markcardiff.tech:/daily-intel/2026-09-01.html
Generated: 2026-09-01 08:00:55 UTC
P1: 4
P2: 1
Items: 250

Daily Cyber Threat Intel Brief — 2026-09-01

Generated: 2026-09-01 08:00:55 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=4, P2=1, P3=67, P4=178.
  • Highest-priority item: CVE-2026-26174 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability (P1, source: Microsoft Security Response Center RSS).
  • 16 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2026-26174 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability — Microsoft Security Response Center RSS; score 75; technologies: Windows Server.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-62823 Windows DHCP Server Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-62889 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-59134 Remote Desktop Client Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Acknowledgement Updated

  • P2 RansomLook: CareerSource Palm Beach County claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: CareerSource Palm Beach County. Description excerpt: www.careersourcepbc.com https://www.zoominfo.com/c/careersource-palm-beach-county/359202628 Headquartered in…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-26174: CVE-2026-26174 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability — technologies: Windows Server.
  • P1 CVE-2026-62823: CVE-2026-62823 Windows DHCP Server Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-62889: CVE-2026-62889 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-59134: CVE-2026-59134 Remote Desktop Client Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-49177: CVE-2026-49177 Windows TCP/IP Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-50344: CVE-2026-50344 Windows OLE Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-65775: CVE-2026-65775 Windows Win32k Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-65776: CVE-2026-65776 Windows Win32k Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: CareerSource Palm Beach County claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: CareerSource Palm Beach County. Description excerpt: www.careersourcepbc.com…
  • P3 Berlin confirms data theft after Rhysida ransomware attack claims — Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. [...]
  • P3 RansomLook: Commission de la construction du Quebec claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Commission de la construction du Quebec. Description excerpt: Government
  • P3 RansomLook: Rise UP claimed by everest — Public RansomLook extortion-site listing claim. Group: everest. Claimed victim/listing: Rise UP. Description excerpt: 2 posts - 1h
  • P3 RansomLook: VIVOTEK claimed by everest — Public RansomLook extortion-site listing claim. Group: everest. Claimed victim/listing: VIVOTEK. Description excerpt: 2 posts - 1h
  • P3 RansomLook: Italtel Peru claimed by everest — Public RansomLook extortion-site listing claim. Group: everest. Claimed victim/listing: Italtel Peru. Description excerpt: 2 posts - 1h
  • P3 RansomLook: iwin claimed by black x — Public RansomLook extortion-site listing claim. Group: black x. Claimed victim/listing: iwin. Description excerpt: This company is a manufacturer of car parts. We have obtained all of your company's technical data.…
  • P3 RansomLook: ahadandco.com claimed by brain cipher — Public RansomLook extortion-site listing claim. Group: brain cipher. Claimed victim/listing: ahadandco.com. Description excerpt: We have about 405,000(405k) documents and files of your company, with a total size of over…
  • P3 RansomLook: sago.com claimed by brain cipher — Public RansomLook extortion-site listing claim. Group: brain cipher. Claimed victim/listing: sago.com. Description excerpt: We have approximately 56,000 (56k) documents and files belonging to your company, including…
  • P3 RansomLook: crmeyer.com claimed by brain cipher — Public RansomLook extortion-site listing claim. Group: brain cipher. Claimed victim/listing: crmeyer.com. Description excerpt: We have about 275,000(275k) documents and files of your company, with a total size of over…
  • P3 RansomLook: ccsperfusion.com claimed by brain cipher — Public RansomLook extortion-site listing claim. Group: brain cipher. Claimed victim/listing: ccsperfusion.com. Description excerpt: We have approximately 306,000 (306k) documents and files belonging to your company,…
  • P3 RansomLook: Inmac claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Inmac. Description excerpt: Architecture, Engineering & Design
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=HijackLoader; url=http://94.26.90.118/webdav/EXEENMLP.msi
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,GuLoader; url=https://sportssurgeon.org.pk/Aksemagtens.qxd
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=.jar malware,hypixel,minecraft,trojan; url=https://taunahi.st/TaunahiLoader-26.2.jar
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=.jar malware,hypixel,minecraft,trojan; url=https://taunahi.st/TaunahiLoader-1.21.11-v4.2.5.jar
  • P3 Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) — Introduction
  • P3 Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams — Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft…
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://112.248.111.26:51657/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=rat,RemcosRAT,stego; url=https://pub-0216fa08b2b94e129cb9e002cf7cb1f4.r2.dev/img_022323.png
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=exe,rat,RemcosRAT; url=https://geoxsecurity.ro/images/xxwealthnow.exe
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=rat,RemcosRAT,stego; url=https://res.cloudinary.com/kmy8ktuk/image/upload/v1788229143/img_221847.jpg
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=AgentTesla,stego; url=https://lively-fog-af49.pablosoftwareplus.workers.dev/ZECCR
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-26174`CVE-2026-26174 Windows Server Update Service (WSUS) Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62823`CVE-2026-62823 Windows DHCP Server Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62889`CVE-2026-62889 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution VulneMicrosoft Security Response Center RSS
    cve`CVE-2026-59134`CVE-2026-59134 Remote Desktop Client Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-49177`CVE-2026-49177 Windows TCP/IP Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50344`CVE-2026-50344 Windows OLE Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-65775`CVE-2026-65775 Windows Win32k Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-65776`CVE-2026-65776 Windows Win32k Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    ipv4`94.26.90.118`URLhaus: malware_download URL observed (online)URLhaus Recent URLs
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`2a3539977521ffdbf815d0e0ecc2a2c8`RansomLook: svfcu.org claimed by lockbit5RansomLook Recent Listings
    hash`37a6fdefc028046fc8625cae8c209e88`RansomLook: hoaattorneys.com claimed by lockbit5RansomLook Recent Listings
    hash`e6fd1d10c844c81b0f735de31e0e7bef`RansomLook: bartelsbv.nl claimed by lockbit5RansomLook Recent Listings
    hash`2be334915a0191df4dc1bfe814393802`RansomLook: vkj.nl claimed by lockbit5RansomLook Recent Listings
    hash`a49c74cceb87d8fada016bf867ecc979`RansomLook: allsteelproducts.nl claimed by lockbit5RansomLook Recent Listings
    hash`4df8a2630497e57d1bffcc5b194f84b5`RansomLook: bkc.org claimed by lockbit5RansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=1 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=40
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=27 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=1 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=39 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.