BRIEFOtherhighP82
Chromium 0-day exploit for Android 14-16 for sale
Detected3 October 2026 · 11:03 UTC
A DarkForums seller is offering a full-chain Chromium remote code execution exploit for Android 14-16, billed as 0-day class. If real, it enables drive-by compromise of most Android devices via the browser with no patch available. Defenders should treat it as a high-risk weaponized exploit and watch for mobile targeting.
CategoryOther
Severityhigh
Priority score82
Detected3 October 2026 · 11:03 UTC
Other● 45
SDK bancario de reconocimiento facial antifraude revertido con clave de bypass expuestaA dark web actor published a fully reversed bank facial-recognition SDK, including nine keywords and a bypass key in clear. This anti-fraud module verifies identity in banking apps, so its circulation lowers the bar to evade biometric checks and commit account-takeover or onboarding fraud. Banks relying on such SDKs should audit their biometric flows.Other● 35
Venden cuentas bancarias y KYC, incluida ArgentinaA vendor advertises cheap 'openups', bank accounts and KYC packages for Argentina and a dozen other countries, enabling fraudulent account creation and money laundering. Relevant for monitoring fraud against the Argentine financial sector, though it is a long-running service ad rather than a fresh breach.Other● 34
Herramienta de elusión de KYC y generación de documentos falsosA tool is being shared that automates KYC bypass and document generation against vendors such as Sumsub, Onfido, Persona, Ondato and Veriff. It lowers the barrier for identity fraud and account opening with forged documents at banks and fintechs relying on those providers. Defenders in financial onboarding should treat it as an active fraud enabler.Other● 66
A la venta exploit RCE de Chromium para Windows 10/11A seller is advertising a Chromium RCE chain for Windows 10/11 that reportedly achieves a full renderer escape to code execution. If genuine, this is a high-value browser 0-day suitable for drive-by and watering-hole attacks against almost any target. Patching levels and browser exploit telemetry should be reviewed urgently.Other● 55
Ciberataque contra instalaciones de agua de Arabia SauditaReports indicate Saudi Arabia's water facilities were hacked, targeting critical infrastructure. Attacks on water utilities can disrupt essential services and reflect tactics that may spread to other regions. Although outside LATAM, it is a notable critical-infrastructure incident to monitor closely.Other● 38
Venta de panel de SMS masivos para Colombia con 631.543 créditosA seller is offering a bulk SMS platform preloaded with 631,543 credits (1 credit = 1 SMS) targeting Colombian numbers. Such panels are typically abused for mass smishing, OTP interception and fraud campaigns against banks and telecom customers. It matters because it provides ready-to-use infrastructure for large-scale SMS fraud in the region, even if the panel itself is not a direct breach.