markcardiff.tech:/daily-intel/2026-09-12.html
Generated: 2026-09-12 08:00:54 UTC
P1: 9
P2: 3
Items: 250

Daily Cyber Threat Intel Brief — 2026-09-12

Generated: 2026-09-12 08:00:54 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=9, P2=3, P3=38, P4=200.
  • Highest-priority item: Metasploit Wrap Up: This One Goes to Sixteen! (P1, source: Rapid7 Blog).
  • 30 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 Metasploit Wrap Up: This One Goes to Sixteen! — Rapid7 Blog; score 82; technologies: Apache, SonicWall.
  • - This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have…

  • P1 CVE-2026-69461 Windows NTFS Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-69732 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-69860 Windows Imaging Component Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-71336 Windows Work Folder Service Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-81355 Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-73016 DirectWrite Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-80080 Microsoft Office Word Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-85892 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

  • P2 Artifactory flaws chained in attacks deploying backdoor malware — BleepingComputer Ransomware News; score 57; technologies: none explicitly matched.
  • - Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]

  • P2 RansomLook: compunnel.com claimed by safepay — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: compunnel.com. Description excerpt: The company provides a combination of talent acquisition, IT consulting, digital engineering, artificial intelligence, cybersecurity,…

  • P2 RansomLook: Medical Department Store claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Medical Department Store. Description excerpt: Medical Department Store in united state

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2025-54988, CVE-2025-66516: Metasploit Wrap Up: This One Goes to Sixteen! — technologies: Apache, SonicWall.
  • P1 CVE-2026-69461: CVE-2026-69461 Windows NTFS Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-69732: CVE-2026-69732 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-69860: CVE-2026-69860 Windows Imaging Component Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-71336: CVE-2026-71336 Windows Work Folder Service Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-81355: CVE-2026-81355 Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-73016: CVE-2026-73016 DirectWrite Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-80080: CVE-2026-80080 Microsoft Office Word Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-85892: CVE-2026-85892 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-85051: Chromium CVE-2026-85051: Type confusion in Compositing — technologies: not watchlist-specific.
  • P3 CVE-2026-85049: Chromium CVE-2026-85049: Use after free in Skia — technologies: not watchlist-specific.
  • P3 CVE-2026-85048: Chromium CVE-2026-85048: Use after free in Compositing — technologies: not watchlist-specific.
  • P3 CVE-2026-85045: Chromium CVE-2026-85045: Race condition in V8 — technologies: not watchlist-specific.
  • P3 CVE-2026-85043: Chromium CVE-2026-85043: Incomplete cleanup in Network — technologies: not watchlist-specific.
  • P3 CVE-2026-85042: Chromium CVE-2026-85042: Use after free in DevTools — technologies: not watchlist-specific.
  • P3 CVE-2026-84333: Chromium: CVE-2026-84333 Use after free in Dawn — technologies: not watchlist-specific.
  • P3 CVE-2026-84330: Chromium: CVE-2026-84330 UI misrepresentation in FullScreen — technologies: not watchlist-specific.
  • P3 CVE-2026-84352: Chromium: CVE-2026-84352 Use after free in WebGL — technologies: not watchlist-specific.
  • P3 CVE-2026-77490: CVE-2026-77490 Microsoft Edge (Chromium-based) Spoofing Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69468: CVE-2026-69468 Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: compunnel.com claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: compunnel.com. Description excerpt: The company provides a combination of talent acquisition, IT consulting, digital engineering,…
  • P2 RansomLook: Medical Department Store claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Medical Department Store. Description excerpt: Medical Department Store in united state
  • P3 Conti ransomware gang member sentenced to 4 years in prison — A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]
  • P3 RansomLook: Shelco Filters claimed by securotrop — Public RansomLook extortion-site listing claim. Group: securotrop. Claimed victim/listing: Shelco Filters. Description excerpt: If the company does not contact us before 20/09/2026, the data will be published.
  • P3 RansomLook: DiamondLease claimed by nightspire — Public RansomLook extortion-site listing claim. Group: nightspire. Claimed victim/listing: DiamondLease.
  • P3 RansomLook: Perimetral Oriental de Bogotá S.A.S. claimed by nightspire — Public RansomLook extortion-site listing claim. Group: nightspire. Claimed victim/listing: Perimetral Oriental de Bogotá S.A.S..
  • P3 RansomLook: Ozel & Ozel Laws Office claimed by nightspire — Public RansomLook extortion-site listing claim. Group: nightspire. Claimed victim/listing: Ozel & Ozel Laws Office.
  • P3 RansomLook: Imperial Healthcare Solutions claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Imperial Healthcare Solutions. Description excerpt: Healthcare Services
  • P3 RansomLook: Port of Tanjung Pelepas claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: Port of Tanjung Pelepas.
  • P3 RansomLook: Tuboaços da Amazônia Ltda. claimed by nightspire — Public RansomLook extortion-site listing claim. Group: nightspire. Claimed victim/listing: Tuboaços da Amazônia Ltda..
  • P3 RansomLook: Foss Inc. claimed by pear — Public RansomLook extortion-site listing claim. Group: pear. Claimed victim/listing: Foss Inc.. Description excerpt: Leading provider of installation, maintenance services to the energy industry
  • P3 RansomLook: Dustin Group claimed by fulcrumsec — Public RansomLook extortion-site listing claim. Group: fulcrumsec. Claimed victim/listing: Dustin Group.
  • Malware / infrastructure / abuse feed highlights

