markcardiff.tech:/daily-intel/2026-08-28.html
Generated: 2026-08-28 08:00:57 UTC
P1: 5
P2: 2
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-28

Generated: 2026-08-28 08:00:57 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=5, P2=2, P3=43, P4=200.
  • Highest-priority item: CVE-2026-65660 Microsoft SharePoint Server Remote Code Execution Vulnerability (P1, source: Microsoft Security Response Center RSS).
  • 14 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2026-65660 Microsoft SharePoint Server Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 100; technologies: SharePoint.
  • - Updated Impact in the Security Updates table, CVE Title, and FAQs. This is an informational change only.

  • P1 CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday — BleepingComputer Ransomware News; score 79; technologies: Citrix NetScaler.
  • - CISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. [...]

  • P1 CVE-2026-68817 Microsoft Excel Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-42993 Remote Desktop Client Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-70329 Microsoft Outlook Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Acknowledgement Updated

  • P2 ATF confirms “major incident” after recent Qilin breach claims — BleepingComputer Ransomware News; score 57; technologies: none explicitly matched.
  • - ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang. [...]

  • P2 RansomLook: SCA Logistik & Fulfillment GmbH claimed by aurora — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: SCA Logistik & Fulfillment GmbH. Description excerpt: SCA is a Bavarian logistics and e-commerce fulfillment provider. The exposed materials includes: Spans customer orders…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-65660: CVE-2026-65660 Microsoft SharePoint Server Remote Code Execution Vulnerability — technologies: SharePoint.
  • P1 CVE-2026-68817: CVE-2026-68817 Microsoft Excel Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-42993: CVE-2026-42993 Remote Desktop Client Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-70329: CVE-2026-70329 Microsoft Outlook Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-50435: CVE-2026-50435 Windows Overlay Filter Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-50351: CVE-2026-50351 Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69550: CVE-2026-69550 Windows App for Mac Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-65779: CVE-2026-65779 Windows Autopilot Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-60004: URLhaus: malware_download URL observed (online) — technologies: not watchlist-specific.
  • P3 CVE-2026-60004: URLhaus: malware_download URL observed (offline) — technologies: not watchlist-specific.
  • P3 CVE-2026-60004: URLhaus: malware_download URL observed (online) — technologies: not watchlist-specific.
  • P3 CVE-2026-60004: URLhaus: malware_download URL observed (offline) — technologies: not watchlist-specific.
  • P3 CVE-2026-60004: URLhaus: malware_download URL observed (online) — technologies: not watchlist-specific.
  • P3 CVE-2026-60004: URLhaus: malware_download URL observed (offline) — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 ATF confirms “major incident” after recent Qilin breach claims — ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang.…
  • P2 RansomLook: SCA Logistik & Fulfillment GmbH claimed by aurora — Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: SCA Logistik & Fulfillment GmbH. Description excerpt: SCA is a Bavarian logistics and e-commerce fulfillment provider. The exposed…
  • P3 RansomLook: Caduceus Medical Group claimed by anubis — Public RansomLook extortion-site listing claim. Group: anubis. Claimed victim/listing: Caduceus Medical Group. Description excerpt: Predictable but dangerous data exposed in a healthcare company breach.
  • P3 RansomLook: Ne...n M... claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Ne...n M.... Description excerpt: To be announced...
  • P3 RansomLook: ETNA Software claimed by eclipse — Public RansomLook extortion-site listing claim. Group: eclipse. Claimed victim/listing: ETNA Software. Description excerpt: ETNA Software is a company that provides white-label online trading solutions for brokers and…
  • P3 RansomLook: singleton.com claimed by chaos — Public RansomLook extortion-site listing claim. Group: chaos. Claimed victim/listing: singleton.com. Description excerpt: Founded in 1986, Singleton Reynolds is a law firm. They are headquartered in Vancouver, British…
  • P3 RansomLook: tnmed.org claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: tnmed.org. Description excerpt: The Tennessee Medical Association is a nonprofit organization that advocates for physicians in…
  • P3 RansomLook: Kling Automaten claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Kling Automaten. Description excerpt: Gambling & Gaming
  • P3 RansomLook: Dotlines claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Dotlines. Description excerpt: Software
  • P3 RansomLook: Globalport Terminals claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Globalport Terminals. Description excerpt: Business Services
  • P3 RansomLook: BENCIVIL claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: BENCIVIL.
  • P3 RansomLook: fpmanagement.nl claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: fpmanagement.nl. Description excerpt: FP Management BV is a licensed trust office based in Rotterdam, Netherlands, offering a…
  • Malware / infrastructure / abuse feed highlights

  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 Some Malicious PE Stats, (Thu, Aug 27th) — During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS.…
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ClickFix; url=https://telemetryloop.net/get_verify?i=76513
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ClickFix; url=https://soft-update.dev/get_verify?i=76875
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ClickFix,ua-ps; url=https://faceit-cdn.org/install.ps1
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=android,apk ; url=https://killurself1337-cdn.doxbin.mom/cdn/odyssey_com_wizardcdn_videopart_a1fe06a10ee6210d.mp4
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://125.41.8.103:46677/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=3,dropped-by-Stealc,RemusStealer; url=http://cryptovectorhub1.lol/crypt/load/QW1.exe
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=elf,iot,Mozi; url=http://123.188.72.146:45830/Mozi.m
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=https://goxlrutility.net/goxlr-software.zip
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=https://goxlr.io/goxlr-software.zip
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ClearFake; url=https://jsma.s3.us-west-2.amazonaws.com/1bJ8TKI/ma.js
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-65660`CVE-2026-65660 Microsoft SharePoint Server Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-68817`CVE-2026-68817 Microsoft Excel Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-42993`CVE-2026-42993 Remote Desktop Client Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-70329`CVE-2026-70329 Microsoft Outlook Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50435`CVE-2026-50435 Windows Overlay Filter Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50351`CVE-2026-50351 Windows Audio Compression Manager (ACM) Elevation of Privilege VulnerabilitMicrosoft Security Response Center RSS
    cve`CVE-2026-69550`CVE-2026-69550 Windows App for Mac Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-65779`CVE-2026-65779 Windows Autopilot Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-60004`URLhaus: malware_download URL observed (online)URLhaus Recent URLs
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`67d1d1b0ab5605493101ea2db133a20a`RansomLook: tnmed.org claimed by lockbit5RansomLook Recent Listings
    hash`e9bafa99d8c40a8434e3f8d8e9ef4090`RansomLook: fpmanagement.nl claimed by lockbit5RansomLook Recent Listings
    hash`089532051352ddbc3b27c893e0740350`RansomLook: takt.be claimed by lockbit5RansomLook Recent Listings
    hash`d2716fc1a7663145decd5bf3cba4b71a`RansomLook: dece.cz claimed by lockbit5RansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=47
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=24 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=1 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=22 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.