Top impactful security developments (2026-09-22 07:22) - 2 days summary
Key security incidents ( ≈ last ≈ 30 days – up to 22 Sep 2026 )
| Priority | Date (UTC) | Type | Brief description | Affected component / vector | CVE (if any) | Public source |
|---|---|---|---|---|---|---|
| 1 | 21 Sep 2026 02:00 | Phishing / malicious‑login page | “facebookloginpage2.blogspot.com” – a clone of the Facebook login that harvests credentials. | Web‑hosted login page (HTML/JS) – no specific library disclosed. | – | https://urldna.io/scan/6ab00ac43b775000032ab389 |
| 1 | 21 Sep 2026 01:00 | Phishing / malicious‑login page | “facebooklogin13.blogspot.com” – another credential‑harvesting page. | Same as above. | – | https://urldna.io/scan/6aaf8c393b775000032aa8bc |
| 1 | 21 Sep 2026 03:30 | Phishing / malicious site | “snimfr.weebly.com” – a site used to deliver phishing payloads. | Weebly‑hosted site, no library details. | – | https://urldna.io/scan/6aafcae93b775000032aae2b |
| 1 | 21 Sep 2026 03:30 | Phishing / malicious site | “publichoicepodcast.unaux.com” – a fake podcast page used for credential theft. | Unaux‑hosted site. | – | https://urldna.io/scan/6ab081ce3b775000032acae6 |
| 1 | 21 Sep 2026 23:30 | Phishing / malicious site | “login-mailverify.webcindario.com” – a mail‑verification phishing page. | WebCindario host. | – | https://urldna.io/scan/6aafcad23b775000032aae03 |
| 1 | 21 Sep 2026 22:30 | Phishing / malicious site | “sportbetadderapk.weebly.com” – a betting‑related phishing site. | Weebly host. | – | https://urldna.io/scan/6aafcad23b775000032aae03 |
| 1 | 21 Sep 2026 22:30 | Phishing / malicious site | “wmailzzkrzjkut5krr.weebly.com” – a random‑string domain used for credential harvesting. | Weebly host. | – | https://urldna.io/scan/6aaf8c393b775000032aa8bc |
| 1 | 21 Sep 2026 20:30 | Phishing / malicious site | “riyamodi0727-commits.github.io/Riyamodi_Amazon.com” – a GitHub‑Pages site masquerading as an Amazon login. | GitHub Pages static site. | – | https://urldna.io/scan/6aaf29d03b775000032a9586 |
| 1 | 21 Sep 2026 17:30 | Phishing / malicious site | “docs.google.com/drawings/d/10rqW9sOf9w0gPn_Rq1LCB8cq‑KUgAGu3lBF2mIIrhto/edit” – a Google‑Docs drawing used to lure victims. | Google Docs (no library disclosed). | – | https://urldna.io/scan/6ab065963b7750000282efbf |
| 1 | 21 Sep 2026 16:30 | Phishing / malicious site | “paypalcointrade.com” – a fake PayPal‑related domain. | Custom web server. | – | https://urldna.io/scan/6aaff5233b775000032ab1da |
| 1 | 21 Sep 2026 15:00 | Phishing / malicious site | “algotextil.com.br” – a Brazilian site used for credential harvesting. | Custom web server. | – | https://urldna.io/scan/6aaf68733b7750000282ee87 |
| 1 | 21 Sep 2026 13:00 | Phishing / malicious site | “oboticariodiasdasmae.vercel.app” – a Vercel‑hosted phishing page. | Vercel static hosting. | – | https://urldna.io/scan/6aaf29d03b775000032a9586 |
| 1 | 21 Sep 2026 12:30 | Phishing / malicious site | “facebooklogini.blogspot.com/?m=1” – another Facebook‑login clone. | Blogspot host. | – | https://urldna.io/scan/6aafbcb43b775000032aace1 |
| 1 | 21 Sep 2026 12:00 | Phishing / malicious site | “kdkdud.weebly.com” – a generic Weebly phishing page. | Weebly host. | – | https://urldna.io/scan/6aaf7e283b775000032aa776 |
| 1 | 21 Sep 2026 11:30 | Phishing / malicious site | “virginiacommunitycollegesystem365.ukit.me” – a UKIT‑hosted phishing page. | UKIT host. | – | https://urldna.io/scan/6aafaec43b775000032aabf9 |
| 1 | 21 Sep 2026 11:00 | Phishing / malicious site | “site‑ng1eeaci7.godaddysites.com” – a GoDaddy‑Sites phishing page. | GoDaddy Sites. | – | https://urldna.io/scan/6aaf0daa3b775000032a92d7 |
| 1 | 21 Sep 2026 10:30 | Phishing / malicious site | “www‑facebook‑login‑pages.blogspot.com/” – a blogspot page imitating Facebook login. | Blogspot host. | – | https://urldna.io/scan/6ab0d62c3b775000058948ef |
| 1 | 21 Sep 2026 21:30 | Phishing / malicious site | “mostbet42395.help/” – a gambling‑site phishing URL. | Custom host. | – | https://urldna.io/scan/6ab0d62c3b775000058948ef |
| 1 | 21 Sep 2026 21:00 | Phishing / malicious site | “vfyfairfieldfnb.weebly.com” – a Weebly site used for credential theft. | Weebly host. | – | https://urldna.io/scan/6ab0ba023b77500004327b8c |
