PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
Kalir Brief · Item21 September 2026 · 10:37 UTC
BRIEFLeakhighP42

Leaked database of Russian postal service Pochta.ru with 499K records

Pochta.ru

Detected21 September 2026 · 10:37 UTC
Why it matters

A 499K-row database from the Russian postal operator Pochta.ru has been shared on DarkForums, reportedly containing names, phone numbers and physical addresses. The dataset is valuable for phishing, smishing and identity fraud against Russian citizens. Even if partly recycled, defenders should flag it for credential-stuffing and mailing-fraud campaigns.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score42
Detected21 September 2026 · 10:37 UTC
Related items6
Leak40
Comparten volcado masivo de 13,5 millones de credenciales URL:usuario:contraseñaA dump advertised as 13.5M URL:login:password records is circulating through the 'vulta.pw' shop, a large fresh credential corpus that can fuel credential stuffing and account takeover. Aggregated logs of this size frequently include government and corporate email access. Defenders should assume their users' credentials are exposed and enforce resets and MFA.
26m
Leak45
Publican la filtración de la base de datos de la empresa paquistaní de IA KhaityA database belonging to the Pakistani AI company Khaity has been published for free in 2026, exposing the firm's stored data. AI vendors typically hold client datasets and model/API material that can be abused for further attacks. Defenders in the AI supply chain should treat the exposure as a lead for credential reuse and downstream targeting.
26m
Leak30
Registros de usuarios de los Tribunales de California filtradosPrivate user records allegedly from the California Courts system have been posted for free on a leak forum. The thread is dated January 2026, making it a stale government-data exposure rather than a fresh alert. It still matters for identifying re-used court-account credentials and downstream targeting.
1h
Leak45
Filtración de 3,8 millones de usuarios de Zain Telecom IrakA database of about 3.8 million Zain Telecom Iraq users is being distributed on a cracking forum, containing subscriber data that can enable SIM-related fraud and targeted attacks. The post, however, appears to be a repost of an older Zain leak, so its freshness is doubtful. Treat as background context rather than a fresh alert.
1h
Leak52
Base de datos de 182.000 tarjetas de crédito filtrada en 2026A database of roughly 182,000 credit cards labelled as a new 2026 leak is being distributed on an underground forum. It provides ready-to-use payment-card data for fraud and carding. Fresh card dumps drive fraud losses and can be cross-referenced with regional BINs to identify affected issuing banks.
1h
Leak68
Base de datos robada de Ledger con 309.000 registros a la ventaA seller claims to hold a stolen 2026 Ledger database of about 309,000 records and is offering it for sale. Ledger is a major crypto hardware-wallet vendor, so the data can fuel phishing and targeted attacks against wallet holders. Fresh customer-database leaks of this scale enable credential stuffing and social engineering against high-value crypto targets.
1h