markcardiff.tech:/daily-intel/2026-09-13.html
Generated: 2026-09-13 08:00:45 UTC
P1: 1
P2: 1
Items: 250

Daily Cyber Threat Intel Brief — 2026-09-13

Generated: 2026-09-13 08:00:45 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=1, P2=1, P3=27, P4=221.
  • Highest-priority item: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent (P1, source: BleepingComputer Ransomware News).
  • 17 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent — BleepingComputer Ransomware News; score 74; technologies: none explicitly matched.
  • - The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]

  • P2 RansomLook: compunnel.com claimed by safepay — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: compunnel.com. Description excerpt: The company provides a combination of talent acquisition, IT consulting, digital engineering, artificial intelligence, cybersecurity,…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-85102, CVE-2026-85103: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: compunnel.com claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: compunnel.com. Description excerpt: The company provides a combination of talent acquisition, IT consulting, digital engineering,…
  • P3 RansomLook: INCOR Group claimed by doommageddon — Public RansomLook extortion-site listing claim. Group: doommageddon. Claimed victim/listing: INCOR Group. Description excerpt: upcoming | — | 0 files
  • P3 RansomLook: Canadian Mental Health Association claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Canadian Mental Health Association. Description excerpt: Healthcare | Toronto, Ontario, Canada | The Canadian Mental Health…
  • P3 RansomLook: watchops.com claimed by unsafe — Public RansomLook extortion-site listing claim. Group: unsafe. Claimed victim/listing: watchops.com. Description excerpt: Revenue: $1.3 million | Views: 209 | Posted: 9/12/2026, 6:51:26 PM | Status: 4d 21h 37m 52s
  • P3 RansomLook: www.tiflispalace.ge claimed by krybit — Public RansomLook extortion-site listing claim. Group: krybit. Claimed victim/listing: www.tiflispalace.ge. Description excerpt: Tiflis Palace is a luxurious boutique hotel located in the heart of Tbilisi, Georgia, in…
  • P3 RansomLook: www.tender.mx claimed by krybit — Public RansomLook extortion-site listing claim. Group: krybit. Claimed victim/listing: www.tender.mx. Description excerpt: Tender (Carnicería Tender) is a Mexican premium butcher shop chain (carnicería) founded under…
  • P3 RansomLook: capricornlogistics.com claimed by krybit — Public RansomLook extortion-site listing claim. Group: krybit. Claimed victim/listing: capricornlogistics.com. Description excerpt: Capricorn Logistics Pvt. Ltd. is an Indian comprehensive supply chain and logistics…
  • P3 RansomLook: www.ibnsinatrust.com claimed by krybit — Public RansomLook extortion-site listing claim. Group: krybit. Claimed victim/listing: www.ibnsinatrust.com. Description excerpt: The Ibn Sina Trust is a pioneering Bangladeshi non-profit welfare trust and major…
  • P3 RansomLook: lasultanahotels.com claimed by krybit — Public RansomLook extortion-site listing claim. Group: krybit. Claimed victim/listing: lasultanahotels.com. Description excerpt: La Sultana Hotel Group is a Moroccan luxury boutique hotel group created in the year 2000,…
  • P3 RansomLook: eracm.fr claimed by krybit — Public RansomLook extortion-site listing claim. Group: krybit. Claimed victim/listing: eracm.fr. Description excerpt: ERACM (École Régionale d'Acteurs de Cannes et Marseille) is a French non-profit association and…
  • P3 RansomLook: pss.ht claimed by krybit — Public RansomLook extortion-site listing claim. Group: krybit. Claimed victim/listing: pss.ht. Description excerpt: Professional Security Services S.A. (PSS) is a Haitian-owned private security services company…
  • P3 RansomLook: www.metalware.ca claimed by krybit — Public RansomLook extortion-site listing claim. Group: krybit. Claimed victim/listing: www.metalware.ca. Description excerpt: Metalware Corporation Inc. is Canada's leading industrial shelving manufacturer, founded in…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=CryptoMiner,elf,Gitea,monero,randomx,RCE,xmrig; url=http://79.137.203.132/2
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=CryptoMiner,elf,Gitea,monero,randomx,RCE,xmrig; url=http://79.137.203.132/3
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=https://true-soft.su/powershell/Loader.ps1
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=10x09x2026,dropped-by-Stealc; url=http://193.178.158.107/bin/46d0be2a38b04583_syshost_loader.exe
  • P4 Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware — A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,Mozi; url=http://103.125.31.101:42943/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://61.52.185.186:50792/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://105.184.25.143:33095/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://124.95.8.174:38161/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://39.70.74.23:34077/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://182.119.93.212:42539/i
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-85102`Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentBleepingComputer Ransomware News
    cve`CVE-2026-85103`Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentBleepingComputer Ransomware News
    ipv4`79.137.203.132`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    ipv4`193.178.158.107`URLhaus: malware_download URL observed (online)URLhaus Recent URLs
    hash`1140ecc00d2b1651dcbd7c391cc074b1fa2b77adbf4421216dd340d5d8ab4f3e`RansomLook: www.tiflispalace.ge claimed by krybitRansomLook Recent Listings
    hash`de0dc89e0f4664f6d02caa2089bc6175035d4fac821ea4afaf133681c2fc9ef9`RansomLook: www.tender.mx claimed by krybitRansomLook Recent Listings
    hash`f1e7412278c348e23c84729e5befb9a1e2b5edd1e58903452f5578e30513a010`RansomLook: capricornlogistics.com claimed by krybitRansomLook Recent Listings
    hash`33de9173455e1b961696e5f8c4742be6d8e49fa1659b7ca43d7fa56f50f674ff`RansomLook: www.ibnsinatrust.com claimed by krybitRansomLook Recent Listings
    hash`e9e57f9b6bfa99eb0ef2abf9853eeb3723fcbfcb5d26c3fd8edad8c493cc4f27`RansomLook: lasultanahotels.com claimed by krybitRansomLook Recent Listings
    hash`a34c6dc5ac3bd4acd0ff22b009c376c1630c21ed2aa3ba56630909633c198cba`RansomLook: eracm.fr claimed by krybitRansomLook Recent Listings
    hash`39102fbc625773f23653d85fad8d6e43df9118ea904daa96281bfe942d144994`RansomLook: pss.ht claimed by krybitRansomLook Recent Listings
    hash`d6c2af1136713d35a9c294992cbed89b7dd21acca7ff34b0549291a2eef5f4cd`RansomLook: www.metalware.ca claimed by krybitRansomLook Recent Listings
    hash`7741ca0d57e7ce30ba01b2b6353c6e3a44a4d2671e6f1ec11ec1ac39dc6ec73a`RansomLook: intherpro.com claimed by krybitRansomLook Recent Listings
    hash`b16512fce4145552826917836c6d8787057f72ee12e78f186354a9883fc304cc`RansomLook: meridian16.hr claimed by krybitRansomLook Recent Listings
    hash`9cb5fece49800a33eddaf3e4cd4a943612fe9701c7ace4e0d84b06784c09ef03`RansomLook: www.eac-airports.com claimed by krybitRansomLook Recent Listings
    hash`96a2ed6c25bce767b64fb11ed2280fd936b35cae45c11f0053a1c8b3e8278271`RansomLook: swadeshicipl.com claimed by krybitRansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=53
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=39 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=1 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=41 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.