markcardiff.tech:/daily-intel/2026-08-07.html
Generated: 2026-08-07 08:00:54 UTC
P1: 6
P2: 11
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-07

Generated: 2026-08-07 08:00:54 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=6, P2=11, P3=120, P4=113.
  • Highest-priority item: CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability (P1, source: Microsoft Security Response Center RSS).
  • 30 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability — Microsoft Security Response Center RSS; score 75; technologies: SharePoint.
  • - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  • P1 CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

  • P1 CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.

  • P1 CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

  • P1 CVE-2026-63522 Azure SQL Database Elevation of Privilege Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.

  • P1 CVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

  • P2 RansomLook: Venture Logistics claimed by helix — RansomLook Recent Listings; score 58; technologies: SharePoint.
  • - Public RansomLook extortion-site listing claim. Group: helix. Claimed victim/listing: Venture Logistics. Description excerpt: SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer…

  • P2 RansomLook: Uber claimed by helix — RansomLook Recent Listings; score 58; technologies: SharePoint.
  • - Public RansomLook extortion-site listing claim. Group: helix. Claimed victim/listing: Uber. Description excerpt: SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0.

  • P2 RansomLook: Highwoods Properties claimed by helix — RansomLook Recent Listings; score 58; technologies: SharePoint.
  • - Public RansomLook extortion-site listing claim. Group: helix. Claimed victim/listing: Highwoods Properties. Description excerpt: SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer…

  • P2 Swiss government SharePoint breach compromised 200 accounts — BleepingComputer Ransomware News; score 54; technologies: SharePoint.
  • - Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. [...]

  • P2 RansomLook: Phase Technologies claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Phase Technologies. Description excerpt: phasetechnologies.com zoominfo.com/c/phase-technologies-llc/92275872 Phase Technologies is a leading American manufacturer…

  • P2 RansomLook: l-a.com.vn claimed by l group — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: l group. Claimed victim/listing: l-a.com.vn. Description excerpt: Founded in 2001, with twelve years operating in the field of developing high quality human resources in Vietnam, Le & Associates (L&A) is…

  • P2 RansomLook: onsite-eng.ca claimed by l group — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: l group. Claimed victim/listing: onsite-eng.ca. Description excerpt: Onsite Engineering Ltd. is a multidisciplinary firm that offers professional engineering, geotechnical, project management, and natural…

  • P2 RansomLook: Liberty Healthcare Corporation claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Liberty Healthcare Corporation. Description excerpt: Liberty Healthcare Corporation is a prominent health and human services management company that has been addressing…

  • P2 RansomLook: RS Automation Co., Ltd. claimed by barracuda — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: barracuda. Claimed victim/listing: RS Automation Co., Ltd.. Description excerpt: Full dump of all files from the servers and developers personal files and NAS. Legal documents, letters, drawings,…

  • P2 RansomLook: Primary Eye Care claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Primary Eye Care. Description excerpt: We offer a full range of options to meet your eyecare needs. From advanced custom LASIK laser vision correction and cataract…

  • P2 RansomLook: EduSpa claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: EduSpa. Description excerpt: Parkmungak has been operating since 1972, providing a range of services and products tailored to meet the needs of its clients. The…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-70332: CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability — technologies: SharePoint.
  • P1 CVE-2026-50516: CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-68823: CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-50515: CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-63522: CVE-2026-63522 Azure SQL Database Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-63508: CVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62836: CVE-2026-62836 Azure SQL Managed Instance Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62896: CVE-2026-62896 Microsoft Teams Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-65668: CVE-2026-65668 Microsoft Purview eDiscovery Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-59118: CVE-2026-59118 Microsoft Power Apps Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-50481: CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62918: CVE-2026-62918 Microsoft Teams Spoofing Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-59115: CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-49163: CVE-2026-49163 Application Insights Profiler Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-56161: CVE-2026-56161 Azure Logic Apps Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62830: CVE-2026-62830 Azure SRE Agent Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-65667: CVE-2026-65667 Microsoft Teams Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-56162: CVE-2026-56162 Azure SQL Database Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62869: CVE-2026-62869 Azure Entra ID Spoofing Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62873: CVE-2026-62873 Microsoft 365 Admin Center Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Venture Logistics claimed by helix — Public RansomLook extortion-site listing claim. Group: helix. Claimed victim/listing: Venture Logistics. Description excerpt: SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers…
  • P2 RansomLook: Uber claimed by helix — Public RansomLook extortion-site listing claim. Group: helix. Claimed victim/listing: Uber. Description excerpt: SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage…
  • P2 RansomLook: Highwoods Properties claimed by helix — Public RansomLook extortion-site listing claim. Group: helix. Claimed victim/listing: Highwoods Properties. Description excerpt: SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers…
  • P2 RansomLook: Phase Technologies claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Phase Technologies. Description excerpt: phasetechnologies.com zoominfo.com/c/phase-technologies-llc/92275872 Phase…
  • P2 RansomLook: l-a.com.vn claimed by l group — Public RansomLook extortion-site listing claim. Group: l group. Claimed victim/listing: l-a.com.vn. Description excerpt: Founded in 2001, with twelve years operating in the field of developing high quality human…
  • P2 RansomLook: onsite-eng.ca claimed by l group — Public RansomLook extortion-site listing claim. Group: l group. Claimed victim/listing: onsite-eng.ca. Description excerpt: Onsite Engineering Ltd. is a multidisciplinary firm that offers professional engineering,…
  • P2 RansomLook: Liberty Healthcare Corporation claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Liberty Healthcare Corporation. Description excerpt: Liberty Healthcare Corporation is a prominent health and human services…
  • P2 RansomLook: RS Automation Co., Ltd. claimed by barracuda — Public RansomLook extortion-site listing claim. Group: barracuda. Claimed victim/listing: RS Automation Co., Ltd.. Description excerpt: Full dump of all files from the servers and developers personal files and NAS.…
  • P2 RansomLook: Primary Eye Care claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Primary Eye Care. Description excerpt: We offer a full range of options to meet your eyecare needs. From advanced custom LASIK…
  • P2 RansomLook: EduSpa claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: EduSpa. Description excerpt: Parkmungak has been operating since 1972, providing a range of services and products tailored to…
  • P3 RansomLook: DHC claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: DHC. Description excerpt: dhc.co.jp zoominfo.com/c/dhc-corp/372590440 DHC Corporation is a prominent Japanese brand renowned…
  • P3 RansomLook: INKA Group GmbH Co claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: INKA Group GmbH Co. Description excerpt: INKA Group GmbH & Co. KG is a German real estate holding company headquartered in…
  • Malware / infrastructure / abuse feed highlights

