markcardiff.tech:/daily-intel/2026-08-27.html
Generated: 2026-08-27 08:00:17 UTC
P1: 2
P2: 2
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-27

Generated: 2026-08-27 08:00:17 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=2, P2=2, P3=56, P4=190.
  • Highest-priority item: Critical Avada WordPress theme flaw enables zero-click RCE (P1, source: BleepingComputer Ransomware News).
  • 18 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 Critical Avada WordPress theme flaw enables zero-click RCE — BleepingComputer Ransomware News; score 79; technologies: WordPress.
  • - A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. [...]

  • P1 Hackers target Microsoft SharePoint RCE chain with PoC exploit — BleepingComputer Ransomware News; score 79; technologies: SharePoint.
  • - Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. [...]

  • P2 RansomLook: KenEp Resources claimed by qilin — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: KenEp Resources. Description excerpt: Architecture, Engineering & Design

  • P2 RansomLook: ERPIS LLC claimed by aurora — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: ERPIS LLC. Description excerpt: ERPIS LLC (doing business as ShipERP) — a Texas-based SAP integrator whose single product is enterprise shipping management software used by…

    Newly exploited vulnerabilities / CVE watch

  • P3 CVE-2026-62890: CVE-2026-62890 Windows GDI+ Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-68819: CVE-2026-68819 Windows Network File System Denial of Service Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: KenEp Resources claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: KenEp Resources. Description excerpt: Architecture, Engineering & Design
  • P2 RansomLook: ERPIS LLC claimed by aurora — Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: ERPIS LLC. Description excerpt: ERPIS LLC (doing business as ShipERP) — a Texas-based SAP integrator whose single product is…
  • P3 RansomLook: JP Molyneux Studio claimed by deadlock — Public RansomLook extortion-site listing claim. Group: deadlock. Claimed victim/listing: JP Molyneux Studio. Description excerpt: JP Molyneux Studio Ltd showcases the exclusive work of internationally renowned interior…
  • P3 RansomLook: NEXT LEVEL MEDICAL, LLC claimed by pear — Public RansomLook extortion-site listing claim. Group: pear. Claimed victim/listing: NEXT LEVEL MEDICAL, LLC. Description excerpt: Affordable urgent care across Texas
  • P3 RansomLook: Q... E... claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Q... E.... Description excerpt: To be announced...
  • P3 RansomLook: N... M... claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: N... M.... Description excerpt: To be announced...
  • P3 RansomLook: S... P... claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: S... P.... Description excerpt: To be announced...
  • P3 RansomLook: K... M... claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: K... M.... Description excerpt: To be announced...
  • P3 RansomLook: H... K... claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: H... K.... Description excerpt: To be announced...
  • P3 RansomLook: H... L... claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: H... L.... Description excerpt: To be announced...
  • P3 RansomLook: C... O... claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: C... O.... Description excerpt: To be announced...
  • P3 RansomLook: A... claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: A.... Description excerpt: To be announced...
  • Malware / infrastructure / abuse feed highlights

  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=https://www.nishiwaki.ne.jp/uploader/uploader.cgi?mode=downld&no=864
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnet,ddos,elf,iot,KHserver,mirai; url=http://213.232.114.14/X86_64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnet,ddos,elf,iot,KHserver,mirai; url=http://213.232.114.14/ARMV4L
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=binzosg,downloader,Sketchfab-ripper,stealer; url=https://fujiarte.com/.well-known/acme-challenge/settings.php
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ClickFix; url=https://metricgw.com/get_verify?i=33
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://42.6.36.45:59697/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://182.113.206.65:60794/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ClickFix,exe; url=https://trf.kookapp.pro/guard.exe
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ClickFix,exe; url=https://trf.kookapp.pro/GameBarPresenceWriters.exe
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ClickFix,exe; url=https://trf.kookapp.pro/MicrosoftEdgeUpdateCore.exe
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ClickFix,exe; url=https://google-meet-verification.icu/rt.exe
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-62890`CVE-2026-62890 Windows GDI+ Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-68819`CVE-2026-68819 Windows Network File System Denial of Service VulnerabilityMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    ipv4`213.232.114.14`URLhaus: malware_download URL observed (online)URLhaus Recent URLs
    hash`b07710eb7e7b56e40014af0a398c606b`RansomLook: theheartcenterofmemphis.com claimed by lockbit5RansomLook Recent Listings
    hash`f9b703dd490fb677614bd2dd48715289ae7f8811e239d5c97a8caab9b4dd7396`RansomLook: sysconth.com claimed by krybitRansomLook Recent Listings
    hash`79296199a4f112d4be2996b7f1f7288fa0a02db21fd752c9ccc203e7c6bd4162`RansomLook: jindallifescience.com claimed by krybitRansomLook Recent Listings
    hash`635ce28baae8183bfa21b23d8ae8c2706d6b628c0273373b801ec70eb871a2b3`RansomLook: mimafoods.net claimed by krybitRansomLook Recent Listings
    hash`3455587bd83dc1208ce17d662972ee350216ecdf624c956e6c96050fee82a060`RansomLook: vascara.com claimed by krybitRansomLook Recent Listings
    hash`4b72823357eb26a73b059f6030eb9aeffe8ab73756f1e4ea50e2581ace156f49`RansomLook: www.neooftalmo.com.br claimed by krybitRansomLook Recent Listings
    hash`636b3338cfa6d08872c31304c45c383971e7705648e43cc2e004c6ccfcc92d18`RansomLook: lemonfarm.com claimed by krybitRansomLook Recent Listings
    hash`73eda7275091c9d7610892dec8a950cc2d802ecfdcea60159ccd3626670d9cca`RansomLook: finodayacapital.com claimed by krybitRansomLook Recent Listings
    hash`e02fe92fe096338b17d746358727c7f8c6cb98b87dd501fc748ffca29ab58884`RansomLook: wmiemporium.com claimed by krybitRansomLook Recent Listings
    hash`c7a8e54a51c1cf81faa31c09f0afab6fe8f10012619a6eb51ee41d92139166a7`RansomLook: cgcgabon.com claimed by krybitRansomLook Recent Listings
    hash`39d9ff3077a7e81c796802af473ee7c13e6d3bf1a34349b9a13471f4b47fc9db`RansomLook: karkinos.in claimed by krybitRansomLook Recent Listings
    hash`002fee6e466f576a6d48f9b578365c2dd33f65b3bb35d16316b298900dd8b26b`RansomLook: ferretornillos.gt claimed by krybitRansomLook Recent Listings
    hash`39b0ed79c320a1362ad3236ddb94ab546b9a18ed7576cc54e4308dd2402cf6e2`RansomLook: www.sankovn.com claimed by krybitRansomLook Recent Listings
    hash`7081c859ec6ec62bc369252d901ee655`RansomLook: Espinos claimed by the gentlemenRansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=45
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=22 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=1 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=64 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.