markcardiff.tech:/daily-intel/2026-09-09.html
Generated: 2026-09-09 08:00:19 UTC
P1: 11
P2: 4
Items: 250

Daily Cyber Threat Intel Brief — 2026-09-09

Generated: 2026-09-09 08:00:19 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=11, P2=4, P3=53, P4=182.
  • Highest-priority item: CVE-2026-55007 Microsoft Exchange Server Remote Code Execution Vulnerability (P1, source: Microsoft Security Response Center RSS).
  • 30 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2026-55007 Microsoft Exchange Server Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 100; technologies: Microsoft Exchange.
  • - Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

  • P1 New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access — BleepingComputer Ransomware News; score 79; technologies: Microsoft Defender.
  • - An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]

  • P1 Adobe fixes critical Magento zero-day exploited to backdoor servers — BleepingComputer Ransomware News; score 74; technologies: none explicitly matched.
  • - Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]

  • P1 CVE-2026-62706 Microsoft Windows Media Foundation Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-62744 Microsoft Windows Media Foundation Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-69522 .NET and Visual Studio Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-70091 Windows DNS Denial of Service Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network.

  • P1 CVE-2026-69782 Windows DNS Server Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-77482 Microsoft SQL Server Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-50349 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • P2 September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th) — SANS Internet Storm Center; score 54; technologies: none explicitly matched.
  • - This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as…

  • P2 RansomLook: The Zhou Law Group claimed by eclipse — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: eclipse. Claimed victim/listing: The Zhou Law Group. Description excerpt: The Zhou Law Group is one of the largest family law firms in California, specializing in divorce and related family law issues…

  • P2 RansomLook: TTG Asia Media claimed by eclipse — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: eclipse. Claimed victim/listing: TTG Asia Media. Description excerpt: TTG Asia is a leading travel trade business resource in the Asia-Pacific region, established in 1974. The company provides a…

  • P2 Patch Tuesday - September 2026 — Rapid7 Blog; score 52; technologies: none explicitly matched.
  • - Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-55007: CVE-2026-55007 Microsoft Exchange Server Remote Code Execution Vulnerability — technologies: Microsoft Exchange.
  • P1 CVE-2026-75650: Adobe fixes critical Magento zero-day exploited to backdoor servers — technologies: not watchlist-specific.
  • P1 CVE-2026-62706: CVE-2026-62706 Microsoft Windows Media Foundation Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-62744: CVE-2026-62744 Microsoft Windows Media Foundation Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-66302: CVE-2026-66302 Skype for Business Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-69522: CVE-2026-69522 .NET and Visual Studio Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-70091: CVE-2026-70091 Windows DNS Denial of Service Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-69782: CVE-2026-69782 Windows DNS Server Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-77482: CVE-2026-77482 Microsoft SQL Server Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-50349: CVE-2026-50349 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62694: CVE-2026-62694 Windows Installer Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-66304: CVE-2026-66304 Skype for Business Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-66306: CVE-2026-66306 Skype for Business Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-66308: CVE-2026-66308 Skype for Business and Lync Denial of Service Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62895: CVE-2026-62895 Azure Arc SQL Server Extension Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69341: CVE-2026-69341 Windows Image Acquisition Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62916: CVE-2026-62916 Microsoft Entra ID Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-65818: CVE-2026-65818 Power Automate Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69857: CVE-2026-69857 Azure Cosmos DB Spoofing Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-83941: CVE-2026-83941 Entra ID Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: The Zhou Law Group claimed by eclipse — Public RansomLook extortion-site listing claim. Group: eclipse. Claimed victim/listing: The Zhou Law Group. Description excerpt: The Zhou Law Group is one of the largest family law firms in California, specializing in…
  • P2 RansomLook: TTG Asia Media claimed by eclipse — Public RansomLook extortion-site listing claim. Group: eclipse. Claimed victim/listing: TTG Asia Media. Description excerpt: TTG Asia is a leading travel trade business resource in the Asia-Pacific region, established…
  • P3 RansomLook: Gellibrand Support Services claimed by anubis — Public RansomLook extortion-site listing claim. Group: anubis. Claimed victim/listing: Gellibrand Support Services. Description excerpt: A data breach at a company full of smiling patients.
  • P3 RansomLook: gayafores.es claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: gayafores.es. Description excerpt: The company is headquartered in Onda, Castellón, one of Europe's most important ceramic…
  • P3 RansomLook: cenmar-manila.com claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: cenmar-manila.com. Description excerpt: The company was registered with the Philippine Securities and Exchange Commission in 1997…
  • P3 RansomLook: gsngestion.es claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: gsngestion.es. Description excerpt: The company is based in Villaviciosa de Odón, Madrid, and operates through the GSN Gestión…
  • P3 RansomLook: hbpro.pt claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: hbpro.pt. Description excerpt: Established in 1994, the company has more than three decades of experience providing technology…
  • P3 RansomLook: Sales Boomerang claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: Sales Boomerang.
  • P3 RansomLook: Red Star Oil claimed by play — Public RansomLook extortion-site listing claim. Group: play. Claimed victim/listing: Red Star Oil.
  • P3 RansomLook: GT Distributors claimed by play — Public RansomLook extortion-site listing claim. Group: play. Claimed victim/listing: GT Distributors.
  • P3 RansomLook: copeplastics.com claimed by chaos — Public RansomLook extortion-site listing claim. Group: chaos. Claimed victim/listing: copeplastics.com. Description excerpt: Cope Plastics is a leading U.S. distributor and fabricator of performance plastics, serving…
  • P3 RansomLook: AUDIT ENTITY: bu*en claimed by audit team — Public RansomLook extortion-site listing claim. Group: audit team. Claimed victim/listing: AUDIT ENTITY: bu*en. Description excerpt: AUDIT ID: 3A8CF838E9FD17A1 / DISCOVERY DATE: 2026-09-08
  • Malware / infrastructure / abuse feed highlights

