PULSE
FEED
vulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOS
Kalir Brief · Item21 September 2026 · 19:37 UTC
BRIEFLeaklowP28

Okx.com virtual machine image leaked on an underground forum

OKX

Detected21 September 2026 · 19:37 UTC
Why it matters

A leaked virtual-machine image tied to OKX, a major crypto exchange, was posted in early January 2026. If genuine, VM access can expose credentials, API keys and internal configuration enabling fund theft or lateral movement. It is now roughly eight months old, so it is background context rather than a fresh alert.

MetadataRECORD
CategoryLeak
Severitylow
Priority score28
Detected21 September 2026 · 19:37 UTC
Related items6
Leak48
Base de datos de clientes de Ledger ofrecida a la ventaA seller in an unverified section is advertising a 'Latest Ledger Database 2026', claiming fresh customer records from the crypto-hardware vendor. Ledger customer lists are high-impact because they fuel phishing, SIM-swap and physical-threat campaigns against wallet holders. The claim is unconfirmed, but verified Ledger data would be of genuine interest to CTI and fraud teams.
29m
Leak48
Filtración de base de datos de Bouygues Telecom (Francia)A database attributed to French telecom operator Bouygues Telecom is offered on an underground forum. Telecoms are critical infrastructure holding large volumes of subscriber data, and such dumps fuel credential-stuffing and phishing. The post dates from around September 2025, so it is stale but still worth monitoring if your users are affected.
1h
Leak72
Base de datos de 1 millón de correos de Coinbase a la ventaRoughly one million Coinbase email addresses are being circulated, with 50,000 given away as free 'freebies' to promote the dump. The post appeared only about an hour before discovery, making it a fresh leak tied to a major crypto exchange. Expect phishing and credential-stuffing against affected users and any reused passwords.
1h
Leak35
Filtración de base de datos de TotalEnergies (50K registros)A database of over 50,000 records attributed to energy major TotalEnergies is being shared on a breach forum, dated January 2026. Energy firms are critical infrastructure, so exposed employee or customer data raises phishing and intrusion risk. The post is months old, so treat it as background intelligence rather than a fresh alert.
2h
Leak48
Filtración de base de datos de pasaportes e identidades de IsraelA hacking forum thread advertises a full database of Israeli passports and identity records under a 2026 fresh-leaks section. National identity data of this kind enables impersonation, large-scale fraud and targeting of citizens. Confirm scope and provenance before acting.
2h
Leak57
Base de datos de PayPal (ULP) a la venta en la brecha HellSkeyA posting advertises a 'HELLSKEY BREACH' PayPal database in ULP (URL/login/password) format dated 2026. Credential sets for a major payment platform fuel account takeover, card fraud and downstream phishing campaigns. Validate the sample and brief fraud and SOC teams.
2h