E-Commerce Access, Vedicline Data, Langflow RCE, ASUS Claim, and Energy Shell Access
SOCRadar found dark web posts selling stolen customer data from a Bangladeshi e-commerce site and Vedicline, an Indian beauty brand. Attackers also claim to sell access to an ASUS database and exploit a zero-day flaw in Langflow 1.12.0 to take over systems remotely.
- Report priority
- High
What is known
- Attackers claim to sell stolen customer records from a Bangladeshi e-commerce site and Vedicline, including names, phone numbers, and addresses.
- They also advertise direct database access and a zero-day exploit for Langflow 1.12.0 that lets them run commands on targeted systems without permission.
- The ASUS database sale suggests stolen login details or system access, while the energy sector shell access implies remote control over an Indian energy company's systems.
What to do
Check if your details appear in leaked databases by searching your email or phone number on breach databases like Have I Been Pwned. If you use Langflow 1.12.0, update immediately to avoid remote code execution attacks. ASUS users should check if their systems were part of a database leak by reviewing recent login activity or contacting ASUS support. For the energy sector shell access, only the unnamed Indian organization is directly affected.
If you recognize your details in leaked databases, monitor your accounts for suspicious activity and enable two-factor authentication. Update Langflow to a version later than 1.12.0 to patch the zero-day exploit. ASUS users should review their system logs for unauthorized access and contact ASUS support if you suspect a breach. The Indian energy sector organization should follow its internal incident response procedures and contact SOCRadar or the relevant authorities for further guidance.
Claim from the attackers
E-Commerce Access, Vedicline Data, Langflow RCE, ASUS Claim, and Energy Shell Access SOCRadar Dark Web Team identified several new underground posts, including an alleged Bangladeshi e-commerce customer database sale, an alleged Vedicline customer database sale, and a claimed Langflow 1.12.0 zero-day RCE exploit. Other posts advertised an alleged ASUS database and shell access to an Indian energy sector organization. Receive a Free Dark Web Report for Your Organization: Alleged Bangladeshi E-Commerce Customer Database is Offered for Sale SOCRadar Dark Web Team detected a threat actor post on a dark web forum advertising an alleged database containing 1,762,697 customer records linked to a Bangladeshi e-commerce or retail environment.
The seller claimed the dataset was mostly dumped from an e-commerce or PoS database and shared it in CSV format. According to the listing, the exposed data includes customer names, phone numbers, and physical addresses. The actor asked for $500 and claimed the sale would be limited to only two buyers.
The post also stated that direct access to the underlying database could be provided, which raises the risk beyond a static data sale if the claim is accurate. Alleged Vedicline Customer Database Sale is Detected SOCRadar Dark Web Team detected a threat actor post advertising an alleged database linked to Vedicline.com, an Indian beauty and wellness brand. The listing claimed the dataset contains 100,000 records and includes fields such as first name, last name, address, city, state, postcode, country, email, phone, and company.
The exposure is notable because the data appears to contain customer contact and location details, which can support targeted phishing, identity fraud, and scam campaigns. The source also notes the presence of hashed password entries, which raises account takeover risk if any hashes are cracked and reused across other services. Alleged Langflow 1.12.0 RCE Exploit Sale is Detected SOCRadar Dark Web Team detected a threat actor post claiming to sell an alleged zero-day RCE vulnerability affecting Langflow 1.12.0.
The seller claimed the exploit was tested in the real world and said they successfully obtained a valid OpenAI API key during exploitation. The exploit was advertised for $2,000, with payment accepted in BTC or RMB.
Reported details
An attacker posts on a dark web forum offering 1.7 million customer records from a Bangladeshi e-commerce site for $500, claiming the data includes names, phone numbers, and physical addresses. The seller also promises direct database access, raising risks beyond a simple data dump.