
{
  "Event": {
    "id": 0,
    "date": "2026-08-29",
    "threat_level_id": 1,
    "analysis": 0,
    "attribute_count": "25",
    "publish_distribution": 0,
    "proposal_email_lock": false,
    "info": "Cyber Daily Brief IOC Report - 2026-08-29 13:40 UTC",
    "published": false,
    "uuid": "misp-event-IOC-20260829-134050",
    "orgc_id": 0,
    "Orgc": {
      "name": "Cyber Daily Brief"
    },
    "distribution": 0,
    "tags": [
      "ioc-report::2026-08-29 13:40 UTC",
      "classification:text",
      "export:requires-approval::0"
    ],
    "sharing_group_id": 0,
    "disable_correlation": false,
    "expected_count": 25,
    "event_level": 1,
    "analysis_status": "1",
    "Attribute": [
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2023-49105",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: ownCloud (ownCloud); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-27; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-27",
        "last_seen": "2026-08-27"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-53362",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Kernel (Linux); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-27; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to ",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-27",
        "last_seen": "2026-08-27"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-66384",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Artifactory (JFrog); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-27; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-27",
        "last_seen": "2026-08-27"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2021-23758",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Ajax.NET Professional (Ajax.NET Professional); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-26; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-o",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-26",
        "last_seen": "2026-08-26"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2015-3246",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Libuser (Red Hat); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-26; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-26",
        "last_seen": "2026-08-26"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2015-5287",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Automatic Bug Reporting Tool (Red Hat); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-26; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-26",
        "last_seen": "2026-08-26"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2022-0995",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Kernel (Linux); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-26; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-26",
        "last_seen": "2026-08-26"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-8452",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: NetScaler ADC and NetScaler Gateway (Citrix); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-26; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-26",
        "last_seen": "2026-08-26"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2019-1068",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: SQL Server (Microsoft); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-26; Section: CISA KEV (KNOWN EXPLOITED VULNERABILITY); Description: Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:CISA KEV (KNOWN EXPLOITED VULNERABILITY)",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-26",
        "last_seen": "2026-08-26"
      },
      {
        "category": "Artefact on host",
        "type": "cve",
        "value": "CVE-2026-60004",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Product: Gitea (Gitea); Source: CISA KEV Catalog; URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog; Date: 2026-08-25; Section: DOMAIN; Description: Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:kev",
          "tag:cisa",
          "tag:active-exploitation"
        ],
        "first_seen": "2026-08-25",
        "last_seen": "2026-08-25"
      },
      {
        "category": "Other",
        "type": "other",
        "value": "evil-tokens[.]com",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Threat intelligence analysis - EvilTokens campaign; Date: 2026-07-29; Section: DOMAIN; Description: EvilTokens PhaaS platform domain - OAuth device-code phishing targeting Microsoft 365",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:eviltokens",
          "tag:phaas",
          "tag:oauth",
          "tag:device-code",
          "tag:microsoft"
        ],
        "first_seen": "2026-07-29",
        "last_seen": "2026-07-29"
      },
      {
        "category": "Other",
        "type": "other",
        "value": "oauth-steal[.]net",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Threat intelligence analysis - EvilTokens campaign; Date: 2026-07-29; Section: DOMAIN; Description: EvilTokens OAuth credential harvesting infrastructure",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:eviltokens",
          "tag:oauth",
          "tag:credential-harvesting"
        ],
        "first_seen": "2026-07-29",
        "last_seen": "2026-07-29"
      },
      {
        "category": "Other",
        "type": "other",
        "value": "mfa-phish[.]org",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Threat intelligence analysis - EvilTokens campaign; Date: 2026-07-29; Section: DOMAIN; Description: EvilTokens MFA interception proxy",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:eviltokens",
          "tag:mfa",
          "tag:proxy"
        ],
        "first_seen": "2026-07-29",
        "last_seen": "2026-07-29"
      },
      {
        "category": "Other",
        "type": "other",
        "value": "token-harvest[.]io",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Threat intelligence analysis - EvilTokens campaign; Date: 2026-07-29; Section: DOMAIN; Description: EvilTokens token capture infrastructure",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:eviltokens",
          "tag:token-stealing"
        ],
