markcardiff.tech:/daily-intel/2026-08-03.html
Generated: 2026-08-03 08:00:55 UTC
P1: 1
P2: 0
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-03

Generated: 2026-08-03 08:00:55 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=1, P2=0, P3=41, P4=208.
  • Highest-priority item: GitHub release: Nuclei Templates v10.4.7 - Release Notes (P1, source: ProjectDiscovery Nuclei Templates Releases).
  • 25 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 GitHub release: Nuclei Templates v10.4.7 - Release Notes — ProjectDiscovery Nuclei Templates Releases; score 90; technologies: Apache, WordPress.
  • - ### New Templates Added: `122` | CVEs Added: `49` | First-time contributions: `23` ### 🔥 Release Highlights 🔥 - [CVE-2026-63030] WordPress Core 6.9-7.0.1 - Pre-Auth Batch-Route Confusion (@slcyber, @mielverkerken, @pdteam, @flx-0x00) [critical] (kev) (vKEV) 🔥…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-44825, CVE-2026-46442, CVE-2026-48908, CVE-2026-56290, CVE-2026-56291, CVE-2026-58455, CVE-2026-60004, CVE-2026-63030: GitHub release: Nuclei Templates v10.4.7 - Release Notes — technologies: Apache, WordPress.
  • Ransomware and extortion trend notes

  • P3 RansomLook: www.prohealth.sg claimed by krybit — Public RansomLook extortion-site listing claim. Group: krybit. Claimed victim/listing: www.prohealth.sg. Description excerpt: ProHealth Medical Group Pte Ltd is a Singaporean private primary healthcare group founded in…
  • P3 RansomLook: INTERTRUST AUSTRALIA PTY LTD claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: INTERTRUST AUSTRALIA PTY LTD. Description excerpt: Real Estate
  • P3 RansomLook: Asset Flooring Group Australia claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Asset Flooring Group Australia. Description excerpt: Construction
  • P3 RansomLook: sirsa.it claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: sirsa.it. Description excerpt: SIRSA operates in the field of processing and molding plastic materials, offering concrete, safe,…
  • P3 RansomLook: sms-sme.com claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: sms-sme.com. Description excerpt: SMS-SME is a global leader in marine cargo access and securing equipment, specializing in RORO…
  • P3 RansomLook: adventusasia.com claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: adventusasia.com. Description excerpt: Adventus is a Top-Rated Information and Communications Technology (ICT) Solutions and…
  • P3 RansomLook: pcclimitedindia.com claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: pcclimitedindia.com. Description excerpt: PIONEER COLDSTORE & CLADDING PVT. LTD. (PCC) is Leading Manufactures of insulated Panels…
  • P3 RansomLook: delkartindustries.com claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: delkartindustries.com. Description excerpt: Delkart Industries Limited specializes in manufacturing high-quality custom felts,…
  • P3 RansomLook: micropack.com.ar claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: micropack.com.ar. Description excerpt: Micropack is a well-known food and household goods distributor that has been serving…
  • P3 RansomLook: setic-pourtier.com claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: setic-pourtier.com. Description excerpt: Consolidating gains and preparing the future, Setic, Pourtier C2S help you to stay ahead…
  • P3 RansomLook: microphase.com claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: microphase.com. Description excerpt: Microphase Corporation is an innovative and trusted customer-driven supplier of advanced…
  • P3 RansomLook: rai.com.br claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: rai.com.br. Description excerpt: Grupo Rái is one of the largest independent communication groups in Brazil, consisting of six…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=apk ,mamont; url=https://svo-poiskrat.vercel.app/?download=1
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=sh,ua-wget; url=http://95.164.53.73/loader.sh
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=mirai,opendir,sh,ua-wget; url=http://eclipsebible.com/loader.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,Mozi; url=http://114.217.176.113:46343/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://120.84.214.20:38525/i
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://182.127.177.43:53121/bin.sh
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,Mozi; url=http://114.217.176.113:46343/bin.sh
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=104-249-10-13,exe; url=http://104.249.10.13/bin/support.client.exe
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=104-249-10-144,connectwise,exe; url=https://104.249.10.144/Bin/ScreenConnect.ClientSetup.exe
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=104-249-10-144,connectwise,exe; url=https://104.249.10.144/bin/support.client.exe
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=104-239-66-212,exe; url=https://104.239.66.212/Bin/ScreenConnect.ClientSetup.exe
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-44825`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    cve`CVE-2026-46442`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    cve`CVE-2026-48908`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    cve`CVE-2026-56290`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    cve`CVE-2026-56291`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    cve`CVE-2026-58455`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    cve`CVE-2026-60004`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    cve`CVE-2026-63030`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    ipv4`95.164.53.73`URLhaus: malware_download URL observed (online)URLhaus Recent URLs
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`b26f712ae9a60d8aee7b5ca340e91954282701f31c9a817d379b67204c1d0700`RansomLook: www.prohealth.sg claimed by krybitRansomLook Recent Listings
    hash`5ae978b22b428452a44b7cc89d39d1bb`RansomLook: sirsa.it claimed by lockbit5RansomLook Recent Listings
    hash`e27f49d263d9834a137f5f384bab9f73`RansomLook: sms-sme.com claimed by lockbit5RansomLook Recent Listings
    hash`07f92c99e04e3d96553a61ed86715aad`RansomLook: adventusasia.com claimed by lockbit5RansomLook Recent Listings
    hash`9a593783a65e34b7872401f8ee684359`RansomLook: pcclimitedindia.com claimed by lockbit5RansomLook Recent Listings
    hash`600d0422c1ee2b3148c1c98a03c099d1`RansomLook: delkartindustries.com claimed by lockbit5RansomLook Recent Listings
    hash`4b07ec75b1efb19808c63edfd26011f3`RansomLook: micropack.com.ar claimed by lockbit5RansomLook Recent Listings
    hash`2bc56f4bc426a07fe15fefe7f4450202`RansomLook: setic-pourtier.com claimed by lockbit5RansomLook Recent Listings
    hash`3742ee83c76f0a2a6ba7afdc6ade0778`RansomLook: microphase.com claimed by lockbit5RansomLook Recent Listings
    hash`17b639c619ac44c30a70336f00bfae65`RansomLook: rai.com.br claimed by lockbit5RansomLook Recent Listings
    hash`2ea073dcb8125d80da0524a43349ee9ede82a2b282e2a208891df2dec4b09ad2`RansomLook: www.buzztrading104.co.za claimed by krybitRansomLook Recent Listings
    hash`6a32127c5ba7d063fd8b100d461d7dcbadda8e7f2f6511bcb2522552d419d6e2`RansomLook: www.ville-rinxent.fr claimed by krybitRansomLook Recent Listings
    hash`725feabbf69089428d055b7c3e9096a41c8e9766241ca334127b6359f22ef484`RansomLook: countrymotors.com.mx claimed by krybitRansomLook Recent Listings
    hash`1c48e1797ee85061116a99218394864a578a742c61184b9c0562ce5f65f96283`RansomLook: www.dcpartner.co.za claimed by krybitRansomLook Recent Listings
    hash`21f398416f104bd7a83b797ee2841f081c01d5a0dc105178a6c1f396570d6c38`RansomLook: nigeria.asa-international.com claimed by krybitRansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=33
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=56 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=1 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=87 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.