markcardiff.tech:/daily-intel/2026-08-08.html
Generated: 2026-08-08 08:00:42 UTC
P1: 3
P2: 2
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-08

Generated: 2026-08-08 08:00:42 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=3, P2=2, P3=121, P4=124.
  • Highest-priority item: CVE-2010-4052 Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD. (P1, source: Microsoft Security Response Center RSS).
  • 30 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 [CVE-2010-4052 Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD.](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2010-4052) — Microsoft Security Response Center RSS; score 82; technologies: none explicitly matched.
  • - Information published.

  • P1 Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077) — Rapid7 Blog; score 77; technologies: none explicitly matched.
  • - Overview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unsafe deserialization vulnerability affecting JetBrains TeamCity . An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling…

  • P1 CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Acknowledgement Updated

  • P2 CVE-2018-5407 Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. — Microsoft Security Response Center RSS; score 57; technologies: none explicitly matched.
  • - Information published.

  • P2 RansomLook: Phase Technologies claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Phase Technologies. Description excerpt: phasetechnologies.com zoominfo.com/c/phase-technologies-llc/92275872 Phase Technologies is a leading American manufacturer…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2010-4052: [CVE-2010-4052 Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD.](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2010-4052) — technologies: not watchlist-specific.
  • P1 CVE-2026-63077: Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077) — technologies: not watchlist-specific.
  • P1 CVE-2026-40400: CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P2 CVE-2018-5407: CVE-2018-5407 Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. — technologies: not watchlist-specific.
  • P3 CVE-2026-55995: CVE-2026-55995 Double-free in the iSNS attribute decoder in open-iscsi — technologies: not watchlist-specific.
  • P3 CVE-2026-44944: CVE-2026-44944 iscsiuio control-socket authentication bypass in open-iscsi — technologies: not watchlist-specific.
  • P3 CVE-2026-44943: CVE-2026-44943 remote limited file-write as root via discovery in open-iscsi — technologies: not watchlist-specific.
  • P3 CVE-2026-6879: CVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index Predicates — technologies: not watchlist-specific.
  • P3 CVE-2026-32597: CVE-2026-32597 PyJWT accepts unknown crit header extensions (RFC 7515 §4.1.11 MUST violation) — technologies: not watchlist-specific.
  • P3 CVE-2026-48524: CVE-2026-48524 PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) — technologies: not watchlist-specific.
  • P3 CVE-2025-62725: CVE-2025-62725 Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations — technologies: not watchlist-specific.
  • P3 CVE-2026-43618, CVE-2026-44508: [CVE-2026-44508 Rejected reason: REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate.](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44508) — technologies: not watchlist-specific.
  • P3 CVE-2026-43620, CVE-2026-44510: [CVE-2026-44510 Rejected reason: REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate.](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44510) — technologies: not watchlist-specific.
  • P3 CVE-2026-43619, CVE-2026-44509: [CVE-2026-44509 Rejected reason: REJECT DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate.](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44509) — technologies: not watchlist-specific.
  • P3 CVE-2026-12080: CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys — technologies: not watchlist-specific.
  • P3 CVE-2026-68480: CVE-2026-68480 x86/bugs: Make Safe-RET robust against interrupt injection — technologies: not watchlist-specific.
  • P3 CVE-2019-9192: CVE-2019-9192 In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion — technologies: not watchlist-specific.
  • P3 CVE-2019-9924: CVE-2019-9924 rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell. — technologies: not watchlist-specific.
  • P3 CVE-2019-6706: CVE-2019-6706 Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships. — technologies: not watchlist-specific.
  • P3 CVE-2018-6829: [CVE-2018-6829 cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2018-6829) — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Phase Technologies claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Phase Technologies. Description excerpt: phasetechnologies.com zoominfo.com/c/phase-technologies-llc/92275872 Phase…
  • P3 RansomLook: Rutan & Tucker, LLP claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Rutan & Tucker, LLP. Description excerpt: Founded in 1909 and headquartered in Costa Mesa, California, Rutan & Tucker, LLP. is a…
  • P3 RansomLook: Floyd Skeren Manukian Langevin, LLP claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Floyd Skeren Manukian Langevin, LLP. Description excerpt: Floyd Skeren Manukian Langevin, LLP is a multi-service law firm with…
  • P3 RansomLook: Ropers Majeski PC claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Ropers Majeski PC. Description excerpt: For more than 75 years, Ropers Majeski has provided high-quality legal advice to a wide…
  • P3 RansomLook: Farella Braun + Martel LLP claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Farella Braun + Martel LLP. Description excerpt: They offered $520,000 to keep the data from being published. Farella Braun +…
  • P3 RansomLook: Sandberg Phoenix claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Sandberg Phoenix. Description excerpt: Over 45 years providing superior legal services to clients of every size throughout the…
  • P3 RansomLook: Porter Wright claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Porter Wright. Description excerpt: Founded in 1846, Porter Wright is a full-service law firm offering legal helo for the…
  • P3 RansomLook: Marshall Dennehey claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Marshall Dennehey. Description excerpt: They offered $100,000 to keep the data from being published. Founded in 1962 and…
