PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
Kalir Brief · Item23 September 2026 · 14:29 UTC
BRIEFOtherhighP50

Sale of 20 kernel 0-day exploits on forum

Detected23 September 2026 · 14:29 UTC
Reposts collapsed2
Why it matters

A seller claims to offer 20 zero-day kernel exploits, posted on 21 September 2026. Unverified, but kernel 0-days enable privilege escalation and full host compromise, feeding access brokers and ransomware crews. Track the seller and any subsequent exploitation chatter.

MetadataRECORD
CategoryOther
Severityhigh
Priority score50
Detected23 September 2026 · 14:29 UTC
Related items6
Other40
Informe sobre el grupo brasileño Slim Spider y robo de secretos criptoA dark web post details Slim Spider, a Brazilian cybercriminal group stealing crypto custody secrets from financial institutions. It highlights an active LATAM threat actor targeting the financial and crypto sector, which is directly relevant to regional defenders. Treat it as threat context rather than a fresh compromise alert.
5d
Other33
Venta de ciudadanía mexicana fraudulenta en foro de cardingA carding forum thread advertises fast, 'risk-free' official Mexican citizenship, implying the sale of forged or fraudulently obtained nationality and identity documents. This matters for Latin America because such documents can enable money laundering, sanctions evasion and impersonation of nationals, undermining immigration and identity integrity. It is a recurring service ad rather than a confirmed breach, so it is a low-priority but regionally relevant indicator.
5d
Other44
Doxeo de Ernestina Godoy Ramos, senadora de MéxicoA fresh dox thread publishes personal data on Ernestina Godoy Ramos, a sitting Mexican senator and former Mexico City attorney general. Doxxing of high-profile Latin American officials can fuel harassment, phishing and physical threats. Worth monitoring given her government role.
5d
Other54
Venta de cadena de exploits privada para iPhone (iOS)A seller is advertising a private iOS exploit chain dated 14 Sep 2026, capable of compromising iPhones at the OS level. If genuine, this is a scarce, high-value capability that could enable zero-click or targeted attacks against executives, journalists and government users, so it warrants tracking.
6d
Other58
Venta de exploit 0-day con cadena completa para Chromium en Android 14-16A seller claims a fresh full-chain Chromium RCE affecting Android 14 through 16, advertised as 0-day class and suitable for drive-by exploitation. If genuine, it endangers any Android user, including government and enterprise mobile fleets common across the region. No date or price is shown, so treat it as unverified but high priority for patching and browser hardening.
6d
Other44
Se vende exploit 0day de escalada de privilegios en Windows 11A user is selling a claimed Windows 11 local privilege escalation 0day, posted within the last day. If real, it enables post-exploitation elevation on fully patched Windows hosts, raising risk across any Windows estate. Unverified 0day claims on forums are frequently scams or repackaged known bugs, so validate before alerting.
10d