Daily Cyber Threat Intel Brief — 2026-07-30
Generated: 2026-07-30 08:00:51 UTC
Executive summary
Collected 250 recent public-source CTI items for technology-only monitoring.
Priority distribution: P1=2, P2=10, P3=100, P4=138.
Highest-priority item: CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity (P1, source: Rapid7 Blog).
3 public IOC highlights selected for analyst awareness.
Priority technology watch items
P1 CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity — Rapid7 Blog; score 77; technologies: none explicitly matched.
- Overview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score…
P1 Cisco warns of FMC static credential flaw exploited in zero-day attacks — BleepingComputer Ransomware News; score 74; technologies: none explicitly matched.
- Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. [...]
P2 RansomLook: Pyramid Analytics B.V. claimed by aurora — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: Pyramid Analytics B.V.. Description excerpt: Pyramid Analytics B.V. — a decision-intelligence platform company headquartered in Amsterdam, acquired by ServiceNow (NYSE:…
P2 RansomLook: Yue Ki Industrial claimed by morpheus — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: morpheus. Claimed victim/listing: Yue Ki Industrial. Description excerpt: Website: yueki.com.tw Revenue: $21 Million Yue Ki Industrial is a manufacturing company that creates high-quality industrial…
P2 RansomLook: Angel Hotel claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Angel Hotel. Description excerpt: angelpershore.co.uk zoominfo.com/c/angel-hotel/1153643926 The Angel, Pershore is a historic Tudor-origin hotel and restaurant…
P2 RansomLook: The Garfield County Sheriff Office claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: The Garfield County Sheriff Office. Description excerpt: garcosheriff.com The Garfield County Sheriff's Office is the primary law enforcement agency serving Garfield…
P2 RansomLook: ETA Technology Pvt claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: ETA Technology Pvt. Description excerpt: etatechnology.in zoominfo.com/c/eta-technology-pvt-ltd/432054929 ETA Technology is a Bangalore-based manufacturing company…
P2 RansomLook: Promatrix claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Promatrix. Description excerpt: promatrixcorp.com zoominfo.com/c/promatrix-corp/347777611 Promatrix Corp is a rapidly growing IT consulting and outsourcing company…
P2 RansomLook: Malaysian Nuclear Agency claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Malaysian Nuclear Agency. Description excerpt: nuclearmalaysia.gov.my zoominfo.com/c/malaysian-nuclear-agency/459120141 The Malaysian Nuclear Agency (Nuklear…
P2 RansomLook: StellarRAD Systems claimed by space bears — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: space bears. Claimed victim/listing: StellarRAD Systems. Description excerpt: Since 1981, StellarRAD Systems exists to solve the critical issues facing our clients, both large and small. We provide a…
P2 RansomLook: Bretford Manufacturing claimed by aurora — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: Bretford Manufacturing. Description excerpt: Bretford Manufacturing, Inc. is a privately held manufacturer of charging solutions for mobile devices, founded in 1948 and…
P2 How AI is Rewriting the Zero-Day Playbook for Preemptive Security — Rapid7 Blog; score 52; technologies: none explicitly matched.
- The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the…
Newly exploited vulnerabilities / CVE watch
P1 CVE-2026-63077: CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity — technologies: not watchlist-specific.
P1 CVE-2026-20316: Cisco warns of FMC static credential flaw exploited in zero-day attacks — technologies: not watchlist-specific.
Ransomware and extortion trend notes
P2 RansomLook: Pyramid Analytics B.V. claimed by aurora — Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: Pyramid Analytics B.V.. Description excerpt: Pyramid Analytics B.V. — a decision-intelligence platform company headquartered in…
P2 RansomLook: Yue Ki Industrial claimed by morpheus — Public RansomLook extortion-site listing claim. Group: morpheus. Claimed victim/listing: Yue Ki Industrial. Description excerpt: Website: yueki.com.tw Revenue: $21 Million Yue Ki Industrial is a manufacturing company…
P2 RansomLook: Angel Hotel claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Angel Hotel. Description excerpt: angelpershore.co.uk zoominfo.com/c/angel-hotel/1153643926 The Angel, Pershore is a historic…
P2 RansomLook: The Garfield County Sheriff Office claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: The Garfield County Sheriff Office. Description excerpt: garcosheriff.com The Garfield County Sheriff's Office is the primary…
P2 RansomLook: ETA Technology Pvt claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: ETA Technology Pvt. Description excerpt: etatechnology.in zoominfo.com/c/eta-technology-pvt-ltd/432054929 ETA Technology is a…
P2 RansomLook: Promatrix claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Promatrix. Description excerpt: promatrixcorp.com zoominfo.com/c/promatrix-corp/347777611 Promatrix Corp is a rapidly growing…
P2 RansomLook: Malaysian Nuclear Agency claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Malaysian Nuclear Agency. Description excerpt: nuclearmalaysia.gov.my zoominfo.com/c/malaysian-nuclear-agency/459120141 The…
P2 RansomLook: StellarRAD Systems claimed by space bears — Public RansomLook extortion-site listing claim. Group: space bears. Claimed victim/listing: StellarRAD Systems. Description excerpt: Since 1981, StellarRAD Systems exists to solve the critical issues facing our clients,…
P2 RansomLook: Bretford Manufacturing claimed by aurora — Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: Bretford Manufacturing. Description excerpt: Bretford Manufacturing, Inc. is a privately held manufacturer of charging solutions for…
P3 RansomLook: Adpo claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Adpo. Description excerpt: Freight & Logistics Services
P3 RansomLook: servitelco claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: servitelco. Description excerpt: Business Services
P3 RansomLook: Orimar claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Orimar. Description excerpt: Business Services
Malware / infrastructure / abuse feed highlights
P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://nigg.tashirpizza.su/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.arm7
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai,sh; url=http://nigg.tashirpizza.su/c.sh
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai,sh; url=http://nigg.tashirpizza.su/w.sh
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai,sh; url=http://nigg.tashirpizza.su/wget.sh
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://nigg.tashirpizza.su/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.ppc
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://nigg.tashirpizza.su/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.arm6
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://nigg.tashirpizza.su/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.arm5
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://nigg.tashirpizza.su/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.x86
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://nigg.tashirpizza.su/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.arm
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://nigg.tashirpizza.su/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.x86_64
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://nigg.tashirpizza.su/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.spc
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-63077` | CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity | Rapid7 Blog |
| cve | `CVE-2026-20316` | Cisco warns of FMC static credential flaw exploited in zero-day attacks | BleepingComputer Ransomware News |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
Defensive takeaways
Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
Sources checked
BleepingComputer Ransomware News: ok new=0 fetched=15
CISA Known Exploited Vulnerabilities: ok new=0 fetched=37
Cisco Talos Blog: ok new=0 fetched=15
Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
Huntress Blog: ok new=0 fetched=25
Microsoft Security Response Center RSS: ok new=0 fetched=25
NVD Recent CVEs: ok new=24 fetched=80
ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
RansomLook Recent Listings: ok new=33 fetched=50
Rapid7 Blog: ok new=0 fetched=20
SANS Internet Storm Center: ok new=0 fetched=10
Sophos X-Ops: ok new=0 fetched=15
The DFIR Report: ok new=0 fetched=10
URLhaus Recent URLs: ok new=76 fetched=120
Unit 42 Threat Research: ok new=0 fetched=15
Limitations
Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
Technology-only matching can miss relevant items that do not name a tracked product explicitly.
Ransomware victim claims are actor/source claims unless independently corroborated.
IOC highlights are publicly sourced and should be validated before enforcement in production controls.