PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / Switchvox
Kalir Brief · Item10 September 2026 · 22:12 UTC
BRIEFLeakhighP72

Database leak of Ecuador's Aviation

Aviación de Ecuador

Detected10 September 2026 · 22:12 UTC
Why it matters

A BreachForums thread claims the actor TerroahOver dumped a database belonging to Ecuador's aviation body, a government/military-linked entity. If authentic, it exposes sensitive personnel or operational data of a LatAm state target and risks credential reuse, phishing and further intrusion. Defenders should verify scope and monitor for downstream abuse.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score72
Detected10 September 2026 · 22:12 UTC
Related items6
Leak28
Filtración de 5 millones de registros de clientes de SFRA database of about 5 million records attributed to French ISP SFR continues to be re-shared on leak forums. The thread is clearly old (a page-26 reply to a long-running post), so it is not a fresh incident, but the data still fuels phishing and account-takeover against subscribers. Treat it as background context rather than a new alert.
2h
Leak55
Filtración de 6,5M de correos de usuarios de JamendoA scraped dataset of roughly 6.5 million Jamendo user email addresses and linked account data was published in 2026. While Jamendo is a music platform rather than critical infrastructure, the volume makes it a strong base for credential-stuffing and phishing campaigns against users worldwide. Organizations should check whether employee or corporate-linked accounts appear in the set.
2h
Leak58
Filtración de base de datos de pasaportes e identidades de IsraelA threat actor posted a claim of a full database of Israeli passports and identity documents in the 2026 leaks section of the SpyHackerz forum. Passport and identity data enable large-scale identity theft, document forgery and targeted fraud. Although outside the AR-LATAM region, the volume and sensitivity justify monitoring for reuse of the data against regional targets.
4h
Leak92
Base de datos del banco mexicano MEXBANK a la ventaA seller posted a 'MEXBANK' database from Mexico (2026) minutes ago in an unverified seller section. It appears to be customer or account records from a Mexican financial institution. Fresh LATAM banking-data leaks require immediate validation and notification planning.
4h
Leak32
Volcado de 5 millones de credenciales de stealer (url:log:pass)Actor 'Napoleon' posted a fresh dump of roughly 5 million url:log:pass stealer-log entries, part of an ongoing series of high-volume credential leaks. The volume makes it a sizable corpus for credential stuffing and account takeover, though no specific organization or region is identified. It carries no evident government or LATAM critical-infrastructure relevance.
6h
Leak40
Filtración de la base de datos de la tienda online de SFR (583k)A ~583,000-record dump of boutique.sfr.fr, the e-commerce site of French telecom operator SFR, is circulating on a breach forum. Telecom is critical national infrastructure, so customer PII and order data can power phishing, account takeover and SIM-swap fraud. The thread dates to January 2026, so it is a stale leak, not a fresh breach.
6h