PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
Kalir Brief · Item23 September 2026 · 04:29 UTC
BRIEFAccess salehighP48

Live citizenship database access for a CIS .gov country for sale

Detected23 September 2026 · 04:29 UTC
Why it matters

A seller is offering live access to a government citizenship database belonging to an ex-Soviet/CIS country on a .gov domain. Live database access lets buyers query and exfiltrate citizen records on demand, a serious state-grade exposure. It is outside Latin America but shows an active market for direct government database access.

MetadataRECORD
CategoryAccess sale
Severityhigh
Priority score48
Detected23 September 2026 · 04:29 UTC
Related items6
Access sale52
Exploit de día cero de WordPress con webshell automáticaA seller is advertising a private WordPress zero-day brute-force exploit bundled with automatic webshell upload, posted as recently as late September 2026. Such a tool enables mass compromise of vulnerable WordPress sites, granting attackers persistent remote access. Defenders hosting WordPress should prioritize patching and monitor for unexpected PHP files and webshells.
2h
Access sale55
Venta de RCE y 0days de escalada local (ROTR)A seller is advertising RCE exploits, an information leak, and local privilege-escalation 0-days under the 'ROTR' label, posted 2026-09-21. Fresh, working exploits of this type enable rapid intrusion into unpatched systems. Although no specific victim is named, defenders should track it for imminent exploitation activity.
4h
Access sale38
Venta de acceso admin al portal educativo australiano eit.edu.net.auA forum user is advertising administrator-level access to eit.edu.net.au, an Australian education site, dated March 2026. Admin access to an academic portal can enable data theft, defacement or lateral movement into connected systems. The listing is already months old, so it is a stale access offer rather than a live incident.
8h
Access sale62
Venta de acceso a un centro de mando de tráfico gubernamental en IránA seller on DarkForums is advertising access to the Iranian Smart Traffic Control Command Center of the Tehran Traffic Police, a government-operated transport/critical-infrastructure system. If genuine, control-plane access to traffic signalling and monitoring could enable physical disruption and safety incidents, not just data theft. It shows access brokers pursuing government OT/ICS targets and is worth tracking for TTPs even though the region is outside LATAM.
1d
Access sale55
Venta de acceso a cuenta corporativa de una empresa de TIA threat actor is selling access to a corporate Microsoft account along with Tally Prime accounting software tied to an IT company. This kind of access enables business email compromise, invoice fraud and lateral movement into the victim's finance systems. Buyers typically use such credentials for wire fraud and data theft.
1d
Access sale52
Venta de acceso de administrador a la web paquistaní Pomilights.pkA threat actor is selling administrator-level access to Pomilights.pk, a Pakistani online retailer, in a DarkForums thread dated 24-08-2026. Admin access to a live storefront enables customer-data theft, web-skimming injection and defacement, and is a concrete initial-access sale rather than generic chatter. It is worth surfacing as a real access offer even though the victim is outside LATAM.
2d