PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
Kalir Brief · Item17 September 2026 · 06:12 UTC
BRIEFLeakhighP72

Database of 1 million+ IKEA users' personal data for sale

IKEA

Detected17 September 2026 · 06:12 UTC
Why it matters

A threat actor is offering personal information of more than one million IKEA users, a large customer database exposed in a fresh post. The scale and recency make it valuable for credential stuffing, phishing and retail fraud against consumers. Defenders should monitor for downstream abuse while IKEA confirms scope and notifies affected users.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score72
Detected17 September 2026 · 06:12 UTC
Related items6
Leak40
Venta de base de datos mundial de filtraciones de la dark web de 7,8 TBA seller is advertising a 7.8TB aggregated collection of worldwide dark web leaks for sale. Although it is a repackaged multi-source bundle rather than a single new breach, it can surface credentials and PII relevant to many organizations. Defenders should treat it as a monitoring lead and check whether their own data appears in such collections.
54m
Leak45
Filtración de base de datos de la consultora CprimeA leaked database attributed to Cprime, a US-based IT and agile consulting firm, has been posted on a forum. If genuine it could expose corporate and client contact data usable for targeted phishing and business email compromise. Verification and scope assessment are needed to gauge the real impact.
2h
Leak67
Base de datos de 200 millones+ de usuarios de Telegram a la ventaA database with over 200 million Telegram records mapping usernames to phone numbers is circulating in a leak forum. Such a dataset enables mass doxxing, SIM-swap, phishing and linking of pseudonymous accounts to real identities. It is valuable to defenders tracking Telegram-linked threat actors and to fraud and anti-abuse teams worldwide, including in Latin America.
2h
Leak85
Filtración de base de datos del estado de Pernambuco (9 millones)A database covering roughly 9 million residents of the Brazilian state of Pernambuco is being offered on BreachForums, likely including full names, CPF/ID numbers, addresses and contact data from state registries. This is a government breach in Latin America, so the data can fuel identity fraud, social engineering and targeting of public services. Defenders in the region should assume the records are exposed and prepare for credential-stuffing and phishing against citizens.
2h
Leak42
Venta de dataset de 536K usuarios saudíes de TalabatA seller offers a 536K-record dataset allegedly from Talabat, the Saudi Arabian food-delivery platform, dated 13 Sep. Customer PII of a large regional service can drive phishing and account takeover. It is outside the AR-LATAM focus and mid-sized, so lower priority.
3h
Leak45
Filtración de datos personales nacionales de Australia (438K)A post offers an Australia national personal data leak of 438,522 records including first and last names, dates of birth and phone numbers. This is enough for identity theft and convincing phishing against Australian residents. It falls outside the AR-LATAM remit but is a genuine, sizable PII exposure.
3h