PULSE
FEED
vulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Kalir Brief · Item18 September 2026 · 00:12 UTC
BRIEFLeakhighP62

1M PII records of money transfer firm mtglobal.org for sale

mtglobal.org

Detected18 September 2026 · 00:12 UTC
Why it matters

A seller is offering roughly one million PII records from mtglobal.org, a UK international money-transfer firm, in what appears to be a fresh listing. Customer identity and financial data fuels fraud, account takeover and regulatory exposure. Financial-sector defenders should watch for reused credentials and customer phishing.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score62
Detected18 September 2026 · 00:12 UTC
Related items6
Leak38
Filtración de base de datos de clientes de German Doner KebabA customer database attributed to German Doner Kebab (GDK) is being offered on a darknet forum in what appears to be a recent post. Customer PII enables phishing, fraud and loyalty-account takeover. Retail and food-sector defenders should verify the claim and prepare customer notification.
1h
Leak50
Filtración de 1,8M de logs de credenciales (stealer)A free dump of about 1.8 million URL:login:password credential logs from private stealer logs was posted to a leak forum. The volume makes it valuable for credential stuffing and account takeover across many services. Defenders should check exposure and force MFA and password resets for affected users.
1h
Leak46
Base de datos de ciudadanos de República Dominicana a la ventaAn actor claims to hold a citizens database of the Dominican Republic, potentially containing names, national IDs and other PII of a whole national population. It matters to LATAM defenders, but the post is dated February 2026, so it is likely a recirculated dump rather than a fresh breach.
2h
Leak48
Filtración de base de datos de la plataforma de apuestas 1winA database allegedly belonging to the betting platform 1win (1winbet) is being leaked on an underground forum. Gambling platforms hold account, payment and KYC data of many users, so a leak of this kind enables fraud, credential stuffing and identity theft against a broad Spanish-speaking user base.
2h
Leak62
Filtración de 1M de datos PII de la firma de transferencias mtglobalA seller is offering roughly 1 million PII records belonging to mtglobal.org, a UK-based international money transfer firm, likely including customer identity and KYC data. Finance-sector defenders should care because such records fuel account takeover, targeted phishing and fraud against the provider and its clients.
2h
Leak40
Volcado de 10 millones de URL:LOG:PASS con credenciales a la ventaA 10-million-line stealer-log set (URL:LOG:PASS) is being distributed, exposing browser-saved credentials together with the sites they belong to. Dumps like this enable credential stuffing against webmail, VPN and admin portals, so any organisation relying on password-only authentication is exposed. Posted in May 2026, it is somewhat stale yet still widely reused by attackers.
3h