  • P2 Artifactory flaws chained in attacks deploying backdoor malware — Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=10x09x2026,dropped-by-Stealc; url=http://193.178.158.107/bin/46d0be2a38b04583_syshost_loader.exe
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=msstore,revoked-cert,signed,WailsLoader; url=https://adpayworks.b-cdn.net/download/1.1.2/AdPayWorks.exe
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=msstore,revoked-cert,signed,WailsLoader; url=https://raw.githubusercontent.com/HartayKirjonrw/sa4/refs/heads/main/Signature%20Nib.exe
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1Oo3B9NwXjOYvxUPrWdwwAF6k906_Gz0T
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=GuLoader; url=https://drive.google.com/uc?export=download&id=1fshZMT3FceUeQeZJDnYCvzsuGeCKfVFN
  • P4 Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware — A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://46.151.29.58:3232/xor-payload.b64
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://119.115.250.2:54313/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=c2-monitor-auto,dropped-by-amadey; url=http://91.92.242.236/files-129312398/files/file_e52c89b6e6519b51.exe
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=https://massgravel.dev/Update.zip
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2025-54988`Metasploit Wrap Up: This One Goes to Sixteen!Rapid7 Blog
    cve`CVE-2025-66516`Metasploit Wrap Up: This One Goes to Sixteen!Rapid7 Blog
    cve`CVE-2026-69461`CVE-2026-69461 Windows NTFS Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69732`CVE-2026-69732 Windows Link Layer Topology Discovery Protocol Remote Code Execution VulnerMicrosoft Security Response Center RSS
    cve`CVE-2026-69860`CVE-2026-69860 Windows Imaging Component Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-71336`CVE-2026-71336 Windows Work Folder Service Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-81355`CVE-2026-81355 Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-73016`CVE-2026-73016 DirectWrite Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-80080`CVE-2026-80080 Microsoft Office Word Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-85892`CVE-2026-85892 Microsoft Edge (Chromium-based) Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-85051`Chromium CVE-2026-85051: Type confusion in CompositingMicrosoft Security Response Center RSS
    cve`CVE-2026-85049`Chromium CVE-2026-85049: Use after free in SkiaMicrosoft Security Response Center RSS
    cve`CVE-2026-85048`Chromium CVE-2026-85048: Use after free in CompositingMicrosoft Security Response Center RSS
    cve`CVE-2026-85045`Chromium CVE-2026-85045: Race condition in V8Microsoft Security Response Center RSS
    cve`CVE-2026-85043`Chromium CVE-2026-85043: Incomplete cleanup in NetworkMicrosoft Security Response Center RSS
    cve`CVE-2026-85042`Chromium CVE-2026-85042: Use after free in DevToolsMicrosoft Security Response Center RSS
    cve`CVE-2026-84333`Chromium: CVE-2026-84333 Use after free in DawnMicrosoft Security Response Center RSS
    cve`CVE-2026-84330`Chromium: CVE-2026-84330 UI misrepresentation in FullScreenMicrosoft Security Response Center RSS
    cve`CVE-2026-84352`Chromium: CVE-2026-84352 Use after free in WebGLMicrosoft Security Response Center RSS
    cve`CVE-2026-77490`CVE-2026-77490 Microsoft Edge (Chromium-based) Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69468`CVE-2026-69468 Windows Volume Manager Extension Driver Elevation of Privilege VulnerabilitMicrosoft Security Response Center RSS
    cve`CVE-2026-70334`CVE-2026-70334 Visual Studio Code Security Feature Bypass VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-77499`CVE-2026-77499 Windows DHCP Server Denial of Service VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-81379`CVE-2026-81379 Visual Studio Code Security Feature Bypass VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-68894`CVE-2026-68894 Windows Error Reporting Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69314`CVE-2026-69314 Windows Device Association Broker Service Elevation of Privilege VulnerabilMicrosoft Security Response Center RSS
    cve`CVE-2026-69405`CVE-2026-69405 Windows DHCP Server Denial of Service VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-81963`CVE-2026-81963 Windows Update Stack Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2025-2137`Chromium: CVE-2025-2137 Out of bounds read in V8Microsoft Security Response Center RSS
    cve`CVE-2025-1920`Chromium: CVE-2025-1920 Type Confusion in V8Microsoft Security Response Center RSS

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=54
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=80 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=5 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=64 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.