PULSE
FEED
vulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOS
Kalir Brief · Item21 September 2026 · 21:32 UTC
BRIEFAccess salelowP45

Access to IT company Microsoft/Tally Prime account for sale

Detected21 September 2026 · 21:32 UTC
Why it matters

A seller offers access to a corporate Microsoft and Tally Prime account belonging to an IT company. Such access enables email takeover, invoice fraud and lateral movement into the provider's client environments. It is a low-tier but genuine initial-access offer worth tracking.

MetadataRECORD
CategoryAccess sale
Severitylow
Priority score45
Detected21 September 2026 · 21:32 UTC
Related items6
Access sale52
Venta de acceso de administrador a la web paquistaní Pomilights.pkA threat actor is selling administrator-level access to Pomilights.pk, a Pakistani online retailer, in a DarkForums thread dated 24-08-2026. Admin access to a live storefront enables customer-data theft, web-skimming injection and defacement, and is a concrete initial-access sale rather than generic chatter. It is worth surfacing as a real access offer even though the victim is outside LATAM.
8h
Access sale70
Venta de SSRF zero-day en base de datos de ciudadanía gubernamentalA seller is advertising a zero-day SSRF vulnerability granting full PII access to a government citizenship database (domain suffixed '.gov.xx'), keeping the exact country concealed. If genuine, it enables wholesale access to national identity records, fueling mass identity fraud, targeted phishing and espionage. Defenders should treat citizenship and identity registries as top-priority attack surface and validate externally exposed endpoints.
11h
Access sale50
Venta de acceso de administrador al instituto educativo indio Amritsar InstitutesA threat actor is selling administrative access to the Amritsar Institutes education portal (amritsarinstitutes.com) in India, including the principal/admin account. With admin control an attacker could alter records, deface the site or pivot into connected systems. Institutions holding personal data should rotate credentials and audit access logs.
12h
Access sale44
Credenciales de administrador de WordPress a la ventaA seller is distributing verified WordPress administrator credentials harvested from stealer logs, offering direct CMS takeover of affected sites. Compromised WordPress admin access enables webshell deployment, defacement, SEO poisoning and hosting of malware or phishing pages. Defenders should hunt for the listed credentials in their sites, force password resets and review admin accounts and plugins.
14h
Access sale47
Venta de acceso a servidores RDP premium de TRUST-RDPA vendor is advertising 'elite' RDP servers under the TRUST-RDP brand, offering remote access brokering to buyers. RDP access sales enable ransomware deployment, data theft and lateral movement, and such listings often broker access to poorly-secured corporate or government hosts. Defenders should audit exposed RDP, enforce MFA and monitor for credentials matching their perimeter.
14h
Access sale45
Venta de servicio de Peticiones de Datos de Emergencia (EDR) fraudulentasA seller on DarkForums is offering Emergency Data Requests (EDRs), a service that lets buyers impersonate law enforcement to compel telecoms, banks and platforms into handing over subscriber data. This enables account takeover and data disclosure with no technical intrusion, so it is very hard to detect by conventional monitoring. For defenders it signals a known fraud-driven exfiltration channel that is actively being commercialized.
17h