BRIEFAccess salehighP76
Tailscale access to a large Asian aerospace company for sale
Large aerospace company (Asia)
Detected28 September 2026 · 13:48 UTC
A seller is offering Tailscale access to a large aerospace company in Asia, a high-value target due to defense and supply-chain sensitivity. Remote-access footholds like this are typically bought to pivot into data theft or ransomware. Defenders should hunt for unauthorized Tailscale nodes and review remote-access logs.
CategoryAccess sale
Severityhigh
Priority score76
Detected28 September 2026 · 13:48 UTC
Access sale● 72
Se ofrece en venta acceso a datos del Departamento de Comercio de EE. UU.A seller on DarkForums is advertising data or access tied to the U.S. Department of Commerce, a high-value federal target. If genuine, such material could enable further intrusion, credential abuse or influence operations against a government body. It should be triaged as a validated government-target lead rather than dismissed as chatter.Access sale● 60
Credenciales de phpMyAdmin del ITESHU de México a la ventaCredentials for the phpMyAdmin panel of ITESHU, a Mexican higher-education institute, are being offered on a hacking forum. Access to phpMyAdmin usually means direct control over the institution's backend databases, risking exfiltration or tampering of student and administrative records. This is a timely lead for defenders at Mexican public education institutions.Access sale● 78
Venta de exploit RCE pre-autenticación para Oracle PeopleSoftShinyHunters is selling a pre-authentication RCE plus WAF bypass for Oracle PeopleSoft, an ERP widely deployed across government agencies, ministries, universities and banks. This kind of unauthenticated exploit enables initial access without credentials and is highly relevant to public-sector targets in Latin America. Defenders running PeopleSoft should urgently hunt for exposed internet-facing instances and review WAF/DB logs for exploitation attempts.Access sale● 50
Credenciales y cookies del Colegio Faraday (Perú) a la ventaCredentials and session cookies for the Peruvian school colegiofaraday.edu.pe are being offered on an underground forum. Such access lets an attacker log in as staff or students, pivot into internal portals and abuse institutional email. It is a fresh compromise of a Latin American education target worth monitoring for lateral movement.Access sale● 45
Venta de email gubernamental de la Policía Estatal italiana (poliziadistato.it)A user is selling a @poliziadistato.it government email account for over $500, posted minutes ago. A law-enforcement credential can enable phishing, internal access and impersonation of Italian authorities. Defenders should treat it as a possible initial-access vector even though it sits outside the AR-LATAM region.Access sale● 57
Lista de 6.938 servicios expuestos verificados (RDP/SQL/SMB)A threat actor is sharing a verified, live list of 6,938 exposed services including RDP, MongoDB, PostgreSQL, MySQL and SMB endpoints. It is effectively a ready-made target list for ransomware and intrusion crews. Defenders should treat it as an exposure-hunting checklist and confirm none of their assets appear.