E-Commerce Access, Vedicline Data, Langflow RCE, ASUS Claim, and Energy Shell Access
SOCRadar Dark Web Team identified several new underground posts, including an alleged Bangladeshi e-commerce customer database sale, an alleged Vedicline customer database sale, and a claimed Langflow 1.12.0 zero-day RCE exploit. Other posts advertised an alleged ASUS database and shell access to an Indian energy sector organization.
Receive a Free Dark Web Report for Your Organization:
Alleged Bangladeshi E-Commerce Customer Database is Offered for Sale

SOCRadar Dark Web Team detected a threat actor post on a dark web forum advertising an alleged database containing 1,762,697 customer records linked to a Bangladeshi e-commerce or retail environment. The seller claimed the dataset was mostly dumped from an e-commerce or PoS database and shared it in CSV format.
According to the listing, the exposed data includes customer names, phone numbers, and physical addresses. The actor asked for $500 and claimed the sale would be limited to only two buyers. The post also stated that direct access to the underlying database could be provided, which raises the risk beyond a static data sale if the claim is accurate.
Alleged Vedicline Customer Database Sale is Detected

SOCRadar Dark Web Team detected a threat actor post advertising an alleged database linked to Vedicline.com, an Indian beauty and wellness brand. The listing claimed the dataset contains 100,000 records and includes fields such as first name, last name, address, city, state, postcode, country, email, phone, and company.
The exposure is notable because the data appears to contain customer contact and location details, which can support targeted phishing, identity fraud, and scam campaigns. The source also notes the presence of hashed password entries, which raises account takeover risk if any hashes are cracked and reused across other services.
Alleged Langflow 1.12.0 RCE Exploit Sale is Detected

SOCRadar Dark Web Team detected a threat actor post claiming to sell an alleged zero-day RCE vulnerability affecting Langflow 1.12.0. The seller claimed the exploit was tested in the real world and said they successfully obtained a valid OpenAI API key during exploitation.
The exploit was advertised for $2,000, with payment accepted in BTC or RMB. If the claim is valid, exploitation could allow arbitrary code execution on affected Langflow instances, exposing stored API keys, credentials, application data, and connected LLM service access.
Alleged ASUS Database Sale is Detected

SOCRadar Dark Web Team detected a threat actor post claiming to sell an alleged ASUS database totaling 1,023.67 GB. The actor provided limited detail about the contents and directed buyers to Telegram, requesting payment in Bitcoin.
The claim should be treated cautiously because the post did not provide specific sample fields or strong technical evidence in the available material. However, if authentic, a terabyte-scale database exposure could create serious risks involving corporate data, customer information, credentials, or internal operational records.
Alleged Indian Energy Shell Access Sale is Detected

SOCRadar Dark Web Team detected a threat actor post advertising alleged shell access to an Indian energy sector organization. The listing described the target as a Linux environment, claimed the organization has $346 million in revenue, and noted SentinelOne as the observed endpoint protection.
The actor stated that the access is not in Active Directory, but claimed there are additional hosts in the network. This makes the listing important from an initial access perspective, because even limited shell access can become a foothold for lateral movement, data theft, ransomware deployment, or long-term intrusion activity against critical infrastructure.
Powered by DarkMirror™
Gaining visibility into deep and dark web threats can be extremely useful from an actionable threat intelligence and digital risk protection perspective. However, monitoring all sources is simply not feasible, which can be time-consuming and challenging. One click-by-mistake can result in malware bot infection. To tackle these challenges, SOCRadar’s DarkMirror™ screen empowers your SOC team to follow up with the latest posts of threat actors and groups filtered by the targeted country or industry.

