markcardiff.tech:/daily-intel/2026-09-05.html
Generated: 2026-09-05 08:00:17 UTC
P1: 1
P2: 4
Items: 250

Daily Cyber Threat Intel Brief — 2026-09-05

Generated: 2026-09-05 08:00:17 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=1, P2=4, P3=26, P4=219.
  • Highest-priority item: Critical Citrix NetScaler auth bypass now leveraged in attacks (P1, source: BleepingComputer Ransomware News).
  • 5 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 Critical Citrix NetScaler auth bypass now leveraged in attacks — BleepingComputer Ransomware News; score 92; technologies: Citrix NetScaler.
  • - Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]

  • P2 RansomLook: MBT Telecom claimed by dysphor1a — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: MBT Telecom. Description excerpt: For Sale: New | Sector: Telecommunications / ISP | Country: 🇲🇲 Myanmar | Records: 209,970 user records — full dump | Myanmar Broadband…

  • P2 RansomLook: EDIF S.p.A. claimed by aurora — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: EDIF S.p.A.. Description excerpt: EDIF S.p.A. is an Italian wholesale distributor of electrical equipment, plumbing, and lighting systems. The exposed files include…

  • P2 RansomLook: Homewood Sales claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Homewood Sales. Description excerpt: Homewood Sales Corporation specializes in equipment life extension solutions, offering a wide range of products including…

  • P2 RansomLook: Norwood Law Firm claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Norwood Law Firm. Description excerpt: Norwood Law is a Tulsa-based legal firm that specializes in personal injury law, criminal defense, business law, and family law.…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-19490: Critical Citrix NetScaler auth bypass now leveraged in attacks — technologies: Citrix NetScaler.
  • Ransomware and extortion trend notes

  • P2 RansomLook: MBT Telecom claimed by dysphor1a — Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: MBT Telecom. Description excerpt: For Sale: New | Sector: Telecommunications / ISP | Country: 🇲🇲 Myanmar | Records: 209,970 user…
  • P2 RansomLook: EDIF S.p.A. claimed by aurora — Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: EDIF S.p.A.. Description excerpt: EDIF S.p.A. is an Italian wholesale distributor of electrical equipment, plumbing, and lighting…
  • P2 RansomLook: Homewood Sales claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Homewood Sales. Description excerpt: Homewood Sales Corporation specializes in equipment life extension solutions, offering a…
  • P2 RansomLook: Norwood Law Firm claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Norwood Law Firm. Description excerpt: Norwood Law is a Tulsa-based legal firm that specializes in personal injury law,…
  • P3 RansomLook: Hochschule Heilbronn Bildungscampus claimed by panzer — Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Hochschule Heilbronn Bildungscampus. Description excerpt: AStA Hochschule Heilbronn is the general students' committee that…
  • P3 RansomLook: Zdrowit claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Zdrowit. Description excerpt: karierazdrowit.pl zoominfo.com/c/zdrowit/535531700 Zdrowit S.A. is a family-owned Polish…
  • P3 RansomLook: Veradigm claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Veradigm. Description excerpt: veradigm.com zoominfo.com/c/veradigm-llc/471134180 3.5+ million personal patient records with…
  • P3 RansomLook: Wolfram Research claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: Wolfram Research.
  • P3 RansomLook: Sports Endeavors claimed by space bears — Public RansomLook extortion-site listing claim. Group: space bears. Claimed victim/listing: Sports Endeavors. Description excerpt: Sports Endeavors is a North Carolina company founded in 1984 by brothers Mike and…
  • P3 RansomLook: Sancity Soft Touch claimed by vexy — Public RansomLook extortion-site listing claim. Group: vexy. Claimed victim/listing: Sancity Soft Touch. Description excerpt: IT services company providing web design & development, software/application development,…
  • P3 RansomLook: kalahealth.eu claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: kalahealth.eu. Description excerpt: KALA Health is an international manufacturing and distribution company of nutraceutical health…
  • P3 RansomLook: huisartsencentrumkleiniterson.nl claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: huisartsencentrumkleiniterson.nl. Description excerpt: Huisartsencentrum Klein Iterson is a Healthcare Services provider operating…
  • Malware / infrastructure / abuse feed highlights

  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=exe,PureLogsStealer; url=https://gaiadeqi.com/scrapbookpocketfordraf.exe
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://49.73.53.63:3588/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://123.129.130.4:34119/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://103.190.23.91:39129/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://115.48.162.240:53193/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://119.118.45.218:54263/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://123.129.130.4:34119/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://125.41.92.37:60332/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://124.131.4.86:37963/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=176-65-139-131,elf,mirai,ua-wget; url=http://176.65.139.131/bins/chud.arm6
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=176-65-139-131,elf,mirai,ua-wget; url=http://176.65.139.131/bins/chud.ppc
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-19490`Critical Citrix NetScaler auth bypass now leveraged in attacksBleepingComputer Ransomware News
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`8ada66fb50893d32c1efcf75d4fd6bd7`RansomLook: kalahealth.eu claimed by lockbit5RansomLook Recent Listings
    hash`ad4c5e4fb3efe31d475d8a10290631e6`RansomLook: huisartsencentrumkleiniterson.nl claimed by lockbit5RansomLook Recent Listings
    hash`4652cbe1e838548b272effe6e93b8f2a`RansomLook: pscindustries.com claimed by lockbit5RansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=44
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=50 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=1 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=65 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.