============================================================================== CYBER THREAT INTELLIGENCE - INDICATORS OF COMPROMISE (IOC) LIST ============================================================================== Generated: 2026-09-08 12:41 UTC Report ID: IOC-20260908-124108 Total Indicators: 43 Classification: OPEN - Law Enforcement / DFIR use Sources: Article: MikroTik Patches Critical Flaws Chained to Hack Routers, Article: N-able Patches Critical Zero-Day in N-central, Article: ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More, CISA KEV Catalog, OpenPhish SUMMARY ------------------------------------------------------------------------------ IP Address: 15 CISA KEV (Known Exploited Vulnerability): 10 Phishing URL: 9 Domain: 9 Severity: CRITICAL=28, HIGH=15 ============================================================================== [CISA KEV (KNOWN EXPLOITED VULNERABILITY)] - 10 indicator(s) ============================================================================== #1 CVE-2026-85046 Severity: CRITICAL Description: Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but Product: Chromium V8 (Google) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85046 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-04 Tags: kev,cisa,active-exploitation #2 CVE-2026-59822 Severity: CRITICAL Description: BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. Product: LiteLLM (BerriAI) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-59822 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #3 CVE-2026-48710 Severity: CRITICAL Description: Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the Product: Starlette (Kludex) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-48710 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #4 CVE-2026-49869 Severity: CRITICAL Description: Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. Product: Kestra OSS (Kestra) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-49869 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #5 CVE-2026-82329 Severity: CRITICAL Description: JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges. Product: Artifactory (JFrog) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-82329 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #6 CVE-2026-9586 Severity: CRITICAL Description: Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and rem Product: Switchvox (Sangoma) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9586 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #7 CVE-2026-83548 Severity: CRITICAL Description: SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. Product: SMA1000 Appliances (SonicWall) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-83548 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #8 CVE-2026-83549 Severity: CRITICAL Description: SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. Product: SMA1000 Appliances (SonicWall) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-83549 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #9 CVE-2026-82078 Severity: CRITICAL Description: PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut serv Product: NG/MF (PaperCut) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-82078 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-08-31 Tags: kev,cisa,active-exploitation #10 CVE-2026-81578 Severity: CRITICAL Description: PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078. Product: NG/MF (PaperCut) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-81578 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-08-31 Tags: kev,cisa,active-exploitation ============================================================================== [IP ADDRESS] - 15 indicator(s) ============================================================================== #11 23.234.64.0 Severity: HIGH Description: C2/infrastructure in threat context: N-able Patches Critical Zero-Day in N-central Source: Article: N-able Patches Critical Zero-Day in N-central URL: https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/ Date: Tags: ip,infrastructure #12 23.234.64.0 Severity: HIGH Description: C2/infrastructure in threat context: N-able Patches Critical Zero-Day in N-central Source: Article: N-able Patches Critical Zero-Day in N-central URL: https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/ Date: Tags: ip,infrastructure #13 23.234.64.0 Severity: HIGH Description: C2/infrastructure in threat context: N-able Patches Critical Zero-Day in N-central Source: Article: N-able Patches Critical Zero-Day in N-central URL: https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/ Date: Tags: ip,infrastructure #14 23.234.64.0 Severity: HIGH Description: C2/infrastructure in threat context: N-able Patches Critical Zero-Day in N-central Source: Article: N-able Patches Critical Zero-Day in N-central URL: https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/ Date: Tags: ip,infrastructure #15 23.234.64.0 Severity: HIGH Description: C2/infrastructure in threat context: N-able Patches Critical Zero-Day in N-central Source: Article: N-able Patches Critical Zero-Day in N-central URL: https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/ Date: Tags: ip,infrastructure #16 82.192.72.4 Severity: HIGH Description: C2/infrastructure in threat context: ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More Source: Article: ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More URL: https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html Date: Tags: ip,infrastructure #17 103.102.31.18 Severity: HIGH Description: C2/infrastructure in threat context: ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More Source: Article: ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More URL: https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html Date: Tags: ip,infrastructure #18 82.192.72.4 Severity: HIGH Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/ Date: Tags: ip,infrastructure #19 103.102.31.18 Severity: HIGH Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/ Date: Tags: ip,infrastructure #20 82.192.72.4 Severity: HIGH Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/ Date: Tags: ip,infrastructure #21 103.102.31.18 Severity: HIGH Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/ Date: Tags: ip,infrastructure #22 82.192.72.4 Severity: HIGH Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/ Date: Tags: ip,infrastructure #23 103.102.31.18 Severity: HIGH Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/ Date: Tags: ip,infrastructure #24 82.192.72.4 Severity: HIGH Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/ Date: Tags: ip,infrastructure #25 103.102.31.18 Severity: HIGH Description: C2/infrastructure in threat context: MikroTik Patches Critical Flaws Chained to Hack Routers Source: Article: MikroTik Patches Critical Flaws Chained to Hack Routers URL: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/ Date: Tags: ip,infrastructure ============================================================================== [PHISHING URL] - 9 indicator(s) ============================================================================== #26 https://gurl.pro/roblox-users-8715356-profile Severity: CRITICAL Description: Active phishing URL: https://gurl.pro/roblox-users-8715356-profile Source: OpenPhish URL: https://gurl.pro/roblox-users-8715356-profile Date: Tags: phishing,openphish #27 https://shorten.tv/l65iO Severity: CRITICAL Description: Active phishing URL: https://shorten.tv/l65iO Source: OpenPhish URL: https://shorten.tv/l65iO Date: Tags: phishing,openphish #28 http://www.shorten.tv/jRftj/ Severity: CRITICAL Description: Active phishing URL: http://www.shorten.tv/jRftj/ Source: OpenPhish URL: http://www.shorten.tv/jRftj/ Date: Tags: phishing,openphish #29 https://itstrafflc.us/edoc/indextgpart.html Severity: CRITICAL Description: Active phishing URL: https://itstrafflc.us/edoc/indextgpart.html Source: OpenPhish URL: https://itstrafflc.us/edoc/indextgpart.html Date: Tags: phishing,openphish #30 https://www.estudiocils.com.ar/home/nkl-log.php Severity: CRITICAL Description: Active phishing URL: https://www.estudiocils.com.ar/home/nkl-log.php Source: OpenPhish URL: https://www.estudiocils.com.ar/home/nkl-log.php Date: Tags: phishing,openphish #31 http://www.estudiocils.com.ar/home Severity: CRITICAL Description: Active phishing URL: http://www.estudiocils.com.ar/home Source: OpenPhish URL: http://www.estudiocils.com.ar/home Date: Tags: phishing,openphish #32 https://metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel.app/embedded-wallets/sdk/unity Severity: CRITICAL Description: Active phishing URL: https://metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel.app/embedded-wallets/sdk/unity Source: OpenPhish URL: https://metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel.app/embedded-wallets/sdk/unity Date: Tags: phishing,openphish #33 https://metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel.app/embedded-wallets/sdk/react-native Severity: CRITICAL Description: Active phishing URL: https://metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel.app/embedded-wallets/sdk/react-native Source: OpenPhish URL: https://metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel.app/embedded-wallets/sdk/react-native Date: Tags: phishing,openphish #34 https://amazon-landing-page-umber.vercel.app/ Severity: CRITICAL Description: Active phishing URL: https://amazon-landing-page-umber.vercel.app/ Source: OpenPhish URL: https://amazon-landing-page-umber.vercel.app/ Date: Tags: phishing,openphish ============================================================================== [DOMAIN] - 9 indicator(s) ============================================================================== #35 gurl.pro Severity: CRITICAL Description: Phishing domain: gurl.pro Source: OpenPhish URL: https://gurl.pro/roblox-users-8715356-profile Date: Tags: phishing,openphish,domain #36 shorten.tv Severity: CRITICAL Description: Phishing domain: shorten.tv Source: OpenPhish URL: https://shorten.tv/l65iO Date: Tags: phishing,openphish,domain #37 www.shorten Severity: CRITICAL Description: Phishing domain: www.shorten Source: OpenPhish URL: http://www.shorten.tv/jRftj/ Date: Tags: phishing,openphish,domain #38 itstrafflc.us Severity: CRITICAL Description: Phishing domain: itstrafflc.us Source: OpenPhish URL: https://itstrafflc.us/edoc/indextgpart.html Date: Tags: phishing,openphish,domain #39 www.estudiocils Severity: CRITICAL Description: Phishing domain: www.estudiocils Source: OpenPhish URL: https://www.estudiocils.com.ar/home/nkl-log.php Date: Tags: phishing,openphish,domain #40 metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel Severity: CRITICAL Description: Phishing domain: metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel Source: OpenPhish URL: https://metamask-docs-git-dependabot-npmandya-95394d-consensys-ddffed67.vercel.app/embedded-wallets/sdk/unity Date: Tags: phishing,openphish,domain #41 amazon-landing-page-umber.vercel Severity: CRITICAL Description: Phishing domain: amazon-landing-page-umber.vercel Source: OpenPhish URL: https://amazon-landing-page-umber.vercel.app/ Date: Tags: phishing,openphish,domain #42 www.amazon Severity: CRITICAL Description: Phishing domain: www.amazon Source: OpenPhish URL: https://www.amazon-landing-page-umber.vercel.app/ Date: Tags: phishing,openphish,domain #43 smilling-long-pannel.edgeone Severity: CRITICAL Description: Phishing domain: smilling-long-pannel.edgeone Source: OpenPhish URL: https://smilling-long-pannel.edgeone.dev/ Date: Tags: phishing,openphish,domain ============================================================================== RECOMMENDED ACTIONS ============================================================================== 1. Search SIEM/network logs for all listed indicators 2. Block listed domains at DNS/proxy immediately 3. Scan endpoints for listed SHA256 hashes 4. Check email gateways for listed sender addresses/links 5. Block listed IP addresses at the firewall 6. Share IOCs with partner agencies and ISACs 7. Update detection rules (Sigma/YARA/Suricata/Splunk) 8. Monitor for indicator rotation (new domains, IP changes) ============================================================================== END OF IOC LIST - IOC-20260908-124108 ==============================================================================