Daily Cyber Threat Intel Brief — 2026-08-07
Generated: 2026-08-07 08:00:54 UTC
Executive summary
Priority technology watch items
- Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
- Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
- Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
- Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.
- Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
- Public RansomLook extortion-site listing claim. Group: helix. Claimed victim/listing: Venture Logistics. Description excerpt: SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer…
- Public RansomLook extortion-site listing claim. Group: helix. Claimed victim/listing: Uber. Description excerpt: SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer reaches 0.
- Public RansomLook extortion-site listing claim. Group: helix. Claimed victim/listing: Highwoods Properties. Description excerpt: SharePoint libraries staged T1 (least) → T4 (most). Release countdown live on Helix. Tiers unlock by stage when each set timer…
- Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. [...]
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Phase Technologies. Description excerpt: phasetechnologies.com zoominfo.com/c/phase-technologies-llc/92275872 Phase Technologies is a leading American manufacturer…
- Public RansomLook extortion-site listing claim. Group: l group. Claimed victim/listing: l-a.com.vn. Description excerpt: Founded in 2001, with twelve years operating in the field of developing high quality human resources in Vietnam, Le & Associates (L&A) is…
- Public RansomLook extortion-site listing claim. Group: l group. Claimed victim/listing: onsite-eng.ca. Description excerpt: Onsite Engineering Ltd. is a multidisciplinary firm that offers professional engineering, geotechnical, project management, and natural…
- Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Liberty Healthcare Corporation. Description excerpt: Liberty Healthcare Corporation is a prominent health and human services management company that has been addressing…
- Public RansomLook extortion-site listing claim. Group: barracuda. Claimed victim/listing: RS Automation Co., Ltd.. Description excerpt: Full dump of all files from the servers and developers personal files and NAS. Legal documents, letters, drawings,…
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Primary Eye Care. Description excerpt: We offer a full range of options to meet your eyecare needs. From advanced custom LASIK laser vision correction and cataract…
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: EduSpa. Description excerpt: Parkmungak has been operating since 1972, providing a range of services and products tailored to meet the needs of its clients. The…
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-70332` | CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50516` | CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-68823` | CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50515` | CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-63522` | CVE-2026-63522 Azure SQL Database Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-63508` | CVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62836` | CVE-2026-62836 Azure SQL Managed Instance Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62896` | CVE-2026-62896 Microsoft Teams Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-65668` | CVE-2026-65668 Microsoft Purview eDiscovery Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-59118` | CVE-2026-59118 Microsoft Power Apps Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50481` | CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62918` | CVE-2026-62918 Microsoft Teams Spoofing Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-59115` | CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-49163` | CVE-2026-49163 Application Insights Profiler Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-56161` | CVE-2026-56161 Azure Logic Apps Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62830` | CVE-2026-62830 Azure SRE Agent Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-65667` | CVE-2026-65667 Microsoft Teams Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-56162` | CVE-2026-56162 Azure SQL Database Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62869` | CVE-2026-62869 Azure Entra ID Spoofing Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62873` | CVE-2026-62873 Microsoft 365 Admin Center Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-55050` | CVE-2026-55050 Microsoft Word Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| ipv4 | `94.154.43.189` | URLhaus: malware_download URL observed (online) | URLhaus Recent URLs |
| ipv4 | `91.92.40.18` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| hash | `6a016f41ca1953ff139063dbb3c3871fbf732c574f69562ccc6db847eb3f24e2` | RansomLook: reflet2000.fr claimed by krybit | RansomLook Recent Listings |
| hash | `8a0bdf901623710a4eef9699878ae33d2fc778edb5e3b5f6302f955744120676` | RansomLook: www.actini.com claimed by krybit | RansomLook Recent Listings |
| hash | `80cae2a90e73a84acb9e51e10c40dd58a836d3f650b8f27c39558c72443c56f2` | RansomLook: www.ernat-bureau-etudes.fr claimed by krybit | RansomLook Recent Listings |
| hash | `7e121542cd77343c3ec610ab2858bc58699b2db394b17158f892e8aecab5efa5` | RansomLook: www.serengetiestates.co.za claimed by krybit | RansomLook Recent Listings |
| hash | `1ab5f193436e8e5bac8c4accc7a225451aa0ed1ca4e6d65d8a1491dc289a84f0` | RansomLook: www.hymiasa.com claimed by krybit | RansomLook Recent Listings |
| hash | `ebf1b68993fb6222ae653b1fa298cbccbc64e605` | RansomLook: TECHVENTURES BANK S.A. claimed by ransomhouse | RansomLook Recent Listings |