markcardiff.tech:/daily-intel/2026-07-28.html
Generated: 2026-07-28 08:00:32 UTC
P1: 0
P2: 5
Items: 250

Daily Cyber Threat Intel Brief — 2026-07-28

Generated: 2026-07-28 08:00:32 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=0, P2=5, P3=118, P4=127.
  • Highest-priority item: RansomLook: vit-best.com claimed by chaos (P2, source: RansomLook Recent Listings).
  • 13 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P2 RansomLook: vit-best.com claimed by chaos — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: chaos. Claimed victim/listing: vit-best.com. Description excerpt: DATA BREACH NOTICE: VIT-BEST.COM Status: The first 3% of the total data (100%) has been published Countdown: 48 hours until the remaining…

  • P2 RansomLook: BH Security, LLC. (brinkshome.com) claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: BH Security, LLC. (brinkshome.com). Description excerpt: Over 4.9 million Salesforce records containing some PII was compromised. This is a final warning to reach out…

  • P2 RansomLook: Park Manufacturing Corp. claimed by global secret group — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: Park Manufacturing Corp.. Description excerpt: Overview Country: Cambridge, Minnesota 55008, US | Website: parkmfg.com | Revenue: $37.9 Million | Industry:…

  • P2 RansomLook: Louisiana Coalition Against | Domestic Violence claimed by global secret group — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: Louisiana Coalition Against | Domestic Violence. Description excerpt: Overview Country: US | Website: lcadv.org | Revenue: $13.3 Million | Industry: Non-Profit…

  • P2 RansomLook: Katathani Phuket Beach Resort claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Katathani Phuket Beach Resort. Description excerpt: Katathani Phuket Beach Resort is a luxury beachfront resort located on Kata Noi Beach in Phuket, Thailand, offering…

    Newly exploited vulnerabilities / CVE watch

  • P3 CVE-2026-50333: CVE-2026-50333 Windows Spaceport.sys Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-50697: CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-50343: CVE-2026-50343 Microsoft Install Service Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-16461: CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting — technologies: not watchlist-specific.
  • P3 CVE-2026-8450: CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file() — technologies: not watchlist-specific.
  • P3 CVE-2026-16277: CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist() — technologies: not watchlist-specific.
  • P3 CVE-2026-64530: CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle — technologies: not watchlist-specific.
  • P3 CVE-2024-14040: CVE-2024-14040 net: nexthop: Increase weight to u16 — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: vit-best.com claimed by chaos — Public RansomLook extortion-site listing claim. Group: chaos. Claimed victim/listing: vit-best.com. Description excerpt: DATA BREACH NOTICE: VIT-BEST.COM Status: The first 3% of the total data (100%) has been published…
  • P2 RansomLook: BH Security, LLC. (brinkshome.com) claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: BH Security, LLC. (brinkshome.com). Description excerpt: Over 4.9 million Salesforce records containing some PII was…
  • P2 RansomLook: Park Manufacturing Corp. claimed by global secret group — Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: Park Manufacturing Corp.. Description excerpt: Overview Country: Cambridge, Minnesota 55008, US | Website: parkmfg.com…
  • P2 RansomLook: Louisiana Coalition Against | Domestic Violence claimed by global secret group — Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: Louisiana Coalition Against | Domestic Violence. Description excerpt: Overview Country: US | Website: lcadv.org |…
  • P2 RansomLook: Katathani Phuket Beach Resort claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Katathani Phuket Beach Resort. Description excerpt: Katathani Phuket Beach Resort is a luxury beachfront resort located on Kata…
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=incransom,Ransomware; url=http://178.20.41.208:1002/login
  • P3 Coca-Cola confirms data theft in Fairlife ransomware attack — The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. [...]
  • P3 RansomLook: https://affiniahealthcare.org/ claimed by termite — Public RansomLook extortion-site listing claim. Group: termite. Claimed victim/listing: https://affiniahealthcare.org/. Description excerpt: Affinia Healthcare
  • P3 RansomLook: minigrip.com.mx claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: minigrip.com.mx.
  • P3 RansomLook: DUCON claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: DUCON.
  • P3 RansomLook: greenecountyga.gov claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: greenecountyga.gov.
  • P3 RansomLook: foundationstofreedom.org claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: foundationstofreedom.org.
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=185-139-214-200,sh; url=http://185.139.214.200/loader.sh
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=elf,opendir,ua-wget,x86; url=http://91.199.133.133:8080/router_exploit_v2
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=elf,mirai,opendir,ua-wget,x86; url=http://91.199.133.133:8080/router_exploit
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=c2-monitor-auto,dropped-by-amadey,HijackLoader; url=http://91.92.242.236/files-129312398/files/file_73ed34a7752ecb3a.exe
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://dsgagfsahkfsahfjs.shop/zero.armv4l
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai,sh; url=http://dsgagfsahkfsahfjs.shop/payload.sh
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://dsgagfsahkfsahfjs.shop/zero.i486
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://dsgagfsahkfsahfjs.shop/zero.mipsel
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://dsgagfsahkfsahfjs.shop/zero.m68k
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://dsgagfsahkfsahfjs.shop/zero.armv7l
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://dsgagfsahkfsahfjs.shop/zero.x86_64
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-50333`CVE-2026-50333 Windows Spaceport.sys Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50697`CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50343`CVE-2026-50343 Microsoft Install Service Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-16461`CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode veMicrosoft Security Response Center RSS
    cve`CVE-2026-8450`CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via seMicrosoft Security Response Center RSS
    cve`CVE-2026-16277`CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()Microsoft Security Response Center RSS
    cve`CVE-2026-64530`CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handleMicrosoft Security Response Center RSS
    cve`CVE-2024-14040`CVE-2024-14040 net: nexthop: Increase weight to u16Microsoft Security Response Center RSS
    ipv4`185.139.214.200`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    ipv4`91.199.133.133`URLhaus: malware_download URL observed (online)URLhaus Recent URLs
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    ipv4`91.92.242.236`URLhaus: malware_download URL observed (online)URLhaus Recent URLs
    ipv4`178.20.41.208`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=36
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=3 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=1 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=84 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.