PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
Kalir Brief · Item17 September 2026 · 02:12 UTC
BRIEFLeakhighP58

29.29 million URL:LOG:PASS credential base published

Detected17 September 2026 · 02:12 UTC
Why it matters

A 29.29 million-line URL:LOG:PASS stealer log is being shared privately as a supposedly fresh base. It contains credentials harvested from infected devices, enabling credential-stuffing, account takeover and fraud at scale. Organizations should assume corporate credentials are exposed and enforce MFA and password resets.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score58
Detected17 September 2026 · 02:12 UTC
Related items6
Leak50
Logs robados con 6,11 millones de credenciales a la ventaA 6.11 million-entry URL:LOG:PASS stealer log (DAXUS.PRO) is advertised as a private, high-quality base. It holds credentials stolen from infected machines and is useful for account-takeover and credential-stuffing. Monitor for reuse of leaked corporate credentials.
59m
Leak66
Base de datos de 7,6 millones de clientes de Coinbase en ventaA 7.6 million-record Coinbase customer dataset tied to a 2025 breach is being reposted for download. It likely includes names, emails, phone numbers and account data usable for phishing and SIM-swap fraud. Crypto holders and exchanges face targeted social engineering.
59m
Leak47
Filtración de la base de datos de Younow.comA full database attributed to Younow.com is being shared on the DarkNetArmy forum, posted today. While the exact record count is not yet detailed, leaked user records of a live-streaming/social platform feed credential stuffing, phishing and account-takeover campaigns. Platform operators and defenders of downstream identity providers should verify the exposure and force resets if valid credentials are confirmed.
2h
Leak54
Filtración de la base de datos de la empresa colombiana sosltda.comA database belonging to the Colombian firm sosltda.com is being distributed on a dark web forum as a 2026 leak. It exposes the organization's internal/customer records to anyone who downloads it, enabling fraud and targeted attacks. Colombian and regional defenders should verify scope and notify affected parties.
3h
Leak32
Base de datos de una repartidora marroquí con 500.000 registrosA full database belonging to a large Moroccan delivery company, roughly 500,000 records, was posted for sale on DarkNetArmy. It is a mid-sized corporate leak outside the AR-LATAM region, more relevant to the affected company than to regional defenders. It is notable only as another logistics-sector data exposure.
4h
Leak38
Volcado de 40 millones de credenciales URL:LOGIN:PASSWORDA private 40 million line URL:LOGIN:PASSWORD stealer log was published on 16/09/2026, indicating freshly harvested infostealer credentials. It is a generic aggregated dump without a named victim, so its direct relevance to AR-LATAM is limited. It still matters as a source of valid credentials that may enable account takeover if re-used broadly.
4h