Mastodon Digest
for the past
scorer
threshold
Posts

Spotted a threat actor doing this.

If you use GitHub Free, you can spin up Windows desktops with up to 32 core CPUs and 1.2tb of bandwidth using GitHub Code Spaces. Connect using RDP.

There’s no card payment details needed and no know your customer checks.

github.com/ItzLevvie/dind

‼️ ShinyHunters has shared a message on their pay or leak portal to Director Brett Leatherman of the FBI Cyber Division and Director Kash Patel of the FBI:

"Dear Assistant Director Brett Leatherman of the FBI Cyber Division & Director Kash Patel of the FBI,

During Quarter Two of this year the Federal Bureau of Investigation (FBI) made substantial false allegations regarding our organisation in a FLASH report. We have been severely offended.

We were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to "disrupt" our operations, an effort that ultimately proved unsuccessful.

For us to properly address and correct these unfounded allegations, we were compelled to adopt a forceful and assertive posture to ensure our response was fully acknowledged. This PSA today does just that.

Our PSA today works to address these allegations and correct them.

We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job. Whether it be a Special Agent or any other role within your agency. The following FBI services were compromised: Criminal Justice (CJ), HR, Medlink, and more.

We are willing to allow you a time of 1 week to correct or simply REMOVE the 2026 Quarter 2 FLASH report on us that includes several FALSE allegations:

- "Threat actors often use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims. "
- "To exert pressure on victims[1], SH actors commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting"
- " Threat actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist."

We wish to state unequivocally our threats and claims are very real. Not exaggerated and never a bluff. This PSA today is living evidence of that.
We wish to state unequivocally we have NEVER conducted swatting attacks against corporate victims personnel nor have we ever texted victims personnel family members any threats.
We wish to state unequivocally we have NEVER claimed to have sensitive or compromising information, including embarrassing photographs and videos of victims. WE ARE NOT SEXTORTIONISTS.

Finally, we wish to STATE UNEQUIVOCALLY we are NOT apart of "The Com". We have NEVER been apart of "The Com". "The Com" is a propaganda started by the Information Security Industry which has brainwashed past FBI and DOJ officials into formalising this nonsense.

As a big believer and supporter of the U.S. Constitution - we are exercising the First Amendment and actively combating disinformation. This is not a ransom, coercion, or extortion. Your federal policies do not apply here. This PSA is NOT financially motivated.

We recognise that certain statements within your FLASH report appear to stem from biased public reporting by certain journalists who have previously and intentionally propagated false narratives about our organisation in an attempt to "disrupt" our operations and hinder clients trust in our organisation hoping nobody pays us. Should those certain journalists and you know very well who you are, continue these unwarranted attacks and defamatory statements, we will be forced to respond in a civil manner with a commensurate and forceful defence of our reputation. As any human being would do.

We welcome any and all journalists to inquire us at shinygroup@onionmail.com to hear our side of the story.

Make the right decision, don't be the next headline.

Thank you for your attention to this matter. -SH"

Critical Vulnerability in F5 BIG-IP APM (CERT-EU Security Advisory 2026-013)

On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild.
CERT-EU recommends taking appropriate actions as soon as possible.

cert.europa.eu/publications/se

🚨 Android spyware and RAT source code advertised for $500

A forum actor using the handle "greekdev" is advertising an Android surveillance application, including its client source code, server code, and web-based control panel.

Some of the claimed capabilities include:

• Live microphone, camera, and screen monitoring
• Call recording across messaging apps
• Keylogging, SMS tracking, and notification interception
• Access to files, contacts, and browsing history
• Remote device control and protection against removal

The actor promises updates for future Android versions, including Android 17, and requires payment through forum escrow.

This claim is currently unverified.

💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing

Boosts

I think the photographer for the listing of this abandoned station house likes the freaky aesthetic 😆

It's from this rightmove listing rightmove.co.uk/properties/927

An