PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
Kalir Brief · Item24 September 2026 · 06:51 UTC
BRIEFAccess salehighP50

Admin access to Horizane database offered for sale

Horizane

Detected24 September 2026 · 06:51 UTC
Why it matters

A forum post advertises administrative access obtained through a database breach of an entity called 'Horizane'. Admin-level access can enable full data exfiltration, backend control, and lateral movement against the victim. The target and date are unclear, but access-to-database offerings like this are directly actionable for defenders monitoring initial-access brokers.

MetadataRECORD
CategoryAccess sale
Severityhigh
Priority score50
Detected24 September 2026 · 06:51 UTC
Related items6
Access sale44
Venta de 0-day RCE y escalada de privilegios localA seller on a Tor marketplace is offering a zero-day remote code execution chain plus local privilege-escalation and information-leak exploits, posted on 2026-09-21. No specific victim is named, so the risk is sector-agnostic, but unpatched RCE is a common entry point for enterprise and government intrusion. Defenders should track this actor and hunt for exploitation attempts.
8h
Access sale40
Venta de acceso de administrador al sitio keniano TikohubA threat actor is offering administrative access to Tikohub.co.ke, a Kenyan online store. Admin-level access enables full site takeover, customer data theft and payment/checkout manipulation. The listing is from April 2026 and the target is outside the LATAM region, so its urgency for AR-LATAM defenders is limited.
9h
Access sale52
Exploit de día cero de WordPress con webshell automáticaA seller is advertising a private WordPress zero-day brute-force exploit bundled with automatic webshell upload, posted as recently as late September 2026. Such a tool enables mass compromise of vulnerable WordPress sites, granting attackers persistent remote access. Defenders hosting WordPress should prioritize patching and monitor for unexpected PHP files and webshells.
1d
Access sale48
Venta de acceso a base de datos de ciudadanía de un país de la CEIA seller is offering live access to a government citizenship database belonging to an ex-Soviet/CIS country on a .gov domain. Live database access lets buyers query and exfiltrate citizen records on demand, a serious state-grade exposure. It is outside Latin America but shows an active market for direct government database access.
1d
Access sale55
Venta de RCE y 0days de escalada local (ROTR)A seller is advertising RCE exploits, an information leak, and local privilege-escalation 0-days under the 'ROTR' label, posted 2026-09-21. Fresh, working exploits of this type enable rapid intrusion into unpatched systems. Although no specific victim is named, defenders should track it for imminent exploitation activity.
1d
Access sale38
Venta de acceso admin al portal educativo australiano eit.edu.net.auA forum user is advertising administrator-level access to eit.edu.net.au, an Australian education site, dated March 2026. Admin access to an academic portal can enable data theft, defacement or lateral movement into connected systems. The listing is already months old, so it is a stale access offer rather than a live incident.
1d