PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
Kalir Brief · Item21 September 2026 · 05:37 UTC
BRIEFAccess salelowP45

Fraudulent Emergency Data Requests (EDR) service for sale

Detected21 September 2026 · 05:37 UTC
Why it matters

A seller on DarkForums is offering Emergency Data Requests (EDRs), a service that lets buyers impersonate law enforcement to compel telecoms, banks and platforms into handing over subscriber data. This enables account takeover and data disclosure with no technical intrusion, so it is very hard to detect by conventional monitoring. For defenders it signals a known fraud-driven exfiltration channel that is actively being commercialized.

MetadataRECORD
CategoryAccess sale
Severitylow
Priority score45
Detected21 September 2026 · 05:37 UTC
Related items6
Access sale78
Venta de acceso a empresa con US$13B de facturaciónA seller on DarkForums is offering verified access to an unnamed company reporting US$13B in annual revenue, posted 3 Sep 2026. Initial-access sales of this caliber let buyers drop ransomware or exfiltrate data directly. Defenders should treat exposed SSLVPN/RDP and recent phishing as likely precursors.
1d
Access sale78
Venta de acceso verificado a infraestructura del Gobierno de FranciaA threat actor is offering verified access to one of the French government's infrastructures, a high-value initial-access sale. Such access enables lateral movement into public-sector networks, data theft or ransomware staging. A confirmed government intrusion is a strategic target demanding urgent validation and attribution.
2d
Access sale62
Acceso al portal gubernamental turco its.gov.tr a la ventaA seller is advertising access to the Turkish government subdomain paydas.its.gov.tr, posted on 2026-09-16. Government portal access can enable data theft, service abuse or lateral movement into other public-sector systems. It is a named high-value government target, so defenders tracking state-sector exposure should note it even though it is outside Latin America.
2d
Access sale30
Venta de acceso de administrador a hadiahmisteri.onlineA poster is trading administrator access to the Indonesian website hadiahmisteri.online, giving full control of the site and its backend. Admin access enables defacement, data theft or use as a foothold for further attacks. It is older (March 2026) and outside the region, so it ranks lower priority.
2d
Access sale78
Venta de acceso Domain Admin a empresa de IndonesiaA seller is offering Active Directory Domain Admin access to an Indonesian food & beverage company with over $5B in revenue. Domain Admin grants full control of the corporate network, enabling ransomware staging, lateral movement and mass data exfiltration. This is a high-value access listing that defenders at large enterprises should treat as a priority and monitor for related IOCs.
2d
Access sale48
Credenciales de administrador de WordPress en venta (Cloud9Base)Stealer logs advertised as valid WordPress administrator credentials were posted by the actor Cloud9Base. Valid CMS admin access allows attackers to deface sites, plant webshells and pivot into hosting infrastructure. Organizations running WordPress should check for compromised admin accounts and force password resets immediately.
3d