OSINT

Man sent to prison for selling data of 7 millions elderly Americans

BleepingComputer | rss | established-security-journalism

A North Carolina man was sentenced to more than 10 years in prison for selling the personal information of over 7 million elderly Americans to Jamaican scammers. [...]

Ransomware & Extortion OSINT

US charges Google security engineer with Polymarket insider trading

BleepingComputer | rss | established-security-journalism

A Google security engineer was charged with insider trading after winning $1.2 million using confidential company data to place bets on the cryptocurrency-based Polymarket decentralized prediction market. [...]

Ransomware & Extortion OSINT

Charter Communications data breach affects 4.9 million accounts

BleepingComputer | rss | established-security-journalism

The ShinyHunters extortion gang stole personal information from 4.9 million accounts after hacking the U.S. telecom giant Charter Communications in early April, according to data breach notification service Have I Been Pwned. [...]

Category 2

Law Enforcement & Policy

Public government, court, policy, and takedown reporting related to darknet and cybercrime activity.

Items
0
Sources
0
Latest
No current items

No current items in Law Enforcement & Policy. Assigned sources remain listed below.

Category 3

Vulnerability Intelligence

Government and security-community advisories about exploited vulnerabilities and exposure risk.

Items
8
Sources
1
Latest
2026-05-29 00:00 UTC

Vulnerability Intelligence

CVE-2026-0257

CISA Known Exploited Vulnerabilities Catalog | json | government-advisory

CVE-2026-0257: Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.

Vulnerability Intelligence

CVE-2026-48027

CISA Known Exploited Vulnerabilities Catalog | json | government-advisory

CVE-2026-48027: Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.

government-advisory Leaked-data indexing: off Public link unavailable

Vulnerability Intelligence

CVE-2026-45321

CISA Known Exploited Vulnerabilities Catalog | json | government-advisory

CVE-2026-45321: TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.

government-advisory Leaked-data indexing: off Public link unavailable

Vulnerability Intelligence

CVE-2026-8398

CISA Known Exploited Vulnerabilities Catalog | json | government-advisory

CVE-2026-8398: Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.

Vulnerability Intelligence

CVE-2026-48172

CISA Known Exploited Vulnerabilities Catalog | json | government-advisory

CVE-2026-48172: LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.

Vulnerability Intelligence

CVE-2026-9082

CISA Known Exploited Vulnerabilities Catalog | json | government-advisory

CVE-2026-9082: Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

Vulnerability Intelligence

CVE-2025-34291

CISA Known Exploited Vulnerabilities Catalog | json | government-advisory

CVE-2025-34291: Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.

government-advisory Leaked-data indexing: off Public link unavailable

Vulnerability Intelligence

CVE-2026-34926

CISA Known Exploited Vulnerabilities Catalog | json | government-advisory

CVE-2026-34926: Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

Category 4

Security Research

Analysis from established security publishers about threat activity, malware, fraud, and defensive findings.

Items
16
Sources
2
Latest
2026-05-29 18:07 UTC

Security Research

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

The Hacker News | atom | established-security-journalism

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant's implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks. The technique has been codenamed ChatGPhish by Permiso Security. "The chatgpt.com response renderer trusts Markdown links and Markdown

Security Research

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

The Hacker News | atom | established-security-journalism

An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclosed vulnerability. "The attacker compromised an internet-reachable Marimo notebook via CVE-2026-39987, extracted two cloud credentials from the compromised

Security Research

New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks

The Hacker News | atom | established-security-journalism

A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 2025. GREYVIBE, per WithSecure, is assessed to be a Russian-speaking group operating broadly in the Russian time zone, with the activities aligning with Kremlin state interests, specifically when it comes to

Security Research

What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks

The Hacker News | atom | established-security-journalism

Shadow AI used to mean employees pasting things they shouldn't into ChatGPT. It now means something bigger: employees building full applications with AI, wiring them into production systems, and publishing them on the open internet. Without Security or IT in the loop. The artifact moved from a prompt to a product. The risk surface moved with it. In The Shadow Builders report (get it here), a

