Daily Cyber Threat Intel Brief — 2026-07-31
Generated: 2026-07-31 08:00:35 UTC
Executive summary
Collected 250 recent public-source CTI items for technology-only monitoring.
Priority distribution: P1=7, P2=3, P3=73, P4=167.
Highest-priority item: Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310) (P1, source: Rapid7 Blog).
9 public IOC highlights selected for analyst awareness.
Priority technology watch items
P1 Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310) — Rapid7 Blog; score 77; technologies: none explicitly matched.
- Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server:…
P1 CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Updated an acknowledgement. This is an informational change only.
P1 CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Updated an acknowledgement. This is an informational change only.
P1 CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
P1 CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Acknowledgement Updated
P1 CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
P1 CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Informational Change. CVE ID stays the same.
P2 KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails — Rapid7 Blog; score 65; technologies: none explicitly matched.
- Overview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing library. The vulnerability…
P2 RansomLook: Pyramid Analytics B.V. claimed by aurora — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: Pyramid Analytics B.V.. Description excerpt: Pyramid Analytics B.V. — a decision-intelligence platform company headquartered in Amsterdam, acquired by ServiceNow (NYSE:…
P2 RansomLook: Yue Ki Industrial claimed by morpheus — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: morpheus. Claimed victim/listing: Yue Ki Industrial. Description excerpt: Website: yueki.com.tw Revenue: $21 Million Yue Ki Industrial is a manufacturing company that creates high-quality industrial…
Newly exploited vulnerabilities / CVE watch
P1 CVE-2026-59309, CVE-2026-59310: Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310) — technologies: not watchlist-specific.
P1 CVE-2026-56197: CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability — technologies: not watchlist-specific.
P1 CVE-2026-54128: CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability — technologies: not watchlist-specific.
P1 CVE-2026-24304: CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability — technologies: not watchlist-specific.
P1 CVE-2026-55129: CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability — technologies: not watchlist-specific.
P1 CVE-2026-66803: CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability — technologies: not watchlist-specific.
P1 CVE-2026-24304: CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
P2 CVE-2026-66066: KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails — technologies: not watchlist-specific.
Ransomware and extortion trend notes
P2 RansomLook: Pyramid Analytics B.V. claimed by aurora — Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: Pyramid Analytics B.V.. Description excerpt: Pyramid Analytics B.V. — a decision-intelligence platform company headquartered in…
P2 RansomLook: Yue Ki Industrial claimed by morpheus — Public RansomLook extortion-site listing claim. Group: morpheus. Claimed victim/listing: Yue Ki Industrial. Description excerpt: Website: yueki.com.tw Revenue: $21 Million Yue Ki Industrial is a manufacturing company…
P3 Microsoft Teams vishing attacks lead to Chaos ransomware attacks — Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...]
P3 RansomLook: Audio Precision, Inc claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Audio Precision, Inc. Description excerpt: Manufacturing
P3 RansomLook: Boyum IT Solutions (HOT!) claimed by genesis — Public RansomLook extortion-site listing claim. Group: genesis. Claimed victim/listing: Boyum IT Solutions (HOT!). Description excerpt: A provider of IT services
P3 RansomLook: C.A. Walker Construction claimed by genesis — Public RansomLook extortion-site listing claim. Group: genesis. Claimed victim/listing: C.A. Walker Construction. Description excerpt: A construction management company
P3 RansomLook: BLUEVISTALLC.COM claimed by clop — Public RansomLook extortion-site listing claim. Group: clop. Claimed victim/listing: BLUEVISTALLC.COM.
P3 RansomLook: RE/MAX 1st Choice claimed by gammax — Public RansomLook extortion-site listing claim. Group: gammax. Claimed victim/listing: RE/MAX 1st Choice. Description excerpt: RE/MAX 1st Choice Florida was established in 2005 and is managed by Katy and John…
P3 RansomLook: AguAseo claimed by gammax — Public RansomLook extortion-site listing claim. Group: gammax. Claimed victim/listing: AguAseo. Description excerpt: AguAseo is a Panamanian organization dedicated to maintaining cleanliness in the province of Colón. It…
P3 RansomLook: MAG USA Inc claimed by securotrop — Public RansomLook extortion-site listing claim. Group: securotrop. Claimed victim/listing: MAG USA Inc. Description excerpt: If the company does not contact us before 10/08/2026 the data will be published.
P3 RansomLook: https://straightperformance.de/ claimed by unsafe — Public RansomLook extortion-site listing claim. Group: unsafe. Claimed victim/listing: https://straightperformance.de/. Description excerpt: Revenue: 2 million | Views: 16727 | Posted: 6/28/2026, 10:31:51 PM | Status:…
P3 RansomLook: Deutsche Bank claimed by unsafe — Public RansomLook extortion-site listing claim. Group: unsafe. Claimed victim/listing: Deutsche Bank. Description excerpt: Revenue: 30 billion | Views: 17629 | Posted: 7/4/2026, 6:15:19 PM | Status: Leaked
Malware / infrastructure / abuse feed highlights
P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai,sh; url=http://salmosnet.duckdns.org:5001/bins.sh
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,exe; url=http://salmosnet.duckdns.org:5001/bot.exe
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://salmosnet.duckdns.org:5001/arm
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://salmosnet.duckdns.org:5001/amd64
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://salmosnet.duckdns.org:5001/arm5
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://salmosnet.duckdns.org:5001/mipsle
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://salmosnet.duckdns.org:5001/android_arm64
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://salmosnet.duckdns.org:5001/arm64
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://salmosnet.duckdns.org:5001/mips
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://83.219.1.198:37564/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://115.61.115.0:49998/i
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-59309` | Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execut | Rapid7 Blog |
| cve | `CVE-2026-59310` | Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execut | Rapid7 Blog |
| cve | `CVE-2026-56197` | CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-54128` | CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-24304` | CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-55129` | CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-66803` | CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-66066` | KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Ex | Rapid7 Blog |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
Defensive takeaways
Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
Sources checked
BleepingComputer Ransomware News: ok new=0 fetched=15
CISA Known Exploited Vulnerabilities: ok new=0 fetched=35
Cisco Talos Blog: ok new=0 fetched=15
Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
Huntress Blog: ok new=0 fetched=25
Microsoft Security Response Center RSS: ok new=0 fetched=25
NVD Recent CVEs: ok new=17 fetched=80
ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
RansomLook Recent Listings: ok new=0 fetched=50
Rapid7 Blog: ok new=0 fetched=20
SANS Internet Storm Center: ok new=0 fetched=10
Sophos X-Ops: ok new=0 fetched=15
The DFIR Report: ok new=0 fetched=10
URLhaus Recent URLs: ok new=59 fetched=120
Unit 42 Threat Research: ok new=0 fetched=15
Limitations
Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
Technology-only matching can miss relevant items that do not name a tracked product explicitly.
Ransomware victim claims are actor/source claims unless independently corroborated.
IOC highlights are publicly sourced and should be validated before enforcement in production controls.