CVE
CVE-2026-15614
IdP-initiated SAML sessions not reliably invalidated (replay)
Exploitation IoCs 8
Domain claudefix-panel[.]org
Domain clickfix-lure[.]com
Domain kali365-host[.]cf
Filename MacSyncStealer.dmg
Filename PhantomStealer.js
SHA-256 a3f1b2c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2
SHA-256 b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5
IP 13[.]229[.]10[.]100
MITRE ATT&CK TTPs 17
T1003.001 T1027 T1055 T1059.001 T1059.003 T1070.004 T1071 T1071.001 T1071.003 T1071.004 T1082 T1190 T1203 T1204.002 T1485 T1496 T1566
LSASS Memory
Credential Access
Obfuscated Files or Information
Defense Evasion
Process Injection
Defense Evasion
PowerShell
Execution
Windows Command Shell
Execution
File Deletion
Defense Evasion
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
Mail Protocols
Command And Control
DNS
Command And Control
System Information Discovery
Discovery
Exploit Public-Facing Application
Initial Access
Exploitation for Client Execution
Execution
Malicious File
Execution
Data Destruction
Impact
Resource Hijacking
Impact
Phishing
Initial Access