ZeroHour

Indicators of compromise

325 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
ipv41.2.0.14mpacts multiple versions of the firmware - US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE UCERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
The Hacker News
· Jul 7, 2026
ipv415.03.06.46_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
The Hacker News
· Jul 7, 2026
ipv415.03.06.48N_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2.0RTL_V15.03.06.51_multi_T The backdoorCERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
The Hacker News
· Jul 7, 2026
ipv415.03.06.51TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2.0RTL_V15.03.06.51_multi_T The backdoor functionality is present within the "lCERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
The Hacker News
· Jul 7, 2026
ipv415.11.0.5mware - US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE0CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
The Hacker News
· Jul 7, 2026
ipv462.182.81.38likely backend server for the Kairos leak site resolving to 62.182.81.38, hosted on Virtual Systems LLC in Ukraine, an ASN that hasU.S. Government Agency Paid $1M to Data Extortion Group Kairos
Security Affairs
· Jul 4, 2026
ipv445.148.10.212. Six IP addresses appear in the indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
Security Affairs
· Jul 4, 2026
ipv483.142.209.11CVE-2025-55182 . Six IP addresses appear in the indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
Security Affairs
· Jul 4, 2026
ipv483.142.209.194ses appear in the indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240. The indiFBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
Security Affairs
· Jul 4, 2026
ipv483.142.209.203e indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240. The indicator set also iFBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
Security Affairs
· Jul 4, 2026
ipv494.154.172.43.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240. The indicator set also includes 27 fileFBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
Security Affairs
· Jul 4, 2026
ipv4192.0.2.1worth 35 points makes an asynchronous connection attempt to 192.0.2.1, an IP address reserved for testing that should never respoRustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow
Security Affairs
· Jul 1, 2026
ipv420.12.7.1Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (FixCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.12.7.2earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and eCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.15.4.4xed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (FixCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.15.4.5arlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (FixedCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.15.5.2ed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.Cisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.15.5.3arlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed iCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.18.3.10.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this articlCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.9.9.1lable for the following versions of Cisco Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (FixeCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv420.9.9.2s of Cisco Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and eCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv426.1.1.1d earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this article interestCisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv426.1.1.220.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this article interesting? Follow us on Google News ,Cisco Catalyst SD-WAN Manager CVE-2026
The Hacker News
· Jun 25, 2026
ipv4202.61.160.201ker-controlled management servers. One of those server IPs, 202.61.160.201, had previously appeared in infrastructure linked to ValleyWhatsApp Malware Campaign Hijacks Trust, Installs Legitimate Admin Tools
Security Affairs
· Jun 22, 2026
ipv4107.150.106.14s XLab threat detection system flagged a single IP address, 107.150.106.14, spreading a Linux binary through two vulnerabilities that4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware
Security Affairs
· Jun 22, 2026

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.