PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
Kalir Brief · Item24 September 2026 · 07:51 UTC
BRIEFLeakhighP52

Binance database of 1.5 million users for sale

Binance

Detected24 September 2026 · 07:51 UTC
Why it matters

A carding-forum seller claims to hold a 1.5-million-record Binance user database, likely assembled from credential stuffing or an older breach. If genuine it exposes crypto customers to account takeover and targeted phishing. Binance's large Latin American user base makes it relevant, though the recycled '2026' framing suggests limited freshness.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score52
Detected24 September 2026 · 07:51 UTC
Related items6
Leak38
Stealer log de 357.000 credenciales URL:login:pass publicadoA stealer log containing roughly 357,000 URL:login:password entries was released by 'Napoleon' and mirrored across several forums. Stealer logs pair credentials with the exact site and often session data, making them directly usable for credential stuffing and account takeover. Although not region-specific, the volume and freshness justify checking for your users' corporate credentials.
38m
Leak40
Dump de 960.000 credenciales URL:login:pass publicadoA forum user published a 960,000-line URL:login:password credential dump labelled 'UHQ FRESH SEP', indicating recently harvested stealer/combolist data. The scale and 'fresh' label mean many entries are likely still valid, feeding credential stuffing, account takeover and initial-access attempts across many services. Defenders should enforce credential-stuffing detection and MFA on any exposed accounts.
38m
Leak45
Cookies de sesión activas de Walmart, LinkedIn y redes sociales a la ventaA threat actor is trading '2f' accounts for Walmart, LinkedIn, Nextdoor, Instagram, Facebook and Twitter bundled with active email session cookies, i.e. takeover-ready access rather than plain credentials. Active cookies let buyers bypass passwords and often 2FA, enabling immediate account takeover and lateral phishing. Organizations on these platforms should force re-authentication and hunt for anomalous session activity.
38m
Leak72
Filtración de la base de datos de Bureau van Dijk (Orbis) a la ventaA DarkForums seller is offering a 2025-2026 leak of Bureau van Dijk's corporate data, the Moody's-owned Orbis business-intelligence platform (posted 21 Sep 2026). It holds financial, ownership and executive records on millions of companies worldwide. If genuine, this is high-value corporate/KYC intelligence for BEC, fraud and supply-chain mapping, so defenders should watch for downstream abuse of leaked business records.
38m
Leak74
Filtración de 42 GB de datos de McDonald's EcuadorA threat actor is distributing a 42 GB dataset allegedly exfiltrated from mcdonalds.com.ec, the Ecuadorian McDonald's operator. A volume that large usually contains customer, HR, supplier and internal business records, enabling fraud, phishing and follow-on intrusion. It signals an active breach of a major consumer brand in Latin America, worth alerting regional defenders.
2h
Leak33
Filtración de datos de 34.500 clientes de Ronis AustraliaA threat actor posted a database containing 34,500+ customer records belonging to the Australian company Ronis on a leak forum in mid-June 2026. The dataset likely holds customer PII usable for phishing, fraud, and credential abuse. It is a genuine named-org leak, but it is outside the AR/LATAM region and already weeks old, so it is not a fresh alert.
3h