PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / Windows
Kalir Brief · Item13 September 2026 · 04:12 UTC
BRIEFLeakhighP75

Grupo ATC (Mexico and USA) 23 databases for sale: 340 GB, 2 billion rows

Grupo ATC

Detected13 September 2026 · 04:12 UTC
Why it matters

A threat actor is selling 23 databases belonging to Grupo ATC across Mexico and the USA, totaling over 340 GB and roughly 2 billion unique rows. The scale implies large volumes of customer or identity data, directly relevant to Latin American breach monitoring. A leak this size can fuel fraud and credential-stuffing against Mexican users and partner organizations.

MetadataRECORD
CategoryLeak
Severityhigh
Priority score75
Detected13 September 2026 · 04:12 UTC
Related items6
Leak48
Filtración de 6,95 millones de credenciales URL:LOG:PASSA 6.95 million-line URL:log:pass credential list of stealer logs is being resold and mirrored across multiple forums. Its scale and cross-forum distribution make it valuable for credential stuffing against web and VPN portals. Organizations should screen exposed credentials for corporate and government domains.
2h
Leak55
Base de datos siria publicada en BreachForumsA freshly posted database labeled 'Syrian' appeared on BreachForums today. Large regional population datasets typically contain PII that supports identity fraud and targeted phishing campaigns. Though outside LATAM, it is worth tracking as part of broader breach-monitoring activity.
2h
Leak58
Base de datos de usuarios de Bitcoin a la venta en DarkNetArmyA vendor on DarkNetArmy is advertising a large 'Bitcoin user database vault 2026' targeting crypto account holders. If genuine, such data fuels account takeover, phishing and theft of funds, and is commonly reused for credential stuffing across exchanges. Authenticity is unverified, so treat it as a lead for monitoring rather than a confirmed breach.
2h
Leak28
Volcado de credenciales ULP de 27 millones de líneas (1,5 GB)A 1.5 GB credential dump labelled 'ULP' containing roughly 27 million URL:LOG:PASS lines was posted to DarkForums in March 2026. These email/password pairs feed credential-stuffing and account-takeover attacks across many services. Defenders should check exposure of corporate and government accounts, though the dump is months old and not directed at a specific entity.
4h
Leak40
Filtración de 6,95 millones de logs URL:LOG:PASS (DAXUS)A 6.95 million-line URL:LOG:PASS stealer-log dump was uploaded to DarkForums and advertised by the handle DAXUS. Such logs hold live credentials harvested by infostealers and are used for account takeover and VPN/SSO intrusion. No single victim is named, so it is a broad credential-exposure alert rather than a targeted access sale.
4h
Leak48
Filtración de base de datos de prisioneros iraquíesA DarkForums thread shares an alleged database of Iraqi prisoners containing identifying and detention data. If genuine, it is a sensitive government and national-security leak affecting detainees and officials. The post is undated so freshness is unconfirmed, but the subject matter warrants monitoring.
4h