PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
Kalir Brief · Item24 September 2026 · 08:51 UTC
BRIEFLeakhighP72

Bureau van Dijk (Orbis) database leak offered for sale

Bureau van Dijk (Moody's)

Detected24 September 2026 · 08:51 UTC
Why it matters

A DarkForums seller is offering a 2025-2026 leak of Bureau van Dijk's corporate data, the Moody's-owned Orbis business-intelligence platform (posted 21 Sep 2026). It holds financial, ownership and executive records on millions of companies worldwide. If genuine, this is high-value corporate/KYC intelligence for BEC, fraud and supply-chain mapping, so defenders should watch for downstream abuse of leaked business records.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score72
Detected24 September 2026 · 08:51 UTC
Related items6
Leak35
Filtración de datos de Grupo Hasar publicada en foroA dumped database tied to Grupo Hasar, a Latin American electronics group, is being shared on DarkForums. The post dates to August 2025, so it is stale and likely already traded, but exposed customer or employee PII could still fuel fraud. Worth tracking for credential reuse.
30m
Leak55
Base de datos de plataforma china de masajes a la ventaA threat actor is selling a Chinese on-demand massage platform database with roughly 7.5 million orders and 1.8 million users, including names, phone numbers and payment data. Although the victim is outside Latin America, the scale makes it a notable bulk-data sale. Buyers could enable large-scale fraud and downstream phishing.
30m
Leak38
Stealer log de 357.000 credenciales URL:login:pass publicadoA stealer log containing roughly 357,000 URL:login:password entries was released by 'Napoleon' and mirrored across several forums. Stealer logs pair credentials with the exact site and often session data, making them directly usable for credential stuffing and account takeover. Although not region-specific, the volume and freshness justify checking for your users' corporate credentials.
1h
Leak40
Dump de 960.000 credenciales URL:login:pass publicadoA forum user published a 960,000-line URL:login:password credential dump labelled 'UHQ FRESH SEP', indicating recently harvested stealer/combolist data. The scale and 'fresh' label mean many entries are likely still valid, feeding credential stuffing, account takeover and initial-access attempts across many services. Defenders should enforce credential-stuffing detection and MFA on any exposed accounts.
1h
Leak45
Cookies de sesión activas de Walmart, LinkedIn y redes sociales a la ventaA threat actor is trading '2f' accounts for Walmart, LinkedIn, Nextdoor, Instagram, Facebook and Twitter bundled with active email session cookies, i.e. takeover-ready access rather than plain credentials. Active cookies let buyers bypass passwords and often 2FA, enabling immediate account takeover and lateral phishing. Organizations on these platforms should force re-authentication and hunt for anomalous session activity.
1h
Leak52
Base de datos de 1,5 millones de usuarios de Binance a la ventaA carding-forum seller claims to hold a 1.5-million-record Binance user database, likely assembled from credential stuffing or an older breach. If genuine it exposes crypto customers to account takeover and targeted phishing. Binance's large Latin American user base makes it relevant, though the recycled '2026' framing suggests limited freshness.
2h