
{
  "Event": {
    "id": 0,
    "date": "2026-09-05",
    "threat_level_id": 1,
    "analysis": 0,
    "attribute_count": "78",
    "publish_distribution": 0,
    "proposal_email_lock": false,
    "info": "Cyber Daily Brief IOC Report - 2026-09-05 19:25 UTC",
    "published": false,
    "uuid": "misp-event-IOC-20260905-192537",
    "orgc_id": 0,
    "Orgc": {
      "name": "Cyber Daily Brief"
    },
    "distribution": 0,
    "tags": [
      "ioc-report::2026-09-05 19:25 UTC",
      "classification:text",
      "export:requires-approval::0"
    ],
    "sharing_group_id": 0,
    "disable_correlation": false,
    "expected_count": 78,
    "event_level": 1,
    "analysis_status": "1",
    "Attribute": [
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-85046",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Chromium V8 (Google); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-04; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple ",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-04",
        "last_seen": "2026-09-04"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-59822",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: LiteLLM (BerriAI); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an ar",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-48710",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Starlette (Kludex); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentica",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-49869",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Kestra OSS (Kestra); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-82329",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Artifactory (JFrog); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-9586",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Switchvox (Sangoma); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single craf",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-83548",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: SMA1000 Appliances (SonicWall); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform ",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-83549",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: SMA1000 Appliances (SonicWall); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote cod",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-02",
        "last_seen": "2026-09-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-82078",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: NG/MF (PaperCut); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-31; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpa",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-31",
        "last_seen": "2026-08-31"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-81578",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: NG/MF (PaperCut); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-31; Section: DOMAIN; Description: PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be ",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-31",
        "last_seen": "2026-08-31"
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "policy.trezor",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Trezor Says ShipMonk Breach Exposed 67,0...; URL: https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html; Section: DOMAIN; Description: Referenced in threat context: Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Dele",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "metabase.however",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Trezor Says ShipMonk Breach Exposed 67,0...; URL: https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html; Section: DOMAIN; Description: Referenced in threat context: Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Dele",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "actions.holborn",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Trezor Says ShipMonk Breach Exposed 67,0...; URL: https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html; Section: DOMAIN; Description: Referenced in threat context: Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Dele",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "remediation.the",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Trezor Says ShipMonk Breach Exposed 67,0...; URL: https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html; Section: DOMAIN; Description: Referenced in threat context: Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Dele",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "restrictions.the",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: OpenAI admits it didn't disclose rogue A...; URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/; Section: DOMAIN; Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "impact.in",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: OpenAI admits it didn't disclose rogue A...; URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/; Section: DOMAIN; Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "succeeded.when",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: OpenAI admits it didn't disclose rogue A...; URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/; Section: DOMAIN; Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "longer.the",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: OpenAI admits it didn't disclose rogue A...; URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/; Section: DOMAIN; Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "addresses.openai",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: OpenAI admits it didn't disclose rogue A...; URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/; Section: DOMAIN; Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "day.openai",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: OpenAI admits it didn't disclose rogue A...; URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/; Section: DOMAIN; Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "incident.the",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: OpenAI admits it didn't disclose rogue A...; URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/; Section: DOMAIN; Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "cybersecurity.in",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: OpenAI admits it didn't disclose rogue A...; URL: https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/; Section: DOMAIN; Description: Referenced in threat context: OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "sandbox.the",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "data.the",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "behind.about",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "method.the",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "blob.core",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "windows.net",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "valid.an",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "bypass.blob",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "core.windows",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "internet.those",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "used.in",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "platform.openai",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "investigation.the",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "on.the",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "testing.openai",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "boards.openai",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "face.the",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Thousands of OpenAI Agents Quietly Turne...; URL: https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html; Section: DOMAIN; Description: Referenced in threat context: Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordinat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "said.the",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Attackers Exploit PaperCut Flaws to Stea...; URL: https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html; Section: DOMAIN; Description: Referenced in threat context: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universit",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "statement.users",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Attackers Exploit PaperCut Flaws to Stea...; URL: https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html; Section: DOMAIN; Description: Referenced in threat context: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universit",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "cmd.exe",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Attackers Exploit PaperCut Flaws to Stea...; URL: https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html; Section: DOMAIN; Description: Referenced in threat context: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universit",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "powershell.exe",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Attackers Exploit PaperCut Flaws to Stea...; URL: https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html; Section: DOMAIN; Description: Referenced in threat context: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universit",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "pc-app.exe",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Attackers Exploit PaperCut Flaws to Stea...; URL: https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html; Section: DOMAIN; Description: Referenced in threat context: Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universit",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "idscan.brian",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: IDScan sued over alleged data breach aff...; URL: https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/; Section: DOMAIN; Description: Referenced in threat context: IDScan