Daily Cyber Threat Intel Brief — 2026-07-28
Generated: 2026-07-28 08:00:32 UTC
Executive summary
Priority technology watch items
- Public RansomLook extortion-site listing claim. Group: chaos. Claimed victim/listing: vit-best.com. Description excerpt: DATA BREACH NOTICE: VIT-BEST.COM Status: The first 3% of the total data (100%) has been published Countdown: 48 hours until the remaining…
- Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: BH Security, LLC. (brinkshome.com). Description excerpt: Over 4.9 million Salesforce records containing some PII was compromised. This is a final warning to reach out…
- Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: Park Manufacturing Corp.. Description excerpt: Overview Country: Cambridge, Minnesota 55008, US | Website: parkmfg.com | Revenue: $37.9 Million | Industry:…
- Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: Louisiana Coalition Against | Domestic Violence. Description excerpt: Overview Country: US | Website: lcadv.org | Revenue: $13.3 Million | Industry: Non-Profit…
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Katathani Phuket Beach Resort. Description excerpt: Katathani Phuket Beach Resort is a luxury beachfront resort located on Kata Noi Beach in Phuket, Thailand, offering…
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-50333` | CVE-2026-50333 Windows Spaceport.sys Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50697` | CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50343` | CVE-2026-50343 Microsoft Install Service Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-16461` | CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode ve | Microsoft Security Response Center RSS |
| cve | `CVE-2026-8450` | CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via se | Microsoft Security Response Center RSS |
| cve | `CVE-2026-16277` | CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist() | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64530` | CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle | Microsoft Security Response Center RSS |
| cve | `CVE-2024-14040` | CVE-2024-14040 net: nexthop: Increase weight to u16 | Microsoft Security Response Center RSS |
| ipv4 | `185.139.214.200` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| ipv4 | `91.199.133.133` | URLhaus: malware_download URL observed (online) | URLhaus Recent URLs |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| ipv4 | `91.92.242.236` | URLhaus: malware_download URL observed (online) | URLhaus Recent URLs |
| ipv4 | `178.20.41.208` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |