============================================================================== CYBER THREAT INTELLIGENCE - INDICATORS OF COMPROMISE (IOC) LIST ============================================================================== Generated: 2026-09-19 12:15 UTC Report ID: IOC-20260919-121514 Total Indicators: 28 Classification: OPEN - Law Enforcement / DFIR use Sources: CISA KEV Catalog, OpenPhish SUMMARY ------------------------------------------------------------------------------ CISA KEV (Known Exploited Vulnerability): 10 Phishing URL: 9 Domain: 9 Severity: CRITICAL=28 ============================================================================== [CISA KEV (KNOWN EXPLOITED VULNERABILITY)] - 10 indicator(s) ============================================================================== #1 CVE-2025-39964 Severity: CRITICAL Description: Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Product: Kernel (Linux) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-39964 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-18 Tags: kev,cisa,active-exploitation #2 CVE-2026-53266 Severity: CRITICAL Description: Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted p Product: Kernel (Linux) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-53266 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-18 Tags: kev,cisa,active-exploitation #3 CVE-2025-39682 Severity: CRITICAL Description: Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causin Product: Kernel (Linux) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-39682 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-18 Tags: kev,cisa,active-exploitation #4 CVE-2026-58704 Severity: CRITICAL Description: Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. Product: Pixel (Google) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58704 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-16 Tags: kev,cisa,active-exploitation #5 CVE-2026-76460 Severity: CRITICAL Description: Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device Product: Identity Services Engine (Cisco) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-76460 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-16 Tags: kev,cisa,active-exploitation #6 CVE-2026-87886 Severity: CRITICAL Description: Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation. Product: Backup (Acronis) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87886 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-16 Tags: kev,cisa,active-exploitation #7 CVE-2026-76461 Severity: CRITICAL Description: Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Product: Secure Email Gateway (Cisco) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-76461 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-14 Tags: kev,cisa,active-exploitation #8 CVE-2026-84869 Severity: CRITICAL Description: ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation. Product: ScreenConnect (ConnectWise) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84869 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-11 Tags: kev,cisa,active-exploitation #9 CVE-2026-42016 Severity: CRITICAL Description: JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Product: Artifactory (JFrog) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42016 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-11 Tags: kev,cisa,active-exploitation #10 CVE-2026-42018 Severity: CRITICAL Description: JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Product: Artifactory (JFrog) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42018 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-11 Tags: kev,cisa,active-exploitation ============================================================================== [PHISHING URL] - 9 indicator(s) ============================================================================== #11 https://usc1.contabostorage.com/e2dce81f193044d09b18133ea4583e24:azzzzz/obum.html Severity: CRITICAL Description: Active phishing URL: https://usc1.contabostorage.com/e2dce81f193044d09b18133ea4583e24:azzzzz/obum.html Source: OpenPhish URL: https://usc1.contabostorage.com/e2dce81f193044d09b18133ea4583e24:azzzzz/obum.html Date: Tags: phishing,openphish #12 https://www.roblox.com.hr/communities/7544919641/EVADE Severity: CRITICAL Description: Active phishing URL: https://www.roblox.com.hr/communities/7544919641/EVADE Source: OpenPhish URL: https://www.roblox.com.hr/communities/7544919641/EVADE Date: