[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fz63J6-lHotj0ysQBSQ-r-r4VjvFKGoNsb5rfYvUAJzY":3},{"article":4,"iocs":59,"watch_terms":76},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"547d19ff-f74f-4405-a919-31f2bf4a86c0","Daily Dose of Dark Web Informer - April 13th, 2026","daily-dose-of-dark-web-informer-april-13th-2026-1aeebc","This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X\u002FTwitter posts.","Dark Web Informer's daily digest aggregates threat intelligence from April 13, 2026, reporting dozens of active threats including a 70GB ITAR-controlled aerospace data sale, breaches of major organizations (VUMI Group, VegeHome, Talabat), a new ransomware group (LAMASHTU), zero-day exploits for Windows RDP and FreeBSD, and extortion attempts against Kraken exchange. The digest also catalogs emerging ransomware-as-a-service partnerships and rogue AI tools advertised by threat actors on cybercrime forums.","Daily dark web threat digest covering multiple breaches, ransomware gangs, zero-days, and ITAR data sales.","Dark Web Informer — Daily Threat Intelligence Digest 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. Explore API → 🔁 Follow across all official platforms — darkwebinformer.com\u002Fsocials 🔥 Advertising Opportunities Reach a highly engaged audience of 75,300+ unique users monthly and growing. View details 75.3k Unique Visitors 154.1k Pageviews Last 30 days as of Mar 30, 2026. Next update Apr 30th. 🔒 Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. View Plans & Subscribe → 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — X\u002FTwitter subscribe 🧾 Today's Intelligence Threat Intelligence ❗️ Threat Actor Selling 70GB of ITAR-Controlled SEKISUI Aerospace Technical Data Including Boeing 737\u002F787 Tooling, STEP Files, and Military Program Schematics for $200,000 FREE ❗️ Polish Eco-Friendly Retailer VegeHome Suffers Data Breach Exposing 100K+ Customers FREE ❗️ International Insurer VUMI Group Allegedly Breached, 300K Policyholders and 25K Staff Exposed With SSNs, Passports, and W-9 Forms FREE ❗️ CVE-2026-34621: Adobe Acrobat Reader Prototype Pollution Zero-Day Enables Code Execution via Malicious PDFs FREE X\u002FTwitter Updates ❗️ A solo hacker leveraged ChatGPT and Claude to infiltrate nine Mexican government agencies running from late December 2025 through mid-February 2026 walking away with hundreds of millions of citizen records in what amounted to one of the most technically advanced campaigns. ❗️ New Ransomware Group Identified: LAMASHTU ❗️ A threat actor leaked a database containing personnel information of Iranian Revolutionary Guard Corps (IRGC) and Basij members, including full names, national ID codes, addresses, ranks, and phone numbers. ❗️ Threat Actor Selling 70GB of ITAR-Controlled SEKISUI Aerospace Technical Data Including Boeing 737\u002F787 Tooling, STEP Files, and Military Program Schematics for $200,000 ❗️ The full CRM PII dataset of Mihnati.com, a Saudi Arabian job recruitment platform, has allegedly been breached and is being sold on a popular cybercrime forum. ❗️ Threat actor Z3r00 claims to have leaked a credential list containing 18,530 records from Mexican pharmacy chain Farmacias del Ahorro, including email addresses and passwords. ❗️ ShinyHunters has priced the Rockstar Games breach at $200K. 💡 The API was updated with the new sources, there is now 5,000+ articles. Do a fresh pull of the news endpoint to get the latest... ❗️ A threat actor is selling two zero-day exploits: a Windows RDP denial-of-service exploit for $850 affecting 1M+ devices, and a FreeBSD FTP remote code execution exploit for $900 affecting 11,689 devices. ❗️ The owners and rentals database of Emaar Properties, one of the largest real estate developers in Dubai\u002FUAE, is allegedly being sold on a popular cybercrime forum. 💡 Just another day on X. ❗️ Kraken is currently being extorted by a criminal group threatening to release videos of it's internal systems. ❗️ Threat actor claims to be selling a dataset containing 563,000 user records from Talabat Saudi Arabia, including personal information such as names, emails, phone numbers, addresses, and account details. ❗️ A group is advertising domain ban, hold, de-delegation, DMCA, and phishing abuse services on a popular cybercrime forum, claiming to process 15,000+ abuses per day. ❗️ JINKUSU is teasing a new AI called EMPIRE GPT, that lets you do whatever you want, for free. Not yet available. ❗️ ShadowByt3$ RaaS has made a Partnership Program post on a popular Russian cybercrime forum ❗️ HYFLOCK RaaS\u002FPanel seen on a popular Russian cybercrime forum ❗️ The forum \"T1erOne\" has launched its first article-writing contest, posted by an Admin on April 13, 2026. ❗️ An advanced phishing suite targeting Twilio SendGrid is being advertised on a popular cybercrime forum, designed for credential theft and 2FA interception. ❗️ The complete source code and full database of vidaecor.com.br, an established Brazilian home linen (enxoval) e-commerce store, is allegedly being sold on a popular cybercrime forum. 💡 Ut oh ❗️ ShinyHunters has leaked the Rockstar Games data. ❗️ Threat actor australia shared 1,000 Minecraft-related database dumps for free download. ❗️ The users database of 247falcon.ro, a Romanian company, has allegedly been breached and is being sold on a popular cybercrime forum. ❗️ Alternativa de Moda SAS has been claimed a victim to Qilin Ransomware ❗️ Colorado Pulmonary Intensivists, a US healthcare provider affiliated with UCHealth, has allegedly been listed on the PEAR (Pure Extraction And Ransom) ransomware group's leak site.","https:\u002F\u002Fdarkwebinformer.com\u002Fdaily-dose-of-dark-web-informer-april-13th-2026\u002F","https:\u002F\u002Fdarkwebinformer.com\u002Fcontent\u002Fimages\u002Fsize\u002Fw1200\u002F2026\u002F02\u002F23597862398746923879872364987342598723.png","2026-04-13T22:42:31+00:00","2026-04-13T23:00:07.45+00:00",9,[18,21,23,25,28,31],{"name":19,"type":20},"ShinyHunters","threat_actor",{"name":22,"type":20},"Z3r00",{"name":24,"type":20},"JINKUSU",{"name":26,"type":27},"Adobe Acrobat Reader","product",{"name":29,"type":30},"Rockstar Games","vendor",{"name":32,"type":30},"SEKISUI Aerospace","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":33,"icon":35,"name":36,"slug":37},null,"Threat Intelligence","threat-intelligence",[39,44,49,54],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":50},{"id":51,"icon":35,"name":52,"slug":53},"7d8b5ab8-ea0b-4ced-ae97-ec251b86993a","Ransomware","ransomware",{"category":55},{"id":56,"icon":35,"name":57,"slug":58},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[60,63,66,69,73],{"type":58,"value":61,"context":62},"LAMASHTU","Newly identified ransomware group",{"type":58,"value":64,"context":65},"ShadowByt3$ RaaS","Ransomware-as-a-Service with active partnership program",{"type":58,"value":67,"context":68},"HYFLOCK RaaS","Ransomware-as-a-Service panel active on Russian cybercrime forum",{"type":70,"value":71,"context":72},"cve","CVE-2026-34621","Adobe Acrobat Reader prototype pollution zero-day enabling code execution via malicious PDFs",{"type":58,"value":74,"context":75},"EMPIRE GPT","Unreleased AI tool advertised by threat actor JINKUSU as unconstrained exploitation tool",[29,32,26]]