PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
Kalir Brief · Item18 September 2026 · 20:12 UTC
BRIEFLeakhighP45

BitMax.io crypto exchange database offered for sale

BitMax.io

Detected18 September 2026 · 20:12 UTC
Why it matters

An actor posted a database attributed to the crypto exchange BitMax.io on a dark web forum. Exchange user data drives credential-stuffing, phishing and targeted wallet theft, and the listing appears freshly posted. Crypto sector defenders should verify scope and force credential resets if the data is confirmed.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score45
Detected18 September 2026 · 20:12 UTC
Related items6
Leak50
Base de documentos de Brasil con 780.000 registros a la ventaA 780,000-record document dataset from Brazil is being shared as 'part 1 of Latin America', signalling a broader regional leak campaign. It contains personal document data useful for fraud, account takeover and impersonation against Brazilian individuals. Regional defenders should anticipate follow-up parts targeting other LATAM countries.
56m
Leak55
Base de datos de clientes de Ledger (309.000 registros) a la ventaAn actor is offering a database of about 309,000 Ledger customer records allegedly stolen in 2026, including personal and contact data of crypto wallet users. Such data feeds phishing, SIM-swap and physical-extortion campaigns against high-value crypto holders. Defenders and crypto users should treat it as a fresh, actionable exposure even if the exact provenance needs verification.
56m
Leak60
Filtración de 55 GB de la app Tea expone chats y documentosA 55 GB dump from the Tea app is being freely distributed, containing private chats, direct messages, verification documents, licences and selfies. The scale and the presence of government-issued ID images make it a serious privacy and identity-fraud exposure for the app's user base. Defenders monitoring leaked KYC/document troves should flag it for downstream impersonation and sextortion risk.
56m
Leak88
Filtración de datos médicos de 6,6 millones de pacientes de EcuadorA threat actor posted on a dark web forum a database with 6.6 million patient records from Ecuador, including medical and personal data. This hits a Latin American healthcare sector target directly and enables identity theft, insurance fraud and targeted extortion of citizens. Ecuadorian health entities and regional defenders should treat this as a high-priority exposure and check for downstream credential reuse.
56m
Leak42
Venta de 185 millones de leads B2B extraídos de ZoomInfoAnother seller is marketing a 185 million record B2B lead database sourced from ZoomInfo, containing corporate names, emails and phone numbers. Though it is an aggregated marketing dataset rather than a named-victim breach, its size and recency make it useful for large-scale social engineering and business email compromise campaigns.
4h
Leak46
Base de datos de 486 millones de contactos B2B de Apollo.io a la ventaA seller is offering a 486M+ record dataset of business contacts (names, emails, phone numbers and company data) attributed to Apollo.io. It is a scraped/aggregated B2B corpus rather than a fresh breach, but its scale makes it valuable for targeted phishing and business-email-compromise against organizations worldwide, including in Latin America.
4h