markcardiff.tech:/daily-intel/2026-09-16.html
Generated: 2026-09-16 08:00:43 UTC
P1: 6
P2: 4
Items: 250

Daily Cyber Threat Intel Brief — 2026-09-16

Generated: 2026-09-16 08:00:43 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=6, P2=4, P3=124, P4=116.
  • Highest-priority item: Hackers target WordPress sites via third-party WooCommerce plugin (P1, source: BleepingComputer Ransomware News).
  • 30 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 Hackers target WordPress sites via third-party WooCommerce plugin — BleepingComputer Ransomware News; score 79; technologies: WordPress.
  • - Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]

  • P1 CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild — Rapid7 Blog; score 77; technologies: none explicitly matched.
  • - Overview On September 14, 2026, Cisco published a security advisory for CVE-2026-76461 , a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and…

  • P1 CVE-2026-78517 Microsoft Office Word Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-73006 DirectWrite Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-68812 Microsoft Excel Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-69486 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • P2 CISA: Critical VMware RCE flaw now exploited by ransomware gangs — BleepingComputer Ransomware News; score 57; technologies: none explicitly matched.
  • - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...]

  • P2 Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites — BleepingComputer Ransomware News; score 54; technologies: WordPress.
  • - Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

  • P2 RansomLook: Community Property Management claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Community Property Management. Description excerpt: full data 200 GB+ We have been in business since 1978 as a management firm specializing in the management of common…

