markcardiff.tech:/daily-intel/2026-09-04.html
Generated: 2026-09-04 08:00:45 UTC
P1: 5
P2: 1
Items: 250

Daily Cyber Threat Intel Brief — 2026-09-04

Generated: 2026-09-04 08:00:45 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=5, P2=1, P3=101, P4=143.
  • Highest-priority item: Critical Elementor Pro flaw exploited to take over WordPress sites (P1, source: BleepingComputer Ransomware News).
  • 30 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 Critical Elementor Pro flaw exploited to take over WordPress sites — BleepingComputer Ransomware News; score 104; technologies: WordPress.
  • - A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]

  • P1 RansomLook: NeoGen Corporation claimed by shinyhunters — RansomLook Recent Listings; score 83; technologies: SharePoint.
  • - Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: NeoGen Corporation. Description excerpt: Over 5 million Salesforce records compromised containing some PII and 541GB+ of Sharepoint internal corporate data was…

  • P1 Chromium: CVE-2026-84326 Uninitialized resource in V8 — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

  • P1 CVE-2026-62815 Microsoft QUIC Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-70352 Azure AI Language Elevation of Privilege Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

  • P2 RansomLook: Schwartz, Giannini, Lantsberger & Adamson (SGLA) claimed by space bears — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: space bears. Claimed victim/listing: Schwartz, Giannini, Lantsberger & Adamson (SGLA). Description excerpt: Schwartz, Giannini, Lantsberger & Adamson (SGLA) Accountancy Corporation is a full-service…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-32475: Critical Elementor Pro flaw exploited to take over WordPress sites — technologies: WordPress.
  • P1 CVE-2026-84326: Chromium: CVE-2026-84326 Uninitialized resource in V8 — technologies: not watchlist-specific.
  • P1 CVE-2026-62815: CVE-2026-62815 Microsoft QUIC Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-70352: CVE-2026-70352 Azure AI Language Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-84358: Chromium: CVE-2026-84358 Improper privilege management in Downloads — technologies: not watchlist-specific.
  • P3 CVE-2026-84355: Chromium: CVE-2026-84355 Incorrect authorization in Navigation — technologies: not watchlist-specific.
  • P3 CVE-2026-84354: Chromium: CVE-2026-84354 Incorrect authorization in FileSystem — technologies: not watchlist-specific.
  • P3 CVE-2026-84353: Chromium: CVE-2026-84353 Use after free in Shared Tab Groups — technologies: not watchlist-specific.
  • P3 CVE-2026-84351: Chromium: CVE-2026-84351 Buffer overflow in GPU — technologies: not watchlist-specific.
  • P3 CVE-2026-84350: Chromium: CVE-2026-84350 Use after free in TabStrip — technologies: not watchlist-specific.
  • P3 CVE-2026-84349: Chromium: CVE-2026-84349 Use after free in Browser — technologies: not watchlist-specific.
  • P3 CVE-2026-84348: Chromium: CVE-2026-84348 Information leak in MediaCapture — technologies: not watchlist-specific.
  • P3 CVE-2026-84347: Chromium: CVE-2026-84347 Use after free in WebRTC — technologies: not watchlist-specific.
  • P3 CVE-2026-84335: Chromium: CVE-2026-84335 Incorrect authorization in TabStrip — technologies: not watchlist-specific.
  • P3 CVE-2026-84334: Chromium: CVE-2026-84334 Incorrect authorization in Chromoting — technologies: not watchlist-specific.
  • P3 CVE-2026-84332: Chromium: CVE-2026-84332 Incorrect authorization in SiteSettings — technologies: not watchlist-specific.
  • P3 CVE-2026-84331: Chromium: CVE-2026-84331 Incorrect authorization in Actor — technologies: not watchlist-specific.
  • P3 CVE-2026-84329: Chromium: CVE-2026-84329 Confused deputy in CredentialProvider — technologies: not watchlist-specific.
  • P3 CVE-2026-84328: Chromium: CVE-2026-84328 Missing authorization in FileSystem — technologies: not watchlist-specific.
  • P3 CVE-2026-84327: Chromium: CVE-2026-84327 Incorrect authorization in Autofill — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P1 RansomLook: NeoGen Corporation claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: NeoGen Corporation. Description excerpt: Over 5 million Salesforce records compromised containing some PII and 541GB+ of…
  • P2 RansomLook: Schwartz, Giannini, Lantsberger & Adamson (SGLA) claimed by space bears — Public RansomLook extortion-site listing claim. Group: space bears. Claimed victim/listing: Schwartz, Giannini, Lantsberger & Adamson (SGLA). Description excerpt: Schwartz, Giannini, Lantsberger & Adamson (SGLA)…
  • P3 RansomLook: AUDIT ENTITY: mansurovogroup claimed by audit team — Public RansomLook extortion-site listing claim. Group: audit team. Claimed victim/listing: AUDIT ENTITY: mansurovogroup. Description excerpt: AUDIT ID: DA68891EA2CD44B6 / DISCOVERY DATE: 2026-08-26
  • P3 RansomLook: AUDIT ENTITY: PIT.local claimed by audit team — Public RansomLook extortion-site listing claim. Group: audit team. Claimed victim/listing: AUDIT ENTITY: PIT.local. Description excerpt: AUDIT ID: 3382542458FC4332 / DISCOVERY DATE: 2026-08-27
  • P3 RansomLook: Studio Oculistico Ciraci claimed by space bears — Public RansomLook extortion-site listing claim. Group: space bears. Claimed victim/listing: Studio Oculistico Ciraci. Description excerpt: Studio Oculistico Ciraci - ophthalmology clinic based in Bari, Italy, that…
  • P3 RansomLook: P... S... claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: P... S.... Description excerpt: To be announced...
  • P3 RansomLook: A...en claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: A...en. Description excerpt: To be announced...
