Daily Cyber Threat Intel Brief — 2026-09-07
Generated: 2026-09-07 08:00:45 UTC
Executive summary
Collected 250 recent public-source CTI items for technology-only monitoring.
Priority distribution: P1=0, P2=2, P3=34, P4=214.
Highest-priority item: Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th) (P2, source: SANS Internet Storm Center).
1 public IOC highlights selected for analyst awareness.
Priority technology watch items
P2 Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th) — SANS Internet Storm Center; score 54; technologies: none explicitly matched.
- Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected…
P2 RansomLook: RTAD GOV MM claimed by dysphor1a — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: RTAD GOV MM. Description excerpt: Leaked: New | Sector: Government / Transport | Country: 🇲🇲 Myanmar | Records: 1.08 GB — full databases dump | Road Transport…
Newly exploited vulnerabilities / CVE watch
None observed.
Ransomware and extortion trend notes
P2 RansomLook: RTAD GOV MM claimed by dysphor1a — Public RansomLook extortion-site listing claim. Group: dysphor1a. Claimed victim/listing: RTAD GOV MM. Description excerpt: Leaked: New | Sector: Government / Transport | Country: 🇲🇲 Myanmar | Records: 1.08 GB — full…
P3 RansomLook: MSM Unify: Global Education Platform - CA claimed by kazu — Public RansomLook extortion-site listing claim. Group: kazu. Claimed victim/listing: MSM Unify: Global Education Platform - CA. Description excerpt: MSM Unify is a global education technology platform that helps…
P3 RansomLook: Statistics South Africa – Official National Data and Insights Portal claimed by kazu — Public RansomLook extortion-site listing claim. Group: kazu. Claimed victim/listing: Statistics South Africa – Official National Data and Insights Portal. Description excerpt: the official online portal of South…
P3 RansomLook: Gauteng City Region Academy (GCRA) claimed by kazu — Public RansomLook extortion-site listing claim. Group: kazu. Claimed victim/listing: Gauteng City Region Academy (GCRA). Description excerpt: government-funded program that helps students from Gauteng Province pursue…
P3 RansomLook: HealthDaq claimed by kazu — Public RansomLook extortion-site listing claim. Group: kazu. Claimed victim/listing: HealthDaq. Description excerpt: Healthdaq is a company that helps hospitals and care providers hire staff directly, without using…
P3 RansomLook: Health Time claimed by kazu — Public RansomLook extortion-site listing claim. Group: kazu. Claimed victim/listing: Health Time. Description excerpt: HT Médica is a comprehensive imaging diagnostic center that offers advanced radiology and digital…
P3 RansomLook: Natclar (S.G. Natclar S.A.C.) claimed by kazu — Public RansomLook extortion-site listing claim. Group: kazu. Claimed victim/listing: Natclar (S.G. Natclar S.A.C.). Description excerpt: Peruvian occupational health services company headquartered in Lima and founded in…
P3 RansomLook: Gauteng Provincial Government claimed by kazu — Public RansomLook extortion-site listing claim. Group: kazu. Claimed victim/listing: Gauteng Provincial Government. Description excerpt: Gauteng Provincial Government Breach ( www.gauteng.gov.za ) Official online portal…
P3 RansomLook: ConsultorioMovil: Telemedicine and Healthcare System claimed by kazu — Public RansomLook extortion-site listing claim. Group: kazu. Claimed victim/listing: ConsultorioMovil: Telemedicine and Healthcare System. Description excerpt: digital healthcare platform designed to help doctors,…
P3 RansomLook: Meducar: Telemedicine and Patient Management System claimed by kazu — Public RansomLook extortion-site listing claim. Group: kazu. Claimed victim/listing: Meducar: Telemedicine and Patient Management System. Description excerpt: Meducar is a Latin American healthtech platform that…
P3 RansomLook: Centro Médico Especializado OSI: Healthcare Solutions claimed by kazu — Public RansomLook extortion-site listing claim. Group: kazu. Claimed victim/listing: Centro Médico Especializado OSI: Healthcare Solutions. Description excerpt: Centro Médico Especializado OSI is a healthcare provider…
P3 RansomLook: Dr Akbar Niazi Teaching Hospital claimed by kazu — Public RansomLook extortion-site listing claim. Group: kazu. Claimed victim/listing: Dr Akbar Niazi Teaching Hospital. Description excerpt: Dr. Akbar Niazi Teaching Hospital (ANTH) is a 500-bed tertiary care teaching…
Malware / infrastructure / abuse feed highlights
P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=exe,msstore,signed,WailsLoader; url=https://authgen.deals/download/12.2.5/t2auth_bastion.exe
P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=exe,msstore,signed,WailsLoader; url=https://adps.pro/download/1.1.2/adpayworkstt.exe
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=exe,msstore,signed,WailsLoader; url=https://pdf-editore.com/download/1.0.1/pdf_editor.exe
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=exe,msstore,signed,WailsLoader; url=https://signaturenib.rest/download/3.7.4/signature_nib.exe
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=exe,msstore,signed,WailsLoader; url=https://pdfmun.software/download/7.3.4/pdf_municipal.exe
P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://123.5.185.244:38342/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=mirai; url=http://210.208.104.156:37194/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=rat,RemcosRAT,stego; url=https://res.cloudinary.com/zd8litqk/image/upload/v1788745964/img_215152.jpg
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=AgentTesla,stego; url=https://pub-17ab5f90ca394fc2a98a106eb938ff35.r2.dev/ghecvjk.png
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=AgentTesla,stego; url=https://pub-cbeeb81b1c2d40df823a412f702451a3.r2.dev/rdklxci.png
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=PureLogsStealer,stego; url=https://res.cloudinary.com/sxajd38y/image/upload/v1788742357/img_024933.jpg
IOC highlights
| Type | Value | Context | Source |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
Defensive takeaways
Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
Sources checked
BleepingComputer Ransomware News: ok new=1 fetched=15
CISA Known Exploited Vulnerabilities: ok new=0 fetched=42
Cisco Talos Blog: ok new=0 fetched=15
Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
Huntress Blog: ok new=0 fetched=25
Microsoft Security Response Center RSS: ok new=0 fetched=25
NVD Recent CVEs: ok new=39 fetched=80
ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
RansomLook Recent Listings: ok new=18 fetched=50
Rapid7 Blog: ok new=0 fetched=20
SANS Internet Storm Center: ok new=0 fetched=10
Sophos X-Ops: ok new=0 fetched=15
The DFIR Report: ok new=0 fetched=10
URLhaus Recent URLs: ok new=119 fetched=120
Unit 42 Threat Research: ok new=0 fetched=15
Limitations
Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
Technology-only matching can miss relevant items that do not name a tracked product explicitly.
Ransomware victim claims are actor/source claims unless independently corroborated.
IOC highlights are publicly sourced and should be validated before enforcement in production controls.