ioc_value,ioc_type,severity,description,product,source,url,date,tags,stix_indicator_id,section,confidence CVE-2026-85046,cve,CRITICAL,"Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but",Chromium V8 (Google),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-04,kev;cisa;active-exploitation,indicator--00000000-00000001-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-59822,cve,CRITICAL,BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.,LiteLLM (BerriAI),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000002-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-48710,cve,CRITICAL,"Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the",Starlette (Kludex),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000003-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-49869,cve,CRITICAL,Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.,Kestra OSS (Kestra),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000004-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-82329,cve,CRITICAL,JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.,Artifactory (JFrog),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000005-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-9586,cve,CRITICAL,"Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and rem",Switchvox (Sangoma),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000006-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-83548,cve,CRITICAL,SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.,SMA1000 Appliances (SonicWall),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000007-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-83549,cve,CRITICAL,"SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.",SMA1000 Appliances (SonicWall),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-09-02,kev;cisa;active-exploitation,indicator--00000000-00000008-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-82078,cve,CRITICAL,PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut serv,NG/MF (PaperCut),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-08-31,kev;cisa;active-exploitation,indicator--00000000-00000009-0000-0000-0000-000000000000,CISA KEV (KNOWN EXPLOITED VULNERABILITY),100 CVE-2026-81578,cve,CRITICAL,PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.,NG/MF (PaperCut),CISA KEV Catalog,https://www.cisa.gov/known-exploited-vulnerabilities-catalog,2026-08-31,kev;cisa;active-exploitation,indicator--00000000-00000010-0000-0000-0000-000000000000,SHA256 HASH,100 5db1b6d52faf60b4f32d6fd0c7c938e4d05d29a14c32ded4a9668357c08b6a91,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000011-0000-0000-0000-000000000000,SHA256 HASH,100 09739441ed4599bac2f8159028f772f71e4b25c8badfff95574e56d7384f3dbe,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000012-0000-0000-0000-000000000000,SHA256 HASH,100 fea1bc36632c71e5a839803469ef60ac47595d36b2c50934ac109ade6df06e61,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000013-0000-0000-0000-000000000000,SHA256 HASH,100 83f7d565b0465546027052b597af46eae3a199e7a91fcc2ab936341147349130,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000014-0000-0000-0000-000000000000,SHA256 HASH,100 7007a78d50a993cb174c685eba96eb442c9507e38fd9d8e5dffc712f613ec110,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000015-0000-0000-0000-000000000000,SHA256 HASH,100 6cf1b5e92a9c0756f597a5ddefb38eba32961c52efac7ab2a0aa52c639a8fc53,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000016-0000-0000-0000-000000000000,SHA256 HASH,100 ed72f4cd8d467b5c5d95ae6aeca4aaeea14d79565d379c1ca5871a714727be16,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000017-0000-0000-0000-000000000000,SHA256 HASH,100 feeea9d0bf6ae7396d28271baa51ae50df5169ce5d32a516865856f91abc50b3,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000018-0000-0000-0000-000000000000,SHA256 HASH,100 d53c760c23b4405eb04ad0f20ead375440344b3bdf1fb7854ed12e40d155eabe,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000019-0000-0000-0000-000000000000,SHA256 HASH,100 2f02b09d61d432134e994ad671258f523bbf289ae6091fd4eae192c60bd51b6f,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000020-0000-0000-0000-000000000000,SHA256 HASH,100 8f30b57928934ae67478d0e690c91d046e35a638da098d02922a4a88a0fdb66c,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000021-0000-0000-0000-000000000000,SHA256 HASH,100 a1d8af3a6acb731f07f72040eccb3450c1c83d40e29f736c2a63d35388660be4,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000022-0000-0000-0000-000000000000,SHA256 HASH,100 12810854c8b2c391b23e2e18b013e873d0369b0637aa3cf993136c07188ba3b8,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000023-0000-0000-0000-000000000000,SHA256 HASH,100 009a1e2d7a582a24e50cf2ffc2a005482c8e38f22bf5ed416053855f8d054e1e,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000024-0000-0000-0000-000000000000,SHA256 HASH,100 4bb923eb040aa13ca8fd409c31ee4729c60ddff32e350efe1c5a4a9168a065f5,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000025-0000-0000-0000-000000000000,SHA256 HASH,100 