Daily Cyber Threat Intel Brief — 2026-09-05
Generated: 2026-09-05 08:00:17 UTC
Executive summary
Collected 250 recent public-source CTI items for technology-only monitoring.
Priority distribution: P1=1, P2=4, P3=26, P4=219.
Highest-priority item: Critical Citrix NetScaler auth bypass now leveraged in attacks (P1, source: BleepingComputer Ransomware News).
5 public IOC highlights selected for analyst awareness.
Priority technology watch items
P1 Critical Citrix NetScaler auth bypass now leveraged in attacks — BleepingComputer Ransomware News; score 92; technologies: Citrix NetScaler.
- Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]
P2 RansomLook: MBT Telecom claimed by dysphor1a — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: MBT Telecom. Description excerpt: For Sale: New | Sector: Telecommunications / ISP | Country: 🇲🇲 Myanmar | Records: 209,970 user records — full dump | Myanmar Broadband…
P2 RansomLook: EDIF S.p.A. claimed by aurora — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: EDIF S.p.A.. Description excerpt: EDIF S.p.A. is an Italian wholesale distributor of electrical equipment, plumbing, and lighting systems. The exposed files include…
P2 RansomLook: Homewood Sales claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Homewood Sales. Description excerpt: Homewood Sales Corporation specializes in equipment life extension solutions, offering a wide range of products including…
P2 RansomLook: Norwood Law Firm claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Norwood Law Firm. Description excerpt: Norwood Law is a Tulsa-based legal firm that specializes in personal injury law, criminal defense, business law, and family law.…
Newly exploited vulnerabilities / CVE watch
P1 CVE-2026-19490: Critical Citrix NetScaler auth bypass now leveraged in attacks — technologies: Citrix NetScaler.
Ransomware and extortion trend notes
P2 RansomLook: MBT Telecom claimed by dysphor1a — Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: MBT Telecom. Description excerpt: For Sale: New | Sector: Telecommunications / ISP | Country: 🇲🇲 Myanmar | Records: 209,970 user…
P2 RansomLook: EDIF S.p.A. claimed by aurora — Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: EDIF S.p.A.. Description excerpt: EDIF S.p.A. is an Italian wholesale distributor of electrical equipment, plumbing, and lighting…
P2 RansomLook: Homewood Sales claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Homewood Sales. Description excerpt: Homewood Sales Corporation specializes in equipment life extension solutions, offering a…
P2 RansomLook: Norwood Law Firm claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Norwood Law Firm. Description excerpt: Norwood Law is a Tulsa-based legal firm that specializes in personal injury law,…
P3 RansomLook: Hochschule Heilbronn Bildungscampus claimed by panzer — Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Hochschule Heilbronn Bildungscampus. Description excerpt: AStA Hochschule Heilbronn is the general students' committee that…
P3 RansomLook: Zdrowit claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Zdrowit. Description excerpt: karierazdrowit.pl zoominfo.com/c/zdrowit/535531700 Zdrowit S.A. is a family-owned Polish…
P3 RansomLook: Veradigm claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Veradigm. Description excerpt: veradigm.com zoominfo.com/c/veradigm-llc/471134180 3.5+ million personal patient records with…
P3 RansomLook: Wolfram Research claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: Wolfram Research.
P3 RansomLook: Sports Endeavors claimed by space bears — Public RansomLook extortion-site listing claim. Group: space bears. Claimed victim/listing: Sports Endeavors. Description excerpt: Sports Endeavors is a North Carolina company founded in 1984 by brothers Mike and…
P3 RansomLook: Sancity Soft Touch claimed by vexy — Public RansomLook extortion-site listing claim. Group: vexy. Claimed victim/listing: Sancity Soft Touch. Description excerpt: IT services company providing web design & development, software/application development,…
P3 RansomLook: kalahealth.eu claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: kalahealth.eu. Description excerpt: KALA Health is an international manufacturing and distribution company of nutraceutical health…
P3 RansomLook: huisartsencentrumkleiniterson.nl claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: huisartsencentrumkleiniterson.nl. Description excerpt: Huisartsencentrum Klein Iterson is a Healthcare Services provider operating…
Malware / infrastructure / abuse feed highlights
P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=exe,PureLogsStealer; url=https://gaiadeqi.com/scrapbookpocketfordraf.exe
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://49.73.53.63:3588/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://123.129.130.4:34119/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://103.190.23.91:39129/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://115.48.162.240:53193/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://119.118.45.218:54263/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://123.129.130.4:34119/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://125.41.92.37:60332/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://124.131.4.86:37963/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=176-65-139-131,elf,mirai,ua-wget; url=http://176.65.139.131/bins/chud.arm6
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=176-65-139-131,elf,mirai,ua-wget; url=http://176.65.139.131/bins/chud.ppc
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-19490` | Critical Citrix NetScaler auth bypass now leveraged in attacks | BleepingComputer Ransomware News |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| hash | `8ada66fb50893d32c1efcf75d4fd6bd7` | RansomLook: kalahealth.eu claimed by lockbit5 | RansomLook Recent Listings |
| hash | `ad4c5e4fb3efe31d475d8a10290631e6` | RansomLook: huisartsencentrumkleiniterson.nl claimed by lockbit5 | RansomLook Recent Listings |
| hash | `4652cbe1e838548b272effe6e93b8f2a` | RansomLook: pscindustries.com claimed by lockbit5 | RansomLook Recent Listings |
Defensive takeaways
Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
Sources checked
BleepingComputer Ransomware News: ok new=0 fetched=15
CISA Known Exploited Vulnerabilities: ok new=0 fetched=44
Cisco Talos Blog: ok new=0 fetched=15
Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
Huntress Blog: ok new=0 fetched=25
Microsoft Security Response Center RSS: ok new=0 fetched=25
NVD Recent CVEs: ok new=50 fetched=80
ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
RansomLook Recent Listings: ok new=1 fetched=50
Rapid7 Blog: ok new=0 fetched=20
SANS Internet Storm Center: ok new=0 fetched=10
Sophos X-Ops: ok new=0 fetched=15
The DFIR Report: ok new=0 fetched=10
URLhaus Recent URLs: ok new=65 fetched=120
Unit 42 Threat Research: ok new=0 fetched=15
Limitations
Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
Technology-only matching can miss relevant items that do not name a tracked product explicitly.
Ransomware victim claims are actor/source claims unless independently corroborated.
IOC highlights are publicly sourced and should be validated before enforcement in production controls.