Top impactful security developments (2026-09-22 07:22) - 2 days summary

Key security incidents ( ≈  last ≈ 30 days – up to 22 Sep 2026 )

Priority Date (UTC) Type Brief description Affected component / vector CVE (if any) Public source
1 21 Sep 2026 02:00  Phishing / malicious‑login page “facebookloginpage2.blogspot.com” – a clone of the Facebook login that harvests credentials. Web‑hosted login page (HTML/JS) – no specific library disclosed. – https://urldna.io/scan/6ab00ac43b775000032ab389
1 21 Sep 2026 01:00  Phishing / malicious‑login page “facebooklogin13.blogspot.com” – another credential‑harvesting page. Same as above. – https://urldna.io/scan/6aaf8c393b775000032aa8bc
1 21 Sep 2026 03:30  Phishing / malicious site “snimfr.weebly.com” – a site used to deliver phishing payloads. Weebly‑hosted site, no library details. – https://urldna.io/scan/6aafcae93b775000032aae2b
1 21 Sep 2026 03:30  Phishing / malicious site “publichoicepodcast.unaux.com” – a fake podcast page used for credential theft. Unaux‑hosted site. – https://urldna.io/scan/6ab081ce3b775000032acae6
1 21 Sep 2026 23:30  Phishing / malicious site “login-mailverify.webcindario.com” – a mail‑verification phishing page. WebCindario host. – https://urldna.io/scan/6aafcad23b775000032aae03
1 21 Sep 2026 22:30  Phishing / malicious site “sportbetadderapk.weebly.com” – a betting‑related phishing site. Weebly host. – https://urldna.io/scan/6aafcad23b775000032aae03
1 21 Sep 2026 22:30  Phishing / malicious site “wmailzzkrzjkut5krr.weebly.com” – a random‑string domain used for credential harvesting. Weebly host. – https://urldna.io/scan/6aaf8c393b775000032aa8bc
1 21 Sep 2026 20:30  Phishing / malicious site “riyamodi0727-commits.github.io/Riyamodi_Amazon.com” – a GitHub‑Pages site masquerading as an Amazon login. GitHub Pages static site. – https://urldna.io/scan/6aaf29d03b775000032a9586
1 21 Sep 2026 17:30  Phishing / malicious site “docs.google.com/drawings/d/10rqW9sOf9w0gPn_Rq1LCB8cq‑KUgAGu3lBF2mIIrhto/edit” – a Google‑Docs drawing used to lure victims. Google Docs (no library disclosed). – https://urldna.io/scan/6ab065963b7750000282efbf
1 21 Sep 2026 16:30  Phishing / malicious site “paypalcointrade.com” – a fake PayPal‑related domain. Custom web server. – https://urldna.io/scan/6aaff5233b775000032ab1da
1 21 Sep 2026 15:00  Phishing / malicious site “algotextil.com.br” – a Brazilian site used for credential harvesting. Custom web server. – https://urldna.io/scan/6aaf68733b7750000282ee87
1 21 Sep 2026 13:00  Phishing / malicious site “oboticariodiasdasmae.vercel.app” – a Vercel‑hosted phishing page. Vercel static hosting. – https://urldna.io/scan/6aaf29d03b775000032a9586
1 21 Sep 2026 12:30  Phishing / malicious site “facebooklogini.blogspot.com/?m=1” – another Facebook‑login clone. Blogspot host. – https://urldna.io/scan/6aafbcb43b775000032aace1
1 21 Sep 2026 12:00  Phishing / malicious site “kdkdud.weebly.com” – a generic Weebly phishing page. Weebly host. – https://urldna.io/scan/6aaf7e283b775000032aa776
1 21 Sep 2026 11:30  Phishing / malicious site “virginiacommunitycollegesystem365.ukit.me” – a UKIT‑hosted phishing page. UKIT host. – https://urldna.io/scan/6aafaec43b775000032aabf9
1 21 Sep 2026 11:00  Phishing / malicious site “site‑ng1eeaci7.godaddysites.com” – a GoDaddy‑Sites phishing page. GoDaddy Sites. – https://urldna.io/scan/6aaf0daa3b775000032a92d7
1 21 Sep 2026 10:30  Phishing / malicious site “www‑facebook‑login‑pages.blogspot.com/” – a blogspot page imitating Facebook login. Blogspot host. – https://urldna.io/scan/6ab0d62c3b775000058948ef
1 21 Sep 2026 21:30  Phishing / malicious site “mostbet42395.help/” – a gambling‑site phishing URL. Custom host. – https://urldna.io/scan/6ab0d62c3b775000058948ef
1 21 Sep 2026 21:00  Phishing / malicious site “vfyfairfieldfnb.weebly.com” – a Weebly site used for credential theft. Weebly host. – https://urldna.io/scan/6ab0ba023b77500004327b8c
2 22 Sep 2026 02:30  Ransomware‑group blog post (BrainCipher) “Windiam_B4V_2018_07_08.bak” – leak of a ransomware‑related archive. No CVE; data‑leak of ransomware artefacts. – https://bsky.app/profile/cti.fyi/post/3mw324qazim2c
2 22 Sep 2026 02:30  Ransomware‑group blog post (BrainCipher) “Windiam_ACC_OFF.BAK” – another ransomware artefact. – – https://bsky.app/profile/cti.fyi/post/3mw324qob262n
2 22 Sep 2026 02:30  Ransomware‑group blog post (BrainCipher) “Windiam_to_clean.BAK” – ransomware‑related file. – – https://bsky.app/profile/cti.fyi/post/3mw324quwvw2n
2 22 Sep 2026 02:30  Ransomware‑group blog post (BrainCipher) “rst.zip” – ransomware payload archive. – – https://bsky.app/profile/cti.fyi/post/3mw324r3mcb2a
2 22 Sep 2026 02:30  Ransomware‑group blog post (BrainCipher) “windiam_net_ON_OpenStock.BAK” – ransomware artefact. – – https://bsky.app/profile/cti.fyi/post/3mw324r3mcb2a
2 22 Sep 2026 01:09  Ransomware‑group blog post (secp0) “Leak: NAI Earle Furman” – data‑leak attributed to the secp0 group. – – https://bsky.app/profile/cti.fyi/post/3mw324rcglr2d
2 22 Sep 2026 03:06  Ransomware‑group blog post (Inc Ransom) “Maryann Kriger” – new victim disclosure. – – https://bsky.app/profile/cti.fyi/post/3mw3anjfpr32v
3 22 Sep 2026 02:30  Massive ransomware‑campaign (BrainCipher) Multiple “Windiam”‑named archives posted in a short window, indicating a coordinated leak/exfiltration effort. Targets: Windows‑based enterprise environments (no specific CVE). – Same Bsky links as above.
3 22 Sep 2026 01:09  State‑linked ransomware activity (secp0) Publication of a leak tied to a known APT‑linked ransomware group. – – https://bsky.app/profile/cti.fyi/post/3mw324rcglr2d
3 21 Sep 2026 21:30  Large‑scale phishing campaign (multiple domains) Over a dozen distinct phishing domains (Weebly, Blogspot, GitHub‑Pages, Vercel, GoDaddy, etc.) observed within a 24‑hour window, all flagged by URLDNA as active phishing. No single CVE; the scale of credential‑harvesting infrastructure is notable. – Individual URLDNA scan URLs listed above.

