Daily Cyber Threat Intel Brief — 2026-09-10
Generated: 2026-09-10 08:00:56 UTC
Executive summary
Collected 250 recent public-source CTI items for technology-only monitoring.
Priority distribution: P1=4, P2=14, P3=90, P4=142.
Highest-priority item: New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access (P1, source: BleepingComputer Ransomware News).
11 public IOC highlights selected for analyst awareness.
Priority technology watch items
P1 New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access — BleepingComputer Ransomware News; score 79; technologies: Microsoft Defender.
- An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]
P1 Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks — BleepingComputer Ransomware News; score 74; technologies: none explicitly matched.
- Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]
P1 CVE-2026-68877 Windows Storage Spaces Controller Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Updated an acknowledgement. This is an informational change only.
P1 CVE-2026-69334 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Updated an acknowledgement. This is an informational change only.
P2 Chromium: CVE-2026-85046 Type confusion in V8 — Microsoft Security Response Center RSS; score 57; technologies: none explicitly matched.
- This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Google is aware that an exploit for…
P2 RansomLook: Logar Network Solutions claimed by vexy — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: vexy. Claimed victim/listing: Logar Network Solutions. Description excerpt: Logar Network Solutions is a Brazilian managed IT services provider (MSP) that delivers outsourced IT management, cybersecurity,…
P2 RansomLook: Air Canada claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Air Canada. Description excerpt: aircanada.com zoominfo.com/c/air-canada/3937344 Air Canada We have taken 51409 critical files! Canada's flag carrier and largest…
P2 RansomLook: Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co claimed by black nevas — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: black nevas. Claimed victim/listing: Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co. Description excerpt: There is very little public information available…
P2 RansomLook: Agrimac claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Agrimac. Description excerpt: Manufacturing | Warrnambool, Victoria, Australia | Agrimac achieves Australian first - Agrimac is the first agricultural dealership in…
P2 RansomLook: Westco Motors Cairns claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Westco Motors Cairns. Description excerpt: Retail & E-commerce | Bungalow, Queensland, Australia | Westco Motors Cairns is a family-owned and operated multi-franchise…
P2 RansomLook: Standard Tool & Die claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Standard Tool & Die. Description excerpt: Manufacturing | Stevensville, Michigan, United States | Standard Tool & Die specializes in designing and manufacturing die cast…
P2 RansomLook: Lowerys claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Lowerys. Description excerpt: Retail & E-commerce | Thunder Bay, Ontario, Canada | Lowerys is a provider of office supplies, printing, and photocopying services, catering to…
P2 RansomLook: Sharp Motor Group claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Sharp Motor Group. Description excerpt: Retail & E-commerce | Tweed Heads, New South Wales, Australia | Sharp Motor Group is a privately owned automotive dealership group…
P2 RansomLook: Southern Metals Company claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Southern Metals Company. Description excerpt: Retail & E-commerce | Charlotte, North Carolina, United States | Southern Metals Company, based in Charlotte, NC, specializes…
P2 RansomLook: Penfold claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Penfold. Description excerpt: Retail & E-commerce | Burwood, Victoria, Australia | Penfold Motor Group is a family-owned auto dealership in Australia that has been serving…
P2 RansomLook: Proveli claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Proveli. Description excerpt: Retail & E-commerce | Bloomington, Indiana, United States | Proveli is a privately held business founded by two brothers: Reinhardt and Thomas.…
P2 RansomLook: Ramsey Bros claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Ramsey Bros. Description excerpt: Retail & E-commerce | Cleve, South Australia, Australia | Ramsey Bros is a family-owned and operated business that serves as an authorized…
P2 RansomLook: Phoenix Group of Companies claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Phoenix Group of Companies. Description excerpt: Manufacturing | Philadelphia, Pennsylvania, United States | The Phoenix Group of Companies is a leading single-source…
Newly exploited vulnerabilities / CVE watch
P1 CVE-2026-20079: Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks — technologies: not watchlist-specific.
P1 CVE-2026-68877: CVE-2026-68877 Windows Storage Spaces Controller Remote Code Execution Vulnerability — technologies: not watchlist-specific.
P1 CVE-2026-69334: CVE-2026-69334 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability — technologies: not watchlist-specific.
P2 CVE-2026-85046: Chromium: CVE-2026-85046 Type confusion in V8 — technologies: not watchlist-specific.
P3 CVE-2026-69777: CVE-2026-69777 Windows DHCP Client Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
P3 CVE-2026-69508: CVE-2026-69508 Windows MIDI Service Module Elevation of Privileges Vulnerability — technologies: not watchlist-specific.
P3 CVE-2026-62693: CVE-2026-62693 Windows MIDI Service Module Elevation of Privileges Vulnerability — technologies: not watchlist-specific.
