Daily Dose of Dark Web Informer - April 13th, 2026
Daily dark web threat digest covering multiple breaches, ransomware gangs, zero-days, and ITAR data sales.
Run Rockstar Games?
Get an email when a reviewed story names Rockstar Games, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
Dark Web Informer's daily digest aggregates threat intelligence from April 13, 2026, reporting dozens of active threats including a 70GB ITAR-controlled aerospace data sale, breaches of major organizations (VUMI Group, VegeHome, Talabat), a new ransomware group (LAMASHTU), zero-day exploits for Windows RDP and FreeBSD, and extortion attempts against Kraken exchange. The digest also catalogs emerging ransomware-as-a-service partnerships and rogue AI tools advertised by threat actors on cybercrime forums.
Full text
Dark Web Informer — Daily Threat Intelligence Digest 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. Explore API → 🔁 Follow across all official platforms — darkwebinformer.com/socials 🔥 Advertising Opportunities Reach a highly engaged audience of 75,300+ unique users monthly and growing. View details 75.3k Unique Visitors 154.1k Pageviews Last 30 days as of Mar 30, 2026. Next update Apr 30th. 🔒 Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. View Plans & Subscribe → 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — X/Twitter subscribe 🧾 Today's Intelligence Threat Intelligence ❗️ Threat Actor Selling 70GB of ITAR-Controlled SEKISUI Aerospace Technical Data Including Boeing 737/787 Tooling, STEP Files, and Military Program Schematics for $200,000 FREE ❗️ Polish Eco-Friendly Retailer VegeHome Suffers Data Breach Exposing 100K+ Customers FREE ❗️ International Insurer VUMI Group Allegedly Breached, 300K Policyholders and 25K Staff Exposed With SSNs, Passports, and W-9 Forms FREE ❗️ CVE-2026-34621: Adobe Acrobat Reader Prototype Pollution Zero-Day Enables Code Execution via Malicious PDFs FREE X/Twitter Updates ❗️ A solo hacker leveraged ChatGPT and Claude to infiltrate nine Mexican government agencies running from late December 2025 through mid-February 2026 walking away with hundreds of millions of citizen records in what amounted to one of the most technically advanced campaigns. ❗️ New Ransomware Group Identified: LAMASHTU ❗️ A threat actor leaked a database containing personnel information of Iranian Revolutionary Guard Corps (IRGC) and Basij members, including full names, national ID codes, addresses, ranks, and phone numbers. ❗️ Threat Actor Selling 70GB of ITAR-Controlled SEKISUI Aerospace Technical Data Including Boeing 737/787 Tooling, STEP Files, and Military Program Schematics for $200,000 ❗️ The full CRM PII dataset of Mihnati.com, a Saudi Arabian job recruitment platform, has allegedly been breached and is being sold on a popular cybercrime forum. ❗️ Threat actor Z3r00 claims to have leaked a credential list containing 18,530 records from Mexican pharmacy chain Farmacias del Ahorro, including email addresses and passwords. ❗️ ShinyHunters has priced the Rockstar Games breach at $200K. 💡 The API was updated with the new sources, there is now 5,000+ articles. Do a fresh pull of the news endpoint to get the latest... ❗️ A threat actor is selling two zero-day exploits: a Windows RDP denial-of-service exploit for $850 affecting 1M+ devices, and a FreeBSD FTP remote code execution exploit for $900 affecting 11,689 devices. ❗️ The owners and rentals database of Emaar Properties, one of the largest real estate developers in Dubai/UAE, is allegedly being sold on a popular cybercrime forum. 💡 Just another day on X. ❗️ Kraken is currently being extorted by a criminal group threatening to release videos of it's internal systems. ❗️ Threat actor claims to be selling a dataset containing 563,000 user records from Talabat Saudi Arabia, including personal information such as names, emails, phone numbers, addresses, and account details. ❗️ A group is advertising domain ban, hold, de-delegation, DMCA, and phishing abuse services on a popular cybercrime forum, claiming to process 15,000+ abuses per day. ❗️ JINKUSU is teasing a new AI called EMPIRE GPT, that lets you do whatever you want, for free. Not yet available. ❗️ ShadowByt3$ RaaS has made a Partnership Program post on a popular Russian cybercrime forum ❗️ HYFLOCK RaaS/Panel seen on a popular Russian cybercrime forum ❗️ The forum "T1erOne" has launched its first article-writing contest, posted by an Admin on April 13, 2026. ❗️ An advanced phishing suite targeting Twilio SendGrid is being advertised on a popular cybercrime forum, designed for credential theft and 2FA interception. ❗️ The complete source code and full database of vidaecor.com.br, an established Brazilian home linen (enxoval) e-commerce store, is allegedly being sold on a popular cybercrime forum. 💡 Ut oh ❗️ ShinyHunters has leaked the Rockstar Games data. ❗️ Threat actor australia shared 1,000 Minecraft-related database dumps for free download. ❗️ The users database of 247falcon.ro, a Romanian company, has allegedly been breached and is being sold on a popular cybercrime forum. ❗️ Alternativa de Moda SAS has been claimed a victim to Qilin Ransomware ❗️ Colorado Pulmonary Intensivists, a US healthcare provider affiliated with UCHealth, has allegedly been listed on the PEAR (Pure Extraction And Ransom) ransomware group's leak site.
Indicators of Compromise
- malware — LAMASHTU
- malware — ShadowByt3$ RaaS
- malware — HYFLOCK RaaS
- cve — CVE-2026-34621
- malware — EMPIRE GPT