PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-85046 — Google / Chromium V8vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MF
Kalir Brief · Item10 September 2026 · 08:13 UTC
BRIEFAccess salelowP42

Sale of admin access to compromised WordPress panels

Detected10 September 2026 · 08:13 UTC
Why it matters

A seller is offering verified administrator-level access to compromised WordPress installations, likely a bulk list of hijacked admin panels. No specific victim or region is named, so the direct impact is unclear, but stolen CMS admin access is commonly reused for webshell deployment, SEO poisoning and malware hosting. Defenders should treat it as a reminder to audit WordPress admin authentication and monitor for unauthorized admin logins.

MetadataRECORD
CategoryAccess sale
Severitylow
Priority score42
Detected10 September 2026 · 08:13 UTC
Related items6
Access sale46
Credenciales de acceso SSL VPN Fortinet obtenidas por fuerza brutaThe actor claims a batch of freshly brute-forced Fortinet SSL VPN credentials, i.e., remote-access footholds into enterprise networks. Valid SSLVPN credentials are a high-value initial-access vector for ransomware and lateral movement, and Fortinet appliances remain a top target. No victim is named, which lowers confidence, but any exposed Fortinet access warrants review of your own edge devices.
8h
Access sale65
Servicio de búsqueda de credenciales filtradas LeakZero ofrece acceso masivo a cuentasThis service aggregates URL:LOG:PASS (ULP) data from multiple breaches and lets subscribers search by domain, making credential stuffing and account takeover trivially easy. It affects organizations worldwide, and the scale (15KKK rows) means many corporate and personal accounts are exposed. Defenders should treat any leaked credential as compromised, enforce MFA, and monitor for anomalous logins.
11d
Access sale75
Venta de acceso total a la red corporativa de Kido Group (kdc.vn)An exclusive bidding thread advertises a complete network compromise of Kido Group (kdc.vn), including executive archives, SharePoint databases and file server repositories. This is a serious initial access sale that could enable ransomware or large-scale data theft. The breadth of access makes it a high-value lead even outside Latin America.
11d
Access sale75
Venta de 74.000 accesos a correos electrónicosA seller is offering 74,000 valid email access credentials, likely obtained from data breaches or stealer malware. These are complete accesses to email accounts, which can be used for account recovery, financial fraud, and further phishing campaigns. The freshness of the data (dated August 28) makes it an immediate threat for email account owners.
12d
Access sale90
Venta de acceso a API de RENAPER y bases de datos gubernamentales de ArgentinaA seller is offering access to an API service tied to RENAPER, Argentina's national identity registry, along with other government databases. This would allow doxing, identity theft, and large-scale fraud against Argentine citizens. It is a direct threat to critical government infrastructure and must be treated as a high-priority incident.
12d
Access sale68
Venta de acceso VMware Horizon a empresa tecnológica suecaAccess to a VMware Horizon environment of a Swedish technology/SaaS company ($100M-$250M revenue) is being sold. VMware Horizon is a known initial attack vector for ransomware. This access could give the buyer a foothold in the corporate network and is a credible threat.
13d