Daily Cyber Threat Intel Brief — 2026-09-01
Generated: 2026-09-01 08:00:55 UTC
Executive summary
Priority technology watch items
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.
- Acknowledgement Updated
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: CareerSource Palm Beach County. Description excerpt: www.careersourcepbc.com https://www.zoominfo.com/c/careersource-palm-beach-county/359202628 Headquartered in…
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-26174` | CVE-2026-26174 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62823` | CVE-2026-62823 Windows DHCP Server Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62889` | CVE-2026-62889 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulne | Microsoft Security Response Center RSS |
| cve | `CVE-2026-59134` | CVE-2026-59134 Remote Desktop Client Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-49177` | CVE-2026-49177 Windows TCP/IP Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50344` | CVE-2026-50344 Windows OLE Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-65775` | CVE-2026-65775 Windows Win32k Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-65776` | CVE-2026-65776 Windows Win32k Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| ipv4 | `94.26.90.118` | URLhaus: malware_download URL observed (online) | URLhaus Recent URLs |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| hash | `2a3539977521ffdbf815d0e0ecc2a2c8` | RansomLook: svfcu.org claimed by lockbit5 | RansomLook Recent Listings |
| hash | `37a6fdefc028046fc8625cae8c209e88` | RansomLook: hoaattorneys.com claimed by lockbit5 | RansomLook Recent Listings |
| hash | `e6fd1d10c844c81b0f735de31e0e7bef` | RansomLook: bartelsbv.nl claimed by lockbit5 | RansomLook Recent Listings |
| hash | `2be334915a0191df4dc1bfe814393802` | RansomLook: vkj.nl claimed by lockbit5 | RansomLook Recent Listings |
| hash | `a49c74cceb87d8fada016bf867ecc979` | RansomLook: allsteelproducts.nl claimed by lockbit5 | RansomLook Recent Listings |
| hash | `4df8a2630497e57d1bffcc5b194f84b5` | RansomLook: bkc.org claimed by lockbit5 | RansomLook Recent Listings |