BRIEFAccess salehighP60
phpMyAdmin credentials of Mexico's ITESHU offered for sale
ITESHU (México)
Detected26 September 2026 · 23:17 UTC
Reposts collapsed2
Credentials for the phpMyAdmin panel of ITESHU, a Mexican higher-education institute, are being offered on a hacking forum. Access to phpMyAdmin usually means direct control over the institution's backend databases, risking exfiltration or tampering of student and administrative records. This is a timely lead for defenders at Mexican public education institutions.
CategoryAccess sale
Severityhigh
Priority score60
Detected26 September 2026 · 23:17 UTC
Access sale● 78
Venta de exploit RCE pre-autenticación para Oracle PeopleSoftShinyHunters is selling a pre-authentication RCE plus WAF bypass for Oracle PeopleSoft, an ERP widely deployed across government agencies, ministries, universities and banks. This kind of unauthenticated exploit enables initial access without credentials and is highly relevant to public-sector targets in Latin America. Defenders running PeopleSoft should urgently hunt for exposed internet-facing instances and review WAF/DB logs for exploitation attempts.Access sale● 50
Credenciales y cookies del Colegio Faraday (Perú) a la ventaCredentials and session cookies for the Peruvian school colegiofaraday.edu.pe are being offered on an underground forum. Such access lets an attacker log in as staff or students, pivot into internal portals and abuse institutional email. It is a fresh compromise of a Latin American education target worth monitoring for lateral movement.Access sale● 45
Venta de email gubernamental de la Policía Estatal italiana (poliziadistato.it)A user is selling a @poliziadistato.it government email account for over $500, posted minutes ago. A law-enforcement credential can enable phishing, internal access and impersonation of Italian authorities. Defenders should treat it as a possible initial-access vector even though it sits outside the AR-LATAM region.Access sale● 57
Lista de 6.938 servicios expuestos verificados (RDP/SQL/SMB)A threat actor is sharing a verified, live list of 6,938 exposed services including RDP, MongoDB, PostgreSQL, MySQL and SMB endpoints. It is effectively a ready-made target list for ransomware and intrusion crews. Defenders should treat it as an exposure-hunting checklist and confirm none of their assets appear.Access sale● 42
Venta de acceso web a la naviera Minnesota Freight ExpressAdmin access to the website of US shipping company minnesotafreightexpress.com is being offered for sale. Website or admin access to a logistics firm can enable data theft, defacement or supply-chain abuse. Verify the claim and notify the victim so access can be revoked.Access sale● 35
Venta de acceso de administrador a la plataforma de pagos paymentwall.comAdmin access to paymentwall.com, a global payment platform, is offered for sale, though the post dates to December 2025 and is therefore stale. Compromise of a payment provider could enable transaction fraud and downstream merchant risk. Verify whether the access is still valid before acting.