markcardiff.tech:/daily-intel/2026-07-29.html
Generated: 2026-07-29 08:00:38 UTC
P1: 1
P2: 1
Items: 250

Daily Cyber Threat Intel Brief — 2026-07-29

Generated: 2026-07-29 08:00:38 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=1, P2=1, P3=95, P4=153.
  • Highest-priority item: Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232) (P1, source: Rapid7 Blog).
  • 10 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232) — Rapid7 Blog; score 77; technologies: none explicitly matched.
  • - Overview On July 22, 2026, Check Point published a security advisory for CVE-2026-16232 , an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging…

  • P2 How AI is Rewriting the Zero-Day Playbook for Preemptive Security — Rapid7 Blog; score 52; technologies: none explicitly matched.
  • - The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-16232: Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232) — technologies: not watchlist-specific.
  • P3 CVE-2026-13037: Chromium: CVE-2026-13037 Use after free in WebView — technologies: not watchlist-specific.
  • P3 CVE-2026-13032: Chromium: CVE-2026-13032 Use after free in WebGL — technologies: not watchlist-specific.
  • P3 CVE-2026-13030: Chromium: CVE-2026-13030 Uninitialized Use in GPU — technologies: not watchlist-specific.
  • P3 CVE-2026-13028: Chromium: CVE-2026-13028 Use after free in WebGL — technologies: not watchlist-specific.
  • P3 CVE-2026-50422: CVE-2026-50422 Windows NTFS Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-47301: CVE-2026-47301 Configuration Manager Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P3 RansomLook: AHENK lab claimed by deadlock — Public RansomLook extortion-site listing claim. Group: deadlock. Claimed victim/listing: AHENK lab. Description excerpt: Ahenk Laboratuvarı is an ISO 15189-accredited medical laboratory in Turkey, founded in 1998 and…
  • P3 RansomLook: Hoc claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Hoc. Description excerpt: Freight & Logistics Services
  • P3 RansomLook: Accesso NEW claimed by coinbase cartel — Public RansomLook extortion-site listing claim. Group: coinbase cartel. Claimed victim/listing: Accesso NEW. Description excerpt: Financial Software - $152.3 Million
  • P3 RansomLook: thecranewaregroup.com claimed by chaos — Public RansomLook extortion-site listing claim. Group: chaos. Claimed victim/listing: thecranewaregroup.com. Description excerpt: Craneware’s Public Deception: The Reality Behind the 'Non-Sensitive' Data Breach Recent…
  • P3 RansomLook: Buck Knives claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Buck Knives. Description excerpt: buckknives.com zoominfo.com/c/buck-knives-inc/16223110 Buck Knives is a historic American…
  • P3 RansomLook: Gran valle negocios claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Gran valle negocios. Description excerpt: Real Estate
  • P3 RansomLook: Della Casa Group AG claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: Della Casa Group AG.
  • P3 RansomLook: https://eclmn.com/ claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: https://eclmn.com/.
  • P3 RansomLook: Takis srl claimed by deadlock — Public RansomLook extortion-site listing claim. Group: deadlock. Claimed victim/listing: Takis srl. Description excerpt: Takis Biotech is an Italian biotechnology company founded in 2009 and headquartered in Rome. The…
  • P3 RansomLook: DIATER claimed by deadlock — Public RansomLook extortion-site listing claim. Group: deadlock. Claimed victim/listing: DIATER. Description excerpt: (Laboratorio de Diagnóstico y Aplicaciones Terapéuticas, SA), a Spanish biopharmaceutical company…
  • P3 RansomLook: Pasello claimed by deadlock — Public RansomLook extortion-site listing claim. Group: deadlock. Claimed victim/listing: Pasello. Description excerpt: Pasello Trattamenti Termici Srl , an Italian specialist company for the heat treatment of metal…
  • P3 RansomLook: B-K Tool & Design claimed by cmd organization — Public RansomLook extortion-site listing claim. Group: cmd organization. Claimed victim/listing: B-K Tool & Design. Description excerpt: Founded in 1981, B-K Tool & Design has transformed from a small machine shop into…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://nobleshadebu.pro/iran.armv6l
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://nobleshadebu.pro/iran.armv5l
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://nobleshadebu.pro/iran.sparc
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://nobleshadebu.pro/iran.armv7l
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://nobleshadebu.pro/iran.aarch64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://nobleshadebu.pro/iran.sh4
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://nobleshadebu.pro/iran.mips
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=fileless,Loader,pastebin,powershell; url=https://pstbn.dev/01KYJ2ZEKMT0TFTABKG9FNRT8W
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=fileless,Loader,pastebin,powershell; url=https://pstbn.dev/01KYJ2ZEKMT0TFTABKG9FNRT8W
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=fileless,Loader,pastebin,powershell; url=https://pstbn.dev/01KYJ3FWRGV7GTXPH4VQ7071TJ
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=fileless,Loader,pastebin,powershell; url=https://pstbn.dev/01KYHNYXVDRE60BM6QDQ95GJRV
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-16232`Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)Rapid7 Blog
    cve`CVE-2026-13037`Chromium: CVE-2026-13037 Use after free in WebViewMicrosoft Security Response Center RSS
    cve`CVE-2026-13032`Chromium: CVE-2026-13032 Use after free in WebGLMicrosoft Security Response Center RSS
    cve`CVE-2026-13030`Chromium: CVE-2026-13030 Uninitialized Use in GPUMicrosoft Security Response Center RSS
    cve`CVE-2026-13028`Chromium: CVE-2026-13028 Use after free in WebGLMicrosoft Security Response Center RSS
    cve`CVE-2026-50422`CVE-2026-50422 Windows NTFS Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-47301`CVE-2026-47301 Configuration Manager Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    ipv4`185.139.214.200`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    ipv4`91.199.133.133`URLhaus: malware_download URL observed (online)URLhaus Recent URLs

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=36
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=4 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=1 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=55 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.