sued over alleged data breach affecting 153 million drivers",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "cards.idscan",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: IDScan sued over alleged data breach aff...; URL: https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/; Section: DOMAIN; Description: Referenced in threat context: IDScan sued over alleged data breach affecting 153 million drivers",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "documents.given",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: IDScan sued over alleged data breach aff...; URL: https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/; Section: DOMAIN; Description: Referenced in threat context: IDScan sued over alleged data breach affecting 153 million drivers",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "litigation.state",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: IDScan sued over alleged data breach aff...; URL: https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/; Section: DOMAIN; Description: Referenced in threat context: IDScan sued over alleged data breach affecting 153 million drivers",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "user.however",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Phishing Campaign Sends Millions of Emai...; URL: https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html; Section: DOMAIN; Description: Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "mondays.weekday",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Phishing Campaign Sends Millions of Emai...; URL: https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html; Section: DOMAIN; Description: Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "applicants.details",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Phishing Campaign Sends Millions of Emai...; URL: https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html; Section: DOMAIN; Description: Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "matches.for",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Phishing Campaign Sends Millions of Emai...; URL: https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html; Section: DOMAIN; Description: Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "basis.the",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Phishing Campaign Sends Millions of Emai...; URL: https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html; Section: DOMAIN; Description: Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "acemlnd.com",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Phishing Campaign Sends Millions of Emai...; URL: https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html; Section: DOMAIN; Description: Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "activehosted.com",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Phishing Campaign Sends Millions of Emai...; URL: https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html; Section: DOMAIN; Description: Referenced in threat context: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filt",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "networks.although",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Critical Citrix NetScaler auth bypass no...; URL: https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/; Section: DOMAIN; Description: Referenced in threat context: Critical Citrix NetScaler auth bypass now leveraged in attacks",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "attacks.the",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Critical Citrix NetScaler auth bypass no...; URL: https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/; Section: DOMAIN; Description: Referenced in threat context: Critical Citrix NetScaler auth bypass now leveraged in attacks",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "sharply.tracked",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: Critical Citrix NetScaler auth bypass no...; URL: https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/; Section: DOMAIN; Description: Referenced in threat context: Critical Citrix NetScaler auth bypass now leveraged in attacks",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "affected.exploitation",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: PostgreSQL Fixes 12-Year-Old Logical Dec...; URL: https://thehackernews.com/2026/09/postgresql-fixes-12-year-old-logical.html; Section: DOMAIN; Description: Referenced in threat context: PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Cod",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "attribute.the",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Article: PostgreSQL Fixes 12-Year-Old Logical Dec...; URL: https://thehackernews.com/2026/09/postgresql-fixes-12-year-old-logical.html; Section: DOMAIN; Description: Referenced in threat context: PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Cod",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:domain",
          "tag:extracted"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "roblox.com",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://roblox.com.mu/communities/7901998248/LeightXyn; Section: DOMAIN; Description: Phishing domain: roblox.com",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "revenuewise.sbs",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://revenuewise.sbs/how-to-file/; Section: DOMAIN; Description: Phishing domain: revenuewise.sbs",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "undian-shopee1772.blogspot",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://undian-shopee1772.blogspot.com/; Section: DOMAIN; Description: Phishing domain: undian-shopee1772.blogspot",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "hadiahshopee3232.blogspot",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://hadiahshopee3232.blogspot.com/?m=1; Section: DOMAIN; Description: Phishing domain: hadiahshopee3232.blogspot",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "www.newcomc",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://www.newcomc.weebly.com/; Section: DOMAIN; Description: Phishing domain: www.newcomc",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "pesta-undian-shopee2023.blogspot",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://pesta-undian-shopee2023.blogspot.com/; Section: DOMAIN; Description: Phishing domain: pesta-undian-shopee2023.blogspot",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "surajyadav-07.github",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://surajyadav-07.github.io/ecommerce-website; Section: DOMAIN; Description: Phishing domain: surajyadav-07.github",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "lbr-icloud.com",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://lbr-icloud.com/help?JpN; Section: DOMAIN; Description: Phishing domain: lbr-icloud.com",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "first-agency-743956.framer",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://first-agency-743956.framer.app/; Section: PHISHING URL; Description: Phishing domain: first-agency-743956.framer",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://roblox.com.mu/communities/7901998248/LeightXyn",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://roblox.com.mu/communities/7901998248/LeightXyn; Section: PHISHING URL; Description: Active phishing URL: http://roblox.com.mu/communities/7901998248/LeightXyn",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://revenuewise.sbs/how-to-file/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://revenuewise.sbs/how-to-file/; Section: PHISHING URL; Description: Active phishing URL: https://revenuewise.sbs/how-to-file/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://revenuewise.sbs/get-transcript/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://revenuewise.sbs/get-transcript/; Section: PHISHING URL; Description: Active phishing URL: https://revenuewise.sbs/get-transcript/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://revenuewise.sbs/businesses-1/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://revenuewise.sbs/businesses-1/; Section: PHISHING URL; Description: Active phishing URL: https://revenuewise.sbs/businesses-1/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://revenuewise.sbs/get-your-refund-faster-tell-irs-to-direct-deposit-your-refund-to-one-two-or-three-accounts/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://revenuewise.sbs/get-your-refund-faster-tell-irs-to-direct-deposit-your-refund-to-one-two-or-three-accounts/; Section: PHISHING URL; Description: Active phishing URL: https://revenuewise.sbs/get-your-refund-faster-tell-irs-to-direct-deposit-your-refund-to-one-two-or-three-accounts/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://revenuewise.sbs/credits-and-deductions-for-individuals/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://revenuewise.sbs/credits-and-deductions-for-individuals/; Section: PHISHING URL; Description: Active phishing URL: https://revenuewise.sbs/credits-and-deductions-for-individuals/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://revenuewise.sbs/clean-vehicle-and-energy-credits/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://revenuewise.sbs/clean-vehicle-and-energy-credits/; Section: PHISHING URL; Description: Active phishing URL: https://revenuewise.sbs/clean-vehicle-and-energy-credits/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://revenuewise.sbs/about-refunds/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://revenuewise.sbs/about-refunds/; Section: PHISHING URL; Description: Active phishing URL: https://revenuewise.sbs/about-refunds/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://undian-shopee1772.blogspot.com/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://undian-shopee1772.blogspot.com/; Section: PHISHING URL; Description: Active phishing URL: https://undian-shopee1772.blogspot.com/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      }
    ]
  }
}