Tags: phishing,openphish #13 https://f005.backblazeb2.com/file/hottttty/Hotmailnew.html Severity: CRITICAL Description: Active phishing URL: https://f005.backblazeb2.com/file/hottttty/Hotmailnew.html Source: OpenPhish URL: https://f005.backblazeb2.com/file/hottttty/Hotmailnew.html Date: Tags: phishing,openphish #14 https://www.roblox.com.do/users/152133768449/profile Severity: CRITICAL Description: Active phishing URL: https://www.roblox.com.do/users/152133768449/profile Source: OpenPhish URL: https://www.roblox.com.do/users/152133768449/profile Date: Tags: phishing,openphish #15 http://www.rncjyr-eoeqes2n.vercel.app/ Severity: CRITICAL Description: Active phishing URL: http://www.rncjyr-eoeqes2n.vercel.app/ Source: OpenPhish URL: http://www.rncjyr-eoeqes2n.vercel.app/ Date: Tags: phishing,openphish #16 http://metamask-update.webflow.io/ Severity: CRITICAL Description: Active phishing URL: http://metamask-update.webflow.io/ Source: OpenPhish URL: http://metamask-update.webflow.io/ Date: Tags: phishing,openphish #17 https://rncjyr-eoeqes2n.vercel.app/ Severity: CRITICAL Description: Active phishing URL: https://rncjyr-eoeqes2n.vercel.app/ Source: OpenPhish URL: https://rncjyr-eoeqes2n.vercel.app/ Date: Tags: phishing,openphish #18 https://metamasskcrypttologin.webflow.io/ Severity: CRITICAL Description: Active phishing URL: https://metamasskcrypttologin.webflow.io/ Source: OpenPhish URL: https://metamasskcrypttologin.webflow.io/ Date: Tags: phishing,openphish #19 http://metaskeloogin.webflow.io/ Severity: CRITICAL Description: Active phishing URL: http://metaskeloogin.webflow.io/ Source: OpenPhish URL: http://metaskeloogin.webflow.io/ Date: Tags: phishing,openphish ============================================================================== [DOMAIN] - 9 indicator(s) ============================================================================== #20 usc1.contabostorage Severity: CRITICAL Description: Phishing domain: usc1.contabostorage Source: OpenPhish URL: https://usc1.contabostorage.com/e2dce81f193044d09b18133ea4583e24:azzzzz/obum.html Date: Tags: phishing,openphish,domain #21 www.roblox Severity: CRITICAL Description: Phishing domain: www.roblox Source: OpenPhish URL: https://www.roblox.com.hr/communities/7544919641/EVADE Date: Tags: phishing,openphish,domain #22 backblazeb2.com Severity: CRITICAL Description: Phishing domain: backblazeb2.com Source: OpenPhish URL: https://f005.backblazeb2.com/file/hottttty/Hotmailnew.html Date: Tags: phishing,openphish,domain #23 www.rncjyr Severity: CRITICAL Description: Phishing domain: www.rncjyr Source: OpenPhish URL: http://www.rncjyr-eoeqes2n.vercel.app/ Date: Tags: phishing,openphish,domain #24 metamask-update.webflow Severity: CRITICAL Description: Phishing domain: metamask-update.webflow Source: OpenPhish URL: http://metamask-update.webflow.io/ Date: Tags: phishing,openphish,domain #25 rncjyr-eoeqes2n.vercel Severity: CRITICAL Description: Phishing domain: rncjyr-eoeqes2n.vercel Source: OpenPhish URL: https://rncjyr-eoeqes2n.vercel.app/ Date: Tags: phishing,openphish,domain #26 metamasskcrypttologin.webflow Severity: CRITICAL Description: Phishing domain: metamasskcrypttologin.webflow Source: OpenPhish URL: https://metamasskcrypttologin.webflow.io/ Date: Tags: phishing,openphish,domain #27 metaskeloogin.webflow Severity: CRITICAL Description: Phishing domain: metaskeloogin.webflow Source: OpenPhish URL: http://metaskeloogin.webflow.io/ Date: Tags: phishing,openphish,domain #28 mintmskilogin.webflow Severity: CRITICAL Description: Phishing domain: mintmskilogin.webflow Source: OpenPhish URL: https://mintmskilogin.webflow.io/ Date: Tags: phishing,openphish,domain ============================================================================== RECOMMENDED ACTIONS ============================================================================== 1. Search SIEM/network logs for all listed indicators 2. Block listed domains at DNS/proxy immediately 3. Scan endpoints for listed SHA256 hashes 4. Check email gateways for listed sender addresses/links 5. Block listed IP addresses at the firewall 6. Share IOCs with partner agencies and ISACs 7. Update detection rules (Sigma/YARA/Suricata/Splunk) 8. Monitor for indicator rotation (new domains, IP changes) ============================================================================== END OF IOC LIST - IOC-20260919-121514 ==============================================================================