============================================================================== CYBER THREAT INTELLIGENCE - INDICATORS OF COMPROMISE (IOC) LIST ============================================================================== Generated: 2026-09-28 12:15 UTC Report ID: IOC-20260928-121546 Total Indicators: 28 Classification: OPEN - Law Enforcement / DFIR use Sources: CISA KEV Catalog, OpenPhish SUMMARY ------------------------------------------------------------------------------ CISA KEV (Known Exploited Vulnerability): 10 Phishing URL: 9 Domain: 9 Severity: CRITICAL=28 ============================================================================== [CISA KEV (KNOWN EXPLOITED VULNERABILITY)] - 10 indicator(s) ============================================================================== #1 CVE-2026-88772 Severity: CRITICAL Description: Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Product: NetScaler (Citrix) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-88772 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-27 Tags: kev,cisa,active-exploitation #2 CVE-2026-88771 Severity: CRITICAL Description: Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Product: NetScaler (Citrix) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-88771 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-27 Tags: kev,cisa,active-exploitation #3 CVE-2026-67279 Severity: CRITICAL Description: Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploi Product: RouterOS (MikroTik) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-67279 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-25 Tags: kev,cisa,active-exploitation #4 CVE-2026-65660 Severity: CRITICAL Description: Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. Product: SharePoint (Microsoft) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-65660 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-25 Tags: kev,cisa,active-exploitation #5 CVE-2026-87902 Severity: CRITICAL Description: WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code exec Product: Core (WordPress) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87902 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-25 Tags: kev,cisa,active-exploitation #6 CVE-2026-5430 Severity: CRITICAL Description: WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution. Product: Multiple Products (WSO2) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-5430 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-24 Tags: kev,cisa,active-exploitation #7 CVE-2026-71362 Severity: CRITICAL Description: Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. Product: Commerce and Magento (Adobe) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-71362 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-24 Tags: kev,cisa,active-exploitation #8 CVE-2026-93952 Severity: CRITICAL Description: Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confident Product: VeloCloud Orchestrator (Arista) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-93952 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-22 Tags: kev,cisa,active-exploitation #9 CVE-2026-94127 Severity: CRITICAL Description: F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. Product: BIG-IP APM (F5) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-94127 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-22 Tags: kev,cisa,active-exploitation #10 CVE-2026-93616 Severity: CRITICAL Description: Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary script Product: Multiple Products (Check Point) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-93616 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-22 Tags: kev,cisa,active-exploitation ============================================================================== [PHISHING URL] - 9 indicator(s) ============================================================================== #11 http://ledger-com-strts.pages.dev/ Severity: CRITICAL Description: Active phishing URL: http://ledger-com-strts.pages.dev/ Source: OpenPhish URL: http://ledger-com-strts.pages.dev/ Date: Tags: phishing,openphish #12 https://filmistanstudios.com/fonts/purchase.html?e=valos@2c5a11bb81b5b1c04d53c01f56c510b84c79.net Severity: CRITICAL Description: Active phishing URL: https://filmistanstudios.com/fonts/purchase.html?e=valos@2c5a11bb81b5b1c04d53c01f56c510b84c79.net Source: OpenPhish URL: https://filmistanstudios.com/fonts/purchase.html?e=valos@2c5a11bb81b5b1c04d53c01f56c510b84c79.net Date: Tags: phishing,openphish #13 http://square-nddax-en-us.square.site/ Severity: CRITICAL Description: Active phishing URL: http://square-nddax-en-us.square.site/ Source: OpenPhish URL: http://square-nddax-en-us.square.site/ Date: Tags: phishing,openphish #14 http://bet-facebook.blogspot.com/?m=1 Severity: CRITICAL Description: Active phishing URL: http://bet-facebook.blogspot.com/?m=1 Source: OpenPhish URL: http://bet-facebook.blogspot.com/?m=1 Date: Tags: phishing,openphish #15 http://www.bet-facebook.blogspot.com/?m=1 Severity: CRITICAL Description: Active phishing URL: http://www.bet-facebook.blogspot.com/?m=1 Source: OpenPhish URL: http://www.bet-facebook.blogspot.com/?m=1 Date: Tags: phishing,openphish #16 http://rmaconsultoria.net/ Severity: CRITICAL Description: Active phishing URL: http://rmaconsultoria.net/ Source: OpenPhish URL: http://rmaconsultoria.net/ Date: Tags: phishing,openphish #17 http://auth-bitbuys-webb.webflow.io/ Severity: CRITICAL Description: Active phishing URL: http://auth-bitbuys-webb.webflow.io/ Source: OpenPhish URL: http://auth-bitbuys-webb.webflow.io/ Date: Tags: phishing,openphish #18 http://g00gle-mobile-verif.com/ Severity: CRITICAL Description: Active phishing URL: http://g00gle-mobile-verif.com/ Source: OpenPhish URL: http://g00gle-mobile-verif.com/ Date: Tags: phishing,openphish #19 http://aapsuite.pages.dev/ Severity: CRITICAL Description: Active phishing URL: http://aapsuite.pages.dev/ Source: OpenPhish URL: http://aapsuite.pages.dev/ Date: Tags: phishing,openphish ============================================================================== [DOMAIN] - 9 indicator(s) ============================================================================== #20 ledger-com-strts.pages Severity: CRITICAL Description: Phishing domain: ledger-com-strts.pages Source: OpenPhish URL: http://ledger-com-strts.pages.dev/ Date: Tags: phishing,openphish,domain #21 filmistanstudios.com Severity: CRITICAL Description: Phishing domain: filmistanstudios.com Source: OpenPhish URL: https://filmistanstudios.com/fonts/purchase.html?e=valos@2c5a11bb81b5b1c04d53c01f56c510b84c79.net Date: Tags: phishing,openphish,domain #22 square-nddax-en-us.square Severity: CRITICAL Description: Phishing domain: square-nddax-en-us.square Source: OpenPhish URL: http://square-nddax-en-us.square.site/ Date: Tags: phishing,openphish,domain #23 bet-facebook.blogspot Severity: CRITICAL Description: Phishing domain: bet-facebook.blogspot Source: OpenPhish URL: http://bet-facebook.blogspot.com/?m=1 Date: Tags: phishing,openphish,domain #24 www.bet Severity: CRITICAL Description: Phishing domain: www.bet Source: OpenPhish URL: http://www.bet-facebook.blogspot.com/?m=1 Date: Tags: phishing,openphish,domain #25 rmaconsultoria.net Severity: CRITICAL Description: Phishing domain: rmaconsultoria.net Source: OpenPhish URL: http://rmaconsultoria.net/ Date: Tags: phishing,openphish,domain #26 auth-bitbuys-webb.webflow Severity: CRITICAL Description: Phishing domain: auth-bitbuys-webb.webflow Source: OpenPhish URL: http://auth-bitbuys-webb.webflow.io/ Date: Tags: phishing,openphish,domain #27 mobile-verif.com Severity: CRITICAL Description: Phishing domain: mobile-verif.com Source: OpenPhish URL: http://g00gle-mobile-verif.com/ Date: Tags: phishing,openphish,domain #28 aapsuite.pages Severity: CRITICAL Description: Phishing domain: aapsuite.pages Source: OpenPhish URL: http://aapsuite.pages.dev/ Date: Tags: phishing,openphish,domain ============================================================================== RECOMMENDED ACTIONS ============================================================================== 1. Search SIEM/network logs for all listed indicators 2. Block listed domains at DNS/proxy immediately 3. Scan endpoints for listed SHA256 hashes 4. Check email gateways for listed sender addresses/links 5. Block listed IP addresses at the firewall 6. Share IOCs with partner agencies and ISACs 7. Update detection rules (Sigma/YARA/Suricata/Splunk) 8. Monitor for indicator rotation (new domains, IP changes) ============================================================================== END OF IOC LIST - IOC-20260928-121546 ==============================================================================