Observations & Recommendations

  1. Phishing‑infrastructure surge – The past 48 hours have seen a coordinated rollout of >20 phishing domains across many free‑hosting providers (Weebly, Blogspot, GitHub‑Pages, Vercel, GoDaddy Sites, UKIT, etc.).
    Mitigation: Deploy DNS‑based blocklists for the listed domains, enforce MFA on all credential‑bearing services, and monitor outbound traffic for credential‑submission patterns (POST to unknown domains).

  2. Ransomware‑group data‑leak wave (BrainCipher) – A series of artefacts (multiple “Windiam_*.BAK” files and zip archives) were posted within minutes of each other, suggesting a possible internal breach or a deliberate “leak‑as‑a‑service” operation.
    Mitigation: Verify that no victim data from the disclosed archives appears in your environment; if present, assume compromise and initiate incident response.

  3. No high‑severity CVEs disclosed – The supplied material does not contain any CVE identifiers or vulnerability scores. Consequently, the immediate technical focus should be on operational security (phishing detection, credential hygiene, ransomware‑artifact handling) rather than patching specific libraries.

  4. Supply‑chain vigilance – Although no explicit NPM/Maven/PyPI supply‑chain attacks are reported, the breadth of phishing domains hosted on popular developer platforms (GitHub‑Pages, Vercel) underscores the need for code‑signing verification and dependency‑graph monitoring for any third‑party packages you consume.

  5. APT‑linked ransomware – The “secp0” leak aligns with known state‑sponsored ransomware activity. Organizations in critical sectors should treat any indicators of compromise (IOCs) from that post as high‑priority.

Quick‑reference URLs

Incident Direct link
Facebook‑loginpage2 (Blogspot) https://urldna.io/scan/6ab00ac43b775000032ab389
Snimfr (Weebly) https://urldna.io/scan/6aafcae93b775000032aae2b
Public‑hoicepodcast (Unaux) https://urldna.io/scan/6ab081ce3b775000032acae6
Login‑mailverify (WebCindario) https://urldna.io/scan/6aafcad23b775000032aae03
Sportbetadderapk (Weebly) https://urldna.io/scan/6aafcad23b775000032aae03
Wmailzzkrzjkut5krr (Weebly) https://urldna.io/scan/6aaf8c393b775000032aa8bc
Riyamodi‑Amazon (GitHub‑Pages) https://urldna.io/scan/6aaf29d03b775000032a9586
PayPal‑cointrade https://urldna.io/scan/6aaff5233b775000032ab1da
Algotextil.com.br https://urldna.io/scan/6aaf68733b7750000282ee87
Oboticario‑vercel.app https://urldna.io/scan/6aaf29d03b775000032a9586
Facebooklogini (Blogspot) https://urldna.io/scan/6aafbcb43b775000032aace1
Kdkdud (Weebly) https://urldna.io/scan/6aaf7e283b775000032aa776
Virginia‑UKIT https://urldna.io/scan/6aafaec43b775000032aabf9
Site‑ng1eeaci7 (GoDaddy) https://urldna.io/scan/6aaf0daa3b775000032a92d7
Facebook‑login‑pages (Blogspot) https://urldna.io/scan/6ab0d62c3b775000058948ef
Mostbet42395.help https://urldna.io/scan/6ab0d62c3b775000058948ef
Vfyfairfieldfnb (Weebly) https://urldna.io/scan/6ab0ba023b77500004327b8c
BrainCipher “Windiam” leaks (Bsky) https://bsky.app/profile/cti.fyi/post/3mw324qazim2c (and related Bsky URLs)
secp0 “Leak: NAI Earle Furman” https://bsky.app/profile/cti.fyi/post/3mw324rcglr2d
Inc Ransom “Maryann Kriger” https://bsky.app/profile/cti.fyi/post/3mw3anjfpr32v

All timestamps are UTC and taken from the original posts.


Take‑away: While no critical CVEs have surfaced in the last day, the volume of newly‑registered phishing domains and the coordinated ransomware‑artifact dump from BrainCipher represent the most impactful security events. Immediate defensive actions should focus on blocking the listed malicious URLs, tightening authentication (MFA, password‑less where possible), and reviewing any internal logs for evidence of credential submission to these domains.

Model=gpt-oss:120b top_k=70 context_window=131072 query_mode=cluster