OTX-6a722ddf8b8c2da176f0ee51 |
Infrastructure of Interest: Medium Confidence C2 - 2026-08 |
high |
ioi |
1 |
10 |
|
|
|
OTX-6a722ddc939f04c5b7fe2d41 |
Infrastructure of Interest: Medium Confidence Phishing - 2026-08 |
high |
ioi |
1 |
10 |
|
|
|
OTX-6a722dd93367ad9680ad63fe |
Infrastructure of Interest: High Confidence General - 2026-08 |
high |
ioi |
1 |
10 |
|
|
|
OTX-6a722dd62b660bc553e0e610 |
Infrastructure of Interest: High Confidence Stealer - 2026-08 |
high |
ioi |
1 |
10 |
|
|
|
OTX-6a722dd4a132dc9e71bc11b2 |
Infrastructure of Interest: High Confidence C2 - 2026-08 |
high |
ioi |
1 |
9 |
|
|
|
CVE-2026-12000 |
Page and Post Restriction <= 1.4.1 - Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API |
high |
wordpress-vulnerability |
3 |
1 |
|
|
|
TF-1868466 |
Vidar: URL that is used for botnet Command&control (C&C) https://bib.sinism188.top/ |
high |
Vidar |
2 |
8 |
|
|
|
TF-1868465 |
Vidar: Domain that is used for botnet Command&control (C&C) bib.sinism188.top |
high |
Vidar |
2 |
8 |
|
|
|
URLhaus-PL-6d87df0326b71dca17d83744d5d26d7c417885c3fc3d3d134ab2062da009de0f |
URLhaus payload: (html) 6d87df0326b71dca… |
medium |
malware |
2 |
10 |
|
|
|
TF-1868464 |
Mozi: URL that delivers a malware payload http://125.41.245.63:39395/Mozi.m |
high |
Mozi |
3 |
10 |
|
|
|
TF-1868463 |
Mozi: URL that delivers a malware payload http://103.186.77.64:51823/Mozi.m |
high |
Mozi |
3 |
10 |
|
|
|
TF-1868462 |
Mozi: URL that delivers a malware payload http://103.148.128.154:35695/Mozi.m |
high |
Mozi |
3 |
10 |
|
|
|
TF-1868461 |
Mozi: URL that delivers a malware payload http://61.174.163.220:39657/Mozi.m |
high |
Mozi |
3 |
10 |
|
|
|
TF-1868460 |
Mozi: URL that delivers a malware payload http://139.135.42.179:41902/Mozi.m |
high |
Mozi |
3 |
10 |
|
|
|
CVE-2026-6627 |
WPFormify <= 1.1.1 - Missing Authorization |
high |
wordpress-vulnerability |
3 |
1 |
|
|
|
MB-0e5159f1b507b56a59adc39564646aa07f83f1fced3dad6872e3752d777ea885 |
SalatStealer: Rexil.exe |
high |
SalatStealer |
1 |
10 |
|
|
|
MB-e64b70bbc632b834064b4b268405323e0a83c5d63102b49c903792cb79c5a1fa |
SalatStealer: Rexil.exe |
high |
SalatStealer |
1 |
10 |
|
|
|
TF-1868459 |
Vidar: URL that is used for botnet Command&control (C&C) https://bib.y8slot.net/ |
high |
Vidar |
2 |
10 |
|
|
|
TF-1868458 |
Vidar: Domain that is used for botnet Command&control (C&C) bib.y8slot.net |
high |
Vidar |
2 |
10 |
|
|
|
MB-1e306e8345ada5cab196a9045f9f63a33d7914408875e77655ffd57ddd4ac673 |
SalatStealer: Zapret.exe |
high |
SalatStealer |
1 |
10 |
|
|
|
URLhaus-PL-a76823df078b029905426affc21b1a0f6dd17327330e9339da6b03beb9069d82 |
URLhaus payload: (zip) a76823df078b0299… |
medium |
malware |
2 |
10 |
|
|
|
CVE-2026-13229 |
Zammad 7.0.1 - Improper authorization in ticket article attachment cloning |
high |
cve |
0 |
0 |
|
|
|
MB-a4aa0f9613695363fdebef9cee46d959bc98a97e5e7fed466157b3afb01c79a5 |
SalatStealer: Zapret.exe |
high |
SalatStealer |
1 |
10 |
|
|
|
CVE-2026-6972 |
SKT Skill Bar <= 2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting |
medium |
wordpress-vulnerability |
3 |
1 |
|
|
|
TF-1868457 |
Cobalt Strike: ip:port combination that is used for botnet Command&control (C&C) 116.212.123.164:443 |
high |
Cobalt Strike |
2 |
7 |
|
|
|
TF-1868456 |
