markcardiff.tech:/daily-intel/2026-09-11.html
Generated: 2026-09-11 08:00:17 UTC
P1: 0
P2: 1
Items: 250

Daily Cyber Threat Intel Brief — 2026-09-11

Generated: 2026-09-11 08:00:17 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=0, P2=1, P3=40, P4=209.
  • Highest-priority item: CISA: WatchGuard RCE flaw now exploited in ransomware attacks (P2, source: BleepingComputer Ransomware News).
  • 7 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P2 CISA: WatchGuard RCE flaw now exploited in ransomware attacks — BleepingComputer Ransomware News; score 57; technologies: none explicitly matched.
  • - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. [...]

    Newly exploited vulnerabilities / CVE watch

  • P3 CVE-2025-2137: Chromium: CVE-2025-2137 Out of bounds read in V8 — technologies: not watchlist-specific.
  • P3 CVE-2025-1920: Chromium: CVE-2025-1920 Type Confusion in V8 — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 CISA: WatchGuard RCE flaw now exploited in ransomware attacks — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in…
  • P3 Conti ransomware gang member sentenced to 4 years in prison — A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]
  • P3 New Android malware encrypts files, steals data, and harasses victims — A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...]
  • P3 Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers — Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]
  • P3 RansomLook: CO-OP URBAN BANK LTD claimed by global secret group — Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: CO-OP URBAN BANK LTD. Description excerpt: Country: India | Website:…
  • P3 RansomLook: i2k2 Networks claimed by vexy — Public RansomLook extortion-site listing claim. Group: vexy. Claimed victim/listing: i2k2 Networks. Description excerpt: i2k2 Networks Pvt. Ltd., established in 1999, is a leading Indian provider of cloud computing, web…
  • P3 RansomLook: M800 and CINNOX claimed by beast — Public RansomLook extortion-site listing claim. Group: beast. Claimed victim/listing: M800 and CINNOX. Description excerpt: M800 helps businesses connect globally with virtual numbers, SMS, voice calls, CINNOX, and…
  • P3 RansomLook: Sys-kool claimed by play — Public RansomLook extortion-site listing claim. Group: play. Claimed victim/listing: Sys-kool.
  • P3 RansomLook: Grunthal Welding & Supplies claimed by play — Public RansomLook extortion-site listing claim. Group: play. Claimed victim/listing: Grunthal Welding & Supplies.
  • P3 RansomLook: AUDIT ENTITY: ki*jp claimed by audit team — Public RansomLook extortion-site listing claim. Group: audit team. Claimed victim/listing: AUDIT ENTITY: ki*jp. Description excerpt: AUDIT ID: 9CB29482AF73366B / DISCOVERY DATE: 2026-09-09
  • P3 RansomLook: AUDIT ENTITY: my*ru claimed by audit team — Public RansomLook extortion-site listing claim. Group: audit team. Claimed victim/listing: AUDIT ENTITY: my*ru. Description excerpt: AUDIT ID: D91BED92A5A9223F / DISCOVERY DATE: 2026-09-09
  • P3 RansomLook: General Santos Doctors Hospital claimed by rhysida — Public RansomLook extortion-site listing claim. Group: rhysida. Claimed victim/listing: General Santos Doctors Hospital. Description excerpt: General Santos Doctors Hospital 3.502.636 files, total volume ~2.44 TBPatient…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1Oo3B9NwXjOYvxUPrWdwwAF6k906_Gz0T
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=GuLoader; url=https://drive.google.com/uc?export=download&id=1fshZMT3FceUeQeZJDnYCvzsuGeCKfVFN
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://38.55.99.215:8080/moot_loader.sh
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,GuLoader; url=http://auravibes04ko.shop/Giftlike.qxd
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=connectwise,rmm,screenconnect,zip; url=https://download.pocketbitcoindesktop.com/PocketSetupBundle.zip
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://103.249.199.3:42986/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://116.138.108.110:33491/i
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=honeypot,ssh; url=http://194.59.31.231:51346/b/linux
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://182.113.208.136:38769/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://123.188.86.36:49613/bin.sh
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=honeypot,ssh; url=http://194.59.31.231:51346/b/kswpad
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2025-2137`Chromium: CVE-2025-2137 Out of bounds read in V8Microsoft Security Response Center RSS
    cve`CVE-2025-1920`Chromium: CVE-2025-1920 Type Confusion in V8Microsoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    ipv4`38.55.99.215`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    hash`2b02392eb9ddc39713c83fafd8c4c1eae88b5bcf`RansomLook: California School Employees Association claimed by ransomhouseRansomLook Recent Listings
    hash`206a4cbc76440d74b64aea01d3bc429d`RansomLook: alphaomega-eng.com claimed by lockbit5RansomLook Recent Listings
    hash`c582d78870d0815a9f37d2ee92981af3`RansomLook: amorsaude.com.br claimed by lockbit5RansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=2 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=50
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=2 fetched=25
  • NVD Recent CVEs: ok new=4 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=69 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.