■ INFO#EDITORIAL#BY JORDANDisclosed2026-05-15Added to DMZ2026-05-15
Why I'm Building DMZ
I served nine years in the Navy as an Aviation Boatswain's Mate before I ever touched a SIEM. A year into my first analyst role, I started building DMZ — the threat intel publication I wish existed when I was sitting at my desk a year ago,…
■ HIGH#DARK WEB#BREACH
VECT RaaS x BreachForums Partnership — Affiliate Keys Now Active for TeamPCP Victim Pool
We are formalizing our operational partnership with ███████. All 300,000 members of this forum are eligible for a personal affiliate key. ████████████. Together we are ready to deploy ransomware across all affected companies. We will chain…
■ MEDIUM#DARK WEB#BREACH
FATETRAFFIC 2070 MIX — Infostealer Log Dump [5,777 logs / 2,070 creds]
Releasing 5,777 individual infostealer logs harvested as recently as ████████████. Dataset contains 2,070 unique email/password combos. Distributed via ████████████. Mix includes browser-saved passwords, session cookies, and sensitive…
■ CRITICAL#ACTOR#NATION-STATE
SAPPHIRE SLEET
Amazon Web Services Threat Intelligence publicly attributed a sustained npm supply-chain campaign to Sapphire Sleet on July 29, 2026, connecting four previously unlinked package compromises — typo-crypto (Mar 2025), debug and chalk (Sep…
■ CRITICAL#ACTOR#NATION-STATE
KIMSUKY
ENKI WhiteHat published a full technical analysis on July 20, 2026, disclosing that Kimsuky spent nearly a year embedded inside at least two South Korean enterprise groupware vendors, deploying two previously unknown Linux backdoors —…