VShell: ip:port combination that is used for botnet Command&control (C&C) 35.240.152.221:8080 |
high |
VShell |
2 |
8 |
|
|
|
CVE-2026-7693 |
Backup Migration <= 2.1.5.1 - Authenticated (Administrator+) OS Command Injection via 'file' Parameter |
high |
wordpress-vulnerability |
3 |
1 |
|
|
|
CVE-2026-5116 |
Contact Form 7 – Dynamic Text Extension <= 5.0.5 - Authenticated (Editor+) Stored Cross-Site Scripting |
medium |
wordpress-vulnerability |
3 |
1 |
|
|
|
CVE-2026-7726 |
Layouts for WPBakery <= 1.1.3 - Missing Authorization to Unauthenticated Template Cache Manipulation via 'handle_sync' AJAX Action |
medium |
wordpress-vulnerability |
3 |
1 |
|
|
|
TF-1868455 |
ClearFake: Domain name that delivers a malware payload nzjnxe.paquetitoexpressny.com |
high |
ClearFake |
2 |
10 |
|
|
|
CVE-2026-70474 |
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak |
high |
cve |
0 |
0 |
|
|
|
TF-1868454 |
ClearFake: Domain name that delivers a malware payload paquetitoexpressny.com |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1868453 |
VBREVSHELL: ip:port combination that is used for botnet Command&control (C&C) 61.54.27.211:8082 |
medium |
VBREVSHELL |
3 |
6 |
|
|
|
CVE-2026-47764 |
pdm: Path traversal in wheel installation via overridden write_to_fs |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70473 |
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-7444 |
Search Analytics for WP <= 1.4.16 - Cross-Site Request Forgery |
high |
wordpress-vulnerability |
3 |
1 |
|
|
|
MB-9dfbe92313bc0d309a0fb07cb6461d6c17f18b9b66842b101593373c1bf9fff7 |
Unknown: b.7z |
high |
Unknown |
1 |
10 |
|
|
|
MB-8442930244e6302279d1a2861608df3c8590aa142ef6ec6fce0bd57d1594b1de |
Unknown: file |
high |
Unknown |
1 |
9 |
|
|
|
CVE-2026-7441 |
Simple Yearly Archive <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting |
medium |
wordpress-vulnerability |
3 |
1 |
|
|
|
MB-34ba0747cd912e37af2273f6b2bbfb579a9b806713f344925a39f6da2c0847bb |
RemusStealer: QuickFetch.exe |
high |
RemusStealer |
1 |
10 |
|
|
|
MB-5892541e8901d5ea993dc7fe55726e90556e84e92f8cb10dbb10cf6d1e3d4705 |
Unknown: composer.dat |
high |
Unknown |
1 |
10 |
|
|
|
CVE-2026-5651 |
Askeet <= 3.0 - Authenticated (Administrator+) SQL Injection via 'sql_query' Parameter |
medium |
wordpress-vulnerability |
3 |
1 |
|
|
|
TF-1868452 |
ClearFake: Domain name that delivers a malware payload wifcimg.planksbiergarten.site |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1868451 |
ClearFake: Domain name that delivers a malware payload planksbiergarten.site |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1868450 |
Remus: ip:port combination that is used for botnet Command&control (C&C) 209.145.55.206:8839 |
high |
Remus |
2 |
8 |
|
|
|
CVE-2026-70472 |
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-69702 |
SnailJob 1.7.0 Denial of Service via FuryUtil.deserialize OOM |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70471 |
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-5108 |
Super Progressive Web Apps <= 2.2.43 - Authenticated (Administrator+) Stored Cross-Site Scripting via Offline Message Setting |
medium |
wordpress-vulnerability |
3 |
1 |
|
|
|
CVE-2026-18830 |
Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness API |
high |
cve |
0 |
0 |
|
|
|