markcardiff.tech:/daily-intel/2026-08-29.html
Generated: 2026-08-29 08:02:41 UTC
P1: 6
P2: 2
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-29

Generated: 2026-08-29 08:02:41 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=6, P2=2, P3=67, P4=175.
  • Highest-priority item: PaperCut NG/MF Critical Zero-Day Exploited in the Wild (P1, source: Rapid7 Blog).
  • 30 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 PaperCut NG/MF Critical Zero-Day Exploited in the Wild — Rapid7 Blog; score 77; technologies: none explicitly matched.
  • - Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the…

  • P1 CVE-2026-58616 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.

  • P1 CVE-2026-66323 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-66798 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-70341 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

  • P1 CVE-2026-72984 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • P2 RansomLook: cutlercapital claimed by lynx — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: lynx. Claimed victim/listing: cutlercapital. Description excerpt: Cutler Capital Management, LLC of Worcester, MA is an investment advisory firm r...

  • P2 PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE — Huntress Blog; score 52; technologies: none explicitly matched.
  • - PaperCut NG and PaperCut MF are under active exploitation. Huntress reproduced a pre-auth RCE chain and shares urgent patching and exposure guidance.

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-81578, CVE-2026-82078: PaperCut NG/MF Critical Zero-Day Exploited in the Wild — technologies: not watchlist-specific.
  • P1 CVE-2026-58616: CVE-2026-58616 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-66323: CVE-2026-66323 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-66798: CVE-2026-66798 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-70341: CVE-2026-70341 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-72984: CVE-2026-72984 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-70331: CVE-2026-70331 Microsoft Edge for iOS Spoofing Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62904: CVE-2026-62904 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-66324: CVE-2026-66324 Microsoft Edge (Chromium-based) Spoofing Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-78891: Chromium: CVE-2026-78891 Buffer overflow in WebRTC — technologies: not watchlist-specific.
  • P3 CVE-2026-78892: Chromium: CVE-2026-78892 Incorrect authorization in Chromoting — technologies: not watchlist-specific.
  • P3 CVE-2026-78893: Chromium: CVE-2026-78893 Information leak in QUIC — technologies: not watchlist-specific.
  • P3 CVE-2026-78894: Chromium: CVE-2026-78894 Race condition in Payments — technologies: not watchlist-specific.
  • P3 CVE-2026-78895: Chromium: CVE-2026-78895 Information leak in Paint — technologies: not watchlist-specific.
  • P3 CVE-2026-78896: Chromium: CVE-2026-78896 Information leak in StorageAccessAPI — technologies: not watchlist-specific.
  • P3 CVE-2026-78897: Chromium: CVE-2026-78897 Missing authorization in BrowserTag — technologies: not watchlist-specific.
  • P3 CVE-2026-78898: Chromium: CVE-2026-78898 Incorrect authorization in Downloads — technologies: not watchlist-specific.
  • P3 CVE-2026-78899: Chromium: CVE-2026-78899 Use after free in V8 — technologies: not watchlist-specific.
  • P3 CVE-2026-78900: Chromium: CVE-2026-78900 Improper input validation in Media — technologies: not watchlist-specific.
  • P3 CVE-2026-78901: Chromium: CVE-2026-78901 Race condition in V8 — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: cutlercapital claimed by lynx — Public RansomLook extortion-site listing claim. Group: lynx. Claimed victim/listing: cutlercapital. Description excerpt: Cutler Capital Management, LLC of Worcester, MA is an investment advisory firm r...
  • P3 RansomLook: Oilquip Inc claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: Oilquip Inc.
  • P3 RansomLook: McKesson Corporation claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: McKesson Corporation. Description excerpt: Hundreds of millions of records/rows of data was compromised containing very…
  • P3 RansomLook: wmdn.net claimed by 3am — Public RansomLook extortion-site listing claim. Group: 3am. Claimed victim/listing: wmdn.net. Description excerpt: Twin States News is a media organization that provides comprehensive coverage of local, state, national,…
  • P3 RansomLook: Elekta AB claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Elekta AB. Description excerpt: This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying…
  • P3 RansomLook: Jack Henry & Associates claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Jack Henry & Associates. Description excerpt: This is a final warning to reach out by 1 Sep 2026 before we leak along with…
  • P3 RansomLook: SITTNAK Lojistik A.Ş. claimed by doommageddon — Public RansomLook extortion-site listing claim. Group: doommageddon. Claimed victim/listing: SITTNAK Lojistik A.Ş.. Description excerpt: upcoming | — | 0 files
  • P3 RansomLook: Akpera Gayrimenkul Yatırım A.Ş. claimed by doommageddon — Public RansomLook extortion-site listing claim. Group: doommageddon. Claimed victim/listing: Akpera Gayrimenkul Yatırım A.Ş.. Description excerpt: upcoming | — | 0 files
  • P3 RansomLook: apatpa.com claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: apatpa.com. Description excerpt: American Plan Administrators offers smart self-funded healthcare solutions designed to maximize…
