============================================================================== CYBER THREAT INTELLIGENCE - INDICATORS OF COMPROMISE (IOC) LIST ============================================================================== Generated: 2026-09-05 19:25 UTC Report ID: IOC-20260905-192537 Total Indicators: 78 Classification: OPEN - Law Enforcement / DFIR use Sources: Article: Attackers Exploit PaperCut Flaws to Stea..., Article: Critical Citrix NetScaler auth bypass no..., Article: IDScan sued over alleged data breach aff..., Article: OpenAI admits it didn't disclose rogue A..., Article: Phishing Campaign Sends Millions of Emai..., Article: PostgreSQL Fixes 12-Year-Old Logical Dec..., Article: Thousands of OpenAI Agents Quietly Turne..., Article: Trezor Says ShipMonk Breach Exposed 67,0..., CISA KEV Catalog, OpenPhish SUMMARY ------------------------------------------------------------------------------ Domain: 59 CISA KEV (Known Exploited Vulnerability): 10 Phishing URL: 9 Severity: CRITICAL=28, HIGH=50 ============================================================================== [CISA KEV (KNOWN EXPLOITED VULNERABILITY)] - 10 indicator(s) ============================================================================== #1 CVE-2026-85046 Severity: CRITICAL Description: Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but Product: Chromium V8 (Google) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-04 Tags: kev,cisa,active-exploitation #2 CVE-2026-59822 Severity: CRITICAL Description: BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. Product: LiteLLM (BerriAI) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #3 CVE-2026-48710 Severity: CRITICAL Description: Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the Product: Starlette (Kludex) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #4 CVE-2026-49869 Severity: CRITICAL Description: Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. Product: Kestra OSS (Kestra) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #5 CVE-2026-82329 Severity: CRITICAL Description: JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges. Product: Artifactory (JFrog) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #6 CVE-2026-9586 Severity: CRITICAL Description: Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and rem Product: Switchvox (Sangoma) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #7 CVE-2026-83548 Severity: CRITICAL Description: SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. Product: SMA1000 Appliances (SonicWall) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #8 CVE-2026-83549 Severity: CRITICAL Description: SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. Product: SMA1000 Appliances (SonicWall) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #9 CVE-2026-82078 Severity: CRITICAL Description: PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut serv Product: NG/MF (PaperCut) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-08-31 Tags: kev,cisa,active-exploitation #10 CVE-2026-81578 Severity: CRITICAL Description: PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078. Product: NG/MF (PaperCut) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-08-31 Tags: kev,cisa,active-exploitation ============================================================================== [DOMAIN] - 59 indicator(s) ============================================================================== #11 policy.trezor Severity: HIGH Description: Referenced in threat context: Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Dele Source: Article: Trezor Says ShipMonk Breach Exposed 67,0... URL: https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html Date: Tags: domain,extracted #12 metabase.however Severity: HIGH Description: Referenced in threat context: Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Dele Source: Article: Trezor Says ShipMonk Breach Exposed 67,0... URL: https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html Date: Tags: domain,extracted #13 actions.holborn Severity: HIGH Description: Referenced in threat context: Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Dele Source: Article: Trezor Says ShipMonk Breach Exposed 67,0... URL: https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html Date: Tags: domain,extracted #14 remediation.the Severity: HIGH Description: Referenced in threat context: Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Dele Source: Article: Trezor Says ShipMonk Breach Exposed 67,0... URL: https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html Date: Tags: domain,extracted #15 restrictions.the Severity: HIGH Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident Source: Article: OpenAI admits it didn't disclose rogue A... URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/ Date: Tags: domain,extracted #16 impact.in Severity: HIGH Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident Source: Article: OpenAI admits it didn't disclose rogue A... URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/ Date: Tags: domain,extracted #17 succeeded.when Severity: HIGH Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident Source: Article: OpenAI admits it didn't disclose rogue A... URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/ Date: Tags: domain,extracted #18 longer.the Severity: HIGH Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident Source: Article: OpenAI admits it didn't disclose rogue A... URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/ Date: Tags: domain,extracted #19 addresses.openai Severity: HIGH Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident Source: Article: OpenAI admits it didn't disclose rogue A... URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/ Date: Tags: domain,extracted #20 day.openai Severity: HIGH Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident Source: Article: OpenAI admits it didn't disclose rogue A... URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/ Date: Tags: domain,extracted #21 incident.the Severity: HIGH Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident Source: Article: OpenAI admits it didn't disclose rogue A... URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/ Date: Tags: domain,extracted #22 cybersecurity.in Severity: HIGH Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident