markcardiff.tech:/daily-intel/2026-09-15.html
Generated: 2026-09-15 08:00:56 UTC
P1: 3
P2: 6
Items: 250

Daily Cyber Threat Intel Brief — 2026-09-15

Generated: 2026-09-15 08:00:56 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=3, P2=6, P3=153, P4=88.
  • Highest-priority item: CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild (P1, source: Rapid7 Blog).
  • 30 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild — Rapid7 Blog; score 77; technologies: none explicitly matched.
  • - Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a critical path traversal vulnerability ( CWE-22 ) in the repository commits API…

  • P1 Chromium CVE-2026-87497: Uninitialized resource in Codecs — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

  • P1 Chromium CVE-2026-87456: Uninitialized resource in Media — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

  • P2 RansomLook: Sarku Japan claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Sarku Japan. Description excerpt: sarkujapan.com zoominfo.com/c/sarku-japan/33898946 SARKU Japan Japan's #1 independent service & wholesale network for foreign cars…

  • P2 RansomLook: Dang Invest Group claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Dang Invest Group. Description excerpt: danginvestgroup.com Dang Invest Group zech family restaurant group from Ostrava, founded in 1998 by Vietnamese immigrants —…

  • P2 RansomLook: Metropolitan Community Health Services claimed by insomnia — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: insomnia. Claimed victim/listing: Metropolitan Community Health Services. Description excerpt: Agape Health Services, a CCBHC/FQHC run by Metropolitan Community Health Services, offers sliding-scale…

  • P2 RansomLook: Aqualogus claimed by panzer — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Aqualogus. Description excerpt: Aqualogus is a private engineering consulting firm that helps communities and businesses solve water-related challenges. They work closely…

  • P2 RansomLook: Agencia Estatal de Meteorología claimed by panzer — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Agencia Estatal de Meteorología. Description excerpt: Agencia Estatal de Meteorología - AEMET is a governmental agency of Spain that provides comprehensive meteorological…

