The European Parliament failed to block the revival of the EU's temporary voluntary message-scanning regime on July 9, 2026 - 314 MEPs opposed it, but the absolute-majority threshold was never reached. With the permanent CSAR talks resuming in September, the fight over scanning and encryption directly shapes the future of anonymity tools.
Slovak intelligence dismantled an EU-funded NERO R-ONE camera and found a rebadged Russian CORDON PRO.M with two modems and a hidden SMS-triggered backdoor tied to twelve Russian phone numbers.
A single actor behind the CameraSwarm campaign compromised at least 14,530 Dahua IP cameras across Ukrainian, Russian and CIS networks in 35 days, leaning heavily on the 2021 authentication bypasses CVE-2021-33044 and CVE-2021-33045. The operation only came to light because the attacker left his own toolkit exposed online.
LockBit 5.0 threatens to publish identity documents tied to more than 100,000 job candidates from French staffing group Actua, spread across ten storage locations at once. What the claim-versus-reality gap looks like, and why scattered leaks change the takedown math.
Telegram has applied to ICANN for the .gram top-level domain, turning usernames into resolvable domains with AI-generated sites behind them. Coming weeks after t.me was suspended under sanctions pressure, the move highlights how infrastructure is drifting away from onion services toward DNS that regulators can actually touch.
A hacker using the alias ZeroBytes advertised a stolen DGFiP database on PwnForums, claiming live access to French tax systems. France's economy ministry confirmed illegitimate access affecting about 678,000 individuals and organizations; the seller's larger claims remain unverified.
The FortiBleed leak exposed admin credentials for tens of thousands of internet-facing FortiGates across 194 countries. Within days of CISA's emergency advisory, an initial access broker was selling bulk US device accesses on Darkforums with forum escrow.
After Abacus went offline in July 2025 amid withdrawal failures and exit-scam suspicions, its buyers scattered toward Torzon and Black Ops Market - while newer platforms rebuilt the payment stack around built-in coin swapping.
After BreachForums fell apart in April 2025, Darkforums absorbed its displaced user base and surged 600 percent in two months, now counting over 12,700 members under admins AnonOne and Knox.
The 2025 disruptions of Lumma and Rhadamanthys barely slowed the infostealer economy. Russian Market now lists 180,000+ logs per half-year, and the data inside them is fueling intrusions within days.
A seller claims a full extraction of a Korean food-delivery platform's unauthenticated Firebase backend: 47.9 million records including door codes, resident registration numbers, plaintext passwords, and live payment keys. The listing is unverified, but the pattern behind it is the most reliable supply line feeding dark-web data markets.
SOCRadar analysts spotted an underground post selling an alleged SCHUFA database of 70 million Germans with IBANs and credit scores, weeks after revelations of a secret shadow database at the credit bureau. The sale remains unverified.