PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / Server
Global Risk · Today03:37 AM UTC

91

Ransom IndexELEVATED
65%vs yesterday
Percentile43of 100
Trend · 7D
Peak112360 days
Projection · 24H105–138
Threat Level

ELEVATED

Elevated global threat

    Top Actor
    DarkSide

    DarkSide

    DOMINANT7530CLAIMS · 7D
    VIEW ACTOR PROFILE
    BRIEF OF THE DAY· 03:37 AM UTC
    RANSOM91.0LEAK21.6MKEV10

    Moderate window in the underground: 29 ransom victims claimed vs 31.8/day baseline — in line with the average. Thegentlemen leads with 16 claims in Professional Services / Manufacturing (United States, India) — Glassdoor, G R Infraprojects. followed by Qilin with 4. On leaks, 21.6M accounts flowed into the feed over 7d (top: Carhartt - 12,933,413 breached accounts). 10 CVEs entered the KEV catalog over 7d (CVE-2023-49105). Kalir surfaced 1 critical underground item in the last 24h (top: Leak — a top-priority item).

    AUTO

    RANSOM IDX

    91.0 +65%

    29 victims claimed today vs baseline 31.8/day — activity in line with the average.

    Top countries (7d)

    • USUnited States54
    • GBUnited Kingdom14
    • BRBrazil8

    Kalir Brief · 24h

    CROSS-SOURCE
    Leak90
    Filtración masiva de 250 millones de credenciales de registros stealerA private dump of 250 million URL:LOGIN:PASSWORD entries from stealer logs was published on August 30, 2026. This represents a massive trove of credentials that could be used to access diverse online services, including potentially corporate and personal accounts. Defenders should treat any credentials from stealer logs as compromised and enforce password resets, MFA, and dark web monitoring.
    9h
    Leak80
    Filtración de base de datos de control vehicular de la Fiscalía de CoahuilaThe Coahuila Prosecutor's Office vehicle control database has been leaked on a dark web forum. The dataset likely contains vehicle registration and ownership records from a Mexican state government, useful for identity fraud and extortion. This is a fresh, government-related data exposure relevant to Latin American defenders.
    8h
    Leak78
    Filtración de base de datos de la empresa de IA mercor.comA seller is offering the source code, user database, and contractor database of mercor.com, an AI training company based in the USA. The leak likely contains source code and personal data of users and contractors, which could facilitate further attacks. This is a significant breach of a real organization and warrants immediate monitoring.
    13h
    Leak75
    Divulgación de más de 10 millones de credenciales URL:LOGIN:PASSWORD de StarLinkCloudsA large dump containing more than 10 million URL:LOGIN:PASSWORD lines attributed to Secretline.top and StarLinkClouds has been posted on a breach forum. The data likely originates from stealer malware and could facilitate account takeovers across many platforms. Organizations should check these credentials for exposure and implement phishing-resistant MFA.
    9h

    External feed

    CURATED
    • Dark Reading[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AInow
    • Dark Reading[Virtual Event] Building a Secure AI Strategy for the Enterprisenow
    • Dark ReadingGISEC GLOBALnow

    Pulse's first editorial note is about to publish. Meanwhile, here's what the data says.

    Enter the admin →
    BY REGION · 24H
    0events · 24h
    RANSOM
    LEAK
    VULN
    0
    NA
    0
    EU
    0
    APAC
    0
    LATAM
    0
    MEA
    Top Origins (7d)VIEW WIRE →
    US
    United States54
    GB
    United Kingdom14
    MX
    Mexico8
    BR
    Brazil8
    DE
    Germany7
    AU
    Australia6
    AR
    Argentina5
    IN
    India4
    ORIGINAL · CTI
    More editorial coming.
    CROSS-SOURCE
    Leak95
    Filtración de Serasa: respaldo de 500 GB a la ventaA 500 GB backup from Serasa, Brazil's largest credit bureau, is being sold on a darknet forum. The archive likely contains personal, financial and credit data of millions of Brazilian consumers. This is a critical exposure that requires immediate verification and fraud monitoring.
    3d
    Gov / Military92
    Filtración de la base de datos del Boletín Oficial de ArgentinaAn unknown actor has leaked the database of Argentina's official gazette (Boletín Oficial Electrónico). The post claims to offer records from the BOE, which may include official government notices and sensitive administrative data. This constitutes a direct compromise of a national government platform and warrants immediate incident response.
    4d
    Leak90
    Filtración masiva de 250 millones de credenciales de registros stealerA private dump of 250 million URL:LOGIN:PASSWORD entries from stealer logs was published on August 30, 2026. This represents a massive trove of credentials that could be used to access diverse online services, including potentially corporate and personal accounts. Defenders should treat any credentials from stealer logs as compromised and enforce password resets, MFA, and dark web monitoring.
    9h
    Access sale90
    Venta de acceso a API de RENAPER y bases de datos gubernamentales de ArgentinaA seller is offering access to an API service tied to RENAPER, Argentina's national identity registry, along with other government databases. This would allow doxing, identity theft, and large-scale fraud against Argentine citizens. It is a direct threat to critical government infrastructure and must be treated as a high-priority incident.
    2d
    Global WiresCURATED
    Underground Indices· daily reading