  • P2 RansomLook: Cerámicas Kantu claimed by panzer — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Cerámicas Kantu. Description excerpt: Cerámicas Kantu S.A.C. is a Peruvian company specializing in the manufacturing of decorative tiles and accessories made from ceramic,…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-85706: CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild — technologies: not watchlist-specific.
  • P1 CVE-2026-87497: Chromium CVE-2026-87497: Uninitialized resource in Codecs — technologies: not watchlist-specific.
  • P1 CVE-2026-87456: Chromium CVE-2026-87456: Uninitialized resource in Media — technologies: not watchlist-specific.
  • P3 CVE-2026-87505: Chromium CVE-2026-87505: Incorrect authorization in FileSystem — technologies: not watchlist-specific.
  • P3 CVE-2026-87504: Chromium CVE-2026-87504: Use after free in Core — technologies: not watchlist-specific.
  • P3 CVE-2026-87502: Chromium CVE-2026-87502: Confused deputy in Fullscreen — technologies: not watchlist-specific.
  • P3 CVE-2026-87501: Chromium CVE-2026-87501: UI misrepresentation in Passwords — technologies: not watchlist-specific.
  • P3 CVE-2026-87500: Chromium CVE-2026-87500: Improper validation of array index in ANGLE — technologies: not watchlist-specific.
  • P3 CVE-2026-87499: Chromium CVE-2026-87499: Incorrect authorization in Network — technologies: not watchlist-specific.
  • P3 CVE-2026-87498: Chromium CVE-2026-87498: Missing authorization in WebUI — technologies: not watchlist-specific.
  • P3 CVE-2026-87496: Chromium CVE-2026-87496: UI misrepresentation in Browser — technologies: not watchlist-specific.
  • P3 CVE-2026-87495: Chromium CVE-2026-87495: Information leak in Scroll — technologies: not watchlist-specific.
  • P3 CVE-2026-87494: Chromium CVE-2026-87494: Use after free in Browser — technologies: not watchlist-specific.
  • P3 CVE-2026-87493: Chromium CVE-2026-87493: Missing authorization in FileSystem — technologies: not watchlist-specific.
  • P3 CVE-2026-87492: Chromium CVE-2026-87492: Incorrect authorization in DevTools — technologies: not watchlist-specific.
  • P3 CVE-2026-87490: Chromium CVE-2026-87490: Information leak in Transactions Platform — technologies: not watchlist-specific.
  • P3 CVE-2026-87489: Chromium CVE-2026-87489: Memory corruption in V8 — technologies: not watchlist-specific.
  • P3 CVE-2026-87487: Chromium CVE-2026-87487: Missing authorization in FileSystem — technologies: not watchlist-specific.
  • P3 CVE-2026-87485: Chromium CVE-2026-87485: Incorrect authorization in CORS — technologies: not watchlist-specific.
  • P3 CVE-2026-87484: Chromium CVE-2026-87484: UI misrepresentation in Geometry — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Sarku Japan claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Sarku Japan. Description excerpt: sarkujapan.com zoominfo.com/c/sarku-japan/33898946 SARKU Japan Japan's #1 independent…
  • P2 RansomLook: Dang Invest Group claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Dang Invest Group. Description excerpt: danginvestgroup.com Dang Invest Group zech family restaurant group from Ostrava,…
  • P2 RansomLook: Metropolitan Community Health Services claimed by insomnia — Public RansomLook extortion-site listing claim. Group: insomnia. Claimed victim/listing: Metropolitan Community Health Services. Description excerpt: Agape Health Services, a CCBHC/FQHC run by Metropolitan Community…
  • P2 RansomLook: Aqualogus claimed by panzer — Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Aqualogus. Description excerpt: Aqualogus is a private engineering consulting firm that helps communities and businesses solve…
  • P2 RansomLook: Agencia Estatal de Meteorología claimed by panzer — Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Agencia Estatal de Meteorología. Description excerpt: Agencia Estatal de Meteorología - AEMET is a governmental agency of Spain that…
  • P2 RansomLook: Cerámicas Kantu claimed by panzer — Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Cerámicas Kantu. Description excerpt: Cerámicas Kantu S.A.C. is a Peruvian company specializing in the manufacturing of decorative…
  • P3 RansomLook: Wada Farms claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Wada Farms. Description excerpt: wadafarms.com Wada Farms third-generation family potato empire from Idaho — founded 1945 by…
  • P3 How Attackers Abuse VSS, and How Huntress Detects It — Attackers exploit Volume Shadow Copy for credential theft and ransomware defense evasion. See how Huntress spots the difference from routine IT activity.
  • P3 RansomLook: Geieg claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Geieg. Description excerpt: Fitness & Dance Facilities
  • P3 RansomLook: Better Accounting Solutions claimed by anubis — Public RansomLook extortion-site listing claim. Group: anubis. Claimed victim/listing: Better Accounting Solutions. Description excerpt: Wall Street accountants data breach.
  • P3 RansomLook: McCarthy Tire Service claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: McCarthy Tire Service. Description excerpt: Manufacturing | Wilkes-Barre, Pennsylvania, United States | McCarthy Tire Service is a…
  • P3 RansomLook: PANTHERx Rare claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: PANTHERx Rare. Description excerpt: Healthcare | Pittsburgh, Pennsylvania, United States | PANTHERx Rare is a leading pharmacy…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://86.122.231.80/mipsel
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://86.122.231.80/sh4
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://5.182.210.61/858300
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://5.182.210.61/81c060
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://86.122.231.80/dc
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://5.182.210.61/2891b0
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://86.122.231.80/586
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://86.122.231.80/m68k
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://86.122.231.80/ppc
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://5.182.210.61/affd05
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://86.122.231.80/mips
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://86.122.231.80/dss
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-85706`CVE-2026-85706: Critical GitLab Path Traversal Exploited in the WildRapid7 Blog
    cve`CVE-2026-87497`Chromium CVE-2026-87497: Uninitialized resource in CodecsMicrosoft Security Response Center RSS
    cve`CVE-2026-87456`Chromium CVE-2026-87456: Uninitialized resource in MediaMicrosoft Security Response Center RSS
    cve`CVE-2026-87505`Chromium CVE-2026-87505: Incorrect authorization in FileSystemMicrosoft Security Response Center RSS
    cve`CVE-2026-87504`Chromium CVE-2026-87504: Use after free in CoreMicrosoft Security Response Center RSS
    cve`CVE-2026-87502`Chromium CVE-2026-87502: Confused deputy in FullscreenMicrosoft Security Response Center RSS
    cve`CVE-2026-87501`Chromium CVE-2026-87501: UI misrepresentation in PasswordsMicrosoft Security Response Center RSS
    cve`CVE-2026-87500`Chromium CVE-2026-87500: Improper validation of array index in ANGLEMicrosoft Security Response Center RSS
    cve`CVE-2026-87499`Chromium CVE-2026-87499: Incorrect authorization in NetworkMicrosoft Security Response Center RSS
    cve`CVE-2026-87498`Chromium CVE-2026-87498: Missing authorization in WebUIMicrosoft Security Response Center RSS
    cve`CVE-2026-87496`Chromium CVE-2026-87496: UI misrepresentation in BrowserMicrosoft Security Response Center RSS
    cve`CVE-2026-87495`Chromium CVE-2026-87495: Information leak in ScrollMicrosoft Security Response Center RSS
    cve`CVE-2026-87494`Chromium CVE-2026-87494: Use after free in BrowserMicrosoft Security Response Center RSS
    cve`CVE-2026-87493`Chromium CVE-2026-87493: Missing authorization in FileSystemMicrosoft Security Response Center RSS
    cve`CVE-2026-87492`Chromium CVE-2026-87492: Incorrect authorization in DevToolsMicrosoft Security Response Center RSS
    cve`CVE-2026-87490`Chromium CVE-2026-87490: Information leak in Transactions PlatformMicrosoft Security Response Center RSS
    cve`CVE-2026-87489`Chromium CVE-2026-87489: Memory corruption in V8Microsoft Security Response Center RSS
    cve`CVE-2026-87487`Chromium CVE-2026-87487: Missing authorization in FileSystemMicrosoft Security Response Center RSS
    cve`CVE-2026-87485`Chromium CVE-2026-87485: Incorrect authorization in CORSMicrosoft Security Response Center RSS
    cve`CVE-2026-87484`Chromium CVE-2026-87484: UI misrepresentation in GeometryMicrosoft Security Response Center RSS
    cve`CVE-2026-87480`Chromium CVE-2026-87480: Use after free in PrintingMicrosoft Security Response Center RSS
    cve`CVE-2026-87458`Chromium CVE-2026-87458: UI misrepresentation in GeometryMicrosoft Security Response Center RSS
    cve`CVE-2026-87457`Chromium CVE-2026-87457: Race condition in UpdaterMicrosoft Security Response Center RSS
    cve`CVE-2026-87455`Chromium CVE-2026-87455: Use after free in AuraMicrosoft Security Response Center RSS
    cve`CVE-2026-87454`Chromium CVE-2026-87454: Information leak in EnterpriseMicrosoft Security Response Center RSS
    cve`CVE-2026-85921`CVE-2026-85921 Windows Secure Kernel Mode Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62721`CVE-2026-62721 Windows User-Mode Power Service (UMPS) Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    ipv4`86.122.231.80`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    ipv4`5.182.210.61`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    ipv4`5.182.210.174`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=1 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=54
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=36 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=1 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=120 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.