PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-central
Kalir Brief · Item17 September 2026 · 04:12 UTC
BRIEFAccess salelowP35

Buyer seeking government email accounts on underground forum

Detected17 September 2026 · 04:12 UTC
Why it matters

A user on DarkForums posted a request to buy government email accounts, a demand signal for access to public-sector mailboxes. Such buyers typically pursue espionage, invoice fraud or further intrusion via trusted government addresses. No specific victim is named, so impact is potential rather than confirmed.

MetadataRECORD
CategoryAccess sale
Severitylow
Priority score35
Detected17 September 2026 · 04:12 UTC
Related items6
Access sale61
Venta de acceso a la base de datos del hospital de la Fuerza Terrestre del IRGC (Irán)A seller on BreachForums is offering full database access to the IRGC Ground Force Hospital, a military medical facility. Selling direct database access to a named military target is a high-value access offering, not generic chatter, and could enable further intrusion or extortion. CTI teams tracking regional military/healthcare threats and any partners with Iranian exposure should monitor this listing.
5h
Access sale72
Venta de acceso OT a un PLC SLC 500 en PoloniaA seller is offering dual-surface OT access bundling an Allen-Bradley SLC 500 PLC with an L2TP VPN foothold in Poland. Control of industrial PLCs lets an attacker manipulate physical processes, so manufacturing and critical-infrastructure defenders should assume this foothold could be resold or weaponized.
13h
Access sale42
Acceso al panel de administración del sitio español legaliti.esA forum user is offering administrator information and the admin email for the Spanish legal website legaliti.es, indicating a compromise of its backend or admin account. Admin access enables defacement, data theft, malware injection and abuse of the site's visitors. Spain is in scope for Spanish-language monitoring and this is a fresh, actionable access listing.
20h
Access sale64
Venta de acceso a PLC industrial CompactLogix en AustriaA seller is offering live read/write access to a CompactLogix 5069 PLC with 274 tags in an Austrian industrial environment. Such access allows manipulation of physical processes, posing a serious OT/ICS safety and availability risk. Though outside Latin America, it signals active brokering of industrial control access relevant to critical-infrastructure defenders.
1d
Access sale48
Filtración de una máquina virtual de la exchange Gate.ioA leaked virtual machine image allegedly belonging to the crypto exchange Gate.io was posted on a Russian-language forum, potentially containing configuration, credentials or keys from the platform's infrastructure. Such artifacts can enable initial access or lateral movement against a major financial platform. Exchanges are high-value targets due to the potential for direct fund theft.
1d
Access sale68
Venta de acceso admin a una plataforma internacional de apuestasA seller is offering admin access to a major international sportsbook platform, posted within the last day. Administrative access could allow manipulation of bets, payouts and user accounts, plus access to customer PII and financial data. Fresh access sales of this type are highly time-sensitive.
1d