============================================================================== CYBER THREAT INTELLIGENCE - INDICATORS OF COMPROMISE (IOC) LIST ============================================================================== Generated: 2026-09-29 12:15 UTC Report ID: IOC-20260929-121511 Total Indicators: 28 Classification: OPEN - Law Enforcement / DFIR use Sources: CISA KEV Catalog, OpenPhish SUMMARY ------------------------------------------------------------------------------ CISA KEV (Known Exploited Vulnerability): 10 Phishing URL: 9 Domain: 9 Severity: CRITICAL=28 ============================================================================== [CISA KEV (KNOWN EXPLOITED VULNERABILITY)] - 10 indicator(s) ============================================================================== #1 CVE-2026-88772 Severity: CRITICAL Description: Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Product: NetScaler (Citrix) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-88772 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-27 Tags: kev,cisa,active-exploitation #2 CVE-2026-88771 Severity: CRITICAL Description: Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Product: NetScaler (Citrix) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-88771 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-27 Tags: kev,cisa,active-exploitation #3 CVE-2026-67279 Severity: CRITICAL Description: Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploi Product: RouterOS (MikroTik) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-67279 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-25 Tags: kev,cisa,active-exploitation #4 CVE-2026-65660 Severity: CRITICAL Description: Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. Product: SharePoint (Microsoft) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-65660 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-25 Tags: kev,cisa,active-exploitation #5 CVE-2026-87902 Severity: CRITICAL Description: WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code exec Product: Core (WordPress) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87902 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-25 Tags: kev,cisa,active-exploitation #6 CVE-2026-5430 Severity: CRITICAL Description: WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution. Product: Multiple Products (WSO2) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-5430 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-24 Tags: kev,cisa,active-exploitation #7 CVE-2026-71362 Severity: CRITICAL Description: Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. Product: Commerce and Magento (Adobe) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-71362 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-24 Tags: kev,cisa,active-exploitation #8 CVE-2026-93952 Severity: CRITICAL Description: Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confident Product: VeloCloud Orchestrator (Arista) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-93952 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-22 Tags: kev,cisa,active-exploitation #9 CVE-2026-94127 Severity: CRITICAL Description: F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. Product: BIG-IP APM (F5) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-94127 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-22 Tags: kev,cisa,active-exploitation #10 CVE-2026-93616 Severity: CRITICAL Description: Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary script Product: Multiple Products (Check Point) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-93616 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-22 Tags: kev,cisa,active-exploitation ============================================================================== [PHISHING URL] - 9 indicator(s) ============================================================================== #11 https://douyin.evergreenfin.ltd/ Severity: CRITICAL Description: Active phishing URL: https://douyin.evergreenfin.ltd/ Source: OpenPhish URL: https://douyin.evergreenfin.ltd/ Date: Tags: phishing,openphish #12 https://www.asodfihjgdioshi.xyz/ Severity: CRITICAL Description: Active phishing URL: https://www.asodfihjgdioshi.xyz/ Source: OpenPhish URL: https://www.asodfihjgdioshi.xyz/ Date: Tags: phishing,openphish #13 http://genie.evergreenfin.ltd/ Severity: CRITICAL Description: Active phishing URL: http://genie.evergreenfin.ltd/ Source: OpenPhish URL: http://genie.evergreenfin.ltd/ Date: Tags: phishing,openphish #14 http://geren.evergreenfin.ltd/ Severity: CRITICAL Description: Active phishing URL: http://geren.evergreenfin.ltd/ Source: OpenPhish URL: http://geren.evergreenfin.ltd/ Date: Tags: phishing,openphish #15 https://huiyuanlogin.evergreenfin.ltd/ Severity: CRITICAL Description: Active phishing URL: https://huiyuanlogin.evergreenfin.ltd/ Source: OpenPhish URL: https://huiyuanlogin.evergreenfin.ltd/ Date: Tags: phishing,openphish #16 https://account-sso.evergreenfin.ltd/ Severity: CRITICAL Description: Active phishing URL: https://account-sso.evergreenfin.ltd/ Source: OpenPhish URL: https://account-sso.evergreenfin.ltd/ Date: Tags: phishing,openphish #17 https://iam.evergreenfin.ltd/ Severity: CRITICAL Description: Active phishing URL: https://iam.evergreenfin.ltd/ Source: OpenPhish URL: https://iam.evergreenfin.ltd/ Date: Tags: phishing,openphish #18 http://idpage.evergreenfin.ltd/ Severity: CRITICAL Description: Active phishing URL: http://idpage.evergreenfin.ltd/ Source: OpenPhish URL: http://idpage.evergreenfin.ltd/ Date: Tags: phishing,openphish #19 https://membership.evergreenfin.ltd/ Severity: CRITICAL Description: Active phishing URL: https://membership.evergreenfin.ltd/ Source: OpenPhish URL: https://membership.evergreenfin.ltd/ Date: Tags: phishing,openphish ============================================================================== [DOMAIN] - 9 indicator(s) ============================================================================== #20 douyin.evergreenfin Severity: CRITICAL Description: Phishing domain: douyin.evergreenfin Source: OpenPhish URL: https://douyin.evergreenfin.ltd/ Date: Tags: phishing,openphish,domain #21 www.asodfihjgdioshi Severity: CRITICAL Description: Phishing domain: www.asodfihjgdioshi Source: OpenPhish URL: https://www.asodfihjgdioshi.xyz/ Date: Tags: phishing,openphish,domain #22 genie.evergreenfin Severity: CRITICAL Description: Phishing domain: genie.evergreenfin Source: OpenPhish URL: http://genie.evergreenfin.ltd/ Date: Tags: phishing,openphish,domain #23 geren.evergreenfin Severity: CRITICAL Description: Phishing domain: geren.evergreenfin Source: OpenPhish URL: http://geren.evergreenfin.ltd/ Date: Tags: phishing,openphish,domain #24 huiyuanlogin.evergreenfin Severity: CRITICAL Description: Phishing domain: huiyuanlogin.evergreenfin Source: OpenPhish URL: https://huiyuanlogin.evergreenfin.ltd/ Date: Tags: phishing,openphish,domain #25 account-sso.evergreenfin Severity: CRITICAL Description: Phishing domain: account-sso.evergreenfin Source: OpenPhish URL: https://account-sso.evergreenfin.ltd/ Date: Tags: phishing,openphish,domain #26 iam.evergreenfin Severity: CRITICAL Description: Phishing domain: iam.evergreenfin Source: OpenPhish URL: https://iam.evergreenfin.ltd/ Date: Tags: phishing,openphish,domain #27 idpage.evergreenfin Severity: CRITICAL Description: Phishing domain: idpage.evergreenfin Source: OpenPhish URL: http://idpage.evergreenfin.ltd/ Date: Tags: phishing,openphish,domain #28 membership.evergreenfin Severity: CRITICAL Description: Phishing domain: membership.evergreenfin Source: OpenPhish URL: https://membership.evergreenfin.ltd/ Date: Tags: phishing,openphish,domain ============================================================================== RECOMMENDED ACTIONS ============================================================================== 1. Search SIEM/network logs for all listed indicators 2. Block listed domains at DNS/proxy immediately 3. Scan endpoints for listed SHA256 hashes 4. Check email gateways for listed sender addresses/links 5. Block listed IP addresses at the firewall 6. Share IOCs with partner agencies and ISACs 7. Update detection rules (Sigma/YARA/Suricata/Splunk) 8. Monitor for indicator rotation (new domains, IP changes) ============================================================================== END OF IOC LIST - IOC-20260929-121511 ==============================================================================