markcardiff.tech:/daily-intel/2026-07-31.html
Generated: 2026-07-31 08:00:35 UTC
P1: 7
P2: 3
Items: 250

Daily Cyber Threat Intel Brief — 2026-07-31

Generated: 2026-07-31 08:00:35 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=7, P2=3, P3=73, P4=167.
  • Highest-priority item: Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310) (P1, source: Rapid7 Blog).
  • 9 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310) — Rapid7 Blog; score 77; technologies: none explicitly matched.
  • - Overview On July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server:…

  • P1 CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Acknowledgement Updated

  • P1 CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Informational Change. CVE ID stays the same.

  • P2 KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails — Rapid7 Blog; score 65; technologies: none explicitly matched.
  • - Overview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing library. The vulnerability…

  • P2 RansomLook: Pyramid Analytics B.V. claimed by aurora — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: Pyramid Analytics B.V.. Description excerpt: Pyramid Analytics B.V. — a decision-intelligence platform company headquartered in Amsterdam, acquired by ServiceNow (NYSE:…

  • P2 RansomLook: Yue Ki Industrial claimed by morpheus — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: morpheus. Claimed victim/listing: Yue Ki Industrial. Description excerpt: Website: yueki.com.tw Revenue: $21 Million Yue Ki Industrial is a manufacturing company that creates high-quality industrial…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-59309, CVE-2026-59310: Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310) — technologies: not watchlist-specific.
  • P1 CVE-2026-56197: CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-54128: CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-24304: CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-55129: CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-66803: CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-24304: CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P2 CVE-2026-66066: KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Pyramid Analytics B.V. claimed by aurora — Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: Pyramid Analytics B.V.. Description excerpt: Pyramid Analytics B.V. — a decision-intelligence platform company headquartered in…
  • P2 RansomLook: Yue Ki Industrial claimed by morpheus — Public RansomLook extortion-site listing claim. Group: morpheus. Claimed victim/listing: Yue Ki Industrial. Description excerpt: Website: yueki.com.tw Revenue: $21 Million Yue Ki Industrial is a manufacturing company…
  • P3 Microsoft Teams vishing attacks lead to Chaos ransomware attacks — Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...]
  • P3 RansomLook: Audio Precision, Inc claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Audio Precision, Inc. Description excerpt: Manufacturing
  • P3 RansomLook: Boyum IT Solutions (HOT!) claimed by genesis — Public RansomLook extortion-site listing claim. Group: genesis. Claimed victim/listing: Boyum IT Solutions (HOT!). Description excerpt: A provider of IT services
  • P3 RansomLook: C.A. Walker Construction claimed by genesis — Public RansomLook extortion-site listing claim. Group: genesis. Claimed victim/listing: C.A. Walker Construction. Description excerpt: A construction management company
  • P3 RansomLook: BLUEVISTALLC.COM claimed by clop — Public RansomLook extortion-site listing claim. Group: clop. Claimed victim/listing: BLUEVISTALLC.COM.
  • P3 RansomLook: RE/MAX 1st Choice claimed by gammax — Public RansomLook extortion-site listing claim. Group: gammax. Claimed victim/listing: RE/MAX 1st Choice. Description excerpt: RE/MAX 1st Choice Florida was established in 2005 and is managed by Katy and John…
  • P3 RansomLook: AguAseo claimed by gammax — Public RansomLook extortion-site listing claim. Group: gammax. Claimed victim/listing: AguAseo. Description excerpt: AguAseo is a Panamanian organization dedicated to maintaining cleanliness in the province of Colón. It…
  • P3 RansomLook: MAG USA Inc claimed by securotrop — Public RansomLook extortion-site listing claim. Group: securotrop. Claimed victim/listing: MAG USA Inc. Description excerpt: If the company does not contact us before 10/08/2026 the data will be published.
  • P3 RansomLook: https://straightperformance.de/ claimed by unsafe — Public RansomLook extortion-site listing claim. Group: unsafe. Claimed victim/listing: https://straightperformance.de/. Description excerpt: Revenue: 2 million | Views: 16727 | Posted: 6/28/2026, 10:31:51 PM | Status:…
  • P3 RansomLook: Deutsche Bank claimed by unsafe — Public RansomLook extortion-site listing claim. Group: unsafe. Claimed victim/listing: Deutsche Bank. Description excerpt: Revenue: 30 billion | Views: 17629 | Posted: 7/4/2026, 6:15:19 PM | Status: Leaked
  • Malware / infrastructure / abuse feed highlights

  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,mirai,sh; url=http://salmosnet.duckdns.org:5001/bins.sh
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,exe; url=http://salmosnet.duckdns.org:5001/bot.exe
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://salmosnet.duckdns.org:5001/arm
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://salmosnet.duckdns.org:5001/amd64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://salmosnet.duckdns.org:5001/arm5
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://salmosnet.duckdns.org:5001/mipsle
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://salmosnet.duckdns.org:5001/android_arm64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://salmosnet.duckdns.org:5001/arm64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://salmosnet.duckdns.org:5001/mips
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://83.219.1.198:37564/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://115.61.115.0:49998/i
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-59309`Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code ExecutRapid7 Blog
    cve`CVE-2026-59310`Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code ExecutRapid7 Blog
    cve`CVE-2026-56197`CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-54128`CVE-2026-54128 Windows DHCP Client Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-24304`CVE-2026-24304 Azure Cosmos DB Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-55129`CVE-2026-55129 Microsoft Office Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-66803`CVE-2026-66803 Azure Cosmos DB Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-66066`KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code ExRapid7 Blog
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=35
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=17 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=59 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.