PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
Kalir Brief · Item21 September 2026 · 17:37 UTC
BRIEFLeakhighP57

PayPal database (ULP) for sale in HellSkey breach

PayPal

Detected21 September 2026 · 17:37 UTC
Why it matters

A posting advertises a 'HELLSKEY BREACH' PayPal database in ULP (URL/login/password) format dated 2026. Credential sets for a major payment platform fuel account takeover, card fraud and downstream phishing campaigns. Validate the sample and brief fraud and SOC teams.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score57
Detected21 September 2026 · 17:37 UTC
Related items6
Leak35
Filtración de base de datos de TotalEnergies (50K registros)A database of over 50,000 records attributed to energy major TotalEnergies is being shared on a breach forum, dated January 2026. Energy firms are critical infrastructure, so exposed employee or customer data raises phishing and intrusion risk. The post is months old, so treat it as background intelligence rather than a fresh alert.
32m
Leak48
Filtración de base de datos de pasaportes e identidades de IsraelA hacking forum thread advertises a full database of Israeli passports and identity records under a 2026 fresh-leaks section. National identity data of this kind enables impersonation, large-scale fraud and targeting of citizens. Confirm scope and provenance before acting.
32m
Leak68
Volcado de datos internos del servicio de inteligencia de IrakA threat actor is offering early access to what is claimed to be an internal data dump from Iraq's intelligence services, posted in 2026 on a breach forum. If authentic it exposes sensitive state files usable for espionage, doxxing of officials and further targeting of government networks. Verify the sample and track reuse by other actors.
32m
Leak60
Filtración de un millón de correos de clientes de CoinbaseA forum user is distributing roughly one million Coinbase customer email addresses covering 2024-2026, with 50k shared as free samples. Although emails alone are lower impact, the volume and brand make it valuable for phishing and account-takeover against crypto users. Warn and monitor affected customers.
2h
Leak48
Filtración de 763K correos de usuarios de BitMartAn attacker claims to have leaked 763,000 BitMart customer email addresses, posted on an onion leak forum. Crypto-exchange user lists fuel credential-stuffing, wallet-drain phishing and SIM-swap attacks against account holders. It is a mid-size leak of a financial platform and is several months old, so it is relevant but not a fresh regional alert.
2h
Leak42
Combolist de 180.000 credenciales de Colombia a la ventaA bulk combolist of roughly 180,000 Colombian credentials dated 11 August 2026 is being circulated. Such lists fuel credential-stuffing and account takeover against Colombian services and users, indicating fresh regional credential theft. Defenders in Colombia should force resets and monitor for credential reuse.
3h