  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=94-154-43-189,DEU,elf,geofenced,mirai,QuirkBotnet; url=http://94.154.43.189/mipsel
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=94-154-43-189,DEU,geofenced,QuirkBotnet,sh; url=http://94.154.43.189/dl.sh
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=94-154-43-189,DEU,elf,geofenced,QuirkBotnet; url=http://94.154.43.189/mips64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=94-154-43-189,DEU,elf,geofenced,QuirkBotnet; url=http://94.154.43.189/riscv64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=94-154-43-189,DEU,elf,geofenced,mirai,QuirkBotnet; url=http://94.154.43.189/ppc64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=94-154-43-189,DEU,elf,geofenced,QuirkBotnet; url=http://94.154.43.189/m68k
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=94-154-43-189,DEU,elf,geofenced,QuirkBotnet; url=http://94.154.43.189/s390x
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=94-154-43-189,DEU,elf,geofenced,mirai,QuirkBotnet; url=http://94.154.43.189/mips64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=rat,RemcosRAT; url=https://pocopaco.co.za/img_110418.png
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ascii; url=http://91.92.40.18:8081/loader.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ps1; url=http://94.26.83.35/ehrvdypc-gjc7hs5p-ysqckcka-5z3sw8fk/VKJEROWP.msi
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-70332`CVE-2026-70332 Microsoft Office SharePoint Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50516`CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-68823`CVE-2026-68823 Azure Confidential Ledger Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50515`CVE-2026-50515 Azure Service Bus Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-63522`CVE-2026-63522 Azure SQL Database Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-63508`CVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62836`CVE-2026-62836 Azure SQL Managed Instance Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62896`CVE-2026-62896 Microsoft Teams Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-65668`CVE-2026-65668 Microsoft Purview eDiscovery Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-59118`CVE-2026-59118 Microsoft Power Apps Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50481`CVE-2026-50481 Azure Active Directory Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62918`CVE-2026-62918 Microsoft Teams Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-59115`CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-49163`CVE-2026-49163 Application Insights Profiler Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-56161`CVE-2026-56161 Azure Logic Apps Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62830`CVE-2026-62830 Azure SRE Agent Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-65667`CVE-2026-65667 Microsoft Teams Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-56162`CVE-2026-56162 Azure SQL Database Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62869`CVE-2026-62869 Azure Entra ID Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62873`CVE-2026-62873 Microsoft 365 Admin Center Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-55050`CVE-2026-55050 Microsoft Word Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    ipv4`94.154.43.189`URLhaus: malware_download URL observed (online)URLhaus Recent URLs
    ipv4`91.92.40.18`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    hash`6a016f41ca1953ff139063dbb3c3871fbf732c574f69562ccc6db847eb3f24e2`RansomLook: reflet2000.fr claimed by krybitRansomLook Recent Listings
    hash`8a0bdf901623710a4eef9699878ae33d2fc778edb5e3b5f6302f955744120676`RansomLook: www.actini.com claimed by krybitRansomLook Recent Listings
    hash`80cae2a90e73a84acb9e51e10c40dd58a836d3f650b8f27c39558c72443c56f2`RansomLook: www.ernat-bureau-etudes.fr claimed by krybitRansomLook Recent Listings
    hash`7e121542cd77343c3ec610ab2858bc58699b2db394b17158f892e8aecab5efa5`RansomLook: www.serengetiestates.co.za claimed by krybitRansomLook Recent Listings
    hash`1ab5f193436e8e5bac8c4accc7a225451aa0ed1ca4e6d65d8a1491dc289a84f0`RansomLook: www.hymiasa.com claimed by krybitRansomLook Recent Listings
    hash`ebf1b68993fb6222ae653b1fa298cbccbc64e605`RansomLook: TECHVENTURES BANK S.A. claimed by ransomhouseRansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=38
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=38 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=24 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=1 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=19 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.