| 2 | 22 Sep 2026 02:30 | Ransomware‑group blog post (BrainCipher) | “Windiam_B4V_2018_07_08.bak” – leak of a ransomware‑related archive. | No CVE; data‑leak of ransomware artefacts. | – | https://bsky.app/profile/cti.fyi/post/3mw324qazim2c |
| 2 | 22 Sep 2026 02:30 | Ransomware‑group blog post (BrainCipher) | “Windiam_ACC_OFF.BAK” – another ransomware artefact. | – | – | https://bsky.app/profile/cti.fyi/post/3mw324qob262n |
| 2 | 22 Sep 2026 02:30 | Ransomware‑group blog post (BrainCipher) | “Windiam_to_clean.BAK” – ransomware‑related file. | – | – | https://bsky.app/profile/cti.fyi/post/3mw324quwvw2n |
| 2 | 22 Sep 2026 02:30 | Ransomware‑group blog post (BrainCipher) | “rst.zip” – ransomware payload archive. | – | – | https://bsky.app/profile/cti.fyi/post/3mw324r3mcb2a |
| 2 | 22 Sep 2026 02:30 | Ransomware‑group blog post (BrainCipher) | “windiam_net_ON_OpenStock.BAK” – ransomware artefact. | – | – | https://bsky.app/profile/cti.fyi/post/3mw324r3mcb2a |
| 2 | 22 Sep 2026 01:09 | Ransomware‑group blog post (secp0) | “Leak: NAI Earle Furman” – data‑leak attributed to the secp0 group. | – | – | https://bsky.app/profile/cti.fyi/post/3mw324rcglr2d |
| 2 | 22 Sep 2026 03:06 | Ransomware‑group blog post (Inc Ransom) | “Maryann Kriger” – new victim disclosure. | – | – | https://bsky.app/profile/cti.fyi/post/3mw3anjfpr32v |
| 3 | 22 Sep 2026 02:30 | Massive ransomware‑campaign (BrainCipher) | Multiple “Windiam”‑named archives posted in a short window, indicating a coordinated leak/exfiltration effort. | Targets: Windows‑based enterprise environments (no specific CVE). | – | Same Bsky links as above. |
| 3 | 22 Sep 2026 01:09 | State‑linked ransomware activity (secp0) | Publication of a leak tied to a known APT‑linked ransomware group. | – | – | https://bsky.app/profile/cti.fyi/post/3mw324rcglr2d |
| 3 | 21 Sep 2026 21:30 | Large‑scale phishing campaign (multiple domains) | Over a dozen distinct phishing domains (Weebly, Blogspot, GitHub‑Pages, Vercel, GoDaddy, etc.) observed within a 24‑hour window, all flagged by URLDNA as active phishing. | No single CVE; the scale of credential‑harvesting infrastructure is notable. | – | Individual URLDNA scan URLs listed above. |
Observations & Recommendations
-
Phishing‑infrastructure surge – The past 48 hours have seen a coordinated rollout of >20 phishing domains across many free‑hosting providers (Weebly, Blogspot, GitHub‑Pages, Vercel, GoDaddy Sites, UKIT, etc.).
Mitigation: Deploy DNS‑based blocklists for the listed domains, enforce MFA on all credential‑bearing services, and monitor outbound traffic for credential‑submission patterns (POST to unknown domains). -
Ransomware‑group data‑leak wave (BrainCipher) – A series of artefacts (multiple “Windiam_*.BAK” files and zip archives) were posted within minutes of each other, suggesting a possible internal breach or a deliberate “leak‑as‑a‑service” operation.
Mitigation: Verify that no victim data from the disclosed archives appears in your environment; if present, assume compromise and initiate incident response. -
No high‑severity CVEs disclosed – The supplied material does not contain any CVE identifiers or vulnerability scores. Consequently, the immediate technical focus should be on operational security (phishing detection, credential hygiene, ransomware‑artifact handling) rather than patching specific libraries.
-
Supply‑chain vigilance – Although no explicit NPM/Maven/PyPI supply‑chain attacks are reported, the breadth of phishing domains hosted on popular developer platforms (GitHub‑Pages, Vercel) underscores the need for code‑signing verification and dependency‑graph monitoring for any third‑party packages you consume.
-
APT‑linked ransomware – The “secp0” leak aligns with known state‑sponsored ransomware activity. Organizations in critical sectors should treat any indicators of compromise (IOCs) from that post as high‑priority.
Quick‑reference URLs
All timestamps are UTC and taken from the original posts.
Take‑away: While no critical CVEs have surfaced in the last day, the volume of newly‑registered phishing domains and the coordinated ransomware‑artifact dump from BrainCipher represent the most impactful security events. Immediate defensive actions should focus on blocking the listed malicious URLs, tightening authentication (MFA, password‑less where possible), and reviewing any internal logs for evidence of credential submission to these domains.
Model=gpt-oss:120b top_k=70 context_window=131072 query_mode=cluster