[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fXHRX56ItJ8Thq9X19hBxTnUlyC24E3pdjDptgLC4W4Y":3},{"article":4,"iocs":52,"watch_terms":70},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"56aa1481-22a9-4751-a185-d5137d9a88c2","Daily Dose of Dark Web Informer - April 7th, 2026","daily-dose-of-dark-web-informer-april-7th-2026","This daily article is intended to make it easier for those who want to stay updated with my regular Dark Web Informer and X\u002FTwitter posts.","The Dark Web Informer publishes a daily threat intelligence digest summarizing recent breaches, vulnerabilities, and cybercriminal activity. Notable items include breaches affecting KBank Vietnam (10.1M records), Colombian government entities, and compromised accounts from Coinbase, Robinhood, and Hisense. Multiple CVEs are cited including FortiClient EMS pre-auth bypass and Linux kernel vulnerabilities.","Daily dark web threat intelligence digest covering breaches, CVEs, and threat actor activity.","Dark Web Informer — Daily Threat Intelligence Digest 🔑 API Access Available High-volume threat intelligence, ransomware data, IOC exports, and comprehensive feed access for security teams and researchers. Explore API → 🔁 Follow across all official platforms — darkwebinformer.com\u002Fsocials 🔥 Advertising Opportunities Reach a highly engaged audience of 75,300+ unique users monthly and growing. View details 75.3k Unique Visitors 154.1k Pageviews Last 30 days as of Mar 30, 2026. Next update Apr 30th. 🔒 Unlock Premium Intelligence Real-time breach tracking, expert analysis, high-resolution evidence, unredacted feeds, and 5,100+ blog posts. View all plans and features on the pricing page. View Plans & Subscribe → 📌 Legend 📰Law Enforcement — LEA updates, investigations ⚠️Dark Web Notices — forums, markets, announcements ❗️Urgent Threats — breaches, ransomware, vulnerabilities 💡Insights & Tools — guides, OSINT, learning resources 🔒Subscribers Only — X\u002FTwitter subscribe 🧾 Today's Intelligence Threat Intelligence ❗️ Alleged Breach of KBank Vietnam Exposes 10.1 Million Credit Registration Records With National IDs, Salaries, Credit Scores, and Employer Details FREE ❗️ CVE-2026-35616: FortiClient EMS Pre-Auth API Bypass Under Active Exploitation FREE ❗️ Alleged Breach of Colombia's Huila Department Government Extranet Exposes Officer Data, Municipal Offices, and Government Operations Across 8 Municipalities FREE ❗️ Threat Actor Selling Root RCE Shell Access to Botswana Government Health Portal Firewall for $300 FREE ❗️ Threat Actor Selling 1.2 Million French FICOBA Banking Leads With IBANs, SSNs, and Tax IDs From 15+ Banks FREE X\u002FTwitter Updates ❗️ Forum IP Leak: ascarding[.]net ❗️ The internal and confidential databases of Banco Agrario de Colombia, a state-owned Colombian bank, have allegedly been leaked on a popular cybercrime forum. ❗️ Threat actor Lvn4t1k0 allegedly leaked personal data from CONALEP Morelos including teacher information (RFC, CURP, Gmail, passwords, usernames, full names) and student credentials. ❗️ A threat actor claims to possess over 609,000 email records from Hisense USA obtained through various registration forms including TV QR code registration, product registration, and customer support forms. ❗️ A threat actor claims to have obtained databases from Plan Ceibal, a Uruguayan government technology agency, affecting 1.2 million users of the CREA social network and 1 million citizens device assignment records. ❗️ Threat actor JINKUSU advertises OMNITRIX IMAP service offering email account monitoring, attachment interception, IBAN replacement in documents, and email editing capabilities via IMAP access. ❗️ Threat actor McLovin is selling a database containing 810 million Chinese shopping delivery addresses for $1000. ❗️ Threat actor OnarDev is allegedly selling a dataset containing personal information of 2 million Coinbase users for $500 USD. ❗️ Threat actor McLovin is allegedly selling a database containing 4.6 million Robinhood Gold membership records for $3,190. ❗️ NyxarGroup and collaborators are allegedly selling personal information from Colombian government websites saul.cali.gov.co and sider.cali.gov.co. 💡 This Hacker (IntelBroker) Kept Embarrassing the FBI ❗️ The FBI has released a joint Cybersecurity Advisory on Iranian-Affiliated cyber actors exploiting programmable logic controllers across US critical infrastructure. 💡 Tor Browser 15.0.9 has been released, update if you haven't already done so. ❗️ CVE-2026-23398: Linux Kernel ICMP DoS Vulnerability ❗️ CVE-2026-28286: ZimaOS Privilege Escalation Vulnerability 💡 DOJ Disrupts Russian Military Intelligence DNS Hijacking Operation Through Court Order","https:\u002F\u002Fdarkwebinformer.com\u002Fdaily-dose-of-dark-web-informer-april-7th-2026\u002F","https:\u002F\u002Fdarkwebinformer.com\u002Fcontent\u002Fimages\u002Fsize\u002Fw1200\u002F2026\u002F02\u002F23597862398746923879872364987342598723.png","2026-04-07T21:36:30+00:00","2026-04-07T22:00:15.594+00:00",8,[18,21,23,25,27,29],{"name":19,"type":20},"Lvn4t1k0","threat_actor",{"name":22,"type":20},"JINKUSU",{"name":24,"type":20},"McLovin",{"name":26,"type":20},"OnarDev",{"name":28,"type":20},"NyxarGroup",{"name":30,"type":20},"IntelBroker","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":31,"icon":33,"name":34,"slug":35},null,"Threat Intelligence","threat-intelligence",[37,42,47],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":43},{"id":44,"icon":33,"name":45,"slug":46},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":48},{"id":49,"icon":33,"name":50,"slug":51},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[53,57,61,64,67],{"type":54,"value":55,"context":56},"domain","ascarding.net","Forum domain associated with IP leak and Banco Agrario de Colombia internal database leak",{"type":58,"value":59,"context":60},"cve","CVE-2026-35616","FortiClient EMS pre-authentication API bypass under active exploitation",{"type":58,"value":62,"context":63},"CVE-2026-23398","Linux Kernel ICMP DoS vulnerability",{"type":58,"value":65,"context":66},"CVE-2026-28286","ZimaOS privilege escalation vulnerability",{"type":51,"value":68,"context":69},"OMNITRIX IMAP","Threat actor JINKUSU offering email account monitoring and interception service",[]]