markcardiff.tech:/daily-intel/2026-09-03.html
Generated: 2026-09-03 08:01:32 UTC
P1: 6
P2: 1
Items: 250

Daily Cyber Threat Intel Brief — 2026-09-03

Generated: 2026-09-03 08:01:32 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=6, P2=1, P3=42, P4=201.
  • Highest-priority item: Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild (P1, source: Rapid7 Blog).
  • 14 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild — Rapid7 Blog; score 107; technologies: SonicWall.
  • - Overview On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549 , can be chained to achieve…

  • P1 SonicWall warns of actively exploited SMA1000 zero-day flaws — BleepingComputer Ransomware News; score 79; technologies: SonicWall.
  • - SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]

  • P1 Hackers exploit Sangoma Switchvox flaw to deploy reverse shells — BleepingComputer Ransomware News; score 74; technologies: none explicitly matched.
  • - Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]

  • P1 Hackers exploit critical JFrog Artifactory flaw to forge admin tokens — BleepingComputer Ransomware News; score 74; technologies: none explicitly matched.
  • - A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]

  • P1 CVE-2026-69320 Visual Studio Code Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Affected software updated with new package information.

  • P1 CVE-2026-70336 Visual Studio Code Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Affected software updated with new package information.

  • P2 Sality botnet infrastructure dismantled in joint global takedown — BleepingComputer Ransomware News; score 57; technologies: none explicitly matched.
  • - International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. [...]

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-83548, CVE-2026-83549: Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild — technologies: SonicWall.
  • P1 CVE-2026-9586: Hackers exploit Sangoma Switchvox flaw to deploy reverse shells — technologies: not watchlist-specific.
  • P1 CVE-2026-82329: Hackers exploit critical JFrog Artifactory flaw to forge admin tokens — technologies: not watchlist-specific.
  • P1 CVE-2026-69320: CVE-2026-69320 Visual Studio Code Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-70336: CVE-2026-70336 Visual Studio Code Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69278: CVE-2026-69278 Visual Studio Code Security Feature Bypass Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69306: CVE-2026-69306 Visual Studio Code Security Feature Bypass Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62768: CVE-2026-62768 Windows Installer Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62880: CVE-2026-62880 Windows NTFS Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-50376: CVE-2026-50376 Windows Remote Desktop Client Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P3 Ransomware protection for MSPs: A 6-point checklist for faster recovery — Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving…
  • P3 RansomLook: Greenberg Traurig claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Greenberg Traurig. Description excerpt: To be announced...
  • P3 RansomLook: Tanner claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Tanner. Description excerpt: Finance
  • P3 RansomLook: G... ...g claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: G... ...g. Description excerpt: To be announced...
  • P3 RansomLook: S... M... claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: S... M.... Description excerpt: To be announced...
  • P3 RansomLook: Cartrack Holdings claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: Cartrack Holdings.
  • P3 RansomLook: Ormond Beach Florida claimed by wallstreet — Public RansomLook extortion-site listing claim. Group: wallstreet. Claimed victim/listing: Ormond Beach Florida. Description excerpt: Ormond Beach, Florida, is a scenic coastal city just north of Daytona Beach, known…
  • P3 RansomLook: PTT Oil and Retail Business claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: PTT Oil and Retail Business.
  • P3 RansomLook: N************* claimed by insomnia — Public RansomLook extortion-site listing claim. Group: insomnia. Claimed victim/listing: N*************. Description excerpt: Medical center with 9 locations offers coordinated care for patients and families,…
  • P3 RansomLook: Asfaltos y Pavimentos S.A. (Asfalpasa) claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: Asfaltos y Pavimentos S.A. (Asfalpasa).
  • P3 RansomLook: Westfield Public School District claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: Westfield Public School District.
  • P3 RansomLook: Trucka claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: Trucka.
  • Malware / infrastructure / abuse feed highlights

  • P2 Sality botnet infrastructure dismantled in joint global takedown — International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. [...]
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=trojan; url=https://aetherone.su/downloads/meta-loader.exe
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=trojan; url=https://kjjt.pages.dev/download/001365-Screenshot-Uploader-portable.exe
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=script; url=http://176.65.139.206/loader.sh
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ClickFix,FakeCaptcha,FakeCloudflare,Loader,powershell,zip; url=https://benotrobot.online/get_verify?i=5696&a=test&b=False
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://182.127.31.85:47759/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://61.53.151.142:41245/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags= rat,IRAHook,stealer; url=https://www.dropbox.com/scl/fi/ba93r9ez5c00fap694aa6/bundle.zip?rlkey=mpxhfmkb4g2adcermiywlc115&st=8p4van4p&dl=1
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://87.15.14.109:59208/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=exe,rat,RemcosRAT; url=https://vintageeventos.com.mx/CHAPO/CHAPO2.exe
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=rat,RemcosRAT; url=https://pub-f36b05599c3043ddb16520acf6cc3cce.r2.dev/core_131541.iso
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-83548`Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in theRapid7 Blog
    cve`CVE-2026-83549`Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in theRapid7 Blog
    cve`CVE-2026-9586`Hackers exploit Sangoma Switchvox flaw to deploy reverse shellsBleepingComputer Ransomware News
    cve`CVE-2026-82329`Hackers exploit critical JFrog Artifactory flaw to forge admin tokensBleepingComputer Ransomware News
    cve`CVE-2026-69320`CVE-2026-69320 Visual Studio Code Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-70336`CVE-2026-70336 Visual Studio Code Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69278`CVE-2026-69278 Visual Studio Code Security Feature Bypass VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69306`CVE-2026-69306 Visual Studio Code Security Feature Bypass VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62768`CVE-2026-62768 Windows Installer Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62880`CVE-2026-62880 Windows NTFS Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50376`CVE-2026-50376 Windows Remote Desktop Client Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    ipv4`176.65.139.206`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`a54827e084a5e2b1a855d24b2c79b809621be1d5`RansomLook: (EVIDENCE)REXT Holdings Co., Ltd. claimed by ransomhouseRansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=47
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=28 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=42 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.