============================================================================== CYBER THREAT INTELLIGENCE - INDICATORS OF COMPROMISE (IOC) LIST ============================================================================== Generated: 2026-09-11 12:15 UTC Report ID: IOC-20260911-121509 Total Indicators: 28 Classification: OPEN - Law Enforcement / DFIR use Sources: CISA KEV Catalog, OpenPhish SUMMARY ------------------------------------------------------------------------------ CISA KEV (Known Exploited Vulnerability): 10 Phishing URL: 9 Domain: 9 Severity: CRITICAL=28 ============================================================================== [CISA KEV (KNOWN EXPLOITED VULNERABILITY)] - 10 indicator(s) ============================================================================== #1 CVE-2026-86060 Severity: CRITICAL Description: MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation. Product: RouterOS (MikroTik) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-86060 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-10 Tags: kev,cisa,active-exploitation #2 CVE-2026-67277 Severity: CRITICAL Description: MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. Product: RouterOS (MikroTik) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-67277 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-10 Tags: kev,cisa,active-exploitation #3 CVE-2026-19490 Severity: CRITICAL Description: Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Pr Product: NetScaler (Citrix) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-19490 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-09 Tags: kev,cisa,active-exploitation #4 CVE-2025-25249 Severity: CRITICAL Description: Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. Product: Multiple Products (Fortinet) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-25249 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-09 Tags: kev,cisa,active-exploitation #5 CVE-2026-87491 Severity: CRITICAL Description: Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, includin Product: Chromium V8 (Google) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87491 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-09 Tags: kev,cisa,active-exploitation #6 CVE-2026-20079 Severity: CRITICAL Description: Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker t Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management (Cisco) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-20079 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-09 Tags: kev,cisa,active-exploitation #7 CVE-2026-75650 Severity: CRITICAL Description: Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code. Product: Commerce and Magento (Adobe) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-75650 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-08 Tags: kev,cisa,active-exploitation #8 CVE-2026-81963 Severity: CRITICAL Description: Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM. Product: Windows (Microsoft) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-81963 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-08 Tags: kev,cisa,active-exploitation #9 CVE-2026-86218 Severity: CRITICAL Description: N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution. Product: N-central (N-able) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-86218 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-08 Tags: kev,cisa,active-exploitation #10 CVE-2026-85880 Severity: CRITICAL Description: Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. Product: Windows (Microsoft) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85880 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-08 Tags: kev,cisa,active-exploitation ============================================================================== [PHISHING URL] - 9 indicator(s) ============================================================================== #11 https://suport-coinsquare.zapier.app/portal Severity: CRITICAL Description: Active phishing URL: https://suport-coinsquare.zapier.app/portal Source: OpenPhish URL: https://suport-coinsquare.zapier.app/portal Date: Tags: phishing,openphish #12 https://view-coisquared.zapier.app/started Severity: CRITICAL Description: Active phishing URL: https://view-coisquared.zapier.app/started Source: OpenPhish URL: https://view-coisquared.zapier.app/started Date: Tags: phishing,openphish #13 http://protecpackonlinedocument-ymafg.ondigitalocean.app/ Severity: CRITICAL Description: Active phishing URL: http://protecpackonlinedocument-ymafg.ondigitalocean.app/ Source: OpenPhish URL: http://protecpackonlinedocument-ymafg.ondigitalocean.app/ Date: Tags: phishing,openphish #14 https://view-coisquared.zapier.app/ Severity: CRITICAL Description: Active phishing URL: https://view-coisquared.zapier.app/ Source: OpenPhish URL: https://view-coisquared.zapier.app/ Date: Tags: phishing,openphish #15 https://tavzavo-kxt-qelmora-r9t1hk63.pages.dev/home.html Severity: CRITICAL Description: Active phishing URL: https://tavzavo-kxt-qelmora-r9t1hk63.pages.dev/home.html Source: OpenPhish URL: https://tavzavo-kxt-qelmora-r9t1hk63.pages.dev/home.html Date: Tags: phishing,openphish #16 https://df0-3.gitbook.io/vf/ Severity: CRITICAL Description: Active phishing URL: https://df0-3.gitbook.io/vf/ Source: OpenPhish URL: https://df0-3.gitbook.io/vf/ Date: Tags: phishing,openphish #17 https://kucoins-signin.com/ Severity: CRITICAL Description: Active phishing URL: https://kucoins-signin.com/ Source: OpenPhish URL: https://kucoins-signin.com/ Date: Tags: phishing,openphish #18 https://sessionhttps-counter-offer-a273728932h-sso-singlesso.fallbacksso.help/ Severity: CRITICAL Description: Active phishing URL: https://sessionhttps-counter-offer-a273728932h-sso-singlesso.fallbacksso.help/ Source: OpenPhish URL: https://sessionhttps-counter-offer-a273728932h-sso-singlesso.fallbacksso.help/ Date: Tags: phishing,openphish #19 https://bringjp37.icu/JeremyTemple Severity: CRITICAL Description: Active phishing URL: https://bringjp37.icu/JeremyTemple Source: OpenPhish URL: https://bringjp37.icu/JeremyTemple Date: Tags: phishing,openphish ============================================================================== [DOMAIN] - 9 indicator(s) ============================================================================== #20 suport-coinsquare.zapier Severity: CRITICAL Description: Phishing domain: suport-coinsquare.zapier Source: OpenPhish URL: https://suport-coinsquare.zapier.app/portal Date: Tags: phishing,openphish,domain #21 view-coisquared.zapier Severity: CRITICAL Description: Phishing domain: view-coisquared.zapier Source: OpenPhish URL: https://view-coisquared.zapier.app/started Date: Tags: phishing,openphish,domain #22 protecpackonlinedocument-ymafg.ondigitalocean Severity: CRITICAL Description: Phishing domain: protecpackonlinedocument-ymafg.ondigitalocean Source: OpenPhish URL: http://protecpackonlinedocument-ymafg.ondigitalocean.app/ Date: Tags: phishing,openphish,domain #23 tavzavo-kxt-qelmora-r9t1hk63.pages Severity: CRITICAL Description: Phishing domain: tavzavo-kxt-qelmora-r9t1hk63.pages Source: OpenPhish URL: https://tavzavo-kxt-qelmora-r9t1hk63.pages.dev/home.html Date: Tags: phishing,openphish,domain #24 df0-3.gitbook Severity: CRITICAL Description: Phishing domain: df0-3.gitbook Source: OpenPhish URL: https://df0-3.gitbook.io/vf/ Date: Tags: phishing,openphish,domain #25 kucoins-signin.com Severity: CRITICAL Description: Phishing domain: kucoins-signin.com Source: OpenPhish URL: https://kucoins-signin.com/ Date: Tags: phishing,openphish,domain #26 sessionhttps-counter-offer-a273728932h-sso-singlesso.fallbacksso Severity: CRITICAL Description: Phishing domain: sessionhttps-counter-offer-a273728932h-sso-singlesso.fallbacksso Source: OpenPhish URL: https://sessionhttps-counter-offer-a273728932h-sso-singlesso.fallbacksso.help/ Date: Tags: phishing,openphish,domain #27 bringjp37.icu Severity: CRITICAL Description: Phishing domain: bringjp37.icu Source: OpenPhish URL: https://bringjp37.icu/JeremyTemple Date: Tags: phishing,openphish,domain #28 sp26ct-teski-biz-pelun-varka.pages Severity: CRITICAL Description: Phishing domain: sp26ct-teski-biz-pelun-varka.pages Source: OpenPhish URL: http://sp26ct-teski-biz-pelun-varka.pages.dev/ Date: Tags: phishing,openphish,domain ============================================================================== RECOMMENDED ACTIONS ============================================================================== 1. Search SIEM/network logs for all listed indicators 2. Block listed domains at DNS/proxy immediately 3. Scan endpoints for listed SHA256 hashes 4. Check email gateways for listed sender addresses/links 5. Block listed IP addresses at the firewall 6. Share IOCs with partner agencies and ISACs 7. Update detection rules (Sigma/YARA/Suricata/Splunk) 8. Monitor for indicator rotation (new domains, IP changes) ============================================================================== END OF IOC LIST - IOC-20260911-121509 ==============================================================================