Source: Article: OpenAI admits it didn't disclose rogue A... URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/ Date: Tags: domain,extracted #23 sandbox.the Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #24 data.the Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #25 behind.about Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #26 method.the Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #27 blob.core Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #28 windows.net Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #29 valid.an Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #30 bypass.blob Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #31 core.windows Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #32 internet.those Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #33 used.in Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #34 platform.openai Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #35 investigation.the Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #36 on.the Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #37 testing.openai Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #38 boards.openai Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #39 face.the Severity: HIGH Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat Source: Article: Thousands of OpenAI Agents Quietly Turne... URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html Date: Tags: domain,extracted #40 said.the Severity: HIGH Description: Referenced in threat context: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universit Source: Article: Attackers Exploit PaperCut Flaws to Stea... URL: https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html Date: Tags: domain,extracted #41 statement.users Severity: HIGH Description: Referenced in threat context: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universit Source: Article: Attackers Exploit PaperCut Flaws to Stea... URL: https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html Date: Tags: domain,extracted #42 cmd.exe Severity: HIGH Description: Referenced in threat context: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universit Source: Article: Attackers Exploit PaperCut Flaws to Stea... URL: https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html Date: Tags: domain,extracted #43 powershell.exe Severity: HIGH Description: Referenced in threat context: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universit Source: Article: Attackers Exploit PaperCut Flaws to Stea... URL: https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html Date: Tags: domain,extracted #44 pc-app.exe Severity: HIGH Description: Referenced in threat context: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universit Source: Article: Attackers Exploit PaperCut Flaws to Stea... URL: https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html Date: Tags: domain,extracted #45 idscan.brian Severity: HIGH Description: Referenced in threat context: IDScan sued over alleged data breach affecting 153 million drivers Source: Article: IDScan sued over alleged data breach aff... URL: https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/ Date: Tags: domain,extracted #46 cards.idscan Severity: HIGH Description: Referenced in threat context: IDScan sued over alleged data breach affecting 153 million drivers Source: Article: IDScan sued over alleged data breach aff... URL: https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/ Date: Tags: domain,extracted #47 documents.given Severity: HIGH Description: Referenced in threat context: IDScan sued over alleged data breach affecting 153 million drivers Source: Article: IDScan sued over alleged data breach aff... URL: https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/ Date: Tags: domain,extracted #48 litigation.state Severity: HIGH Description: Referenced in threat context: IDScan sued over alleged data breach affecting 153 million drivers Source: Article: IDScan sued over alleged data breach aff... URL: https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/ Date: Tags: domain,extracted #49 user.however Severity: HIGH Description: Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt Source: Article: Phishing Campaign Sends Millions of Emai... URL: https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html Date: Tags: domain,extracted #50 mondays.weekday Severity: HIGH Description: Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt Source: Article: Phishing Campaign Sends Millions of Emai... URL: https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html Date: Tags: domain,extracted #51 applicants.details Severity: HIGH Description: Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt Source: Article: Phishing Campaign Sends Millions of Emai... URL: https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html Date: Tags: domain,extracted #52 matches.for Severity: HIGH Description: Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt Source: Article: Phishing Campaign Sends Millions of Emai... URL: https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html Date: Tags: domain,extracted #53 basis.the Severity: HIGH Description: Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt Source: Article: Phishing Campaign Sends Millions of Emai... URL: https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html Date: Tags: domain,extracted #54 acemlnd.com Severity: HIGH Description: Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt Source: Article: Phishing Campaign Sends Millions of Emai... URL: https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html Date: Tags: domain,extracted #55 activehosted.com Severity: HIGH Description: Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt Source: Article: Phishing Campaign Sends Millions of Emai... URL: https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html Date: Tags: domain,extracted #56 networks.although Severity: HIGH Description: Referenced in threat context: Critical Citrix NetScaler auth bypass now leveraged in attacks Source: Article: Critical Citrix NetScaler auth bypass no... URL: https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/ Date: Tags: domain,extracted #57 attacks.the Severity: HIGH Description: Referenced in threat context: