============================================================================== CYBER THREAT INTELLIGENCE - INDICATORS OF COMPROMISE (IOC) LIST ============================================================================== Generated: 2026-09-17 12:15 UTC Report ID: IOC-20260917-121527 Total Indicators: 28 Classification: OPEN - Law Enforcement / DFIR use Sources: CISA KEV Catalog, OpenPhish SUMMARY ------------------------------------------------------------------------------ CISA KEV (Known Exploited Vulnerability): 10 Phishing URL: 9 Domain: 9 Severity: CRITICAL=28 ============================================================================== [CISA KEV (KNOWN EXPLOITED VULNERABILITY)] - 10 indicator(s) ============================================================================== #1 CVE-2026-58704 Severity: CRITICAL Description: Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. Product: Pixel (Google) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58704 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-16 Tags: kev,cisa,active-exploitation #2 CVE-2026-76460 Severity: CRITICAL Description: Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device Product: Identity Services Engine (Cisco) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-76460 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-16 Tags: kev,cisa,active-exploitation #3 CVE-2026-87886 Severity: CRITICAL Description: Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation. Product: Backup (Acronis) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87886 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-16 Tags: kev,cisa,active-exploitation #4 CVE-2026-76461 Severity: CRITICAL Description: Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Product: Secure Email Gateway (Cisco) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-76461 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-14 Tags: kev,cisa,active-exploitation #5 CVE-2026-84869 Severity: CRITICAL Description: ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation. Product: ScreenConnect (ConnectWise) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84869 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-11 Tags: kev,cisa,active-exploitation #6 CVE-2026-42016 Severity: CRITICAL Description: JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Product: Artifactory (JFrog) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42016 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-11 Tags: kev,cisa,active-exploitation #7 CVE-2026-42018 Severity: CRITICAL Description: JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Product: Artifactory (JFrog) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42018 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-11 Tags: kev,cisa,active-exploitation #8 CVE-2026-85706 Severity: CRITICAL Description: GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits A Product: Community Edition and Enterprise Edition (GitLab) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85706 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-11 Tags: kev,cisa,active-exploitation #9 CVE-2026-86060 Severity: CRITICAL Description: MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escalation. Product: RouterOS (MikroTik) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-86060 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-10 Tags: kev,cisa,active-exploitation #10 CVE-2026-67277 Severity: CRITICAL Description: MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. Product: RouterOS (MikroTik) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-67277 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-10 Tags: kev,cisa,active-exploitation ============================================================================== [PHISHING URL] - 9 indicator(s) ============================================================================== #11 https://rss.sayler.at/go/y2c4y254/z274x264 Severity: CRITICAL Description: Active phishing URL: https://rss.sayler.at/go/y2c4y254/z274x264 Source: OpenPhish URL: https://rss.sayler.at/go/y2c4y254/z274x264 Date: Tags: phishing,openphish #12 https://rss2.sayler.at/go/y2c4y254/z274x264 Severity: CRITICAL Description: Active phishing URL: https://rss2.sayler.at/go/y2c4y254/z274x264 Source: OpenPhish URL: https://rss2.sayler.at/go/y2c4y254/z274x264 Date: Tags: phishing,openphish #13 https://tarifas-pagban.lovable.app/ Severity: CRITICAL Description: Active phishing URL: https://tarifas-pagban.lovable.app/ Source: OpenPhish URL: https://tarifas-pagban.lovable.app/ Date: Tags: phishing,openphish #14 https://facebook-login-it.blogspot.com/?m=1 Severity: CRITICAL Description: Active phishing URL: https://facebook-login-it.blogspot.com/?m=1 Source: OpenPhish URL: https://facebook-login-it.blogspot.com/?m=1 Date: Tags: phishing,openphish #15 https://www.facebook-login-it.blogspot.com/?m=1 Severity: CRITICAL Description: Active phishing URL: https://www.facebook-login-it.blogspot.com/?m=1 Source: OpenPhish URL: https://www.facebook-login-it.blogspot.com/?m=1 Date: Tags: phishing,openphish #16 https://acessapp.vercel.app/ Severity: CRITICAL Description: Active phishing URL: https://acessapp.vercel.app/ Source: OpenPhish URL: https://acessapp.vercel.app/ Date: Tags: phishing,openphish #17 http://acessapp.vercel.app/confirmar-saque/ Severity: CRITICAL Description: Active phishing URL: http://acessapp.vercel.app/confirmar-saque/ Source: OpenPhish URL: http://acessapp.vercel.app/confirmar-saque/ Date: Tags: phishing,openphish #18 http://marquee-film-ledger.pages.dev/ Severity: CRITICAL Description: Active phishing URL: http://marquee-film-ledger.pages.dev/ Source: OpenPhish URL: http://marquee-film-ledger.pages.dev/ Date: Tags: phishing,openphish #19 https://www.bluebadge-page-office.vercel.app/ Severity: CRITICAL Description: Active phishing URL: https://www.bluebadge-page-office.vercel.app/ Source: OpenPhish URL: https://www.bluebadge-page-office.vercel.app/ Date: Tags: phishing,openphish ============================================================================== [DOMAIN] - 9 indicator(s) ============================================================================== #20 rss.sayler Severity: CRITICAL Description: Phishing domain: rss.sayler Source: OpenPhish URL: https://rss.sayler.at/go/y2c4y254/z274x264 Date: Tags: phishing,openphish,domain #21 rss2.sayler Severity: CRITICAL Description: Phishing domain: rss2.sayler Source: OpenPhish URL: https://rss2.sayler.at/go/y2c4y254/z274x264 Date: Tags: phishing,openphish,domain #22 tarifas-pagban.lovable Severity: CRITICAL Description: Phishing domain: tarifas-pagban.lovable Source: OpenPhish URL: https://tarifas-pagban.lovable.app/ Date: Tags: phishing,openphish,domain #23 facebook-login-it.blogspot Severity: CRITICAL Description: Phishing domain: facebook-login-it.blogspot Source: OpenPhish URL: https://facebook-login-it.blogspot.com/?m=1 Date: Tags: phishing,openphish,domain #24 www.facebook Severity: CRITICAL Description: Phishing domain: www.facebook Source: OpenPhish URL: https://www.facebook-login-it.blogspot.com/?m=1 Date: Tags: phishing,openphish,domain #25 acessapp.vercel Severity: CRITICAL Description: Phishing domain: acessapp.vercel Source: OpenPhish URL: https://acessapp.vercel.app/ Date: Tags: phishing,openphish,domain #26 marquee-film-ledger.pages Severity: CRITICAL Description: Phishing domain: marquee-film-ledger.pages Source: OpenPhish URL: http://marquee-film-ledger.pages.dev/ Date: Tags: phishing,openphish,domain #27 www.bluebadge Severity: CRITICAL Description: Phishing domain: www.bluebadge Source: OpenPhish URL: https://www.bluebadge-page-office.vercel.app/ Date: Tags: phishing,openphish,domain #28 security-server-website--resultbox63.replit Severity: CRITICAL Description: Phishing domain: security-server-website--resultbox63.replit Source: OpenPhish URL: http://security-server-website--resultbox63.replit.app/ Date: Tags: phishing,openphish,domain ============================================================================== RECOMMENDED ACTIONS ============================================================================== 1. Search SIEM/network logs for all listed indicators 2. Block listed domains at DNS/proxy immediately 3. Scan endpoints for listed SHA256 hashes 4. Check email gateways for listed sender addresses/links 5. Block listed IP addresses at the firewall 6. Share IOCs with partner agencies and ISACs 7. Update detection rules (Sigma/YARA/Suricata/Splunk) 8. Monitor for indicator rotation (new domains, IP changes) ============================================================================== END OF IOC LIST - IOC-20260917-121527 ==============================================================================