BRIEFOtherlowP34
Automated KYC bypass and fake document generator
Detected27 September 2026 · 18:48 UTC
A tool is being shared that automates KYC bypass and document generation against vendors such as Sumsub, Onfido, Persona, Ondato and Veriff. It lowers the barrier for identity fraud and account opening with forged documents at banks and fintechs relying on those providers. Defenders in financial onboarding should treat it as an active fraud enabler.
CategoryOther
Severitylow
Priority score34
Detected27 September 2026 · 18:48 UTC
Other● 66
A la venta exploit RCE de Chromium para Windows 10/11A seller is advertising a Chromium RCE chain for Windows 10/11 that reportedly achieves a full renderer escape to code execution. If genuine, this is a high-value browser 0-day suitable for drive-by and watering-hole attacks against almost any target. Patching levels and browser exploit telemetry should be reviewed urgently.Other● 55
Ciberataque contra instalaciones de agua de Arabia SauditaReports indicate Saudi Arabia's water facilities were hacked, targeting critical infrastructure. Attacks on water utilities can disrupt essential services and reflect tactics that may spread to other regions. Although outside LATAM, it is a notable critical-infrastructure incident to monitor closely.Other● 38
Venta de panel de SMS masivos para Colombia con 631.543 créditosA seller is offering a bulk SMS platform preloaded with 631,543 credits (1 credit = 1 SMS) targeting Colombian numbers. Such panels are typically abused for mass smishing, OTP interception and fraud campaigns against banks and telecom customers. It matters because it provides ready-to-use infrastructure for large-scale SMS fraud in the region, even if the panel itself is not a direct breach.Other● 50
Venta de 20 exploits 0-day de kernel en foroA seller claims to offer 20 zero-day kernel exploits, posted on 21 September 2026. Unverified, but kernel 0-days enable privilege escalation and full host compromise, feeding access brokers and ransomware crews. Track the seller and any subsequent exploitation chatter.Other● 40
Informe sobre el grupo brasileño Slim Spider y robo de secretos criptoA dark web post details Slim Spider, a Brazilian cybercriminal group stealing crypto custody secrets from financial institutions. It highlights an active LATAM threat actor targeting the financial and crypto sector, which is directly relevant to regional defenders. Treat it as threat context rather than a fresh compromise alert.Other● 33
Venta de ciudadanía mexicana fraudulenta en foro de cardingA carding forum thread advertises fast, 'risk-free' official Mexican citizenship, implying the sale of forged or fraudulently obtained nationality and identity documents. This matters for Latin America because such documents can enable money laundering, sanctions evasion and impersonation of nationals, undermining immigration and identity integrity. It is a recurring service ad rather than a confirmed breach, so it is a low-priority but regionally relevant indicator.