  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=IRAHOOK-loader,stealer,zip; url=https://opalcraftsmp.com/assets/OpalCraftSMP-CurseForge.zip
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://222.113.196.55:59257/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://130.12.209.132:49060/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://119.116.140.32:39074/i
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=malware-download,redis; url=https://101.99.76.207:443/stage/8cfb8d1ead3f6ca1848fc5cc87689828
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=malware-download,redis; url=https://101.99.76.207:443/stage/fb40d01272c0f4c3012915d498b1c7b3
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=malware-download,redis; url=https://101.99.76.207:443/stage/0f4368592aa55d5c302ab3c877736767
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=malware-download,redis; url=https://101.99.76.207:443/stage/e768106426985a9130f2c34d65565442
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=malware-download,redis; url=https://101.99.76.207:443/stage/ed62a22958e209a1ed3580641e85a533
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=malware-download,redis; url=https://101.99.76.207:443/stage/211cf61519f8707edef320dd3db39654
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=malware-download,redis; url=https://101.99.76.207:443/stage/212389792e427ec9d8d8cba0fe50ff79
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-55007`CVE-2026-55007 Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-75650`Adobe fixes critical Magento zero-day exploited to backdoor serversBleepingComputer Ransomware News
    cve`CVE-2026-62706`CVE-2026-62706 Microsoft Windows Media Foundation Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62744`CVE-2026-62744 Microsoft Windows Media Foundation Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-66302`CVE-2026-66302 Skype for Business Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69522`CVE-2026-69522 .NET and Visual Studio Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-70091`CVE-2026-70091 Windows DNS Denial of Service VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69782`CVE-2026-69782 Windows DNS Server Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-77482`CVE-2026-77482 Microsoft SQL Server Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50349`CVE-2026-50349 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerMicrosoft Security Response Center RSS
    cve`CVE-2026-62694`CVE-2026-62694 Windows Installer Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-66304`CVE-2026-66304 Skype for Business Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-66306`CVE-2026-66306 Skype for Business Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-66308`CVE-2026-66308 Skype for Business and Lync Denial of Service VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62895`CVE-2026-62895 Azure Arc SQL Server Extension Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69341`CVE-2026-69341 Windows Image Acquisition Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62916`CVE-2026-62916 Microsoft Entra ID Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-65818`CVE-2026-65818 Power Automate Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69857`CVE-2026-69857 Azure Cosmos DB Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-83941`CVE-2026-83941 Entra ID Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-85360`CVE-2026-85360 Windows Kernel Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-57098`CVE-2026-57098 Microsoft Remote Desktop App for Windows Information Disclosure VulnerabiliMicrosoft Security Response Center RSS
    cve`CVE-2026-62801`CVE-2026-62801 Microsoft PowerShell Security Feature Bypass VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-67368`CVE-2026-67368 Microsoft SQL Server Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-67370`CVE-2026-67370 Microsoft SQL Server Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-18577`CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)Rapid7 Blog
    cve`CVE-2026-86206`CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)Rapid7 Blog
    cve`CVE-2026-86207`CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)Rapid7 Blog
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`b4282657ac697c09ff05210c91e3dece`RansomLook: fdcputman.nl claimed by lockbit5RansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=2 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=46
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=14 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=5 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=120 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.