PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
Kalir Brief · Item18 September 2026 · 23:12 UTC
BRIEFAccess salehighP78

Active Directory Domain Admin access to Indonesian firm for sale

Indonesian food & beverage company ($5B+ revenue)

Detected18 September 2026 · 23:12 UTC
Why it matters

A seller is offering Active Directory Domain Admin access to an Indonesian food & beverage company with over $5B in revenue. Domain Admin grants full control of the corporate network, enabling ransomware staging, lateral movement and mass data exfiltration. This is a high-value access listing that defenders at large enterprises should treat as a priority and monitor for related IOCs.

MetadataRECORD
CategoryAccess sale
Severityhigh
Priority score78
Detected18 September 2026 · 23:12 UTC
Related items6
Access sale48
Credenciales de administrador de WordPress en venta (Cloud9Base)Stealer logs advertised as valid WordPress administrator credentials were posted by the actor Cloud9Base. Valid CMS admin access allows attackers to deface sites, plant webshells and pivot into hosting infrastructure. Organizations running WordPress should check for compromised admin accounts and force password resets immediately.
12h
Access sale48
Venta de acceso admin a sitios WordPressSeller CLOUD9BASE is advertising valid WordPress administrator credentials in bulk, the kind of access that lets an intruder deploy webshells, deface sites or pivot into hosting. It is cross-posted across several forums, signalling an active broker, and any organisation running unpatched WordPress should treat it as a live risk.
14h
Access sale38
Venta de accesos de administrador de WordPress (URL y credenciales)A dump of WordPress administrator URLs paired with username and password credentials is being circulated, giving buyers ready access to web control panels. Sites running unpatched plugins are the usual victims, and such access is frequently the entry point for defacement, SEO spam or webshell deployment. No specific targets are named, so immediate relevance is limited, but it is a live access-sale listing.
15h
Access sale62
Compra de datos de la argentina Bull Market BrokersA buyer on DarkForums is soliciting valid leads or credentials tied to inversiones.bullmarket.com.ar, an Argentine brokerage. This signals active interest in compromising an Argentine financial-sector target, likely via credential stuffing or account takeover. Defenders at the firm should watch for brute-force, phishing and anomalous logins.
20h
Access sale42
Dump y acceso admin de alifyaeducation.co.uk a la ventaA fresh listing offers a dumped database plus administrative access for alifyaeducation.co.uk. Admin access allows full site takeover, data theft and abuse of the host for further attacks. Even a small education target is a useful pivot for phishing and hosting infrastructure.
1d
Access sale70
Filtración y acceso de administrador a la base de datos de personal de Xarxa Tecla (SISCAT)A threat actor is leaking a personnel database from xarxatecla.cat (SISCAT) while offering associated email and admin access. This combines a data leak with privileged access to a Catalan telecom/technology network, enabling follow-on intrusion. Privileged access plus PII raises both fraud and lateral-movement risk.
1d