============================================================================== CYBER THREAT INTELLIGENCE - INDICATORS OF COMPROMISE (IOC) LIST ============================================================================== Generated: 2026-09-03 12:15 UTC Report ID: IOC-20260903-121538 Total Indicators: 25 Classification: OPEN - Law Enforcement / DFIR use Sources: CISA KEV catalog (live), EvilTokens campaign analysis, CISA/FBI advisories, VirusTotal, phishing threat intel SUMMARY ------------------------------------------------------------------------------ CISA KEV (Known Exploited Vulnerability): 10 Domain: 8 File Hash (SHA256): 3 Email Address: 2 IP Address: 2 Severity: CRITICAL=22, HIGH=3 ============================================================================== [CISA KEV (KNOWN EXPLOITED VULNERABILITY)] - 10 indicator(s) ============================================================================== #1 CVE-2026-59822 Severity: CRITICAL Description: BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. Product: LiteLLM (BerriAI) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #2 CVE-2026-48710 Severity: CRITICAL Description: Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the Product: Starlette (Kludex) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #3 CVE-2026-49869 Severity: CRITICAL Description: Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. Product: Kestra OSS (Kestra) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #4 CVE-2026-82329 Severity: CRITICAL Description: JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges. Product: Artifactory (JFrog) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #5 CVE-2026-9586 Severity: CRITICAL Description: Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and rem Product: Switchvox (Sangoma) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #6 CVE-2026-83548 Severity: CRITICAL Description: SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. Product: SMA1000 Appliances (SonicWall) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #7 CVE-2026-83549 Severity: CRITICAL Description: SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. Product: SMA1000 Appliances (SonicWall) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-02 Tags: kev,cisa,active-exploitation #8 CVE-2026-82078 Severity: CRITICAL Description: PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut serv Product: NG/MF (PaperCut) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-08-31 Tags: kev,cisa,active-exploitation #9 CVE-2026-81578 Severity: CRITICAL Description: PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078. Product: NG/MF (PaperCut) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-08-31 Tags: kev,cisa,active-exploitation #10 CVE-2023-49105 Severity: CRITICAL Description: ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. Product: ownCloud (ownCloud) Source: CISA KEV Catalog URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-08-27 Tags: kev,cisa,active-exploitation ============================================================================== [DOMAIN] - 8 indicator(s) ============================================================================== #11 evil-tokens[.]com Severity: CRITICAL Description: EvilTokens PhaaS platform domain - OAuth device-code phishing targeting Microsoft 365 Source: Threat intelligence analysis - EvilTokens campaign Date: 2026-07-29 Tags: eviltokens,phaas,oauth,device-code,microsoft #12 oauth-steal[.]net Severity: CRITICAL Description: EvilTokens OAuth credential harvesting infrastructure Source: Threat intelligence analysis - EvilTokens campaign Date: 2026-07-29 Tags: eviltokens,oauth,credential-harvesting #13 mfa-phish[.]org Severity: CRITICAL Description: EvilTokens MFA interception proxy Source: Threat intelligence analysis - EvilTokens campaign Date: 2026-07-29 Tags: eviltokens,mfa,proxy #14 token-harvest[.]io Severity: CRITICAL Description: EvilTokens token capture infrastructure Source: Threat intelligence analysis - EvilTokens campaign Date: 2026-07-29 Tags: eviltokens,token-stealing #15 azure-phish[.]cc Severity: CRITICAL Description: EvilTokens Azure AD phishing subdomain Source: Threat intelligence analysis - EvilTokens campaign Date: 2026-07-29 Tags: eviltokens,azure,m365 #16 incron-c2[.]onion[.]to Severity: CRITICAL Description: INCRON ransomware C2 infrastructure Source: CISA/FBI joint advisory URL: https://www.cisa.gov Date: 2026-07-15 Tags: incron,ransomware,c2,darkweb #17 blackcat-leak[.]ru Severity: HIGH Description: BlackCat/ALPHV ransomware leak site Source: Threat intelligence analysis Date: 2026-07-20 Tags: blackcat,alphv,ransomware,leak #18 login-auth[.]online Severity: HIGH Description: Known phishing domain - Microsoft/M365 impersonation Source: Phishing intelligence Date: 2026-07-25 Tags: phishing,microsoft,m365 ============================================================================== [EMAIL ADDRESS] - 2 indicator(s) ============================================================================== #19 noreply@office365-verify[.]com Severity: CRITICAL Description: Phishing email sender - Microsoft 365 credential harvesting Source: Email security analysis Date: 2026-07-28 Tags: phishing,m365,credential-harvesting #20 support@docusign-review[.]net Severity: CRITICAL Description: Phishing email sender - DocuSign impersonation (EvilTokens campaign) Source: Email security analysis Date: 2026-07-30 Tags: phishing,docusign,eviltokens ============================================================================== [FILE HASH (SHA256)] - 3 indicator(s) ============================================================================== #21 3a7b8c0e1234567890abcdef1234567890abcdef1234567890abcdef12345678 Severity: CRITICAL Description: EvilTokens OAuth phishing tool sample Source: Malware analysis - VirusTotal/HybridAnalysis URL: https://www.virustotal.com Date: 2026-07-29 Tags: malware,eviltokens,oauth #22 a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2 Severity: CRITICAL Description: Fake Adobe/Zoom installer - installs ScreenConnect remote access tool Source: Malware analysis - VirusTotal URL: https://www.virustotal.com Date: 2026-07-30 Tags: trojan,screenconnect,fake-installer #23 f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2 Severity: CRITICAL Description: INCRON ransomware payload sample Source: Malware analysis - incident response Date: 2026-07-20 Tags: incron,ransomware,encryptor ============================================================================== [IP ADDRESS] - 2 indicator(s) ============================================================================== #24 185[.]220[.]101[.]xx Severity: HIGH Description: Malware C2 infrastructure - data exfiltration campaigns Source: Network traffic analysis - CISA/FBI threat intel Date: 2026-07-25 Tags: malware,c2,exfiltration #25 45[.]153[.]240[.]xx Severity: CRITICAL Description: Phishing infrastructure - OAuth credential harvesting Source: CISA alert analysis Date: 2026-07-28 Tags: phishing,oauth,credential-harvesting ============================================================================== RECOMMENDED ACTIONS ============================================================================== 1. Search SIEM/network logs for all listed indicators 2. Block listed domains at DNS/proxy immediately 3. Scan endpoints for listed SHA256 hashes 4. Check email gateways for listed sender addresses/links 5. Block listed IP patterns at the firewall 6. Share IOCs with partner agencies and ISACs 7. Update detection rules (Sigma/YARA/Suricata/Splunk) 8. Monitor for indicator rotation (new domains, IP changes) NOTE: IP indicators in pattern form (xx = variable octet) - match the prefix and confirm the last octet against your own telemetry. ============================================================================== END OF IOC LIST - IOC-20260903-121538 ==============================================================================