Security Research

Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

The Hacker News | atom | established-security-journalism

Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil's largest cooperative financial systems, to siphon client IDs and PFX certificates. According to Socket, versions 2.0.0 through 2.0.4 of "Sicoob.Sdk" contain functionality to exfiltrate sensitive information, including PFX certificates that are used to

Security Research

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

The Hacker News | atom | established-security-journalism

The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through March and April 2026. "Kimsuky employed a range of tailored social engineering tactics, such as spoofing security software installation pages and crafting a fake Webex meeting page that leveraged

Security Research

Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

The Hacker News | atom | established-security-journalism

A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute arbitrary code under certain conditions. The security flaw, per Rapid7, is rated 9.4 on the CVSS scoring system. It does not have a CVE identifier. "The vulnerability allows any authenticated user to achieve remote code execution (RCE) on

Security Research

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

The Hacker News | atom | established-security-journalism

Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malware. "The campaign abused trusted endpoint management infrastructure to deliver malware across managed endpoints," Arctic Wolf said. "Threat actors disguised the credential stealer payload as a Fortinet endpoint

Security Research

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

KrebsOnSecurity | rss | established-security-journalism

Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the focus of a 2025 KrebsOnSecurity story about how their hosting companies had assumed control over the technical infrastructure of Stark Industries Solutions, an Internet service provider sanctioned last year by the EU as a frequent staging ground for cyber mischief from Russia's intelligence agencies.

Security Research

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

KrebsOnSecurity | rss | established-security-journalism

Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked credentials.

Security Research

Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

KrebsOnSecurity | rss | established-security-journalism

Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. KrebsOnSecurity publicly named the suspect in February 2026 after the accused launched a volley of DDoS, doxing and swatting campaigns against this author and a security researcher. He now faces criminal hacking charges in both Canada and the United States.

Security Research

CISA Admin Leaked AWS GovCloud Keys on Github

KrebsOnSecurity | rss | established-security-journalism

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally, and that it represents one of the most egregious government data leaks in recent history.

Security Research

Patch Tuesday, May 2026 Edition

KrebsOnSecurity | rss | established-security-journalism

Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on full display this month with some of the more widely-used software makers -- including Apple, Google, Microsoft, Mozilla and Oracle -- fixing near record volumes of security bugs, and/or quickening the tempo of their patch releases.

Security Research

Canvas Breach Disrupts Schools & Colleges Nationwide

KrebsOnSecurity | rss | established-security-journalism

An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service's login page with a ransom demand that threatened to leak data from 275 million students and faculty across nearly 9,000 educational institutions.

Security Research

Anti-DDoS Firm Heaped Attacks on Brazilian ISPs

KrebsOnSecurity | rss | established-security-journalism

A Brazilian tech firm that specializes in protecting networks from distributed denial-of-service (DDoS) attacks has been enabling a botnet responsible for an extended campaign of massive DDoS attacks against other network operators in Brazil, KrebsOnSecurity has learned. The firm's chief executive says the malicious activity resulted from a security breach and was likely the work of a competitor trying to tarnish his company's public image.

Security Research

‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty

KrebsOnSecurity | rss | established-security-journalism

A 24-year-old British national and senior member of the cybercrime group "Scattered Spider" has pleaded guilty to wire fraud conspiracy and aggravated identity theft. Tyler Robert Buchanan admitted his role in a series of text-message phishing attacks in the summer of 2022 that allowed the group to hack into at least a dozen major technology companies and steal tens of millions of dollars worth of cryptocurrency from investors.

Category 5

Darknet Policy & Safety

Context on darknet-adjacent policy, safety, privacy, and public-interest research.

Items
0
Sources
0
Latest
No current items

No current items in Darknet Policy & Safety. Assigned sources remain listed below.

Source directory

Allowlisted sources