markcardiff.tech:/daily-intel/2026-09-14.html
Generated: 2026-09-14 08:00:17 UTC
P1: 1
P2: 0
Items: 250

Daily Cyber Threat Intel Brief — 2026-09-14

Generated: 2026-09-14 08:00:17 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=1, P2=0, P3=10, P4=239.
  • Highest-priority item: Hackers exploit Tencent app flaw to deploy GrayRabbit malware (P1, source: BleepingComputer Ransomware News).
  • 3 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 Hackers exploit Tencent app flaw to deploy GrayRabbit malware — BleepingComputer Ransomware News; score 74; technologies: none explicitly matched.
  • - Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-51990: Hackers exploit Tencent app flaw to deploy GrayRabbit malware — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P3 RansomLook: Gilco Scaffolding claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Gilco Scaffolding. Description excerpt: Construction
  • P3 RansomLook: Kimberly-Clark claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Kimberly-Clark. Description excerpt: This is a final warning to reach out by 16 Sep 2026 before we leak along with several…
  • P3 RansomLook: CARIDRO VAL DE LOIRE claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: CARIDRO VAL DE LOIRE. Description excerpt: Business Services
  • P3 RansomLook: www.kashkha.com claimed by krybit — Public RansomLook extortion-site listing claim. Group: krybit. Claimed victim/listing: www.kashkha.com. Description excerpt: Kashkha is a multinational modest fashion brand founded three decades ago in Dubai, UAE,…
  • P3 RansomLook: Strad Solutions claimed by vexy — Public RansomLook extortion-site listing claim. Group: vexy. Claimed victim/listing: Strad Solutions. Description excerpt: Strad Solutions provides cloud hosting, dedicated servers, managed IT, cybersecurity, and…
  • P3 RansomLook: Navitrans claimed by emperador — Public RansomLook extortion-site listing claim. Group: emperador. Claimed victim/listing: Navitrans. Description excerpt: Navitrans is a leading Colombian distributor and service provider specializing in commercial…
  • P3 RansomLook: AUDIT ENTITY: vi*in claimed by audit team — Public RansomLook extortion-site listing claim. Group: audit team. Claimed victim/listing: AUDIT ENTITY: vi*in. Description excerpt: AUDIT ID: 5DC9129A6EA7F384 / DISCOVERY DATE: 2026-09-13
  • P3 RansomLook: INCOR Group claimed by doommageddon — Public RansomLook extortion-site listing claim. Group: doommageddon. Claimed victim/listing: INCOR Group. Description excerpt: upcoming | — | 0 files
  • P3 RansomLook: Canadian Mental Health Association claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Canadian Mental Health Association. Description excerpt: Healthcare | Toronto, Ontario, Canada | The Canadian Mental Health…
  • Malware / infrastructure / abuse feed highlights

  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P4 Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware — A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://125.43.246.211:40926/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://101.59.79.119:50248/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=mirai; url=http://105.186.221.48:45881/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://113.228.148.143:56788/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://182.116.48.4:52963/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://101.59.79.119:50248/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://113.228.148.143:56788/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://112.239.122.204:54893/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=rat,RemcosRAT,stego; url=https://res.cloudinary.com/slwv2ypq/image/upload/v1789351375/img_220206.jpg
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=fakemas; url=https://workerstats.net/downloadables/nig20083.zip
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-51990`Hackers exploit Tencent app flaw to deploy GrayRabbit malwareBleepingComputer Ransomware News
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`f80863cff7bd3f7607c6486f3615c67a133e57a0cd5f4b6d749c3f1f3c3a1a9e`RansomLook: www.kashkha.com claimed by krybitRansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=1 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=53
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=48 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=54 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.