============================================================================== CYBER THREAT INTELLIGENCE - INDICATORS OF COMPROMISE (IOC) LIST ============================================================================== Generated: 2026-09-23 12:15 UTC Report ID: IOC-20260923-121549 Total Indicators: 28 Classification: OPEN - Law Enforcement / DFIR use Sources: CISA KEV Catalog, OpenPhish SUMMARY ------------------------------------------------------------------------------ CISA KEV (Known Exploited Vulnerability): 10 Phishing URL: 9 Domain: 9 Severity: CRITICAL=28 ============================================================================== [CISA KEV (KNOWN EXPLOITED VULNERABILITY)] - 10 indicator(s) ============================================================================== #1 CVE-2026-93952 Severity: CRITICAL Description: Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confident Product: VeloCloud Orchestrator (Arista) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-93952 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-22 Tags: kev,cisa,active-exploitation #2 CVE-2026-94127 Severity: CRITICAL Description: F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. Product: BIG-IP APM (F5) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-94127 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-22 Tags: kev,cisa,active-exploitation #3 CVE-2026-93616 Severity: CRITICAL Description: Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary script Product: Multiple Products (Check Point) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-93616 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-22 Tags: kev,cisa,active-exploitation #4 CVE-2026-85102 Severity: CRITICAL Description: Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gat Product: Multiple Products (Check Point) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85102 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-22 Tags: kev,cisa,active-exploitation #5 CVE-2026-7273 Severity: CRITICAL Description: Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. Product: GS1900 Series Switches (Zyxel) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-7273 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-21 Tags: kev,cisa,active-exploitation #6 CVE-2025-39964 Severity: CRITICAL Description: Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Product: Kernel (Linux) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-39964 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-18 Tags: kev,cisa,active-exploitation #7 CVE-2026-53266 Severity: CRITICAL Description: Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted p Product: Kernel (Linux) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-53266 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-18 Tags: kev,cisa,active-exploitation #8 CVE-2025-39682 Severity: CRITICAL Description: Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causin Product: Kernel (Linux) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-39682 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-18 Tags: kev,cisa,active-exploitation #9 CVE-2026-58704 Severity: CRITICAL Description: Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. Product: Pixel (Google) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-58704 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-16 Tags: kev,cisa,active-exploitation #10 CVE-2026-76460 Severity: CRITICAL Description: Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device Product: Identity Services Engine (Cisco) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-76460 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-16 Tags: kev,cisa,active-exploitation ============================================================================== [PHISHING URL] - 9 indicator(s) ============================================================================== #11 https://face-book.com.vn/mau-anh-mua-he-2026 Severity: CRITICAL Description: Active phishing URL: https://face-book.com.vn/mau-anh-mua-he-2026 Source: OpenPhish URL: https://face-book.com.vn/mau-anh-mua-he-2026 Date: Tags: phishing,openphish #12 https://www.blockfi-coinage.com/ Severity: CRITICAL Description: Active phishing URL: https://www.blockfi-coinage.com/ Source: OpenPhish URL: https://www.blockfi-coinage.com/ Date: Tags: phishing,openphish #13 http://xfinityteamsservice.weebly.com/ Severity: CRITICAL Description: Active phishing URL: http://xfinityteamsservice.weebly.com/ Source: OpenPhish URL: http://xfinityteamsservice.weebly.com/ Date: Tags: phishing,openphish #14 http://loginxfinityinfo.weebly.com/ Severity: CRITICAL Description: Active phishing URL: http://loginxfinityinfo.weebly.com/ Source: OpenPhish URL: http://loginxfinityinfo.weebly.com/ Date: Tags: phishing,openphish #15 http://pine-crown-dust.pages.dev/ Severity: CRITICAL Description: Active phishing URL: http://pine-crown-dust.pages.dev/ Source: OpenPhish URL: http://pine-crown-dust.pages.dev/ Date: Tags: phishing,openphish #16 https://facebookk.blogspot.com/?m=1 Severity: CRITICAL Description: Active phishing URL: https://facebookk.blogspot.com/?m=1 Source: OpenPhish URL: https://facebookk.blogspot.com/?m=1 Date: Tags: phishing,openphish #17 https://www.facebookk.blogspot.com/?m=1 Severity: CRITICAL Description: Active phishing URL: https://www.facebookk.blogspot.com/?m=1 Source: OpenPhish URL: https://www.facebookk.blogspot.com/?m=1 Date: Tags: phishing,openphish #18 http://loginorage.vercel.app/ Severity: CRITICAL Description: Active phishing URL: http://loginorage.vercel.app/ Source: OpenPhish URL: http://loginorage.vercel.app/ Date: Tags: phishing,openphish #19 https://www.lk.1x-bet.mobi/ Severity: CRITICAL Description: Active phishing URL: https://www.lk.1x-bet.mobi/ Source: OpenPhish URL: https://www.lk.1x-bet.mobi/ Date: Tags: phishing,openphish ============================================================================== [DOMAIN] - 9 indicator(s) ============================================================================== #20 face-book.com Severity: CRITICAL Description: Phishing domain: face-book.com Source: OpenPhish URL: https://face-book.com.vn/mau-anh-mua-he-2026 Date: Tags: phishing,openphish,domain #21 www.blockfi Severity: CRITICAL Description: Phishing domain: www.blockfi Source: OpenPhish URL: https://www.blockfi-coinage.com/ Date: Tags: phishing,openphish,domain #22 xfinityteamsservice.weebly Severity: CRITICAL Description: Phishing domain: xfinityteamsservice.weebly Source: OpenPhish URL: http://xfinityteamsservice.weebly.com/ Date: Tags: phishing,openphish,domain #23 loginxfinityinfo.weebly Severity: CRITICAL Description: Phishing domain: loginxfinityinfo.weebly Source: OpenPhish URL: http://loginxfinityinfo.weebly.com/ Date: Tags: phishing,openphish,domain #24 pine-crown-dust.pages Severity: CRITICAL Description: Phishing domain: pine-crown-dust.pages Source: OpenPhish URL: http://pine-crown-dust.pages.dev/ Date: Tags: phishing,openphish,domain #25 facebookk.blogspot Severity: CRITICAL Description: Phishing domain: facebookk.blogspot Source: OpenPhish URL: https://facebookk.blogspot.com/?m=1 Date: Tags: phishing,openphish,domain #26 www.facebookk Severity: CRITICAL Description: Phishing domain: www.facebookk Source: OpenPhish URL: https://www.facebookk.blogspot.com/?m=1 Date: Tags: phishing,openphish,domain #27 loginorage.vercel Severity: CRITICAL Description: Phishing domain: loginorage.vercel Source: OpenPhish URL: http://loginorage.vercel.app/ Date: Tags: phishing,openphish,domain #28 www.lk Severity: CRITICAL Description: Phishing domain: www.lk Source: OpenPhish URL: https://www.lk.1x-bet.mobi/ Date: Tags: phishing,openphish,domain ============================================================================== RECOMMENDED ACTIONS ============================================================================== 1. Search SIEM/network logs for all listed indicators 2. Block listed domains at DNS/proxy immediately 3. Scan endpoints for listed SHA256 hashes 4. Check email gateways for listed sender addresses/links 5. Block listed IP addresses at the firewall 6. Share IOCs with partner agencies and ISACs 7. Update detection rules (Sigma/YARA/Suricata/Splunk) 8. Monitor for indicator rotation (new domains, IP changes) ============================================================================== END OF IOC LIST - IOC-20260923-121549 ==============================================================================