PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSS
Kalir Brief · Item12 September 2026 · 01:12 UTC
BRIEFAccess salehighP78

Admin access and defacement at Universidad César Vallejo (Peru)

ucv.edu.pe (Universidad César Vallejo, Perú)

Detected12 September 2026 · 01:12 UTC
Why it matters

Threat actor Keishell posted admin-level access to ucv.edu.pe, the Universidad César Vallejo in Peru, along with a website defacement, claiming over 200,000 students affected. This exposes student PII, staff credentials and internal systems to further intrusion or fraud. A large Latin American university is a valuable target for both data theft and reputational disruption.

MetadataRECORD
CategoryAccess sale
Severityhigh
Priority score78
Detected12 September 2026 · 01:12 UTC
Related items6
Access sale74
Venta de acceso de administrador a la infraestructura FTTH/GPON del ISP AlfatihnetA seller is offering administrative access to the FTTH/GPON infrastructure of ISP Alfatihnet, i.e. management control of a telecom operator's access network. Compromise of an ISP access layer enables traffic interception, subscriber data theft and mass service disruption across all customers. Telecom operators should verify and rotate credentials on exposed management interfaces immediately.
3h
Access sale66
Venta de acceso admin a plataforma internacional de apuestasA seller on BreachForums is offering administrative access to a major international sportsbook platform. Admin-level access to a betting platform enables mass account manipulation, fraud, and theft of customer funds and data. Such access is time-sensitive and typically monetized quickly, so defenders in gaming and finance should treat it as actionable.
14h
Access sale50
Venta de datos bancarios y credenciales de Color Communications LLCA carding-forum listing offers bank account data, check images, and login credentials belonging to Color Communications LLC, a named corporate victim. If genuine, the material enables direct account takeover and fraudulent payments against the company. Defenders should corroborate with the organization and monitor for fraudulent transactions and credential misuse.
1d
Access sale46
Exposición de API ugdpay y Jenkins del portal digital.gov.mgCredentials and configuration for the ugdpay payment API and a Jenkins CI server on Madagascar's digital.gov.mg portal were posted on a criminal forum. Exposed CI/CD and payment-API access can let an attacker pivot into government infrastructure or manipulate transactions. It should be treated as a live initial-access opportunity against a national government system.
1d
Access sale42
Venta de accesos de administrador a paneles WordPress comprometidosA seller is offering verified administrator-level access to compromised WordPress installations, likely a bulk list of hijacked admin panels. No specific victim or region is named, so the direct impact is unclear, but stolen CMS admin access is commonly reused for webshell deployment, SEO poisoning and malware hosting. Defenders should treat it as a reminder to audit WordPress admin authentication and monitor for unauthorized admin logins.
2d
Access sale46
Credenciales de acceso SSL VPN Fortinet obtenidas por fuerza brutaThe actor claims a batch of freshly brute-forced Fortinet SSL VPN credentials, i.e., remote-access footholds into enterprise networks. Valid SSLVPN credentials are a high-value initial-access vector for ransomware and lateral movement, and Fortinet appliances remain a top target. No victim is named, which lowers confidence, but any exposed Fortinet access warrants review of your own edge devices.
2d