94630b96f628c96a6bff7904b40ffc9ad67c86f8a4ff6080c3b524831c93f402,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000026-0000-0000-0000-000000000000,SHA256 HASH,100 72e70936f0dbe459142a1d867617c35f8d0cce5d18c6a49e1090a2a5adc8e558,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000027-0000-0000-0000-000000000000,SHA256 HASH,100 a8bfab4de81a1acb04aacdf757346946b0f5e30f0c9f402004016d0e425119c7,file-hash:sha256,CRITICAL,Malware/payload hash: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,,Article: DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms,https://cybersecuritynews.com/dprk-linked-hackers/,,hash;malware,indicator--00000000-00000028-0000-0000-0000-000000000000,PHISHING URL,100 https://loyaltyprogram.ink/aQzXm,other,CRITICAL,Active phishing URL: https://loyaltyprogram.ink/aQzXm,,OpenPhish,https://loyaltyprogram.ink/aQzXm,,phishing;openphish,indicator--00000000-00000029-0000-0000-0000-000000000000,PHISHING URL,100 http://hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/,other,CRITICAL,Active phishing URL: http://hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/,,OpenPhish,http://hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/,,phishing;openphish,indicator--00000000-00000030-0000-0000-0000-000000000000,PHISHING URL,100 http://www.hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/,other,CRITICAL,Active phishing URL: http://www.hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/,,OpenPhish,http://www.hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/,,phishing;openphish,indicator--00000000-00000031-0000-0000-0000-000000000000,PHISHING URL,100 https://ledgerw.vercel.app/login,other,CRITICAL,Active phishing URL: https://ledgerw.vercel.app/login,,OpenPhish,https://ledgerw.vercel.app/login,,phishing;openphish,indicator--00000000-00000032-0000-0000-0000-000000000000,PHISHING URL,100 https://zwjf76j-h07j.vercel.app/,other,CRITICAL,Active phishing URL: https://zwjf76j-h07j.vercel.app/,,OpenPhish,https://zwjf76j-h07j.vercel.app/,,phishing;openphish,indicator--00000000-00000033-0000-0000-0000-000000000000,PHISHING URL,100 https://cjrb11r-h07r.vercel.app/,other,CRITICAL,Active phishing URL: https://cjrb11r-h07r.vercel.app/,,OpenPhish,https://cjrb11r-h07r.vercel.app/,,phishing;openphish,indicator--00000000-00000034-0000-0000-0000-000000000000,PHISHING URL,100 http://boaa.privatbanks.org/,other,CRITICAL,Active phishing URL: http://boaa.privatbanks.org/,,OpenPhish,http://boaa.privatbanks.org/,,phishing;openphish,indicator--00000000-00000035-0000-0000-0000-000000000000,PHISHING URL,100 http://wteamcommunity.com/,other,CRITICAL,Active phishing URL: http://wteamcommunity.com/,,OpenPhish,http://wteamcommunity.com/,,phishing;openphish,indicator--00000000-00000036-0000-0000-0000-000000000000,PHISHING URL,100 http://zavravo-kxt-felquro-p9t2dp56.pages.dev/,other,CRITICAL,Active phishing URL: http://zavravo-kxt-felquro-p9t2dp56.pages.dev/,,OpenPhish,http://zavravo-kxt-felquro-p9t2dp56.pages.dev/,,phishing;openphish,indicator--00000000-00000037-0000-0000-0000-000000000000,DOMAIN,100 loyaltyprogram.ink,domain-name,CRITICAL,Phishing domain: loyaltyprogram.ink,,OpenPhish,https://loyaltyprogram.ink/aQzXm,,phishing;openphish;domain,indicator--00000000-00000038-0000-0000-0000-000000000000,DOMAIN,100 nexusqalinka2.quest,domain-name,CRITICAL,Phishing domain: nexusqalinka2.quest,,OpenPhish,http://hs393765aff890a3eac6911d6f8eb9dd9b.nexusqalinka2.quest/,,phishing;openphish;domain,indicator--00000000-00000039-0000-0000-0000-000000000000,DOMAIN,100 ledgerw.vercel,domain-name,CRITICAL,Phishing domain: ledgerw.vercel,,OpenPhish,https://ledgerw.vercel.app/login,,phishing;openphish;domain,indicator--00000000-00000040-0000-0000-0000-000000000000,DOMAIN,100 zwjf76j-h07j.vercel,domain-name,CRITICAL,Phishing domain: zwjf76j-h07j.vercel,,OpenPhish,https://zwjf76j-h07j.vercel.app/,,phishing;openphish;domain,indicator--00000000-00000041-0000-0000-0000-000000000000,DOMAIN,100 cjrb11r-h07r.vercel,domain-name,CRITICAL,Phishing domain: cjrb11r-h07r.vercel,,OpenPhish,https://cjrb11r-h07r.vercel.app/,,phishing;openphish;domain,indicator--00000000-00000042-0000-0000-0000-000000000000,DOMAIN,100 boaa.privatbanks,domain-name,CRITICAL,Phishing domain: boaa.privatbanks,,OpenPhish,http://boaa.privatbanks.org/,,phishing;openphish;domain,indicator--00000000-00000043-0000-0000-0000-000000000000,DOMAIN,100 wteamcommunity.com,domain-name,CRITICAL,Phishing domain: wteamcommunity.com,,OpenPhish,http://wteamcommunity.com/,,phishing;openphish;domain,indicator--00000000-00000044-0000-0000-0000-000000000000,DOMAIN,100 zavravo-kxt-felquro-p9t2dp56.pages,domain-name,CRITICAL,Phishing domain: zavravo-kxt-felquro-p9t2dp56.pages,,OpenPhish,http://zavravo-kxt-felquro-p9t2dp56.pages.dev/,,phishing;openphish;domain,indicator--00000000-00000045-0000-0000-0000-000000000000,DOMAIN,100 amplifyapp.com,domain-name,CRITICAL,Phishing domain: amplifyapp.com,,OpenPhish,https://staging.d8yffvk7rzff1.amplifyapp.com/,,phishing;openphish;domain,indicator--00000000-00000046-0000-0000-0000-000000000000,DOMAIN,100