markcardiff.tech:/daily-intel/2026-09-10.html
Generated: 2026-09-10 08:00:56 UTC
P1: 4
P2: 14
Items: 250

Daily Cyber Threat Intel Brief — 2026-09-10

Generated: 2026-09-10 08:00:56 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=4, P2=14, P3=90, P4=142.
  • Highest-priority item: New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access (P1, source: BleepingComputer Ransomware News).
  • 11 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access — BleepingComputer Ransomware News; score 79; technologies: Microsoft Defender.
  • - An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]

  • P1 Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks — BleepingComputer Ransomware News; score 74; technologies: none explicitly matched.
  • - Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]

  • P1 CVE-2026-68877 Windows Storage Spaces Controller Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-69334 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P2 Chromium: CVE-2026-85046 Type confusion in V8 — Microsoft Security Response Center RSS; score 57; technologies: none explicitly matched.
  • - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Google is aware that an exploit for…

  • P2 RansomLook: Logar Network Solutions claimed by vexy — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: vexy. Claimed victim/listing: Logar Network Solutions. Description excerpt: Logar Network Solutions is a Brazilian managed IT services provider (MSP) that delivers outsourced IT management, cybersecurity,…

  • P2 RansomLook: Air Canada claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Air Canada. Description excerpt: aircanada.com zoominfo.com/c/air-canada/3937344 Air Canada We have taken 51409 critical files! Canada's flag carrier and largest…

  • P2 RansomLook: Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co claimed by black nevas — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: black nevas. Claimed victim/listing: Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co. Description excerpt: There is very little public information available…

  • P2 RansomLook: Agrimac claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Agrimac. Description excerpt: Manufacturing | Warrnambool, Victoria, Australia | Agrimac achieves Australian first - Agrimac is the first agricultural dealership in…

  • P2 RansomLook: Westco Motors Cairns claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Westco Motors Cairns. Description excerpt: Retail & E-commerce | Bungalow, Queensland, Australia | Westco Motors Cairns is a family-owned and operated multi-franchise…

  • P2 RansomLook: Standard Tool & Die claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Standard Tool & Die. Description excerpt: Manufacturing | Stevensville, Michigan, United States | Standard Tool & Die specializes in designing and manufacturing die cast…

  • P2 RansomLook: Lowerys claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Lowerys. Description excerpt: Retail & E-commerce | Thunder Bay, Ontario, Canada | Lowerys is a provider of office supplies, printing, and photocopying services, catering to…

  • P2 RansomLook: Sharp Motor Group claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Sharp Motor Group. Description excerpt: Retail & E-commerce | Tweed Heads, New South Wales, Australia | Sharp Motor Group is a privately owned automotive dealership group…

  • P2 RansomLook: Southern Metals Company claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Southern Metals Company. Description excerpt: Retail & E-commerce | Charlotte, North Carolina, United States | Southern Metals Company, based in Charlotte, NC, specializes…

  • P2 RansomLook: Penfold claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Penfold. Description excerpt: Retail & E-commerce | Burwood, Victoria, Australia | Penfold Motor Group is a family-owned auto dealership in Australia that has been serving…

  • P2 RansomLook: Proveli claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Proveli. Description excerpt: Retail & E-commerce | Bloomington, Indiana, United States | Proveli is a privately held business founded by two brothers: Reinhardt and Thomas.…

  • P2 RansomLook: Ramsey Bros claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Ramsey Bros. Description excerpt: Retail & E-commerce | Cleve, South Australia, Australia | Ramsey Bros is a family-owned and operated business that serves as an authorized…

