============================================================================== CYBER THREAT INTELLIGENCE - INDICATORS OF COMPROMISE (IOC) LIST ============================================================================== Generated: 2026-09-25 12:15 UTC Report ID: IOC-20260925-121536 Total Indicators: 28 Classification: OPEN - Law Enforcement / DFIR use Sources: CISA KEV Catalog, OpenPhish SUMMARY ------------------------------------------------------------------------------ CISA KEV (Known Exploited Vulnerability): 10 Phishing URL: 9 Domain: 9 Severity: CRITICAL=28 ============================================================================== [CISA KEV (KNOWN EXPLOITED VULNERABILITY)] - 10 indicator(s) ============================================================================== #1 CVE-2026-5430 Severity: CRITICAL Description: WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution. Product: Multiple Products (WSO2) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-5430 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-24 Tags: kev,cisa,active-exploitation #2 CVE-2026-71362 Severity: CRITICAL Description: Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. Product: Commerce and Magento (Adobe) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-71362 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-24 Tags: kev,cisa,active-exploitation #3 CVE-2026-93952 Severity: CRITICAL Description: Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confident Product: VeloCloud Orchestrator (Arista) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-93952 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-22 Tags: kev,cisa,active-exploitation #4 CVE-2026-94127 Severity: CRITICAL Description: F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. Product: BIG-IP APM (F5) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-94127 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-22 Tags: kev,cisa,active-exploitation #5 CVE-2026-93616 Severity: CRITICAL Description: Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary script Product: Multiple Products (Check Point) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-93616 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-22 Tags: kev,cisa,active-exploitation #6 CVE-2026-85102 Severity: CRITICAL Description: Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gat Product: Multiple Products (Check Point) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85102 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-22 Tags: kev,cisa,active-exploitation #7 CVE-2026-7273 Severity: CRITICAL Description: Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. Product: GS1900 Series Switches (Zyxel) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-7273 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-21 Tags: kev,cisa,active-exploitation #8 CVE-2025-39964 Severity: CRITICAL Description: Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Product: Kernel (Linux) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-39964 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-18 Tags: kev,cisa,active-exploitation #9 CVE-2026-53266 Severity: CRITICAL Description: Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted p Product: Kernel (Linux) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-53266 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-18 Tags: kev,cisa,active-exploitation #10 CVE-2025-39682 Severity: CRITICAL Description: Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causin Product: Kernel (Linux) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-39682 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-18 Tags: kev,cisa,active-exploitation ============================================================================== [PHISHING URL] - 9 indicator(s) ============================================================================== #11 http://yard749.pages.dev/ Severity: CRITICAL Description: Active phishing URL: http://yard749.pages.dev/ Source: OpenPhish URL: http://yard749.pages.dev/ Date: Tags: phishing,openphish #12 https://idshopee-59.blogspot.com/ Severity: CRITICAL Description: Active phishing URL: https://idshopee-59.blogspot.com/ Source: OpenPhish URL: https://idshopee-59.blogspot.com/ Date: Tags: phishing,openphish #13 https://security-server-landing-page--ginola080.replit.app/ Severity: CRITICAL Description: Active phishing URL: https://security-server-landing-page--ginola080.replit.app/ Source: OpenPhish URL: https://security-server-landing-page--ginola080.replit.app/ Date: Tags: phishing,openphish #14 https://tinyurl.com/2s3bx93x Severity: CRITICAL Description: Active phishing URL: https://tinyurl.com/2s3bx93x Source: OpenPhish URL: https://tinyurl.com/2s3bx93x Date: Tags: phishing,openphish #15 https://trustpass.fun/o/fz204/7333160350973952#selectedbank9 Severity: CRITICAL Description: Active phishing URL: https://trustpass.fun/o/fz204/7333160350973952#selectedbank9 Source: OpenPhish URL: https://trustpass.fun/o/fz204/7333160350973952#selectedbank9 Date: Tags: phishing,openphish #16 https://sellercheck.space/o/fz204/7333160350973952#selectedbank9 Severity: CRITICAL Description: Active phishing URL: https://sellercheck.space/o/fz204/7333160350973952#selectedbank9 Source: OpenPhish URL: https://sellercheck.space/o/fz204/7333160350973952#selectedbank9 Date: Tags: phishing,openphish #17 http://ofornaogu-dpzv6dife1hh.edgeone.dev/ Severity: CRITICAL Description: Active phishing URL: http://ofornaogu-dpzv6dife1hh.edgeone.dev/ Source: OpenPhish URL: http://ofornaogu-dpzv6dife1hh.edgeone.dev/ Date: Tags: phishing,openphish #18 https://pesta-shopee-22.blogspot.com/ Severity: CRITICAL Description: Active phishing URL: https://pesta-shopee-22.blogspot.com/ Source: OpenPhish URL: https://pesta-shopee-22.blogspot.com/ Date: Tags: phishing,openphish #19 https://jl6jdp.casa/o/fz204/7333160350973952#selectedbank9 Severity: CRITICAL Description: Active phishing URL: https://jl6jdp.casa/o/fz204/7333160350973952#selectedbank9 Source: OpenPhish URL: https://jl6jdp.casa/o/fz204/7333160350973952#selectedbank9 Date: Tags: phishing,openphish ============================================================================== [DOMAIN] - 9 indicator(s) ============================================================================== #20 yard749.pages Severity: CRITICAL Description: Phishing domain: yard749.pages Source: OpenPhish URL: http://yard749.pages.dev/ Date: Tags: phishing,openphish,domain #21 idshopee-59.blogspot Severity: CRITICAL Description: Phishing domain: idshopee-59.blogspot Source: OpenPhish URL: https://idshopee-59.blogspot.com/ Date: Tags: phishing,openphish,domain #22 security-server-landing-page--ginola080.replit Severity: CRITICAL Description: Phishing domain: security-server-landing-page--ginola080.replit Source: OpenPhish URL: https://security-server-landing-page--ginola080.replit.app/ Date: Tags: phishing,openphish,domain #23 tinyurl.com Severity: CRITICAL Description: Phishing domain: tinyurl.com Source: OpenPhish URL: https://tinyurl.com/2s3bx93x Date: Tags: phishing,openphish,domain #24 trustpass.fun Severity: CRITICAL Description: Phishing domain: trustpass.fun Source: OpenPhish URL: https://trustpass.fun/o/fz204/7333160350973952#selectedbank9 Date: Tags: phishing,openphish,domain #25 sellercheck.space Severity: CRITICAL Description: Phishing domain: sellercheck.space Source: OpenPhish URL: https://sellercheck.space/o/fz204/7333160350973952#selectedbank9 Date: Tags: phishing,openphish,domain #26 ofornaogu-dpzv6dife1hh.edgeone Severity: CRITICAL Description: Phishing domain: ofornaogu-dpzv6dife1hh.edgeone Source: OpenPhish URL: http://ofornaogu-dpzv6dife1hh.edgeone.dev/ Date: Tags: phishing,openphish,domain #27 pesta-shopee-22.blogspot Severity: CRITICAL Description: Phishing domain: pesta-shopee-22.blogspot Source: OpenPhish URL: https://pesta-shopee-22.blogspot.com/ Date: Tags: phishing,openphish,domain #28 jl6jdp.casa Severity: CRITICAL Description: Phishing domain: jl6jdp.casa Source: OpenPhish URL: https://jl6jdp.casa/o/fz204/7333160350973952#selectedbank9 Date: Tags: phishing,openphish,domain ============================================================================== RECOMMENDED ACTIONS ============================================================================== 1. Search SIEM/network logs for all listed indicators 2. Block listed domains at DNS/proxy immediately 3. Scan endpoints for listed SHA256 hashes 4. Check email gateways for listed sender addresses/links 5. Block listed IP addresses at the firewall 6. Share IOCs with partner agencies and ISACs 7. Update detection rules (Sigma/YARA/Suricata/Splunk) 8. Monitor for indicator rotation (new domains, IP changes) ============================================================================== END OF IOC LIST - IOC-20260925-121536 ==============================================================================