Daily Cyber Threat Intel Brief — 2026-09-15
Generated: 2026-09-15 08:00:56 UTC
Executive summary
Priority technology watch items
- Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a critical path traversal vulnerability ( CWE-22 ) in the repository commits API…
- This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
- This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Sarku Japan. Description excerpt: sarkujapan.com zoominfo.com/c/sarku-japan/33898946 SARKU Japan Japan's #1 independent service & wholesale network for foreign cars…
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Dang Invest Group. Description excerpt: danginvestgroup.com Dang Invest Group zech family restaurant group from Ostrava, founded in 1998 by Vietnamese immigrants —…
- Public RansomLook extortion-site listing claim. Group: insomnia. Claimed victim/listing: Metropolitan Community Health Services. Description excerpt: Agape Health Services, a CCBHC/FQHC run by Metropolitan Community Health Services, offers sliding-scale…
- Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Aqualogus. Description excerpt: Aqualogus is a private engineering consulting firm that helps communities and businesses solve water-related challenges. They work closely…
- Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Agencia Estatal de Meteorología. Description excerpt: Agencia Estatal de Meteorología - AEMET is a governmental agency of Spain that provides comprehensive meteorological…
- Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Cerámicas Kantu. Description excerpt: Cerámicas Kantu S.A.C. is a Peruvian company specializing in the manufacturing of decorative tiles and accessories made from ceramic,…
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-85706` | CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild | Rapid7 Blog |
| cve | `CVE-2026-87497` | Chromium CVE-2026-87497: Uninitialized resource in Codecs | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87456` | Chromium CVE-2026-87456: Uninitialized resource in Media | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87505` | Chromium CVE-2026-87505: Incorrect authorization in FileSystem | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87504` | Chromium CVE-2026-87504: Use after free in Core | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87502` | Chromium CVE-2026-87502: Confused deputy in Fullscreen | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87501` | Chromium CVE-2026-87501: UI misrepresentation in Passwords | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87500` | Chromium CVE-2026-87500: Improper validation of array index in ANGLE | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87499` | Chromium CVE-2026-87499: Incorrect authorization in Network | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87498` | Chromium CVE-2026-87498: Missing authorization in WebUI | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87496` | Chromium CVE-2026-87496: UI misrepresentation in Browser | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87495` | Chromium CVE-2026-87495: Information leak in Scroll | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87494` | Chromium CVE-2026-87494: Use after free in Browser | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87493` | Chromium CVE-2026-87493: Missing authorization in FileSystem | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87492` | Chromium CVE-2026-87492: Incorrect authorization in DevTools | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87490` | Chromium CVE-2026-87490: Information leak in Transactions Platform | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87489` | Chromium CVE-2026-87489: Memory corruption in V8 | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87487` | Chromium CVE-2026-87487: Missing authorization in FileSystem | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87485` | Chromium CVE-2026-87485: Incorrect authorization in CORS | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87484` | Chromium CVE-2026-87484: UI misrepresentation in Geometry | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87480` | Chromium CVE-2026-87480: Use after free in Printing | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87458` | Chromium CVE-2026-87458: UI misrepresentation in Geometry | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87457` | Chromium CVE-2026-87457: Race condition in Updater | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87455` | Chromium CVE-2026-87455: Use after free in Aura | Microsoft Security Response Center RSS |
| cve | `CVE-2026-87454` | Chromium CVE-2026-87454: Information leak in Enterprise | Microsoft Security Response Center RSS |
| cve | `CVE-2026-85921` | CVE-2026-85921 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62721` | CVE-2026-62721 Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| ipv4 | `86.122.231.80` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| ipv4 | `5.182.210.61` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| ipv4 | `5.182.210.174` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |