Daily Cyber Threat Intel Brief — 2026-08-28
Generated: 2026-08-28 08:00:57 UTC
Executive summary
Priority technology watch items
- Updated Impact in the Security Updates table, CVE Title, and FAQs. This is an informational change only.
- CISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. [...]
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.
- Acknowledgement Updated
- ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang. [...]
- Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: SCA Logistik & Fulfillment GmbH. Description excerpt: SCA is a Bavarian logistics and e-commerce fulfillment provider. The exposed materials includes: Spans customer orders…
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-65660` | CVE-2026-65660 Microsoft SharePoint Server Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-68817` | CVE-2026-68817 Microsoft Excel Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-42993` | CVE-2026-42993 Remote Desktop Client Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-70329` | CVE-2026-70329 Microsoft Outlook Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50435` | CVE-2026-50435 Windows Overlay Filter Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50351` | CVE-2026-50351 Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerabilit | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69550` | CVE-2026-69550 Windows App for Mac Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-65779` | CVE-2026-65779 Windows Autopilot Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-60004` | URLhaus: malware_download URL observed (online) | URLhaus Recent URLs |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| hash | `67d1d1b0ab5605493101ea2db133a20a` | RansomLook: tnmed.org claimed by lockbit5 | RansomLook Recent Listings |
| hash | `e9bafa99d8c40a8434e3f8d8e9ef4090` | RansomLook: fpmanagement.nl claimed by lockbit5 | RansomLook Recent Listings |
| hash | `089532051352ddbc3b27c893e0740350` | RansomLook: takt.be claimed by lockbit5 | RansomLook Recent Listings |
| hash | `d2716fc1a7663145decd5bf3cba4b71a` | RansomLook: dece.cz claimed by lockbit5 | RansomLook Recent Listings |