markcardiff.tech:/daily-intel/2026-09-02.html
Generated: 2026-09-02 08:00:46 UTC
P1: 2
P2: 2
Items: 250

Daily Cyber Threat Intel Brief — 2026-09-02

Generated: 2026-09-02 08:00:46 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=2, P2=2, P3=134, P4=112.
  • Highest-priority item: SonicWall warns of actively exploited SMA1000 zero-day flaws (P1, source: BleepingComputer Ransomware News).
  • 18 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 SonicWall warns of actively exploited SMA1000 zero-day flaws — BleepingComputer Ransomware News; score 79; technologies: SonicWall.
  • - SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]

  • P1 Critical Langflow flaw exploited to steal OpenAI and AWS keys — BleepingComputer Ransomware News; score 74; technologies: none explicitly matched.
  • - Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...]

  • P2 RansomLook: Quality Resource Pvt claimed by global secret group — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: Quality Resource Pvt. Description excerpt: Country: United States | Website: qualityresourcepvt.com | Revenue: $19 Million | Industry: Advertising Networks |…

  • P2 RansomLook: rubbermill.com claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: rubbermill.com. Description excerpt: ═════════════════ ═════════════════ ═════════════════ RUBBERMILL, INC. DUMP: BREAKDOWN OF AN OEM MANUFACTURER LEAK…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-0768: Critical Langflow flaw exploited to steal OpenAI and AWS keys — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Quality Resource Pvt claimed by global secret group — Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: Quality Resource Pvt. Description excerpt: Country: United States | Website: qualityresourcepvt.com | Revenue: $19…
  • P2 RansomLook: rubbermill.com claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: rubbermill.com. Description excerpt: ═════════════════ ═════════════════ ═════════════════ RUBBERMILL, INC. DUMP: BREAKDOWN OF…
  • P3 RansomLook: Chip 1 Exchange claimed by aurora — Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: Chip 1 Exchange. Description excerpt: Chip 1 Exchange — a global independent electronics distributor headquartered in Neu-Isenburg,…
  • P3 RansomLook: Grayson Rural Electric Cooperative claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Grayson Rural Electric Cooperative. Description excerpt: Electricity, Oil & Gas
  • P3 RansomLook: Marlborough Partners claimed by anubis — Public RansomLook extortion-site listing claim. Group: anubis. Claimed victim/listing: Marlborough Partners. Description excerpt: Major data breach at a capital solutions advisory firm.
  • P3 RansomLook: Proliance Surgeons claimed by payoutsking — Public RansomLook extortion-site listing claim. Group: payoutsking. Claimed victim/listing: Proliance Surgeons.
  • P3 RansomLook: Holland & Knight claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Holland & Knight. Description excerpt: Holland & Knight, headquartered in Tampa, Florida, and established in 1968, is a law firm…
  • P3 RansomLook: SHAHEEN LAW GROUP PLC - Richmond, Virginia, USA claimed by deadlock — Public RansomLook extortion-site listing claim. Group: deadlock. Claimed victim/listing: SHAHEEN LAW GROUP PLC - Richmond, Virginia, USA. Description excerpt: Family law firm , established 1995 by Victor A. Shaheen…
  • P3 RansomLook: Szechenyi Programiroda Nonprofit Kf claimed by rhysida — Public RansomLook extortion-site listing claim. Group: rhysida. Claimed victim/listing: Szechenyi Programiroda Nonprofit Kf. Description excerpt: Szechenyi Programiroda Nonprofit Kf As a key player in Hungarian…
  • P3 RansomLook: H... ...s claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: H... ...s. Description excerpt: To be announced...
  • P3 RansomLook: Honeycomb Programs Inc claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: Honeycomb Programs Inc.
  • P3 RansomLook: PT Intraco Penta Tbk claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: PT Intraco Penta Tbk.
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ClickFix,FakeCaptcha,FakeCloudflare,Loader,powershell,zip; url=https://benotrobot.online/get_verify?i=5696&a=test&b=False
