
{
  "Event": {
    "id": 0,
    "date": "2026-09-16",
    "threat_level_id": 1,
    "analysis": 0,
    "attribute_count": "28",
    "publish_distribution": 0,
    "proposal_email_lock": false,
    "info": "Cyber Daily Brief IOC Report - 2026-09-16 15:40 UTC",
    "published": false,
    "uuid": "misp-event-IOC-20260916-154039",
    "orgc_id": 0,
    "Orgc": {
      "name": "Cyber Daily Brief"
    },
    "distribution": 0,
    "tags": [
      "ioc-report::2026-09-16 15:40 UTC",
      "classification:text",
      "export:requires-approval::0"
    ],
    "sharing_group_id": 0,
    "disable_correlation": false,
    "expected_count": 28,
    "event_level": 1,
    "analysis_status": "1",
    "Attribute": [
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-58704",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Pixel (Google); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-16; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-16",
        "last_seen": "2026-09-16"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-76461",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Secure Email Gateway (Cisco); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-14; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileg",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-14",
        "last_seen": "2026-09-14"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-84869",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: ScreenConnect (ConnectWise); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-11; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote sessi",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-11",
        "last_seen": "2026-09-11"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-42016",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Artifactory (JFrog); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-11; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token\u2019s scope.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-11",
        "last_seen": "2026-09-11"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-42018",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Artifactory (JFrog); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-11; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially expos",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-11",
        "last_seen": "2026-09-11"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-85706",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Community Edition and Enterprise Edition (GitLab); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-11; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing auth",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-11",
        "last_seen": "2026-09-11"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-86060",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: RouterOS (MikroTik); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-10; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacker to change the trusted RouterOS policy mask, leading to privilege escala",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-10",
        "last_seen": "2026-09-10"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-67277",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: RouterOS (MikroTik); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-10; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: MikroTik RouterOS contains a missing authentication for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-10",
        "last_seen": "2026-09-10"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-19490",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: NetScaler (Citrix); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-09; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-09",
        "last_seen": "2026-09-09"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2025-25249",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Multiple Products (Fortinet); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-09; Section: PHISHING URL; Description: Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-09",
        "last_seen": "2026-09-09"
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://schtrekh.de/img/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://schtrekh.de/img/; Section: PHISHING URL; Description: Active phishing URL: https://schtrekh.de/img/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://farren.webdesignla.info/ga/click/2-115159033-1585-17249-33739-18616-2212d2c02a-1b10dc49b9",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://farren.webdesignla.info/ga/click/2-115159033-1585-17249-33739-18616-2212d2c02a-1b10dc49b9; Section: PHISHING URL; Description: Active phishing URL: https://farren.webdesignla.info/ga/click/2-115159033-1585-17249-33739-18616-2212d2c02a-1b10dc49b9",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://brayden-15.pages.dev/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://brayden-15.pages.dev/; Section: PHISHING URL; Description: Active phishing URL: https://brayden-15.pages.dev/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://ch-pak-informations.bolt.host/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://ch-pak-informations.bolt.host/; Section: PHISHING URL; Description: Active phishing URL: https://ch-pak-informations.bolt.host/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://jdbdkdbsosu.blogspot.com/?m=1",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://jdbdkdbsosu.blogspot.com/?m=1; Section: PHISHING URL; Description: Active phishing URL: https://jdbdkdbsosu.blogspot.com/?m=1",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://www.adsbot2-eauj.vercel.app/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://www.adsbot2-eauj.vercel.app/; Section: PHISHING URL; Description: Active phishing URL: http://www.adsbot2-eauj.vercel.app/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://proxy-test-001.pages.dev/mac-mini-2023-service-program-for-no-power-issu",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://proxy-test-001.pages.dev/mac-mini-2023-service-program-for-no-power-issu; Section: PHISHING URL; Description: Active phishing URL: https://proxy-test-001.pages.dev/mac-mini-2023-service-program-for-no-power-issu",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://ei1i7-qqt-v6l4-2qu9k-08-09-2026-hh.pages.dev/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://ei1i7-qqt-v6l4-2qu9k-08-09-2026-hh.pages.dev/; Section: PHISHING URL; Description: Active phishing URL: http://ei1i7-qqt-v6l4-2qu9k-08-09-2026-hh.pages.dev/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://coinbse-extesnsion.framer.website/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://coinbse-extesnsion.framer.website/; Section: DOMAIN; Description: Active phishing URL: http://coinbse-extesnsion.framer.website/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "schtrekh.de",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://schtrekh.de/img/; Section: DOMAIN; Description: Phishing domain: schtrekh.de",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "farren.webdesignla",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://farren.webdesignla.info/ga/click/2-115159033-1585-17249-33739-18616-2212d2c02a-1b10dc49b9; Section: DOMAIN; Description: Phishing domain: farren.webdesignla",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "brayden-15.pages",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://brayden-15.pages.dev/; Section: DOMAIN; Description: Phishing domain: brayden-15.pages",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "ch-pak-informations.bolt",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://ch-pak-informations.bolt.host/; Section: DOMAIN; Description: Phishing domain: ch-pak-informations.bolt",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "jdbdkdbsosu.blogspot",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://jdbdkdbsosu.blogspot.com/?m=1; Section: DOMAIN; Description: Phishing domain: jdbdkdbsosu.blogspot",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "adsbot2-eauj.vercel",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://www.adsbot2-eauj.vercel.app/; Section: DOMAIN; Description: Phishing domain: adsbot2-eauj.vercel",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "proxy-test-001.pages",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://proxy-test-001.pages.dev/mac-mini-2023-service-program-for-no-power-issu; Section: DOMAIN; Description: Phishing domain: proxy-test-001.pages",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "ei1i7-qqt-v6l4-2qu9k-08-09-2026-hh.pages",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://ei1i7-qqt-v6l4-2qu9k-08-09-2026-hh.pages.dev/; Section: DOMAIN; Description: Phishing domain: ei1i7-qqt-v6l4-2qu9k-08-09-2026-hh.pages",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "coinbse-extesnsion.framer",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://coinbse-extesnsion.framer.website/; Section: DOMAIN; Description: Phishing domain: coinbse-extesnsion.framer",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      }
    ]
  }
}