Critical Citrix NetScaler auth bypass now leveraged in attacks Source: Article: Critical Citrix NetScaler auth bypass no... URL: https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/ Date: Tags: domain,extracted #58 sharply.tracked Severity: HIGH Description: Referenced in threat context: Critical Citrix NetScaler auth bypass now leveraged in attacks Source: Article: Critical Citrix NetScaler auth bypass no... URL: https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/ Date: Tags: domain,extracted #59 affected.exploitation Severity: HIGH Description: Referenced in threat context: PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Cod Source: Article: PostgreSQL Fixes 12-Year-Old Logical Dec... URL: https://thehackernews.com/2026/09/postgresql-fixes-12-year-old-logical.html Date: Tags: domain,extracted #60 attribute.the Severity: HIGH Description: Referenced in threat context: PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Cod Source: Article: PostgreSQL Fixes 12-Year-Old Logical Dec... URL: https://thehackernews.com/2026/09/postgresql-fixes-12-year-old-logical.html Date: Tags: domain,extracted #61 roblox.com Severity: CRITICAL Description: Phishing domain: roblox.com Source: OpenPhish URL: http://roblox.com.mu/communities/7901998248/LeightXyn Date: Tags: phishing,openphish,domain #62 revenuewise.sbs Severity: CRITICAL Description: Phishing domain: revenuewise.sbs Source: OpenPhish URL: https://revenuewise.sbs/how-to-file/ Date: Tags: phishing,openphish,domain #63 undian-shopee1772.blogspot Severity: CRITICAL Description: Phishing domain: undian-shopee1772.blogspot Source: OpenPhish URL: https://undian-shopee1772.blogspot.com/ Date: Tags: phishing,openphish,domain #64 hadiahshopee3232.blogspot Severity: CRITICAL Description: Phishing domain: hadiahshopee3232.blogspot Source: OpenPhish URL: https://hadiahshopee3232.blogspot.com/?m=1 Date: Tags: phishing,openphish,domain #65 www.newcomc Severity: CRITICAL Description: Phishing domain: www.newcomc Source: OpenPhish URL: http://www.newcomc.weebly.com/ Date: Tags: phishing,openphish,domain #66 pesta-undian-shopee2023.blogspot Severity: CRITICAL Description: Phishing domain: pesta-undian-shopee2023.blogspot Source: OpenPhish URL: https://pesta-undian-shopee2023.blogspot.com/ Date: Tags: phishing,openphish,domain #67 surajyadav-07.github Severity: CRITICAL Description: Phishing domain: surajyadav-07.github Source: OpenPhish URL: https://surajyadav-07.github.io/ecommerce-website Date: Tags: phishing,openphish,domain #68 lbr-icloud.com Severity: CRITICAL Description: Phishing domain: lbr-icloud.com Source: OpenPhish URL: https://lbr-icloud.com/help?JpN Date: Tags: phishing,openphish,domain #69 first-agency-743956.framer Severity: CRITICAL Description: Phishing domain: first-agency-743956.framer Source: OpenPhish URL: http://first-agency-743956.framer.app/ Date: Tags: phishing,openphish,domain ============================================================================== [PHISHING URL] - 9 indicator(s) ============================================================================== #70 http://roblox.com.mu/communities/7901998248/LeightXyn Severity: CRITICAL Description: Active phishing URL: http://roblox.com.mu/communities/7901998248/LeightXyn Source: OpenPhish URL: http://roblox.com.mu/communities/7901998248/LeightXyn Date: Tags: phishing,openphish #71 https://revenuewise.sbs/how-to-file/ Severity: CRITICAL Description: Active phishing URL: https://revenuewise.sbs/how-to-file/ Source: OpenPhish URL: https://revenuewise.sbs/how-to-file/ Date: Tags: phishing,openphish #72 https://revenuewise.sbs/get-transcript/ Severity: CRITICAL Description: Active phishing URL: https://revenuewise.sbs/get-transcript/ Source: OpenPhish URL: https://revenuewise.sbs/get-transcript/ Date: Tags: phishing,openphish #73 https://revenuewise.sbs/businesses-1/ Severity: CRITICAL Description: Active phishing URL: https://revenuewise.sbs/businesses-1/ Source: OpenPhish URL: https://revenuewise.sbs/businesses-1/ Date: Tags: phishing,openphish #74 https://revenuewise.sbs/get-your-refund-faster-tell-irs-to-direct-deposit-your-refund-to-one-two-or-three-accounts/ Severity: CRITICAL Description: Active phishing URL: https://revenuewise.sbs/get-your-refund-faster-tell-irs-to-direct-deposit-your-refund-to-one-two-or-three-accounts/ Source: OpenPhish URL: https://revenuewise.sbs/get-your-refund-faster-tell-irs-to-direct-deposit-your-refund-to-one-two-or-three-accounts/ Date: Tags: phishing,openphish #75 https://revenuewise.sbs/credits-and-deductions-for-individuals/ Severity: CRITICAL Description: Active phishing URL: https://revenuewise.sbs/credits-and-deductions-for-individuals/ Source: OpenPhish URL: https://revenuewise.sbs/credits-and-deductions-for-individuals/ Date: Tags: phishing,openphish #76 https://revenuewise.sbs/clean-vehicle-and-energy-credits/ Severity: CRITICAL Description: Active phishing URL: https://revenuewise.sbs/clean-vehicle-and-energy-credits/ Source: OpenPhish URL: https://revenuewise.sbs/clean-vehicle-and-energy-credits/ Date: Tags: phishing,openphish #77 https://revenuewise.sbs/about-refunds/ Severity: CRITICAL Description: Active phishing URL: https://revenuewise.sbs/about-refunds/ Source: OpenPhish URL: https://revenuewise.sbs/about-refunds/ Date: Tags: phishing,openphish #78 https://undian-shopee1772.blogspot.com/ Severity: CRITICAL Description: Active phishing URL: https://undian-shopee1772.blogspot.com/ Source: OpenPhish URL: https://undian-shopee1772.blogspot.com/ Date: Tags: phishing,openphish ============================================================================== RECOMMENDED ACTIONS ============================================================================== 1. Search SIEM/network logs for all listed indicators 2. Block listed domains at DNS/proxy immediately 3. Scan endpoints for listed SHA256 hashes 4. Check email gateways for listed sender addresses/links 5. Block listed IP addresses at the firewall 6. Share IOCs with partner agencies and ISACs 7. Update detection rules (Sigma/YARA/Suricata/Splunk) 8. Monitor for indicator rotation (new domains, IP changes) ============================================================================== END OF IOC LIST - IOC-20260905-192537 ==============================================================================