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,ua-wget,www-93-152-221-234-plesk-page; url=http://www.93-152-221-234.plesk.page/arm64
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,sh,ua-wget,www-93-152-221-234-plesk-page; url=http://www.93-152-221-234.plesk.page/run.sh
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,DDoSAgent,elf,ua-wget,www-93-152-221-234-plesk-page; url=http://www.93-152-221-234.plesk.page/x86
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,DDoSAgent,elf,ua-wget,www-93-152-221-234-plesk-page; url=http://www.93-152-221-234.plesk.page/mips
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,DDoSAgent,elf,ua-wget,www-93-152-221-234-plesk-page; url=http://www.93-152-221-234.plesk.page/mips64le
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,ua-wget,www-93-152-221-234-plesk-page; url=http://www.93-152-221-234.plesk.page/aarch64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,DDoSAgent,elf,ua-wget,www-93-152-221-234-plesk-page; url=http://www.93-152-221-234.plesk.page/ppc64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,ua-wget,www-93-152-221-234-plesk-page; url=http://www.93-152-221-234.plesk.page/armv6l
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,DDoSAgent,elf,ua-wget,www-93-152-221-234-plesk-page; url=http://www.93-152-221-234.plesk.page/i686
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,ua-wget,www-93-152-221-234-plesk-page; url=http://www.93-152-221-234.plesk.page/aarch64
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-0768`Critical Langflow flaw exploited to steal OpenAI and AWS keysBleepingComputer Ransomware News
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    ipv4`94.26.90.118`URLhaus: malware_download URL observed (online)URLhaus Recent URLs
    hash`0a9134b3273d30891b3c95edea912dde64428957`RansomLook: REXT Holdings Co., Ltd. claimed by ransomhouseRansomLook Recent Listings
    hash`1f6acc99bc4cf24c193c37f93cdb7646832889985bab111d38d1dd5fdbe1a6ea`RansomLook: seashellhospital.com claimed by krybitRansomLook Recent Listings
    hash`e9a122ddcb62e924dca32e8ae95772f75bfd368a5aeb38ca883764cbbacf1df3`RansomLook: uicc.org claimed by krybitRansomLook Recent Listings
    hash`ef6c76b6b5b16d083e8d389d65a557f0508753cdf9d6c9587a50f8e6141ffd45`RansomLook: tum.com.mx claimed by krybitRansomLook Recent Listings
    hash`4cbd84e6fad4c509ca2e838b55850baa2999b06d47e17b62c62de5e7c5108f11`RansomLook: www.alphaplantes.com claimed by krybitRansomLook Recent Listings
    hash`a4b7783f228e95d687242d90c562f3c82007667ab2c25634bc4dcc7a97dd6b7f`RansomLook: reignwoodpark.com claimed by krybitRansomLook Recent Listings
    hash`0cc1b08a430375b81d49f1e0bc6faa8f0f963165831ba630bb530e6f4913437b`RansomLook: orex.co.th claimed by krybitRansomLook Recent Listings
    hash`1e58b691ac4e24572b7d184beddefa3fc67addeb830714852e3c5d87c5a54b4f`RansomLook: amptc.net claimed by krybitRansomLook Recent Listings
    hash`f6d3a75e05df78f42ef573ea36c91f4ae27682d98a1f4b152b836772912be9cd`RansomLook: dmt-group.com claimed by krybitRansomLook Recent Listings
    hash`eef2674fa5fbd480f4e5d9e74b67388f89ebd936cb7b47cd9ac6449a0545c0de`RansomLook: jswlaw.bt claimed by krybitRansomLook Recent Listings
    hash`a6192b6dd1341e11255961b0434a7f6b3ecbe1ca982dc4d8cb8035c2bbc8978e`RansomLook: vedantaainstitute.in claimed by krybitRansomLook Recent Listings
    hash`1801921261dfee2323d1805c368ef40de7f9ea55a9c81b786eb119fdaceff14e`RansomLook: meccahighfeed.blogspot.com claimed by krybitRansomLook Recent Listings
    hash`6a9b514ef9eeea3ab76331ed34f0b796b5026d954b82857cac761f071d677438`RansomLook: transportesmontejo.com claimed by krybitRansomLook Recent Listings
    hash`345b9d9a8ff8d46121bcb22a787654becef59c35fa7f13e5489693a22437268d`RansomLook: southsign.in claimed by krybitRansomLook Recent Listings
    hash`e6c5461f72626d0dd12186aa932006643c9a45b9cc7c4c024ccb73ad550c7b98`RansomLook: hccd-construction.com claimed by krybitRansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=1 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=40
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=12 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=3 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=65 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.