P3 CVE-2026-69492: CVE-2026-69492 Windows Partition Management Driver Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
P3 CVE-2026-73024: CVE-2026-73024 Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
Ransomware and extortion trend notes
P2 RansomLook: Logar Network Solutions claimed by vexy — Public RansomLook extortion-site listing claim. Group: vexy. Claimed victim/listing: Logar Network Solutions. Description excerpt: Logar Network Solutions is a Brazilian managed IT services provider (MSP) that delivers…
P2 RansomLook: Air Canada claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Air Canada. Description excerpt: aircanada.com zoominfo.com/c/air-canada/3937344 Air Canada We have taken 51409 critical…
P2 RansomLook: Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co claimed by black nevas — Public RansomLook extortion-site listing claim. Group: black nevas. Claimed victim/listing: Enteroptyx Ophthalmology Products www.enteroptyx.com serviced by an IT company Computer Co. Description excerpt: There is very…
P2 RansomLook: Agrimac claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Agrimac. Description excerpt: Manufacturing | Warrnambool, Victoria, Australia | Agrimac achieves Australian first - Agrimac is the…
P2 RansomLook: Westco Motors Cairns claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Westco Motors Cairns. Description excerpt: Retail & E-commerce | Bungalow, Queensland, Australia | Westco Motors Cairns is a…
P2 RansomLook: Standard Tool & Die claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Standard Tool & Die. Description excerpt: Manufacturing | Stevensville, Michigan, United States | Standard Tool & Die specializes in…
P2 RansomLook: Lowerys claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Lowerys. Description excerpt: Retail & E-commerce | Thunder Bay, Ontario, Canada | Lowerys is a provider of office supplies,…
P2 RansomLook: Sharp Motor Group claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Sharp Motor Group. Description excerpt: Retail & E-commerce | Tweed Heads, New South Wales, Australia | Sharp Motor Group is a…
P2 RansomLook: Southern Metals Company claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Southern Metals Company. Description excerpt: Retail & E-commerce | Charlotte, North Carolina, United States | Southern Metals…
P2 RansomLook: Penfold claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Penfold. Description excerpt: Retail & E-commerce | Burwood, Victoria, Australia | Penfold Motor Group is a family-owned auto…
P2 RansomLook: Proveli claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Proveli. Description excerpt: Retail & E-commerce | Bloomington, Indiana, United States | Proveli is a privately held business…
P2 RansomLook: Ramsey Bros claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Ramsey Bros. Description excerpt: Retail & E-commerce | Cleve, South Australia, Australia | Ramsey Bros is a family-owned and…
Malware / infrastructure / abuse feed highlights
P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=connectwise,rmm,screenconnect,zip; url=https://download.pocketbitcoindesktop.com/PocketSetupBundle.zip
P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=encrypted,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1vGK7VwXP5gMMSm47LY8cn6Jw4bf8tFOp
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1NQFkpFufupWakv5t5BlwnirI3TmrKoPw
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1yrdjegjjRJwouQAawbZs2ssombia2PDw
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=encrypted,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1KH3sfRGqojZzIETO2SQVXeZfnrv9gPoi
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Encoded,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=15PE9xs7YgZwZpsEZTl__yTsrk0OsjiKB
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1x4p5eilCDCy_aBTKjv4LQnQNWStlk3MX
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1TEl5dE_u2rdOAUcVgIgBxuVV4E94FU_D
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=encrypted,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=18Sk2_goSIJdTQeofy4br2IZZSSWUj6q2
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1HS8TsqD0A4pQPLmjPMAShT74KCIb_yMk
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=GuLoader; url=https://drive.google.com/uc?export=download&id=1HQEnhH1B1bdArmL6PY9UkQzbJWMWjfi_
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-20079` | Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks | BleepingComputer Ransomware News |
| cve | `CVE-2026-68877` | CVE-2026-68877 Windows Storage Spaces Controller Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69334` | CVE-2026-69334 Windows Volume Manager Extension Driver Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-85046` | Chromium: CVE-2026-85046 Type confusion in V8 | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69777` | CVE-2026-69777 Windows DHCP Client Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69508` | CVE-2026-69508 Windows MIDI Service Module Elevation of Privileges Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62693` | CVE-2026-62693 Windows MIDI Service Module Elevation of Privileges Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69492` | CVE-2026-69492 Windows Partition Management Driver Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-73024` | CVE-2026-73024 Windows Services for NFS ONCRPC XDR Driver Elevation of Privilege Vulnerabi | Microsoft Security Response Center RSS |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| hash | `c582d78870d0815a9f37d2ee92981af3` | RansomLook: amorsaude.com.br claimed by lockbit5 | RansomLook Recent Listings |
Defensive takeaways
Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
Sources checked
BleepingComputer Ransomware News: ok new=1 fetched=15
CISA Known Exploited Vulnerabilities: ok new=0 fetched=50
Cisco Talos Blog: ok new=0 fetched=15
Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
Huntress Blog: ok new=0 fetched=25
Microsoft Security Response Center RSS: ok new=0 fetched=25
NVD Recent CVEs: ok new=17 fetched=80
ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
RansomLook Recent Listings: ok new=3 fetched=50
Rapid7 Blog: ok new=0 fetched=20
SANS Internet Storm Center: ok new=0 fetched=10
Sophos X-Ops: ok new=0 fetched=15
The DFIR Report: ok new=0 fetched=10
URLhaus Recent URLs: ok new=70 fetched=120
Unit 42 Threat Research: ok new=0 fetched=15
Limitations
Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
Technology-only matching can miss relevant items that do not name a tracked product explicitly.
Ransomware victim claims are actor/source claims unless independently corroborated.
IOC highlights are publicly sourced and should be validated before enforcement in production controls.