markcardiff.tech:/daily-intel/2026-08-04.html
Generated: 2026-08-04 08:00:53 UTC
P1: 1
P2: 3
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-04

Generated: 2026-08-04 08:00:53 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=1, P2=3, P3=32, P4=214.
  • Highest-priority item: GitHub release: Nuclei Templates v10.4.7 - Release Notes (P1, source: ProjectDiscovery Nuclei Templates Releases).
  • 20 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 GitHub release: Nuclei Templates v10.4.7 - Release Notes — ProjectDiscovery Nuclei Templates Releases; score 90; technologies: Apache, WordPress.
  • - ### New Templates Added: `122` | CVEs Added: `49` | First-time contributions: `23` ### 🔥 Release Highlights 🔥 - [CVE-2026-63030] WordPress Core 6.9-7.0.1 - Pre-Auth Batch-Route Confusion (@slcyber, @mielverkerken, @pdteam, @flx-0x00) [critical] (kev) (vKEV) 🔥…

  • P2 RansomLook: Baicizhan claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Baicizhan. Description excerpt: Baicizhan is a language learning platform specializing in English instruction. It offers a wide range of tools and resources designed…

  • P2 RansomLook: TUI China claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: TUI China. Description excerpt: An affiliate of TUI Group, the world's number one leisure tourism business, TUI China was established in late 2003 as the first joint…

  • P2 Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066) — Rapid7 Blog; score 52; technologies: none explicitly matched.
  • - Overview On July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066 , an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are =…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-44825, CVE-2026-46442, CVE-2026-48908, CVE-2026-56290, CVE-2026-56291, CVE-2026-58455, CVE-2026-60004, CVE-2026-63030: GitHub release: Nuclei Templates v10.4.7 - Release Notes — technologies: Apache, WordPress.
  • P2 CVE-2026-66066: Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066) — technologies: not watchlist-specific.
  • P3 CVE-2026-18577: N-able warns of N-central auth bypass flaw exploited in attacks — technologies: not watchlist-specific.
  • P3 CVE-2026-50416: CVE-2026-50416 Win32k Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-50493: CVE-2026-50493 DirectX Graphics Kernel Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Baicizhan claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Baicizhan. Description excerpt: Baicizhan is a language learning platform specializing in English instruction. It offers a wide…
  • P2 RansomLook: TUI China claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: TUI China. Description excerpt: An affiliate of TUI Group, the world's number one leisure tourism business, TUI China was…
  • P3 RansomLook: clintonhealthaccess.org claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: clintonhealthaccess.org.
  • P3 RansomLook: pushidrosal.id claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: pushidrosal.id.
  • P3 RansomLook: lccgroup.com claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: lccgroup.com.
  • P3 RansomLook: https://geleximco.vn/ claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: https://geleximco.vn/.
  • P3 RansomLook: azn.co.jp claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: azn.co.jp. Description excerpt: Founded in 1991, the company specializes in comprehensive asset management, inheritance planning,…
  • P3 RansomLook: southshorerecycling.com claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: southshorerecycling.com. Description excerpt: The company specializes in metal recycling, concrete and asphalt recycling, aggregate…
  • P3 RansomLook: cpu-ag.com claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: cpu-ag.com. Description excerpt: Founded in 1981 and headquartered in Friedberg, Bavaria, the company has more than four decades of…
  • P3 RansomLook: multiaqua.com claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: multiaqua.com. Description excerpt: Founded in 1999, the company specializes in the design, engineering, and production of…
  • P3 RansomLook: pradotuylaw.com claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: pradotuylaw.com. Description excerpt: The firm focuses on practice areas including personal injury, wrongful death, workplace…
  • P3 RansomLook: naskdoorinc.com claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: naskdoorinc.com. Description excerpt: Headquartered in West Chester, Pennsylvania, the company has served customers throughout…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=remcos; url=http://107.172.235.200/ww.adyen.comknowledge-hubpayment-gatewaymsclkid=0dcc9c9da58815369da2f6a715a7654d&utm_source=bing&utm_medium=cpc&utm_camiii.php
  • P3 Inside the Underground Business of the Android BTMOB RAT malware — Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales…
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 New DOUBLECUP ClickFix service hides malware in browser cache images — A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote…
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ps1; url=http://213.165.78.201/9876567890/crypted.ps1
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=vbe; url=http://217.154.188.255/36/ecc/iwantsomethingbetterformegetbackgoodthings.vbe
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://129.121.114.124/rOY
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://129.121.114.124/fUE0
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://129.121.114.124/oI5j
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://129.121.114.124/RKY
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://129.121.114.124/Yu9
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=exe,PhantomStealer; url=http://172.245.95.62/ph/velogs.exe
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-44825`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    cve`CVE-2026-46442`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    cve`CVE-2026-48908`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    cve`CVE-2026-56290`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    cve`CVE-2026-56291`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    cve`CVE-2026-58455`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    cve`CVE-2026-60004`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    cve`CVE-2026-63030`GitHub release: Nuclei Templates v10.4.7 - Release NotesProjectDiscovery Nuclei Templates Releases
    cve`CVE-2026-66066`Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)Rapid7 Blog
    ipv4`7.2.3.2`Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)Rapid7 Blog
    ipv4`8.0.5.1`Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)Rapid7 Blog
    ipv4`8.1.3.1`Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)Rapid7 Blog
    cve`CVE-2026-18577`N-able warns of N-central auth bypass flaw exploited in attacksBleepingComputer Ransomware News
    hash`0dcc9c9da58815369da2f6a715a7654d`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    ipv4`107.172.235.200`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    cve`CVE-2026-50416`CVE-2026-50416 Win32k Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50493`CVE-2026-50493 DirectX Graphics Kernel Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`f6f65115ec051af06829450763071a69fb9c21c0`RansomLook: PCL Holding claimed by ransomhouseRansomLook Recent Listings
    hash`06f7d45e0c97a87e0473d0f5a3eab706044f22b1`RansomLook: (DISCLOSED)Fidelity Services Group claimed by ransomhouseRansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=34
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=31 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=120 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.