PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
Kalir Brief · Item19 September 2026 · 19:13 UTC
BRIEFLeaklowP50

Leak of 64 million credentials (URL:login:password)

Detected19 September 2026 · 19:13 UTC
Why it matters

A freshly posted dump claims 64 million URL:login:password records from stealer logs, a large-scale credential exposure despite lacking a named victim. Such volumes fuel credential stuffing against corporate and government services, including in Latin America. While generic, its recency makes it worth ingesting for exposure checks and blocking.

MetadataRECORD
CategoryLeak
Severitylow
Priority score50
Detected19 September 2026 · 19:13 UTC
Related items6
Leak35
Filtración del portal de empleo de DWASA, BangladeshA database from erecruitmentdwasa.org, the Dhaka Water Supply and Sewerage Authority recruitment portal, was leaked on BreachForums in December 2025. Applicant PII from a municipal water utility can enable targeted phishing and credential abuse. It is stale and outside the region, so it ranks low.
31m
Leak42
Base de datos GSM de 145 millones de Turquía circula en forosA 145 million-record GSM subscriber database for Turkey continues to circulate on RaidForums. The scale makes it a long-lived asset for SIM-swap, smishing and identity fraud. It is not fresh and outside Latin America, so it is context rather than an urgent alert.
31m
Leak58
Filtración de 643 GB de i2i-Systems y VeriskopA 643 GB document dump attributed to i2i-Systems and Veriskop was posted to DarkForums today. The volume suggests an internal file-server or document-repository compromise rather than a simple credential list. If either firm serves telecom or regulated clients, the exposure can seed further intrusion and extortion.
31m
Leak58
Venta de código fuente y bases de usuarios de mercor.comA seller is offering the source code plus user and contractor databases of mercor.com, a US AI-training and hiring platform. Combining proprietary source with personal and contractor records raises risk of account takeover, extortion and supply-chain abuse against the company and its clients. The post is undated, so recency is unconfirmed but the asset value is high.
2h
Leak60
Base de datos de CoinPayments a la venta en foro clandestinoA seller is offering the database of CoinPayments, a real cryptocurrency payment processor, on DarkForums. Payment-processor data compromises expose customer identities, balances and transaction histories, enabling fraud and account takeover. Although posted roughly two weeks ago, it remains recent enough to warrant verification and downstream monitoring.
2h
Leak78
Base de datos de clientes de la energética española Apolo Energía a la ventaA threat actor is selling a fresh database of roughly 40,000 Apolo Energía customers, an energy utility in Spain. Energy providers are critical infrastructure, so exposed customer PII enables targeted phishing, fraud and account takeover against ratepayers. Defenders should reset credentials and monitor for downstream identity abuse.
4h