Daily Cyber Threat Intel Brief — 2026-08-08
Generated: 2026-08-08 08:00:42 UTC
Executive summary
Priority technology watch items
- Information published.
- Overview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unsafe deserialization vulnerability affecting JetBrains TeamCity . An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling…
- Acknowledgement Updated
- Information published.
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Phase Technologies. Description excerpt: phasetechnologies.com zoominfo.com/c/phase-technologies-llc/92275872 Phase Technologies is a leading American manufacturer…
Newly exploited vulnerabilities / CVE watch
crit header extensions (RFC 7515 §4.1.11 MUST violation) — technologies: not watchlist-specific.Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2010-4052` | CVE-2010-4052 Stack consumption vulnerability in the regcomp implementation in the GNU C L | Microsoft Security Response Center RSS |
| cve | `CVE-2026-63077` | Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-630 | Rapid7 Blog |
| cve | `CVE-2026-40400` | CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2018-5407` | CVE-2018-5407 Simultaneous Multi-threading (SMT) in processors can enable local users to e | Microsoft Security Response Center RSS |
| cve | `CVE-2026-55995` | CVE-2026-55995 Double-free in the iSNS attribute decoder in open-iscsi | Microsoft Security Response Center RSS |
| cve | `CVE-2026-44944` | CVE-2026-44944 iscsiuio control-socket authentication bypass in open-iscsi | Microsoft Security Response Center RSS |
| cve | `CVE-2026-44943` | CVE-2026-44943 remote limited file-write as root via discovery in open-iscsi | Microsoft Security Response Center RSS |
| cve | `CVE-2026-6879` | CVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index Predicates | Microsoft Security Response Center RSS |
| cve | `CVE-2026-32597` | CVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST viola | Microsoft Security Response Center RSS |
| cve | `CVE-2026-48524` | CVE-2026-48524 PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled | Microsoft Security Response Center RSS |
| cve | `CVE-2025-62725` | CVE-2025-62725 Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotati | Microsoft Security Response Center RSS |
| cve | `CVE-2026-43618` | CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: | Microsoft Security Response Center RSS |
| cve | `CVE-2026-44508` | CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: | Microsoft Security Response Center RSS |
| cve | `CVE-2026-43620` | CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: | Microsoft Security Response Center RSS |
| cve | `CVE-2026-44510` | CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: | Microsoft Security Response Center RSS |
| cve | `CVE-2026-43619` | CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: | Microsoft Security Response Center RSS |
| cve | `CVE-2026-44509` | CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: | Microsoft Security Response Center RSS |
| cve | `CVE-2026-12080` | CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack i | Microsoft Security Response Center RSS |
| cve | `CVE-2026-68480` | CVE-2026-68480 x86/bugs: Make Safe-RET robust against interrupt injection | Microsoft Security Response Center RSS |
| cve | `CVE-2019-9192` | CVE-2019-9192 In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_cal | Microsoft Security Response Center RSS |
| cve | `CVE-2019-9924` | CVE-2019-9924 rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying | Microsoft Security Response Center RSS |
| cve | `CVE-2019-6706` | CVE-2019-6706 Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a c | Microsoft Security Response Center RSS |
| cve | `CVE-2018-6829` | CVE-2018-6829 cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages d | Microsoft Security Response Center RSS |
| cve | `CVE-2018-1128` | CVE-2018-1128 It was found that cephx authentication protocol did not verify ceph clients | Microsoft Security Response Center RSS |
| cve | `CVE-2016-2568` | CVE-2016-2568 pkexec, when used with --user nonpriv, allows local users to escape to the p | Microsoft Security Response Center RSS |
| cve | `CVE-2007-3205` | CVE-2007-3205 The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when c | Microsoft Security Response Center RSS |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| hash | `19bca2b67df413d91b31d025de4d2f745cb3c60a` | RansomLook: Alya Construtora claimed by ransomhouse | RansomLook Recent Listings |
| hash | `6a016f41ca1953ff139063dbb3c3871fbf732c574f69562ccc6db847eb3f24e2` | RansomLook: reflet2000.fr claimed by krybit | RansomLook Recent Listings |
| hash | `8a0bdf901623710a4eef9699878ae33d2fc778edb5e3b5f6302f955744120676` | RansomLook: www.actini.com claimed by krybit | RansomLook Recent Listings |