
{
  "Event": {
    "id": 0,
    "date": "2026-10-05",
    "threat_level_id": 1,
    "analysis": 0,
    "attribute_count": "28",
    "publish_distribution": 0,
    "proposal_email_lock": false,
    "info": "Cyber Daily Brief IOC Report - 2026-10-05 12:15 UTC",
    "published": false,
    "uuid": "misp-event-IOC-20261005-121535",
    "orgc_id": 0,
    "Orgc": {
      "name": "Cyber Daily Brief"
    },
    "distribution": 0,
    "tags": [
      "ioc-report::2026-10-05 12:15 UTC",
      "classification:text",
      "export:requires-approval::0"
    ],
    "sharing_group_id": 0,
    "disable_correlation": false,
    "expected_count": 28,
    "event_level": 1,
    "analysis_status": "1",
    "Attribute": [
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-88779",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: NetScaler (Citrix); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-10-04; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that ",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-10-04",
        "last_seen": "2026-10-04"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-102490",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Zammad (Zammad GmbH); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-10-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-10-02",
        "last_seen": "2026-10-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-102489",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Zammad (Zammad GmbH); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-10-02; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-10-02",
        "last_seen": "2026-10-02"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-104286",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: FortiMail (Fortinet); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-10-01; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the unde",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-10-01",
        "last_seen": "2026-10-01"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-76504",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Catalyst SD-WAN Manager (Cisco); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-30; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper ",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-30",
        "last_seen": "2026-09-30"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-86950",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Multiple Products (Apple); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-29; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-29",
        "last_seen": "2026-09-29"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-88772",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: NetScaler (Citrix); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-27; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of serv",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-27",
        "last_seen": "2026-09-27"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-88771",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: NetScaler (Citrix); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-27; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-27",
        "last_seen": "2026-09-27"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-67279",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: RouterOS (MikroTik); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-25; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerabilit",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-25",
        "last_seen": "2026-09-25"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-65660",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: SharePoint (Microsoft); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-09-25; Section: PHISHING URL; Description: Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-09-25",
        "last_seen": "2026-09-25"
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://dune-wave.pages.dev/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://dune-wave.pages.dev/; Section: PHISHING URL; Description: Active phishing URL: http://dune-wave.pages.dev/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Email address",
        "type": "email",
        "value": "https://wetransfer-smoky.vercel.app/#mirensys@f91b7a73195f98d78e426e2bef4f4056457a.net",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://wetransfer-smoky.vercel.app/#mirensys@f91b7a73195f98d78e426e2bef4f4056457a.net; Section: PHISHING URL; Description: Active phishing URL: https://wetransfer-smoky.vercel.app/#mirensys@f91b7a73195f98d78e426e2bef4f4056457a.net",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://neu.planen.95-179-167-177.cpanel.site/de/update.php",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://neu.planen.95-179-167-177.cpanel.site/de/update.php; Section: PHISHING URL; Description: Active phishing URL: https://neu.planen.95-179-167-177.cpanel.site/de/update.php",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://site-cpwcg5s76.godaddysites.com/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://site-cpwcg5s76.godaddysites.com/; Section: PHISHING URL; Description: Active phishing URL: https://site-cpwcg5s76.godaddysites.com/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://lundraif.vercel.app/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://lundraif.vercel.app/; Section: PHISHING URL; Description: Active phishing URL: https://lundraif.vercel.app/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://www.roblox.com.mu/users/976201056/profile",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://www.roblox.com.mu/users/976201056/profile; Section: PHISHING URL; Description: Active phishing URL: https://www.roblox.com.mu/users/976201056/profile",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://porgu-8y3-87x4-6osm4-29-09-2026-hh.pages.dev/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://porgu-8y3-87x4-6osm4-29-09-2026-hh.pages.dev/; Section: PHISHING URL; Description: Active phishing URL: http://porgu-8y3-87x4-6osm4-29-09-2026-hh.pages.dev/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "http://sp1ct10-purvek-biz-nulqo-vemri.pages.dev/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://sp1ct10-purvek-biz-nulqo-vemri.pages.dev/; Section: PHISHING URL; Description: Active phishing URL: http://sp1ct10-purvek-biz-nulqo-vemri.pages.dev/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:PHISHING URL",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Other",
        "type": "other",
        "value": "https://zunfuri-mpt-qalveno-r5x7me86.pages.dev/",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://zunfuri-mpt-qalveno-r5x7me86.pages.dev/; Section: DOMAIN; Description: Active phishing URL: https://zunfuri-mpt-qalveno-r5x7me86.pages.dev/",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "dune-wave.pages",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://dune-wave.pages.dev/; Section: DOMAIN; Description: Phishing domain: dune-wave.pages",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "wetransfer-smoky.vercel",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://wetransfer-smoky.vercel.app/#mirensys@f91b7a73195f98d78e426e2bef4f4056457a.net; Section: DOMAIN; Description: Phishing domain: wetransfer-smoky.vercel",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "neu.planen",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://neu.planen.95-179-167-177.cpanel.site/de/update.php; Section: DOMAIN; Description: Phishing domain: neu.planen",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "site-cpwcg5s76.godaddysites",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://site-cpwcg5s76.godaddysites.com/; Section: DOMAIN; Description: Phishing domain: site-cpwcg5s76.godaddysites",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "lundraif.vercel",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://lundraif.vercel.app/; Section: DOMAIN; Description: Phishing domain: lundraif.vercel",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "www.roblox",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://www.roblox.com.mu/users/976201056/profile; Section: DOMAIN; Description: Phishing domain: www.roblox",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "porgu-8y3-87x4-6osm4-29-09-2026-hh.pages",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://porgu-8y3-87x4-6osm4-29-09-2026-hh.pages.dev/; Section: DOMAIN; Description: Phishing domain: porgu-8y3-87x4-6osm4-29-09-2026-hh.pages",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "sp1ct10-purvek-biz-nulqo-vemri.pages",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: http://sp1ct10-purvek-biz-nulqo-vemri.pages.dev/; Section: DOMAIN; Description: Phishing domain: sp1ct10-purvek-biz-nulqo-vemri.pages",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      },
      {
        "category": "Domain and name",
        "type": "domain",
        "value": "zunfuri-mpt-qalveno-r5x7me86.pages",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: OpenPhish; URL: https://zunfuri-mpt-qalveno-r5x7me86.pages.dev/; Section: DOMAIN; Description: Phishing domain: zunfuri-mpt-qalveno-r5x7me86.pages",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:phishing",
          "tag:openphish",
          "tag:domain"
        ],
        "first_seen": "",
        "last_seen": ""
      }
    ]
  }
}