
{
  "Event": {
    "id": 0,
    "date": "2026-09-28",
    "threat_level_id": 1,
    "analysis": 0,
    "attribute_count": "28",
    "publish_distribution": 0,
    "proposal_email_lock": false,
    "info": "Cyber Daily Brief IOC Report - 2026-09-28 12:15 UTC",
    "published": false,
    "uuid": "misp-event-IOC-20260928-121546",
    "orgc_id": 0,
    "Orgc": {
      "name": "Cyber Daily Brief"
    },
    "distribution": 0,
    "tags": [
      "ioc-report::2026-09-28 12:15 UTC",
      "classification:text",
      "export:requires-approval::0"
    ],
    "sharing_group_id": 0,
    "disable_correlation": false,
    "expected_count": 28,
    "event_level": 1,
    "analysis_status": "1",
    "Attribute": [
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-88772",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: NetScaler (Citrix); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-27; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of serv",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-27",
        "last_seen": "2026-09-27"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-88771",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: NetScaler (Citrix); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-27; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-27",
        "last_seen": "2026-09-27"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-67279",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: RouterOS (MikroTik); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-25; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerabilit",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-25",
        "last_seen": "2026-09-25"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-65660",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: SharePoint (Microsoft); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-25; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-25",
        "last_seen": "2026-09-25"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-87902",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Core (WordPress); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-25; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the act",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-25",
        "last_seen": "2026-09-25"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-5430",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Multiple Products (WSO2); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-24; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-24",
        "last_seen": "2026-09-24"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-71362",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Commerce and Magento  (Adobe); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-24; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-24",
        "last_seen": "2026-09-24"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-93952",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: VeloCloud Orchestrator (Arista); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-22; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Su",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-22",
        "last_seen": "2026-09-22"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-94127",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: BIG-IP APM (F5); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-22; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-22",
        "last_seen": "2026-09-22"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-93616",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Multiple Products (Check Point); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-22; Section: PHISHING URL; Description: Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticat",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-22",
        "last_seen": "2026-09-22"
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://ledger-com-strts.pages.dev/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://ledger-com-strts.pages.dev/; Section: PHISHING URL; Description: Active phishing URL: http://ledger-com-strts.pages.dev/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Email address",
        "type": "email",
        "value": "https://filmistanstudios.com/fonts/purchase.html?e=valos@2c5a11bb81b5b1c04d53c01f56c510b84c79.net",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://filmistanstudios.com/fonts/purchase.html?e=valos@2c5a11bb81b5b1c04d53c01f56c510b84c79.net; Section: PHISHING URL; Description: Active phishing URL: https://filmistanstudios.com/fonts/purchase.html?e=valos@2c5a11bb81b5b1c04d53c01f56c510b84c79.net",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://square-nddax-en-us.square.site/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://square-nddax-en-us.square.site/; Section: PHISHING URL; Description: Active phishing URL: http://square-nddax-en-us.square.site/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://bet-facebook.blogspot.com/?m=1",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://bet-facebook.blogspot.com/?m=1; Section: PHISHING URL; Description: Active phishing URL: http://bet-facebook.blogspot.com/?m=1",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://www.bet-facebook.blogspot.com/?m=1",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://www.bet-facebook.blogspot.com/?m=1; Section: PHISHING URL; Description: Active phishing URL: http://www.bet-facebook.blogspot.com/?m=1",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://rmaconsultoria.net/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://rmaconsultoria.net/; Section: PHISHING URL; Description: Active phishing URL: http://rmaconsultoria.net/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://auth-bitbuys-webb.webflow.io/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://auth-bitbuys-webb.webflow.io/; Section: PHISHING URL; Description: Active phishing URL: http://auth-bitbuys-webb.webflow.io/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://g00gle-mobile-verif.com/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://g00gle-mobile-verif.com/; Section: PHISHING URL; Description: Active phishing URL: http://g00gle-mobile-verif.com/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://aapsuite.pages.dev/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://aapsuite.pages.dev/; Section: DOMAIN; Description: Active phishing URL: http://aapsuite.pages.dev/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "ledger-com-strts.pages",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://ledger-com-strts.pages.dev/; Section: DOMAIN; Description: Phishing domain: ledger-com-strts.pages",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "filmistanstudios.com",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://filmistanstudios.com/fonts/purchase.html?e=valos@2c5a11bb81b5b1c04d53c01f56c510b84c79.net; Section: DOMAIN; Description: Phishing domain: filmistanstudios.com",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "square-nddax-en-us.square",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://square-nddax-en-us.square.site/; Section: DOMAIN; Description: Phishing domain: square-nddax-en-us.square",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "bet-facebook.blogspot",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://bet-facebook.blogspot.com/?m=1; Section: DOMAIN; Description: Phishing domain: bet-facebook.blogspot",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "www.bet",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://www.bet-facebook.blogspot.com/?m=1; Section: DOMAIN; Description: Phishing domain: www.bet",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "rmaconsultoria.net",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://rmaconsultoria.net/; Section: DOMAIN; Description: Phishing domain: rmaconsultoria.net",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "auth-bitbuys-webb.webflow",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://auth-bitbuys-webb.webflow.io/; Section: DOMAIN; Description: Phishing domain: auth-bitbuys-webb.webflow",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "mobile-verif.com",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://g00gle-mobile-verif.com/; Section: DOMAIN; Description: Phishing domain: mobile-verif.com",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "aapsuite.pages",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://aapsuite.pages.dev/; Section: DOMAIN; Description: Phishing domain: aapsuite.pages",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      }
    ]
  }
}