Daily Cyber Threat Intel Brief — 2026-07-27
Generated: 2026-07-27 08:00:24 UTC
Executive summary
Collected 250 recent public-source CTI items for technology-only monitoring.
Priority distribution: P1=0, P2=7, P3=197, P4=46.
Highest-priority item: RansomLook: Katathani Phuket Beach Resort claimed by dragonforce (P2, source: RansomLook Recent Listings).
8 public IOC highlights selected for analyst awareness.
Priority technology watch items
P2 RansomLook: Katathani Phuket Beach Resort claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Katathani Phuket Beach Resort. Description excerpt: Katathani Phuket Beach Resort is a luxury beachfront resort located on Kata Noi Beach in Phuket, Thailand, offering…
P2 RansomLook: West African Resources ltd claimed by deadlock — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: deadlock. Claimed victim/listing: West African Resources ltd. Description excerpt: West African Resources Limited (ASX: WAF) isan Australia-based, mid-tier gold mining and exploration companywith its…
P2 RansomLook: Syntron Bioresearch claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Syntron Bioresearch. Description excerpt: Syntron Bioresearch, Inc. specializes in manufacturing rapid in vitro diagnostic tests and detection readers, focusing on…
P2 RansomLook: Deluxe Medical Supply claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Deluxe Medical Supply. Description excerpt: Deluxe Medical Supply is a distributor of healthcare supplies that focuses on delivering quality home healthcare products…
P2 RansomLook: Police National Legal Database claimed by exfilsquad — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: exfilsquad. Claimed victim/listing: Police National Legal Database. Description excerpt: COUNTRY : GB REVENUE : NA SIZE : 1.9 GB UNCOMPRESSED ======================================== DATA SUMMARY: 135k…
P2 RansomLook: Nourison | Home claimed by global secret group — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: Nourison | Home. Description excerpt: Overview Country: New Jersey 07663, US | Website: nourison.com | Revenue: $59.4 Million | Industry: Wholesale, Furniture,…
P2 RansomLook: Carpets Direct claimed by global secret group — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: Carpets Direct. Description excerpt: Overview Country: Ohio, United States | Website: carpetsdirectfindlay.com | Revenue: $5 Million | Industry:…
Newly exploited vulnerabilities / CVE watch
P3 CVE-2026-16461: CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting — technologies: not watchlist-specific.
P3 CVE-2026-8450: CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file() — technologies: not watchlist-specific.
P3 CVE-2026-16277: CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist() — technologies: not watchlist-specific.
P3 CVE-2026-64530: CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle — technologies: not watchlist-specific.
P3 CVE-2024-14040: CVE-2024-14040 net: nexthop: Increase weight to u16 — technologies: not watchlist-specific.
Ransomware and extortion trend notes
P2 RansomLook: Katathani Phuket Beach Resort claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Katathani Phuket Beach Resort. Description excerpt: Katathani Phuket Beach Resort is a luxury beachfront resort located on Kata…
P2 RansomLook: West African Resources ltd claimed by deadlock — Public RansomLook extortion-site listing claim. Group: deadlock. Claimed victim/listing: West African Resources ltd. Description excerpt: West African Resources Limited (ASX: WAF) isan Australia-based, mid-tier gold…
P2 RansomLook: Syntron Bioresearch claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Syntron Bioresearch. Description excerpt: Syntron Bioresearch, Inc. specializes in manufacturing rapid in vitro diagnostic…
P2 RansomLook: Deluxe Medical Supply claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Deluxe Medical Supply. Description excerpt: Deluxe Medical Supply is a distributor of healthcare supplies that focuses on…
P2 RansomLook: Police National Legal Database claimed by exfilsquad — Public RansomLook extortion-site listing claim. Group: exfilsquad. Claimed victim/listing: Police National Legal Database. Description excerpt: COUNTRY : GB REVENUE : NA SIZE : 1.9 GB UNCOMPRESSED…
P2 RansomLook: Nourison | Home claimed by global secret group — Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: Nourison | Home. Description excerpt: Overview Country: New Jersey 07663, US | Website: nourison.com | Revenue: $59.4…
P2 RansomLook: Carpets Direct claimed by global secret group — Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: Carpets Direct. Description excerpt: Overview Country: Ohio, United States | Website: carpetsdirectfindlay.com |…
P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=incransom,Ransomware; url=http://178.20.41.208:1002/login
P3 RansomLook: Tesco Engineer claimed by deadlock — Public RansomLook extortion-site listing claim. Group: deadlock. Claimed victim/listing: Tesco Engineer. Description excerpt: Tesco Engineer Co., Ltd. is a Thai construction and manufacturing company based in Bangkok,…
P3 RansomLook: Hardware Asesorias Software Ltda claimed by deadlock — Public RansomLook extortion-site listing claim. Group: deadlock. Claimed victim/listing: Hardware Asesorias Software Ltda. Description excerpt: Hardware Asesorías Software Ltda (HAS Ltda) is a technology provider based…
P3 RansomLook: takethehop.com claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: takethehop.com.