  • P2 RansomLook: Owen Leigh Optometry claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Owen Leigh Optometry. Description excerpt: Full DATA 400 GB+ The brain uses the eyes to gather information about our surroundings. The brain cannot process all our…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-76461: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild — technologies: not watchlist-specific.
  • P1 CVE-2026-78517: CVE-2026-78517 Microsoft Office Word Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-73006: CVE-2026-73006 DirectWrite Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-68812: CVE-2026-68812 Microsoft Excel Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-69486: CVE-2026-69486 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-68824: CVE-2026-68824 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-68841: CVE-2026-68841 Windows NTFS Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-68847: CVE-2026-68847 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69406: CVE-2026-69406 Windows Kernel Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69608: CVE-2026-69608 Microsoft Windows Search Component Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69605: CVE-2026-69605 Microsoft Install Service Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-80075: CVE-2026-80075 Windows Work Folders Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69286: CVE-2026-69286 Windows USB Audio Class Driver Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69321: CVE-2026-69321 Windows Power Dependency Coordinator Tampering Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69416: CVE-2026-69416 Windows DHCP Server Denial of Service Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69619: CVE-2026-69619 Windows exFAT File System Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69714: CVE-2026-69714 Windows Device Association Service Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-61923: CVE-2026-61923 Windows Display Enhancement Service Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62753: CVE-2026-62753 Windows HTTP.sys Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62772: CVE-2026-62772 Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 CISA: Critical VMware RCE flaw now exploited by ransomware gangs — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...]
  • P2 RansomLook: Community Property Management claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Community Property Management. Description excerpt: full data 200 GB+ We have been in business since 1978 as a management firm…
  • P2 RansomLook: Owen Leigh Optometry claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Owen Leigh Optometry. Description excerpt: Full DATA 400 GB+ The brain uses the eyes to gather information about our…
  • P3 RansomLook: Aarsleff claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Aarsleff. Description excerpt: Construction
  • P3 RansomLook: Hashimoto Jimuki claimed by vexy — Public RansomLook extortion-site listing claim. Group: vexy. Claimed victim/listing: Hashimoto Jimuki. Description excerpt: Japanese company providing office equipment, IT equipment and services, office furniture,…
  • P3 RansomLook: marlinhvac.com claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: marlinhvac.com. Description excerpt: Founded in 1989 by Michael and Richard Pellino, the company has developed more than three…
  • P3 RansomLook: neumerkel-gmbh.de claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: neumerkel-gmbh.de. Description excerpt: The business traces its origins to 1963 and has operated under the Neumerkel GmbH name…
  • P3 RansomLook: triniticaring.org claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: triniticaring.org. Description excerpt: The organization is jointly owned by Guardian Angels Senior Services of Elk River and…
  • P3 RansomLook: laconcepcion.com.mx claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: laconcepcion.com.mx. Description excerpt: The organization identifies itself as one of the principal private healthcare providers…
  • P3 RansomLook: meterex.com claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: meterex.com. Description excerpt: The company is headquartered in Langenfeld, North Rhine-Westphalia, and is legally registered as…
  • P3 RansomLook: stoecklin-kuechen.ch claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: stoecklin-kuechen.ch. Description excerpt: The company is based in Aesch near Basel and has developed from a traditional carpentry…
  • P3 RansomLook: ryomo.co.jp claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: ryomo.co.jp. Description excerpt: Established in January 1970 as a regional computer-services center, the company has developed…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=jar,minecraft,SilentNet,stealer; url=https://prestige-client.org/PrestigeLoader-26.2.jar
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=jar,minecraft,SilentNet,stealer; url=https://breezeclient.com/BreezeLoader-1.21.11.jar
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=encrypted,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1hftRGP_fORn9dGRhmKYth3Eg8BkK2H7B
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Encoded,GuLoader,rat,RemcosRAT; url=https://drive.google.com/uc?export=download&id=1aQEw42oLO2paAWiGDi6bsaSIcBkA4dLv
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://86.122.231.80/mipsel
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://86.122.231.80/sh4
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://5.182.210.61/858300
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://5.182.210.61/81c060
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://86.122.231.80/dc
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://5.182.210.61/2891b0
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=cowrie,honeypot,loader-payload; url=http://86.122.231.80/586
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-76461`CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the WildRapid7 Blog
    cve`CVE-2026-78517`CVE-2026-78517 Microsoft Office Word Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-73006`CVE-2026-73006 DirectWrite Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-68812`CVE-2026-68812 Microsoft Excel Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69486`CVE-2026-69486 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-68824`CVE-2026-68824 Connected User Experiences and Telemetry Elevation of Privilege VulnerabiliMicrosoft Security Response Center RSS
    cve`CVE-2026-68841`CVE-2026-68841 Windows NTFS Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-68847`CVE-2026-68847 Connected User Experiences and Telemetry Elevation of Privilege VulnerabiliMicrosoft Security Response Center RSS
    cve`CVE-2026-69406`CVE-2026-69406 Windows Kernel Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69608`CVE-2026-69608 Microsoft Windows Search Component Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69605`CVE-2026-69605 Microsoft Install Service Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-80075`CVE-2026-80075 Windows Work Folders Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69286`CVE-2026-69286 Windows USB Audio Class Driver Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69321`CVE-2026-69321 Windows Power Dependency Coordinator Tampering VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69416`CVE-2026-69416 Windows DHCP Server Denial of Service VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69619`CVE-2026-69619 Windows exFAT File System Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69714`CVE-2026-69714 Windows Device Association Service Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-61923`CVE-2026-61923 Windows Display Enhancement Service Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62753`CVE-2026-62753 Windows HTTP.sys Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62772`CVE-2026-62772 Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of PriMicrosoft Security Response Center RSS
    cve`CVE-2026-62717`CVE-2026-62717 Windows Message Queuing Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-80097`CVE-2026-80097 Microsoft Authenticator Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69559`CVE-2026-69559 Microsoft Teams for Android Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-65812`CVE-2026-65812 Microsoft Teams for Android Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-85893`CVE-2026-85893 Microsoft Edge (Chromium-based) Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    ipv4`86.122.231.80`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    ipv4`5.182.210.61`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    ipv4`5.182.210.174`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    ipv4`213.232.114.14`URLhaus: malware_download URL observed (online)URLhaus Recent URLs

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=1 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=54
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=17 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=3 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=117 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.