Indicators of compromise
325 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| ipv4 | 1.2.0.14 | mpacts multiple versions of the firmware - US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE U | CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware The Hacker News | · Jul 7, 2026 |
| ipv4 | 15.03.06.46 | _W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2 | CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware The Hacker News | · Jul 7, 2026 |
| ipv4 | 15.03.06.48 | N_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2.0RTL_V15.03.06.51_multi_T The backdoor | CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware The Hacker News | · Jul 7, 2026 |
| ipv4 | 15.03.06.51 | TDE01 US_AC5V1.0RTL_V15.03.06.48_multi_TDE01 US_AC6V2.0RTL_V15.03.06.51_multi_T The backdoor functionality is present within the "l | CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware The Hacker News | · Jul 7, 2026 |
| ipv4 | 15.11.0.5 | mware - US_FH1201V1.0BR_V1.2.0.14(408)_EN_TD US_W15EV1.0br_V15.11.0.5(1068_1567_841)_EN_TDE US_AC10V1.0re_V15.03.06.46_multi_TDE0 | CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware The Hacker News | · Jul 7, 2026 |
| ipv4 | 62.182.81.38 | likely backend server for the Kairos leak site resolving to 62.182.81.38, hosted on Virtual Systems LLC in Ukraine, an ASN that has | U.S. Government Agency Paid $1M to Data Extortion Group Kairos Security Affairs | · Jul 4, 2026 |
| ipv4 | 45.148.10.212 | . Six IP addresses appear in the indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217. | FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials Security Affairs | · Jul 4, 2026 |
| ipv4 | 83.142.209.11 | CVE-2025-55182 . Six IP addresses appear in the indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172. | FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials Security Affairs | · Jul 4, 2026 |
| ipv4 | 83.142.209.194 | ses appear in the indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240. The indi | FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials Security Affairs | · Jul 4, 2026 |
| ipv4 | 83.142.209.203 | e indicators: 83.142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240. The indicator set also i | FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials Security Affairs | · Jul 4, 2026 |
| ipv4 | 94.154.172.43 | .142.209.11, 45.148.10.212, 83.142.209.194, 83.142.209.203, 94.154.172.43, and 67.217.57.240. The indicator set also includes 27 file | FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials Security Affairs | · Jul 4, 2026 |
| ipv4 | 192.0.2.1 | worth 35 points makes an asynchronous connection attempt to 192.0.2.1, an IP address reserved for testing that should never respo | RustDuck: The Botnet That's Still Small but Engineering Like It Plans to Grow Security Affairs | · Jul 1, 2026 |
| ipv4 | 20.12.7.1 | Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fix | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.12.7.2 | earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and e | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.15.4.4 | xed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fix | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.15.4.5 | arlier (Fixed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.15.5.2 | ed in 20.12.7.2) 20.15.4.4 and earlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3. | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.15.5.3 | arlier (Fixed in 20.15.4.5) 20.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed i | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.18.3.1 | 0.15.5.2 and earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this articl | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.9.9.1 | lable for the following versions of Cisco Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixe | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 20.9.9.2 | s of Cisco Catalyst SD-WAN - 20.9.9.1 and earlier (Fixed in 20.9.9.2) 20.12.7.1 and earlier (Fixed in 20.12.7.2) 20.15.4.4 and e | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 26.1.1.1 | d earlier (Fixed in 20.15.5.3) 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this article interest | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 26.1.1.2 | 20.18.3 (Fixed in 20.18.3.1) 26.1.1.1 and earlier (Fixed in 26.1.1.2) Found this article interesting? Follow us on Google News , | Cisco Catalyst SD-WAN Manager CVE-2026 The Hacker News | · Jun 25, 2026 |
| ipv4 | 202.61.160.201 | ker-controlled management servers. One of those server IPs, 202.61.160.201, had previously appeared in infrastructure linked to Valley | WhatsApp Malware Campaign Hijacks Trust, Installs Legitimate Admin Tools Security Affairs | · Jun 22, 2026 |
| ipv4 | 107.150.106.14 | s XLab threat detection system flagged a single IP address, 107.150.106.14, spreading a Linux binary through two vulnerabilities that | 4,300+ Outdated Routers Hijacked in Stealthy Spy Infrastructure by AryStinger malware Security Affairs | · Jun 22, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.