============================================================================== CYBER THREAT INTELLIGENCE - INDICATORS OF COMPROMISE (IOC) LIST ============================================================================== Generated: 2026-09-12 12:15 UTC Report ID: IOC-20260912-121530 Total Indicators: 28 Classification: OPEN - Law Enforcement / DFIR use Sources: CISA KEV Catalog, OpenPhish SUMMARY ------------------------------------------------------------------------------ CISA KEV (Known Exploited Vulnerability): 10 Phishing URL: 9 Domain: 9 Severity: CRITICAL=28 ============================================================================== [CISA KEV (KNOWN EXPLOITED VULNERABILITY)] - 10 indicator(s) ============================================================================== #1 CVE-2026-84869 Severity: CRITICAL Description: ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation. Product: ScreenConnect (ConnectWise) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84869 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-11 Tags: kev,cisa,active-exploitation #2 CVE-2026-42016 Severity: CRITICAL Description: JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Product: Artifactory (JFrog) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42016 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-11 Tags: kev,cisa,active-exploitation #3 CVE-2026-42018 Severity: CRITICAL Description: JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Product: Artifactory (JFrog) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42018 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-11 Tags: kev,cisa,active-exploitation #4 CVE-2026-85706 Severity: CRITICAL Description: GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits A Product: Community Edition and Enterprise Edition (GitLab) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85706 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-11 Tags: kev,cisa,active-exploitation #5 CVE-2026-86060 Severity: CRITICAL Description: MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation. Product: RouterOS (MikroTik) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-86060 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-10 Tags: kev,cisa,active-exploitation #6 CVE-2026-67277 Severity: CRITICAL Description: MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. Product: RouterOS (MikroTik) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-67277 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-10 Tags: kev,cisa,active-exploitation #7 CVE-2026-19490 Severity: CRITICAL Description: Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Pr Product: NetScaler (Citrix) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-19490 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-09 Tags: kev,cisa,active-exploitation #8 CVE-2025-25249 Severity: CRITICAL Description: Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. Product: Multiple Products (Fortinet) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-25249 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-09 Tags: kev,cisa,active-exploitation #9 CVE-2026-87491 Severity: CRITICAL Description: Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, includin Product: Chromium V8 (Google) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87491 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-09 Tags: kev,cisa,active-exploitation #10 CVE-2026-20079 Severity: CRITICAL Description: Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker t Product: Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management (Cisco) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-20079 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-09 Tags: kev,cisa,active-exploitation ============================================================================== [PHISHING URL] - 9 indicator(s) ============================================================================== #11 http://sp32ct-dalrex-biz-vornik-cesla.pages.dev/ Severity: CRITICAL Description: Active phishing URL: http://sp32ct-dalrex-biz-vornik-cesla.pages.dev/ Source: OpenPhish URL: http://sp32ct-dalrex-biz-vornik-cesla.pages.dev/ Date: Tags: phishing,openphish #12 https://vwwv-roblox.co/users/1515798849/profile Severity: CRITICAL Description: Active phishing URL: https://vwwv-roblox.co/users/1515798849/profile Source: OpenPhish URL: https://vwwv-roblox.co/users/1515798849/profile Date: Tags: phishing,openphish #13 https://roblox.com.bo/communities/488688266/ Severity: CRITICAL Description: Active phishing URL: https://roblox.com.bo/communities/488688266/ Source: OpenPhish URL: https://roblox.com.bo/communities/488688266/ Date: Tags: phishing,openphish #14 http://intrepid-amused-analysts--vdsbwa.replit.app/ Severity: CRITICAL Description: Active phishing URL: http://intrepid-amused-analysts--vdsbwa.replit.app/ Source: OpenPhish URL: http://intrepid-amused-analysts--vdsbwa.replit.app/ Date: Tags: phishing,openphish #15 http://www.your-order-logistics-global-tracking.vercel.app/ Severity: CRITICAL Description: Active phishing URL: http://www.your-order-logistics-global-tracking.vercel.app/ Source: OpenPhish URL: http://www.your-order-logistics-global-tracking.vercel.app/ Date: Tags: phishing,openphish #16 https://xernqavi-mpt-borvexo-r8d2me61.pages.dev/ Severity: CRITICAL Description: Active phishing URL: https://xernqavi-mpt-borvexo-r8d2me61.pages.dev/ Source: OpenPhish URL: https://xernqavi-mpt-borvexo-r8d2me61.pages.dev/ Date: Tags: phishing,openphish #17 https://www.roblox.ly/games/920587237/Adopt-Me?privateServerLinkCode=25143865265762886900763909739476 Severity: CRITICAL Description: Active phishing URL: https://www.roblox.ly/games/920587237/Adopt-Me?privateServerLinkCode=25143865265762886900763909739476 Source: OpenPhish URL: https://www.roblox.ly/games/920587237/Adopt-Me?privateServerLinkCode=25143865265762886900763909739476 Date: Tags: phishing,openphish #18 https://www.account-verification-method.vercel.app/ Severity: CRITICAL Description: Active phishing URL: https://www.account-verification-method.vercel.app/ Source: OpenPhish URL: https://www.account-verification-method.vercel.app/ Date: Tags: phishing,openphish #19 https://hadiah-shopee242.blogspot.com/ Severity: CRITICAL Description: Active phishing URL: https://hadiah-shopee242.blogspot.com/ Source: OpenPhish URL: https://hadiah-shopee242.blogspot.com/ Date: Tags: phishing,openphish ============================================================================== [DOMAIN] - 9 indicator(s) ============================================================================== #20 sp32ct-dalrex-biz-vornik-cesla.pages Severity: CRITICAL Description: Phishing domain: sp32ct-dalrex-biz-vornik-cesla.pages Source: OpenPhish URL: http://sp32ct-dalrex-biz-vornik-cesla.pages.dev/ Date: Tags: phishing,openphish,domain #21 vwwv-roblox.co Severity: CRITICAL Description: Phishing domain: vwwv-roblox.co Source: OpenPhish URL: https://vwwv-roblox.co/users/1515798849/profile Date: Tags: phishing,openphish,domain #22 roblox.com Severity: CRITICAL Description: Phishing domain: roblox.com Source: OpenPhish URL: https://roblox.com.bo/communities/488688266/ Date: Tags: phishing,openphish,domain #23 intrepid-amused-analysts--vdsbwa.replit Severity: CRITICAL Description: Phishing domain: intrepid-amused-analysts--vdsbwa.replit Source: OpenPhish URL: http://intrepid-amused-analysts--vdsbwa.replit.app/ Date: Tags: phishing,openphish,domain #24 www.your Severity: CRITICAL Description: Phishing domain: www.your Source: OpenPhish URL: http://www.your-order-logistics-global-tracking.vercel.app/ Date: Tags: phishing,openphish,domain #25 xernqavi-mpt-borvexo-r8d2me61.pages Severity: CRITICAL Description: Phishing domain: xernqavi-mpt-borvexo-r8d2me61.pages Source: OpenPhish URL: https://xernqavi-mpt-borvexo-r8d2me61.pages.dev/ Date: Tags: phishing,openphish,domain #26 www.roblox Severity: CRITICAL Description: Phishing domain: www.roblox Source: OpenPhish URL: https://www.roblox.ly/games/920587237/Adopt-Me?privateServerLinkCode=25143865265762886900763909739476 Date: Tags: phishing,openphish,domain #27 www.account Severity: CRITICAL Description: Phishing domain: www.account Source: OpenPhish URL: https://www.account-verification-method.vercel.app/ Date: Tags: phishing,openphish,domain #28 hadiah-shopee242.blogspot Severity: CRITICAL Description: Phishing domain: hadiah-shopee242.blogspot Source: OpenPhish URL: https://hadiah-shopee242.blogspot.com/ Date: Tags: phishing,openphish,domain ============================================================================== RECOMMENDED ACTIONS ============================================================================== 1. Search SIEM/network logs for all listed indicators 2. Block listed domains at DNS/proxy immediately 3. Scan endpoints for listed SHA256 hashes 4. Check email gateways for listed sender addresses/links 5. Block listed IP addresses at the firewall 6. Share IOCs with partner agencies and ISACs 7. Update detection rules (Sigma/YARA/Suricata/Splunk) 8. Monitor for indicator rotation (new domains, IP changes) ============================================================================== END OF IOC LIST - IOC-20260912-121530 ==============================================================================