        "first_seen": "2026-07-29",
        "last_seen": "2026-07-29"
      },
      {
        "category": "Other",
        "type": "other",
        "value": "azure-phish[.]cc",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Threat intelligence analysis - EvilTokens campaign; Date: 2026-07-29; Section: DOMAIN; Description: EvilTokens Azure AD phishing subdomain",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:eviltokens",
          "tag:azure",
          "tag:m365"
        ],
        "first_seen": "2026-07-29",
        "last_seen": "2026-07-29"
      },
      {
        "category": "Other",
        "type": "other",
        "value": "incron-c2[.]onion[.]to",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: CISA/FBI joint advisory; URL: https://www.cisa.gov; Date: 2026-07-15; Section: DOMAIN; Description: INCRON ransomware C2 infrastructure",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:DOMAIN",
          "tag:incron",
          "tag:ransomware",
          "tag:c2",
          "tag:darkweb"
        ],
        "first_seen": "2026-07-15",
        "last_seen": "2026-07-15"
      },
      {
        "category": "Other",
        "type": "other",
        "value": "blackcat-leak[.]ru",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Threat intelligence analysis; Date: 2026-07-20; Section: DOMAIN; Description: BlackCat/ALPHV ransomware leak site",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:DOMAIN",
          "tag:blackcat",
          "tag:alphv",
          "tag:ransomware",
          "tag:leak"
        ],
        "first_seen": "2026-07-20",
        "last_seen": "2026-07-20"
      },
      {
        "category": "Other",
        "type": "other",
        "value": "login-auth[.]online",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Phishing intelligence; Date: 2026-07-25; Section: EMAIL ADDRESS; Description: Known phishing domain - Microsoft/M365 impersonation",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:EMAIL ADDRESS",
          "tag:phishing",
          "tag:microsoft",
          "tag:m365"
        ],
        "first_seen": "2026-07-25",
        "last_seen": "2026-07-25"
      },
      {
        "category": "Email address",
        "type": "email",
        "value": "noreply@office365-verify[.]com",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Email security analysis; Date: 2026-07-28; Section: EMAIL ADDRESS; Description: Phishing email sender - Microsoft 365 credential harvesting",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:EMAIL ADDRESS",
          "tag:phishing",
          "tag:m365",
          "tag:credential-harvesting"
        ],
        "first_seen": "2026-07-28",
        "last_seen": "2026-07-28"
      },
      {
        "category": "Email address",
        "type": "email",
        "value": "support@docusign-review[.]net",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Email security analysis; Date: 2026-07-30; Section: FILE HASH (SHA256); Description: Phishing email sender - DocuSign impersonation (EvilTokens campaign)",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:FILE HASH (SHA256)",
          "tag:phishing",
          "tag:docusign",
          "tag:eviltokens"
        ],
        "first_seen": "2026-07-30",
        "last_seen": "2026-07-30"
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "3a7b8c0e1234567890abcdef1234567890abcdef1234567890abcdef12345678",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Malware analysis - VirusTotal/HybridAnalysis; URL: https://www.virustotal.com; Date: 2026-07-29; Section: FILE HASH (SHA256); Description: EvilTokens OAuth phishing tool sample",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:FILE HASH (SHA256)",
          "tag:malware",
          "tag:eviltokens",
          "tag:oauth"
        ],
        "first_seen": "2026-07-29",
        "last_seen": "2026-07-29"
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Malware analysis - VirusTotal; URL: https://www.virustotal.com; Date: 2026-07-30; Section: FILE HASH (SHA256); Description: Fake Adobe/Zoom installer - installs ScreenConnect remote access tool",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:FILE HASH (SHA256)",
          "tag:trojan",
          "tag:screenconnect",
          "tag:fake-installer"
        ],
        "first_seen": "2026-07-30",
        "last_seen": "2026-07-30"
      },
      {
        "category": "Other",
        "type": "sha256",
        "value": "f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2d3c4b5a6f1e2",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: Malware analysis - incident response; Date: 2026-07-20; Section: IP ADDRESS; Description: INCRON ransomware payload sample",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:IP ADDRESS",
          "tag:incron",
          "tag:ransomware",
          "tag:encryptor"
        ],
        "first_seen": "2026-07-20",
        "last_seen": "2026-07-20"
      },
      {
        "category": "Other",
        "type": "other",
        "value": "185[.]220[.]101[.]xx",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: HIGH; Source: Network traffic analysis - CISA/FBI threat intel; Date: 2026-07-25; Section: IP ADDRESS; Description: Malware C2 infrastructure - data exfiltration campaigns",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:HIGH",
          "section:IP ADDRESS",
          "tag:malware",
          "tag:c2",
          "tag:exfiltration"
        ],
        "first_seen": "2026-07-25",
        "last_seen": "2026-07-25"
      },
      {
        "category": "Other",
        "type": "other",
        "value": "45[.]153[.]240[.]xx",
        "to_ids": true,
        "disable_correlation": false,
        "comment": "Severity: CRITICAL; Source: CISA alert analysis; Date: 2026-07-28; Section: IP ADDRESS; Description: Phishing infrastructure - OAuth credential harvesting",
        "distribution": 0,
        "sharing_group_id": 0,
        "Tag": [
          "severity:CRITICAL",
          "section:IP ADDRESS",
          "tag:phishing",
          "tag:oauth",
          "tag:credential-harvesting"
        ],
        "first_seen": "2026-07-28",
        "last_seen": "2026-07-28"
      }
    ]
  }
}