markcardiff.tech:/daily-intel/2026-08-26.html
Generated: 2026-08-26 08:00:43 UTC
P1: 2
P2: 0
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-26

Generated: 2026-08-26 08:00:43 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=2, P2=0, P3=37, P4=211.
  • Highest-priority item: CVE-2026-55137 Microsoft Excel Remote Code Execution Vulnerability (P1, source: Microsoft Security Response Center RSS).
  • 7 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2026-55137 Microsoft Excel Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-50448 Windows NTFS Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-55137: CVE-2026-55137 Microsoft Excel Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-50448: CVE-2026-50448 Windows NTFS Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-61939: CVE-2026-61939 Winlogon Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-59131: CVE-2026-59131 AMD Zen Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-45639: CVE-2026-45639 Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P3 RansomLook: FBC claimed by deadlock — Public RansomLook extortion-site listing claim. Group: deadlock. Claimed victim/listing: FBC. Description excerpt: Furniture Bargaining Council in South Africa. This is the tariff council for the furniture, mattress and…
  • P3 RansomLook: Integrex RCM claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Integrex RCM. Description excerpt: Healthcare Services
  • P3 RansomLook: Air International Thermal Systems claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Air International Thermal Systems. Description excerpt: Automotive Parts
  • P3 RansomLook: Global Terminal Services claimed by deadlock — Public RansomLook extortion-site listing claim. Group: deadlock. Claimed victim/listing: Global Terminal Services. Description excerpt: GTS legally registered as Global Terminal Hizmetleri A.Ş. It is the largest…
  • P3 RansomLook: AUDIT ENTITY: ma*up claimed by audit team — Public RansomLook extortion-site listing claim. Group: audit team. Claimed victim/listing: AUDIT ENTITY: ma*up. Description excerpt: AUDIT ID: DA68891EA2CD44B6 / DISCOVERY DATE: 2026-08-26
  • P3 RansomLook: industry.airliquide.kr claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: industry.airliquide.kr. Description excerpt: Air Liquide has operated in South Korea for several decades and supplies essential…
  • P3 RansomLook: Brazosport College claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Brazosport College. Description excerpt: Education
  • P3 RansomLook: parkderochie.com claimed by chaos — Public RansomLook extortion-site listing claim. Group: chaos. Claimed victim/listing: parkderochie.com. Description excerpt: Park de Rochie (parkderochie.com) – Countdown to Publication Management at Park de Rochie has…
  • P3 RansomLook: mswalker.com claimed by chaos — Public RansomLook extortion-site listing claim. Group: chaos. Claimed victim/listing: mswalker.com. Description excerpt: MS Walker (mswalker.com) – Countdown to Publication Management at MS Walker has chosen to…
  • P3 RansomLook: copcp.com claimed by chaos — Public RansomLook extortion-site listing claim. Group: chaos. Claimed victim/listing: copcp.com. Description excerpt: Central Ohio Primary Care (copcp.com) – Countdown to Publication Management at Central Ohio Primary…
  • P3 RansomLook: Johnson City Honda claimed by global secret group — Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: Johnson City Honda. Description excerpt: Country: Tennessee, United States | Website: johnsoncityhonda.com | Revenue:…
  • P3 RansomLook: Lockheed Architectural Solutions, Inc. claimed by global secret group — Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: Lockheed Architectural Solutions, Inc.. Description excerpt: Country: Pascoag, RI 02859, United States | Website:…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnet,ddos,elf,iot,KHserver,mirai; url=http://213.232.114.14/X86_64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnet,ddos,elf,iot,KHserver,mirai; url=http://213.232.114.14/ARMV4L
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=binzosg,downloader,Sketchfab-ripper,stealer; url=https://fujiarte.com/.well-known/acme-challenge/settings.php
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=HijackLoader; url=https://zcalton.com/UTODYIBG.msi
  • P3 The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution — Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand…
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,Mozi; url=http://130.12.209.153:51945/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://193.104.58.65/rump25th.png
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://182.116.50.75:54311/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=exe; url=https://github.com/harveyjuansara/upd2352vhjh/raw/refs/heads/main/uninstall.exe
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=exe; url=https://github.com/harveyjuansara/upd2352vhjh/raw/refs/heads/main/minecraftpatch.exe
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=exe; url=https://github.com/harveyjuansara/upd2352vhjh/raw/refs/heads/main/GitHub.exe
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-55137`CVE-2026-55137 Microsoft Excel Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50448`CVE-2026-50448 Windows NTFS Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-61939`CVE-2026-61939 Winlogon Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-59131`CVE-2026-59131 AMD Zen Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-45639`CVE-2026-45639 Windows Remote Desktop Protocol (RDP) Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    ipv4`213.232.114.14`URLhaus: malware_download URL observed (online)URLhaus Recent URLs
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=39
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=10 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=3 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=94 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.