  • P3 RansomLook: Barclay Damon claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Barclay Damon. Description excerpt: They are offering 325,000 for the safety of their clients' data. Barclay Damon LLP is a…
  • P3 RansomLook: Fox Rothschild LLP claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Fox Rothschild LLP. Description excerpt: Fox Rothschild LLP is an AmLaw 100 full-service law firm built to serve businesses of…
  • P3 RansomLook: Mayer Brown claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Mayer Brown. Description excerpt: Mayer Brown is a distinctively global law firm, uniquely positioned to advise the world's…
  • P3 RansomLook: Moses & Singer claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Moses & Singer. Description excerpt: They offered $250,000 to keep the data from being published........Moses & Singer LLP is a…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ua-curl; url=https://quick-load.vercel.app/api/settings/bootstraplinux
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-curl; url=https://quick-load.vercel.app/api/settings/env
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ua-curl; url=https://quick-load.vercel.app/api/settings/bootstrap
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ua-curl; url=https://quick-load.vercel.app/api/settings/package
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags= contagious-interview, curl-bash, Dropper, fake-recruiter, folderOpen, tasks-json, vscode,ua-curl,vercel; url=https://quick-load.vercel.app/api/settings/mac
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags= contagious-interview, curl-bash, Dropper, fake-recruiter, folderOpen, tasks-json, vscode,ua-curl,vercel; url=https://quick-load.vercel.app/api/settings/linux
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags= contagious-interview, curl-bash, Dropper, fake-recruiter, folderOpen, tasks-json, vscode,ua-curl,vercel; url=https://quick-load.vercel.app/api/settings/windows
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,DEU,geofenced,ladvix,mirai; url=http://rippled.cleverpondky.com/traff
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,DEU,geofenced,ladvix,mirai; url=http://rippled.cleverpondky.com/traff
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,DEU,geofenced,mirai; url=http://rippled.cleverpondky.com/log
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,DEU,geofenced,mirai; url=http://rippled.cleverpondky.com/log
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2010-4052`CVE-2010-4052 Stack consumption vulnerability in the regcomp implementation in the GNU C LMicrosoft Security Response Center RSS
    cve`CVE-2026-63077`Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-630Rapid7 Blog
    cve`CVE-2026-40400`CVE-2026-40400 Windows PowerShell Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2018-5407`CVE-2018-5407 Simultaneous Multi-threading (SMT) in processors can enable local users to eMicrosoft Security Response Center RSS
    cve`CVE-2026-55995`CVE-2026-55995 Double-free in the iSNS attribute decoder in open-iscsiMicrosoft Security Response Center RSS
    cve`CVE-2026-44944`CVE-2026-44944 iscsiuio control-socket authentication bypass in open-iscsiMicrosoft Security Response Center RSS
    cve`CVE-2026-44943`CVE-2026-44943 remote limited file-write as root via discovery in open-iscsiMicrosoft Security Response Center RSS
    cve`CVE-2026-6879`CVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index PredicatesMicrosoft Security Response Center RSS
    cve`CVE-2026-32597`CVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violaMicrosoft Security Response Center RSS
    cve`CVE-2026-48524`CVE-2026-48524 PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlledMicrosoft Security Response Center RSS
    cve`CVE-2025-62725`CVE-2025-62725 Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer AnnotatiMicrosoft Security Response Center RSS
    cve`CVE-2026-43618`CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:Microsoft Security Response Center RSS
    cve`CVE-2026-44508`CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:Microsoft Security Response Center RSS
    cve`CVE-2026-43620`CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:Microsoft Security Response Center RSS
    cve`CVE-2026-44510`CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:Microsoft Security Response Center RSS
    cve`CVE-2026-43619`CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:Microsoft Security Response Center RSS
    cve`CVE-2026-44509`CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:Microsoft Security Response Center RSS
    cve`CVE-2026-12080`CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack iMicrosoft Security Response Center RSS
    cve`CVE-2026-68480`CVE-2026-68480 x86/bugs: Make Safe-RET robust against interrupt injectionMicrosoft Security Response Center RSS
    cve`CVE-2019-9192`CVE-2019-9192 In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calMicrosoft Security Response Center RSS
    cve`CVE-2019-9924`CVE-2019-9924 rbash in Bash before 4.4-beta2 did not prevent the shell user from modifyingMicrosoft Security Response Center RSS
    cve`CVE-2019-6706`CVE-2019-6706 Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a cMicrosoft Security Response Center RSS
    cve`CVE-2018-6829`CVE-2018-6829 cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages dMicrosoft Security Response Center RSS
    cve`CVE-2018-1128`CVE-2018-1128 It was found that cephx authentication protocol did not verify ceph clientsMicrosoft Security Response Center RSS
    cve`CVE-2016-2568`CVE-2016-2568 pkexec, when used with --user nonpriv, allows local users to escape to the pMicrosoft Security Response Center RSS
    cve`CVE-2007-3205`CVE-2007-3205 The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when cMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`19bca2b67df413d91b31d025de4d2f745cb3c60a`RansomLook: Alya Construtora claimed by ransomhouseRansomLook Recent Listings
    hash`6a016f41ca1953ff139063dbb3c3871fbf732c574f69562ccc6db847eb3f24e2`RansomLook: reflet2000.fr claimed by krybitRansomLook Recent Listings
    hash`8a0bdf901623710a4eef9699878ae33d2fc778edb5e3b5f6302f955744120676`RansomLook: www.actini.com claimed by krybitRansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=35
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=2 fetched=25
  • NVD Recent CVEs: ok new=73 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=15 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=97 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.