Daily Cyber Threat Intel Brief — 2026-09-09
Generated: 2026-09-09 08:00:19 UTC
Executive summary
Priority technology watch items
- Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
- An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]
- Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]
- Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
- Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
- Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network.
- Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.
- Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
- Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as…
- Public RansomLook extortion-site listing claim. Group: eclipse. Claimed victim/listing: The Zhou Law Group. Description excerpt: The Zhou Law Group is one of the largest family law firms in California, specializing in divorce and related family law issues…
- Public RansomLook extortion-site listing claim. Group: eclipse. Claimed victim/listing: TTG Asia Media. Description excerpt: TTG Asia is a leading travel trade business resource in the Asia-Pacific region, established in 1974. The company provides a…
- Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to…
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-55007` | CVE-2026-55007 Microsoft Exchange Server Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-75650` | Adobe fixes critical Magento zero-day exploited to backdoor servers | BleepingComputer Ransomware News |
| cve | `CVE-2026-62706` | CVE-2026-62706 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62744` | CVE-2026-62744 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-66302` | CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69522` | CVE-2026-69522 .NET and Visual Studio Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-70091` | CVE-2026-70091 Windows DNS Denial of Service Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69782` | CVE-2026-69782 Windows DNS Server Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-77482` | CVE-2026-77482 Microsoft SQL Server Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50349` | CVE-2026-50349 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulner | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62694` | CVE-2026-62694 Windows Installer Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-66304` | CVE-2026-66304 Skype for Business Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-66306` | CVE-2026-66306 Skype for Business Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-66308` | CVE-2026-66308 Skype for Business and Lync Denial of Service Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62895` | CVE-2026-62895 Azure Arc SQL Server Extension Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69341` | CVE-2026-69341 Windows Image Acquisition Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62916` | CVE-2026-62916 Microsoft Entra ID Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-65818` | CVE-2026-65818 Power Automate Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69857` | CVE-2026-69857 Azure Cosmos DB Spoofing Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-83941` | CVE-2026-83941 Entra ID Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-85360` | CVE-2026-85360 Windows Kernel Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-57098` | CVE-2026-57098 Microsoft Remote Desktop App for Windows Information Disclosure Vulnerabili | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62801` | CVE-2026-62801 Microsoft PowerShell Security Feature Bypass Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-67368` | CVE-2026-67368 Microsoft SQL Server Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-67370` | CVE-2026-67370 Microsoft SQL Server Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-18577` | CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED) | Rapid7 Blog |
| cve | `CVE-2026-86206` | CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED) | Rapid7 Blog |
| cve | `CVE-2026-86207` | CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED) | Rapid7 Blog |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| hash | `b4282657ac697c09ff05210c91e3dece` | RansomLook: fdcputman.nl claimed by lockbit5 | RansomLook Recent Listings |