P3 RansomLook: Williams Accounting Professional claimed by genesis — Public RansomLook extortion-site listing claim. Group: genesis. Claimed victim/listing: Williams Accounting Professional. Description excerpt: A full service CPA firm
Malware / infrastructure / abuse feed highlights
P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=rev-base64-loader; url=http://192.162.199.78/public_files/AvLeMQb.txt
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,sandystudiogh-blog,ua-wget; url=http://sandystudiogh.blog/hiddenbin/zombie.ppc
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,sandystudiogh-blog,ua-wget; url=http://sandystudiogh.blog/hiddenbin/zombie.x86_64
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mail-sandystudiogh-blog,mirai,ua-wget; url=http://mail.sandystudiogh.blog/hiddenbin/zombie.m68k
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,sandystudiogh-blog,ua-wget; url=http://sandystudiogh.blog/hiddenbin/zombie.sh4
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,sandystudiogh-blog,ua-wget; url=http://sandystudiogh.blog/hiddenbin/zombie.arc
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,sandystudiogh-blog,ua-wget; url=http://sandystudiogh.blog/hiddenbin/zombie.arm6
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mail-sandystudiogh-blog,mirai,ua-wget; url=http://mail.sandystudiogh.blog/hiddenbin/zombie.x86
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai,sh,ua-wget,www-69cnc-duckdns-org; url=http://www.69cnc.duckdns.org/bins/wget.sh
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,sandystudiogh-blog,ua-wget; url=http://sandystudiogh.blog/hiddenbin/zombie.mpsl
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,sandystudiogh-blog,ua-wget; url=http://sandystudiogh.blog/hiddenbin/zombie.arm5
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-16461` | CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode ve | Microsoft Security Response Center RSS |
| cve | `CVE-2026-8450` | CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via se | Microsoft Security Response Center RSS |
| cve | `CVE-2026-16277` | CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist() | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64530` | CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle | Microsoft Security Response Center RSS |
| cve | `CVE-2024-14040` | CVE-2024-14040 net: nexthop: Increase weight to u16 | Microsoft Security Response Center RSS |
| ipv4 | `178.20.41.208` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| ipv4 | `192.162.199.78` | URLhaus: malware_download URL observed (online) | URLhaus Recent URLs |
Defensive takeaways
Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
Sources checked
BleepingComputer Ransomware News: ok new=0 fetched=15
CISA Known Exploited Vulnerabilities: ok new=0 fetched=35
Cisco Talos Blog: ok new=0 fetched=15
Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
Huntress Blog: ok new=0 fetched=25
Microsoft Security Response Center RSS: ok new=5 fetched=25
NVD Recent CVEs: ok new=22 fetched=80
ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
RansomLook Recent Listings: ok new=3 fetched=50
Rapid7 Blog: ok new=0 fetched=20
SANS Internet Storm Center: ok new=0 fetched=10
Sophos X-Ops: ok new=0 fetched=15
The DFIR Report: ok new=0 fetched=10
URLhaus Recent URLs: ok new=108 fetched=120
Unit 42 Threat Research: ok new=0 fetched=15
Limitations
Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
Technology-only matching can miss relevant items that do not name a tracked product explicitly.
Ransomware victim claims are actor/source claims unless independently corroborated.
IOC highlights are publicly sourced and should be validated before enforcement in production controls.