PULSE
FEED
vulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOS
Kalir Brief · Item22 September 2026 · 13:49 UTC
BRIEFLeakhighP32

Leaked 15,000-record KYC collection (Alphaex.net)

Alphaex.net

Detected22 September 2026 · 13:49 UTC
Why it matters

A collection of roughly 15,000 KYC records, including passports and driving licenses linked to Alphaex.net, is being traded on underground forums. These verified identity documents enable account-opening fraud and KYC bypass for financial services. Regional relevance is low, but it remains a meaningful identity-theft supply that fraud teams should flag.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score32
Detected22 September 2026 · 13:49 UTC
Related items6
Leak38
Filtración de 3,5 GB de pasaportes y documentos de identidad de EAUA 3.5 GB archive of UAE passports and national ID documents is being circulated on underground forums, exposing high-value identity data usable for forgery and account takeover. Government-issued document dumps like this fuel KYC bypass and cross-border identity fraud. Although not regional and likely an older thread, the material can be reused against regional targets so it is worth tracking.
34m
Leak40
Combolist dirigida al dominio telefonica.net (Telefónica)A forum user published a ~5,919-line credential list sorted and targeted at the telefonica.net domain (Telefonica). Although small, it is a named telecom target with extensive Latin America and Spain operations, making it useful for credential stuffing against corporate mail and VPN portals. Defenders should force credential rotation and MFA on affected accounts and watch for reused passwords.
1h
Leak70
Filtración de base de datos con 945.000 clientes de ChileA threat actor is distributing a database containing roughly 945,000 complete customer records from Chile via a BreachForums leak channel. The volume and per-customer detail suggest it can fuel identity theft, phishing and credential-stuffing against Chilean consumers. Defenders in Chilean finance, retail and telecom should treat it as a fresh regional exposure and monitor for downstream fraud.
1h
Leak40
Combolist de 253.000 credenciales de correo de BrasilA 253,000-line Mail:Pass combolist targeting Brazilian email accounts was posted in 2026 as a fresh 'unique combo'. Dumps of this size expose a large victim pool to account takeover and are frequently reused in region-focused phishing and fraud. Brazilian users, ISPs and banks should treat it as an active credential-reuse risk.
2h
Leak24
Filtración de 2,1 millones de credenciales URL:LOG:PASSA private 2.1-million-line URL:LOG:PASS credential dump was posted to DarkForums. Dumps this size fuel credential-stuffing across many services and can contain valid corporate logins. However, the post dates to July 2025, so the data is stale and now of mostly background value for defenders.
2h
Leak42
Filtración de base de datos de la Universidad Lambung MangkuratA database from Universitas Lambung Mangkurat, a public university in Indonesia, was published on BreachForums. Such leaks typically expose student and staff PII, academic records and contact data, enabling downstream phishing and credential reuse. Track it as a confirmed named-organization breach, although it falls outside the AR-LATAM region.
2h