BRIEFAccess salehighP44
Zero-day RCE and local privilege-escalation exploit for sale
Detected24 September 2026 · 00:51 UTC
A seller on a Tor marketplace is offering a zero-day remote code execution chain plus local privilege-escalation and information-leak exploits, posted on 2026-09-21. No specific victim is named, so the risk is sector-agnostic, but unpatched RCE is a common entry point for enterprise and government intrusion. Defenders should track this actor and hunt for exploitation attempts.
CategoryAccess sale
Severityhigh
Priority score44
Detected24 September 2026 · 00:51 UTC
Access sale● 40
Venta de acceso de administrador al sitio keniano TikohubA threat actor is offering administrative access to Tikohub.co.ke, a Kenyan online store. Admin-level access enables full site takeover, customer data theft and payment/checkout manipulation. The listing is from April 2026 and the target is outside the LATAM region, so its urgency for AR-LATAM defenders is limited.Access sale● 52
Exploit de día cero de WordPress con webshell automáticaA seller is advertising a private WordPress zero-day brute-force exploit bundled with automatic webshell upload, posted as recently as late September 2026. Such a tool enables mass compromise of vulnerable WordPress sites, granting attackers persistent remote access. Defenders hosting WordPress should prioritize patching and monitor for unexpected PHP files and webshells.Access sale● 48
Venta de acceso a base de datos de ciudadanía de un país de la CEIA seller is offering live access to a government citizenship database belonging to an ex-Soviet/CIS country on a .gov domain. Live database access lets buyers query and exfiltrate citizen records on demand, a serious state-grade exposure. It is outside Latin America but shows an active market for direct government database access.Access sale● 55
Venta de RCE y 0days de escalada local (ROTR)A seller is advertising RCE exploits, an information leak, and local privilege-escalation 0-days under the 'ROTR' label, posted 2026-09-21. Fresh, working exploits of this type enable rapid intrusion into unpatched systems. Although no specific victim is named, defenders should track it for imminent exploitation activity.Access sale● 38
Venta de acceso admin al portal educativo australiano eit.edu.net.auA forum user is advertising administrator-level access to eit.edu.net.au, an Australian education site, dated March 2026. Admin access to an academic portal can enable data theft, defacement or lateral movement into connected systems. The listing is already months old, so it is a stale access offer rather than a live incident.Access sale● 62
Venta de acceso a un centro de mando de tráfico gubernamental en IránA seller on DarkForums is advertising access to the Iranian Smart Traffic Control Command Center of the Tehran Traffic Police, a government-operated transport/critical-infrastructure system. If genuine, control-plane access to traffic signalling and monitoring could enable physical disruption and safety incidents, not just data theft. It shows access brokers pursuing government OT/ICS targets and is worth tracking for TTPs even though the region is outside LATAM.