  • P2 RansomLook: Phoenix Group of Companies claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Phoenix Group of Companies. Description excerpt: Manufacturing | Philadelphia, Pennsylvania, United States | The Phoenix Group of Companies is a leading single-source…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-20079: Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks — technologies: not watchlist-specific.
  • P1 CVE-2026-68877: CVE-2026-68877 Windows Storage Spaces Controller Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-69334: CVE-2026-69334 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P2 CVE-2026-85046: Chromium: CVE-2026-85046 Type confusion in V8 — technologies: not watchlist-specific.
  • P3 CVE-2026-69777: CVE-2026-69777 Windows DHCP Client Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69508: CVE-2026-69508 Windows MIDI Service Module Elevation of Privileges Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62693: CVE-2026-62693 Windows MIDI Service Module Elevation of Privileges Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69492: CVE-2026-69492 Windows Partition Management Driver Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-73024: CVE-2026-73024 Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Logar Network Solutions claimed by vexy — Public RansomLook extortion-site listing claim. Group: vexy. Claimed victim/listing: Logar Network Solutions. Description excerpt: Logar Network Solutions is a Brazilian managed IT services provider (MSP) that delivers…
  • P2 RansomLook: Air Canada claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Air Canada. Description excerpt: aircanada.com zoominfo.com/c/air-canada/3937344 Air Canada We have taken 51409 critical…
  • P2 RansomLook: Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co claimed by black nevas — Public RansomLook extortion-site listing claim. Group: black nevas. Claimed victim/listing: Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co. Description excerpt: There is very…
  • P2 RansomLook: Agrimac claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Agrimac. Description excerpt: Manufacturing | Warrnambool, Victoria, Australia | Agrimac achieves Australian first - Agrimac is the…
  • P2 RansomLook: Westco Motors Cairns claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Westco Motors Cairns. Description excerpt: Retail & E-commerce | Bungalow, Queensland, Australia | Westco Motors Cairns is a…
  • P2 RansomLook: Standard Tool & Die claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Standard Tool & Die. Description excerpt: Manufacturing | Stevensville, Michigan, United States | Standard Tool & Die specializes in…
  • P2 RansomLook: Lowerys claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Lowerys. Description excerpt: Retail & E-commerce | Thunder Bay, Ontario, Canada | Lowerys is a provider of office supplies,…
  • P2 RansomLook: Sharp Motor Group claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Sharp Motor Group. Description excerpt: Retail & E-commerce | Tweed Heads, New South Wales, Australia | Sharp Motor Group is a…
  • P2 RansomLook: Southern Metals Company claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Southern Metals Company. Description excerpt: Retail & E-commerce | Charlotte, North Carolina, United States | Southern Metals…
  • P2 RansomLook: Penfold claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Penfold. Description excerpt: Retail & E-commerce | Burwood, Victoria, Australia | Penfold Motor Group is a family-owned auto…
  • P2 RansomLook: Proveli claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Proveli. Description excerpt: Retail & E-commerce | Bloomington, Indiana, United States | Proveli is a privately held business…
  • P2 RansomLook: Ramsey Bros claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Ramsey Bros. Description excerpt: Retail & E-commerce | Cleve, South Australia, Australia | Ramsey Bros is a family-owned and…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=connectwise,rmm,screenconnect,zip; url=https://download.pocketbitcoindesktop.com/PocketSetupBundle.zip
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=encrypted,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1vGK7VwXP5gMMSm47LY8cn6Jw4bf8tFOp
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1NQFkpFufupWakv5t5BlwnirI3TmrKoPw
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1yrdjegjjRJwouQAawbZs2ssombia2PDw
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=encrypted,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1KH3sfRGqojZzIETO2SQVXeZfnrv9gPoi
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Encoded,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=15PE9xs7YgZwZpsEZTl__yTsrk0OsjiKB
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1x4p5eilCDCy_aBTKjv4LQnQNWStlk3MX
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1TEl5dE_u2rdOAUcVgIgBxuVV4E94FU_D
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=encrypted,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=18Sk2_goSIJdTQeofy4br2IZZSSWUj6q2
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1HS8TsqD0A4pQPLmjPMAShT74KCIb_yMk
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=GuLoader; url=https://drive.google.com/uc?export=download&id=1HQEnhH1B1bdArmL6PY9UkQzbJWMWjfi_
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-20079`Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacksBleepingComputer Ransomware News
    cve`CVE-2026-68877`CVE-2026-68877 Windows Storage Spaces Controller Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69334`CVE-2026-69334 Windows Volume Manager Extension Driver Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-85046`Chromium: CVE-2026-85046 Type confusion in V8Microsoft Security Response Center RSS
    cve`CVE-2026-69777`CVE-2026-69777 Windows DHCP Client Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69508`CVE-2026-69508 Windows MIDI Service Module Elevation of Privileges VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62693`CVE-2026-62693 Windows MIDI Service Module Elevation of Privileges VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69492`CVE-2026-69492 Windows Partition Management Driver Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-73024`CVE-2026-73024 Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege VulnerabiMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`c582d78870d0815a9f37d2ee92981af3`RansomLook: amorsaude.com.br claimed by lockbit5RansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=1 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=50
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=17 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=3 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=70 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.