
{
  "Event": {
    "id": 0,
    "date": "2026-09-22",
    "threat_level_id": 1,
    "analysis": 0,
    "attribute_count": "28",
    "publish_distribution": 0,
    "proposal_email_lock": false,
    "info": "Cyber Daily Brief IOC Report - 2026-09-22 12:15 UTC",
    "published": false,
    "uuid": "misp-event-IOC-20260922-121533",
    "orgc_id": 0,
    "Orgc": {
      "name": "Cyber Daily Brief"
    },
    "distribution": 0,
    "tags": [
      "ioc-report::2026-09-22 12:15 UTC",
      "classification:text",
      "export:requires-approval::0"
    ],
    "sharing_group_id": 0,
    "disable_correlation": false,
    "expected_count": 28,
    "event_level": 1,
    "analysis_status": "1",
    "Attribute": [
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-7273",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: GS1900 Series Switches (Zyxel); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-21; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute ",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-21",
        "last_seen": "2026-09-21"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2025-39964",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Kernel (Linux); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-18; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's ",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-53266",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Kernel (Linux); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-18; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment bac",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2025-39682",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Kernel (Linux); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-18; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended ",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-18",
        "last_seen": "2026-09-18"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-58704",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Pixel (Google); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-16; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-16",
        "last_seen": "2026-09-16"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-76460",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Identity Services Engine (Cisco); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-16; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker t",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-16",
        "last_seen": "2026-09-16"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-87886",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Backup (Acronis); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-16; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-16",
        "last_seen": "2026-09-16"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-76461",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Secure Email Gateway (Cisco); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-14; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileg",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-14",
        "last_seen": "2026-09-14"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-84869",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: ScreenConnect (ConnectWise); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-11; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote sessi",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-11",
        "last_seen": "2026-09-11"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-42016",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Artifactory (JFrog); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-11; Section: PHISHING URL; Description: JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token\u2019s scope.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-11",
        "last_seen": "2026-09-11"
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://kucoin_u_logi.godaddysites.com/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://kucoin_u_logi.godaddysites.com/; Section: PHISHING URL; Description: Active phishing URL: https://kucoin_u_logi.godaddysites.com/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://www.kucoin_u_logi.godaddysites.com/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://www.kucoin_u_logi.godaddysites.com/; Section: PHISHING URL; Description: Active phishing URL: https://www.kucoin_u_logi.godaddysites.com/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://pranavraj0562.github.io/Alfido_Tech_Task3",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://pranavraj0562.github.io/Alfido_Tech_Task3; Section: PHISHING URL; Description: Active phishing URL: http://pranavraj0562.github.io/Alfido_Tech_Task3",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://22e2915e.pinme.dev/for.html",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://22e2915e.pinme.dev/for.html; Section: PHISHING URL; Description: Active phishing URL: https://22e2915e.pinme.dev/for.html",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://geminuni-lggin0.godaddysites.com/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://geminuni-lggin0.godaddysites.com/; Section: PHISHING URL; Description: Active phishing URL: https://geminuni-lggin0.godaddysites.com/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://www.geminuni-lggin0.godaddysites.com/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://www.geminuni-lggin0.godaddysites.com/; Section: PHISHING URL; Description: Active phishing URL: https://www.geminuni-lggin0.godaddysites.com/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://scsproyectos.cl/bx/bell.html",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://scsproyectos.cl/bx/bell.html; Section: PHISHING URL; Description: Active phishing URL: https://scsproyectos.cl/bx/bell.html",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://dewanshigarg2007.github.io/Amazon-clone",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://dewanshigarg2007.github.io/Amazon-clone; Section: PHISHING URL; Description: Active phishing URL: https://dewanshigarg2007.github.io/Amazon-clone",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://ayeshakamranabbas.github.io/clone-website",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://ayeshakamranabbas.github.io/clone-website; Section: DOMAIN; Description: Active phishing URL: http://ayeshakamranabbas.github.io/clone-website",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "godaddysites.com",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://kucoin_u_logi.godaddysites.com/; Section: DOMAIN; Description: Phishing domain: godaddysites.com",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "pranavraj0562.github",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://pranavraj0562.github.io/Alfido_Tech_Task3; Section: DOMAIN; Description: Phishing domain: pranavraj0562.github",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "pinme.dev",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://22e2915e.pinme.dev/for.html; Section: DOMAIN; Description: Phishing domain: pinme.dev",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "geminuni-lggin0.godaddysites",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://geminuni-lggin0.godaddysites.com/; Section: DOMAIN; Description: Phishing domain: geminuni-lggin0.godaddysites",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "www.geminuni",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://www.geminuni-lggin0.godaddysites.com/; Section: DOMAIN; Description: Phishing domain: www.geminuni",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "scsproyectos.cl",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://scsproyectos.cl/bx/bell.html; Section: DOMAIN; Description: Phishing domain: scsproyectos.cl",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "dewanshigarg2007.github",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://dewanshigarg2007.github.io/Amazon-clone; Section: DOMAIN; Description: Phishing domain: dewanshigarg2007.github",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "ayeshakamranabbas.github",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://ayeshakamranabbas.github.io/clone-website; Section: DOMAIN; Description: Phishing domain: ayeshakamranabbas.github",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "sia.inicioseguro",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://sia.inicioseguro.com/c/p/tc/4522/216e4578-cf00-4d39-ba3c-1b0194c7ed19-126c912d-ef35-44a2-a10c-63ca636af561/; Section: DOMAIN; Description: Phishing domain: sia.inicioseguro",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      }
    ]
  }
}