BRIEFAccess salehighP48
WordPress admin credentials offered by Cloud9Base
Detected18 September 2026 · 12:12 UTC
Stealer logs advertised as valid WordPress administrator credentials were posted by the actor Cloud9Base. Valid CMS admin access allows attackers to deface sites, plant webshells and pivot into hosting infrastructure. Organizations running WordPress should check for compromised admin accounts and force password resets immediately.
CategoryAccess sale
Severityhigh
Priority score48
Detected18 September 2026 · 12:12 UTC
Access sale● 48
Venta de acceso admin a sitios WordPressSeller CLOUD9BASE is advertising valid WordPress administrator credentials in bulk, the kind of access that lets an intruder deploy webshells, deface sites or pivot into hosting. It is cross-posted across several forums, signalling an active broker, and any organisation running unpatched WordPress should treat it as a live risk.Access sale● 38
Venta de accesos de administrador de WordPress (URL y credenciales)A dump of WordPress administrator URLs paired with username and password credentials is being circulated, giving buyers ready access to web control panels. Sites running unpatched plugins are the usual victims, and such access is frequently the entry point for defacement, SEO spam or webshell deployment. No specific targets are named, so immediate relevance is limited, but it is a live access-sale listing.Access sale● 62
Compra de datos de la argentina Bull Market BrokersA buyer on DarkForums is soliciting valid leads or credentials tied to inversiones.bullmarket.com.ar, an Argentine brokerage. This signals active interest in compromising an Argentine financial-sector target, likely via credential stuffing or account takeover. Defenders at the firm should watch for brute-force, phishing and anomalous logins.Access sale● 42
Dump y acceso admin de alifyaeducation.co.uk a la ventaA fresh listing offers a dumped database plus administrative access for alifyaeducation.co.uk. Admin access allows full site takeover, data theft and abuse of the host for further attacks. Even a small education target is a useful pivot for phishing and hosting infrastructure.Access sale● 70
Filtración y acceso de administrador a la base de datos de personal de Xarxa Tecla (SISCAT)A threat actor is leaking a personnel database from xarxatecla.cat (SISCAT) while offering associated email and admin access. This combines a data leak with privileged access to a Catalan telecom/technology network, enabling follow-on intrusion. Privileged access plus PII raises both fraud and lateral-movement risk.Access sale● 45
Venta de acceso admin WordPress al Ministerio de Educación de UgandaA seller is offering administrative WordPress access to the Uganda Ministry of Education's website. Government CMS takeovers enable defacement, malware or phishing hosting under an official domain, and can serve as a pivot into connected government infrastructure, so it should be validated and monitored.