  • P3 RansomLook: Alter Consultores Legales claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Alter Consultores Legales. Description excerpt: Law Firms & Legal Services
  • P3 RansomLook: H.W. Lochner claimed by payoutsking — Public RansomLook extortion-site listing claim. Group: payoutsking. Claimed victim/listing: H.W. Lochner.
  • P3 RansomLook: corematerials.com claimed by chaos — Public RansomLook extortion-site listing claim. Group: chaos. Claimed victim/listing: corematerials.com. Description excerpt: Core Materials (corematerials.com) — Countdown to Publication Management at Core Materials…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=185-100-157-222,sh,ua-wget; url=http://185.100.157.222/loader.sh
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=GuLoader; url=https://drive.google.com/uc?export=download&id=1pxZ86u3QanfKU3WPmIdLZ9Bf6lWvnKjB
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=GuLoader; url=https://drive.google.com/uc?export=download&id=1ZszPErDOLdtd_HeJ9T7C_dWrXFapTZsk
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=encrypted,GuLoader; url=https://packmate.in/LtUHpIfVXKoIfkhmgiAO172.bin
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,rev-base64-loader; url=https://raw.githubusercontent.com/vito674/tthh/refs/heads/main/FnaAffg.txt
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,rev-base64-loader; url=https://raw.githubusercontent.com/Orukemer/bestweek/refs/heads/main/mnonfAk.txt
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,rev-base64-loader; url=https://raw.githubusercontent.com/Orukemer/Biniebiere/refs/heads/main/mffIhbI.txt
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,rev-base64-loader; url=https://raw.githubusercontent.com/vito674/uu/refs/heads/main/mFjamon.txt
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,rev-base64-loader; url=https://raw.githubusercontent.com/vito674/gg/refs/heads/main/nihmihA.txt
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=AgentTesla,rev-base64-loader; url=https://raw.githubusercontent.com/vito674/coco/refs/heads/main/hienoId.txt
  • P3 Some Malicious PE Stats, (Thu, Aug 27th) — During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS.…
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-81578`PaperCut NG/MF Critical Zero-Day Exploited in the WildRapid7 Blog
    cve`CVE-2026-82078`PaperCut NG/MF Critical Zero-Day Exploited in the WildRapid7 Blog
    cve`CVE-2026-58616`CVE-2026-58616 Copilot Chat (Microsoft Edge) Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-66323`CVE-2026-66323 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-66798`CVE-2026-66798 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-70341`CVE-2026-70341 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-72984`CVE-2026-72984 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-70331`CVE-2026-70331 Microsoft Edge for iOS Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62904`CVE-2026-62904 Microsoft Edge (Chromium-based) Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-66324`CVE-2026-66324 Microsoft Edge (Chromium-based) Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-78891`Chromium: CVE-2026-78891 Buffer overflow in WebRTCMicrosoft Security Response Center RSS
    cve`CVE-2026-78892`Chromium: CVE-2026-78892 Incorrect authorization in ChromotingMicrosoft Security Response Center RSS
    cve`CVE-2026-78893`Chromium: CVE-2026-78893 Information leak in QUICMicrosoft Security Response Center RSS
    cve`CVE-2026-78894`Chromium: CVE-2026-78894 Race condition in PaymentsMicrosoft Security Response Center RSS
    cve`CVE-2026-78895`Chromium: CVE-2026-78895 Information leak in PaintMicrosoft Security Response Center RSS
    cve`CVE-2026-78896`Chromium: CVE-2026-78896 Information leak in StorageAccessAPIMicrosoft Security Response Center RSS
    cve`CVE-2026-78897`Chromium: CVE-2026-78897 Missing authorization in BrowserTagMicrosoft Security Response Center RSS
    cve`CVE-2026-78898`Chromium: CVE-2026-78898 Incorrect authorization in DownloadsMicrosoft Security Response Center RSS
    cve`CVE-2026-78899`Chromium: CVE-2026-78899 Use after free in V8Microsoft Security Response Center RSS
    cve`CVE-2026-78900`Chromium: CVE-2026-78900 Improper input validation in MediaMicrosoft Security Response Center RSS
    cve`CVE-2026-78901`Chromium: CVE-2026-78901 Race condition in V8Microsoft Security Response Center RSS
    cve`CVE-2026-78903`Chromium: CVE-2026-78903 Incomplete cleanup in SiteIsolationMicrosoft Security Response Center RSS
    cve`CVE-2026-78904`Chromium: CVE-2026-78904 Type confusion in ANGLEMicrosoft Security Response Center RSS
    cve`CVE-2026-78905`Chromium: CVE-2026-78905 Type confusion in ANGLEMicrosoft Security Response Center RSS
    cve`CVE-2026-78906`Chromium: CVE-2026-78906 Race condition in ANGLEMicrosoft Security Response Center RSS
    cve`CVE-2026-78907`Chromium: CVE-2026-78907 Incorrect authorization in WebProtectMicrosoft Security Response Center RSS
    cve`CVE-2026-78908`Chromium: CVE-2026-78908 Information leak in CanvasMicrosoft Security Response Center RSS
    ipv4`185.100.157.222`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`1f9182de04597cb54beb4537be5582aa`RansomLook: apatpa.com claimed by lockbit5RansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=43
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: error: fetch failed for https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt: The read operation timed out
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=73 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=1 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=59 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.