PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
Kalir Brief · Item18 September 2026 · 20:12 UTC
BRIEFOtherhighP40

Report on Brazilian group Slim Spider stealing crypto custody secrets

Slim Spider (actor brasileño)

Detected18 September 2026 · 20:12 UTC
Why it matters

A dark web post details Slim Spider, a Brazilian cybercriminal group stealing crypto custody secrets from financial institutions. It highlights an active LATAM threat actor targeting the financial and crypto sector, which is directly relevant to regional defenders. Treat it as threat context rather than a fresh compromise alert.

MetadataRECORD
CategoryOther
Severityhigh
Priority score40
Detected18 September 2026 · 20:12 UTC
Related items6
Other33
Venta de ciudadanía mexicana fraudulenta en foro de cardingA carding forum thread advertises fast, 'risk-free' official Mexican citizenship, implying the sale of forged or fraudulently obtained nationality and identity documents. This matters for Latin America because such documents can enable money laundering, sanctions evasion and impersonation of nationals, undermining immigration and identity integrity. It is a recurring service ad rather than a confirmed breach, so it is a low-priority but regionally relevant indicator.
7h
Other44
Doxeo de Ernestina Godoy Ramos, senadora de MéxicoA fresh dox thread publishes personal data on Ernestina Godoy Ramos, a sitting Mexican senator and former Mexico City attorney general. Doxxing of high-profile Latin American officials can fuel harassment, phishing and physical threats. Worth monitoring given her government role.
17h
Other54
Venta de cadena de exploits privada para iPhone (iOS)A seller is advertising a private iOS exploit chain dated 14 Sep 2026, capable of compromising iPhones at the OS level. If genuine, this is a scarce, high-value capability that could enable zero-click or targeted attacks against executives, journalists and government users, so it warrants tracking.
22h
Other58
Venta de exploit 0-day con cadena completa para Chromium en Android 14-16A seller claims a fresh full-chain Chromium RCE affecting Android 14 through 16, advertised as 0-day class and suitable for drive-by exploitation. If genuine, it endangers any Android user, including government and enterprise mobile fleets common across the region. No date or price is shown, so treat it as unverified but high priority for patching and browser hardening.
23h
Other44
Se vende exploit 0day de escalada de privilegios en Windows 11A user is selling a claimed Windows 11 local privilege escalation 0day, posted within the last day. If real, it enables post-exploitation elevation on fully patched Windows hosts, raising risk across any Windows estate. Unverified 0day claims on forums are frequently scams or repackaged known bugs, so validate before alerting.
5d
Other45
AnkaTeam hackea el sitio del club español Villarreal CFThe Turkish hacking group AnkaTeam claims to have compromised Villarreal CF, a Spanish La Liga football club, as part of a defacement and data-theft campaign. Sports organizations hold fan personal data, ticketing and payment information, plus partner credentials that can be abused for fraud and downstream attacks. The public claim raises reputational risk and warrants verification of any leaked data.
6d
Report on Brazilian group Slim Spider stealing crypto custody secrets · Kalir Brief · Pulse | Pulse