PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
Kalir Brief · Item21 September 2026 · 14:37 UTC
BRIEFGov / MilitaryhighP76

Massive leak exposes 70,000 Moroccan intelligence agents

DGST (Marruecos)

Detected21 September 2026 · 14:37 UTC
Why it matters

A leak attributed to the 'Jabaroot' group exposed roughly 70,000 members of Morocco's DGST intelligence service, including identities, photographs and contact details. Publishing this data can unmask undercover officers and enable targeting, retaliation and follow-on phishing against them. It is a landmark government intelligence breach that CTI teams should track even though it falls outside the LATAM region.

MetadataRECORD
CategoryGov / Military
Severityhigh
Priority score76
Detected21 September 2026 · 14:37 UTC
Related items6
Gov / Military55
Filtración de base de datos del portal de empleo kirkuk.gov.iqThe full database behind the Iraqi government job-registration portal kirkuk.gov.iq has been leaked, exposing applicant personal data handled by a public administration. It is a government records exposure with PII and identity-fraud potential. Although outside Latin America, it is a public-sector database leak defenders monitoring government exposures should track.
6h
Gov / Military33
Bases de datos gubernamentales de México (INE, SAT) ofrecidasA forum user claims to hold sensitive Mexican datasets including SAT 2021, BBVA 2022 and editable INE records, and offers to share them. The material appears to be older (2021-2022) recycled data rather than a fresh breach, so it is not an urgent alert, but INE and SAT data are highly sensitive for identity fraud and electoral/tax abuse. Defenders should treat it as background exposure and confirm whether records are already known.
7h
Gov / Military72
Base de datos de proveedores del Gobierno de Morelos filtradaA database of Morelos government suppliers was published on a dark web forum, exposing contracting and vendor records of a Mexican state government. Supplier data reveals procurement relationships, tax/contact details and internal contacts valuable for BEC, invoice fraud and supply-chain targeting. State defenders should assess exposure and warn listed vendors about impersonation and phishing risks.
7h
Gov / Military88
Filtración de base de datos del municipio de Naucalpan de JuárezA SQL database dump from Naucalpan de Juárez's citizen services portal (trámites y servicios) in Mexico has been posted on a leak forum, likely containing citizen personal data, identifiers and service records. This is a direct government exposure in Latin America, exactly the kind of fresh public-sector breach that requires notification and PII review. Defenders should treat it as an active incident, not a stale repost.
7h
Gov / Military87
Filtración de base de datos del Ministerio de Defensa (DCSA)A threat actor posted a database attributed to DCSA, a military/Ministry of National Defence body, in a dark web leaks forum just minutes ago, making it a fresh, time-sensitive alert. Exposed defence data can reveal personnel, contracts and internal systems, enabling espionage or follow-on intrusion. Affected networks should assume credential compromise and rotate secrets immediately.
17h
Gov / Military42
Filtración de base de datos del portal de empleo kirkuk.gov.iq (Irak)A forum post offers a leaked database from Iraq's government jobs portal kirkuk.gov.iq, including applicant registration data. Government recruitment databases typically hold national ID numbers, addresses, and contact details, enabling identity fraud and phishing. Although outside Latin America, it is a genuine government leak and the credentials may be reused elsewhere.
1d