  • P3 RansomLook: myglobal.com claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: myglobal.com.
  • P3 RansomLook: Se... claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Se.... Description excerpt: To be announced...
  • P3 RansomLook: Katten Muchin Rosenman claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Katten Muchin Rosenman. Description excerpt: To be announced...
  • P3 RansomLook: America’s Food Basket claimed by wallstreet — Public RansomLook extortion-site listing claim. Group: wallstreet. Claimed victim/listing: America’s Food Basket. Description excerpt: America’s Food Basket is a U.S. cooperative grocery-store network. Its site,…
  • P3 RansomLook: Maglin, Miskiv & Associates claimed by insomnia — Public RansomLook extortion-site listing claim. Group: insomnia. Claimed victim/listing: Maglin, Miskiv & Associates. Description excerpt: Maglin Miskiv & Associates in Parsippany, NJ offers personalized accounting, tax…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=c2,macOS,stealer; url=https://counterscale.jean-r-mi-larcelet-prost.workers.dev/
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=apk ,mamont; url=https://nonspamplsgood.vercel.app/?download=1
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai; url=http://b2b.jewmailer.net/arm7
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai; url=http://b2b.jewmailer.net/android-arm64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai; url=http://b2b.jewmailer.net/reflect/or1k
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai; url=http://b2b.jewmailer.net/working.Services.apk
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai; url=http://b2b.jewmailer.net/hiddenbin/reflect.x86_64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai; url=http://b2b.jewmailer.net/persist.arm7
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai; url=http://b2b.jewmailer.net/hiddenbin/reflect.sh4
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai; url=http://b2b.jewmailer.net/hiddenbin/reflect.arm
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai; url=http://b2b.jewmailer.net/reflect/android-arm
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-32475`Critical Elementor Pro flaw exploited to take over WordPress sitesBleepingComputer Ransomware News
    cve`CVE-2026-84326`Chromium: CVE-2026-84326 Uninitialized resource in V8Microsoft Security Response Center RSS
    cve`CVE-2026-62815`CVE-2026-62815 Microsoft QUIC Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-70352`CVE-2026-70352 Azure AI Language Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-84358`Chromium: CVE-2026-84358 Improper privilege management in DownloadsMicrosoft Security Response Center RSS
    cve`CVE-2026-84355`Chromium: CVE-2026-84355 Incorrect authorization in NavigationMicrosoft Security Response Center RSS
    cve`CVE-2026-84354`Chromium: CVE-2026-84354 Incorrect authorization in FileSystemMicrosoft Security Response Center RSS
    cve`CVE-2026-84353`Chromium: CVE-2026-84353 Use after free in Shared Tab GroupsMicrosoft Security Response Center RSS
    cve`CVE-2026-84351`Chromium: CVE-2026-84351 Buffer overflow in GPUMicrosoft Security Response Center RSS
    cve`CVE-2026-84350`Chromium: CVE-2026-84350 Use after free in TabStripMicrosoft Security Response Center RSS
    cve`CVE-2026-84349`Chromium: CVE-2026-84349 Use after free in BrowserMicrosoft Security Response Center RSS
    cve`CVE-2026-84348`Chromium: CVE-2026-84348 Information leak in MediaCaptureMicrosoft Security Response Center RSS
    cve`CVE-2026-84347`Chromium: CVE-2026-84347 Use after free in WebRTCMicrosoft Security Response Center RSS
    cve`CVE-2026-84335`Chromium: CVE-2026-84335 Incorrect authorization in TabStripMicrosoft Security Response Center RSS
    cve`CVE-2026-84334`Chromium: CVE-2026-84334 Incorrect authorization in ChromotingMicrosoft Security Response Center RSS
    cve`CVE-2026-84332`Chromium: CVE-2026-84332 Incorrect authorization in SiteSettingsMicrosoft Security Response Center RSS
    cve`CVE-2026-84331`Chromium: CVE-2026-84331 Incorrect authorization in ActorMicrosoft Security Response Center RSS
    cve`CVE-2026-84329`Chromium: CVE-2026-84329 Confused deputy in CredentialProviderMicrosoft Security Response Center RSS
    cve`CVE-2026-84328`Chromium: CVE-2026-84328 Missing authorization in FileSystemMicrosoft Security Response Center RSS
    cve`CVE-2026-84327`Chromium: CVE-2026-84327 Incorrect authorization in AutofillMicrosoft Security Response Center RSS
    cve`CVE-2026-84325`Chromium: CVE-2026-84325 Improper input validation in DataTransferMicrosoft Security Response Center RSS
    cve`CVE-2026-84324`Chromium: CVE-2026-84324 Use after free in ProxyMicrosoft Security Response Center RSS
    cve`CVE-2026-84323`Chromium: CVE-2026-84323 Missing authorization in FileSystemMicrosoft Security Response Center RSS
    cve`CVE-2026-58641`CVE-2026-58641 .NET Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62906`CVE-2026-62906 Microsoft Discovery Studio Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-70178`CVE-2026-70178 Microsoft Fabric Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-80098`CVE-2026-80098 Copilot Studio Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-83711`CVE-2026-83711 Microsoft Azure Active Directory B2C Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    ipv4`176.65.139.206`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=47
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=39 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=97 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.