markcardiff.tech:/daily-intel/2026-08-09.html
Generated: 2026-08-09 08:00:23 UTC
P1: 4
P2: 0
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-09

Generated: 2026-08-09 08:00:23 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=4, P2=0, P3=171, P4=75.
  • Highest-priority item: CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client (P1, source: Microsoft Security Response Center RSS).
  • 30 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client — Microsoft Security Response Center RSS; score 75; technologies: Apache.
  • - Information published.

  • P1 CVE-2026-34501 Apache Portable Runtime Utility: Heap buffer overflow in APR redis client — Microsoft Security Response Center RSS; score 75; technologies: Apache.
  • - Information published.

  • P1 CVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle — Microsoft Security Response Center RSS; score 75; technologies: Apache.
  • - Information published.

  • P1 CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack — Microsoft Security Response Center RSS; score 75; technologies: Apache.
  • - Information published.

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-34502: CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client — technologies: Apache.
  • P1 CVE-2026-34501: CVE-2026-34501 Apache Portable Runtime Utility: Heap buffer overflow in APR redis client — technologies: Apache.
  • P1 CVE-2026-34191: CVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle — technologies: Apache.
  • P1 CVE-2025-49506: CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack — technologies: Apache.
  • P3 CVE-2026-64584: CVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi object — technologies: not watchlist-specific.
  • P3 CVE-2026-64583: CVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown — technologies: not watchlist-specific.
  • P3 CVE-2026-64590: CVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning — technologies: not watchlist-specific.
  • P3 CVE-2026-64577: CVE-2026-64577 gtp: check skb_pull_data() return in gtp1u_send_echo_resp() — technologies: not watchlist-specific.
  • P3 CVE-2026-64567: CVE-2026-64567 btrfs: reject free space cache with more entries than pages — technologies: not watchlist-specific.
  • P3 CVE-2026-64569: CVE-2026-64569 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n — technologies: not watchlist-specific.
  • P3 CVE-2026-64572: CVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error path — technologies: not watchlist-specific.
  • P3 CVE-2026-64576: CVE-2026-64576 nexthop: initialize extack in nh_res_bucket_migrate() — technologies: not watchlist-specific.
  • P3 CVE-2026-64571: CVE-2026-64571 wifi: p54: validate RX frame length in p54_rx_eeprom_readback() — technologies: not watchlist-specific.
  • P3 CVE-2026-64562: CVE-2026-64562 KVM: nVMX: Hide shadow VMCS right after VMCLEAR — technologies: not watchlist-specific.
  • P3 CVE-2026-64564: CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processing — technologies: not watchlist-specific.
  • P3 CVE-2026-64561: CVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages available — technologies: not watchlist-specific.
  • P3 CVE-2026-18839: CVE-2026-18839 Popt-devel: popt-static: size_t underflow in singleoptionhelp — technologies: not watchlist-specific.
  • P3 CVE-2026-71227: CVE-2026-71227 Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return — technologies: not watchlist-specific.
  • P3 CVE-2026-71226: CVE-2026-71226 Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path — technologies: not watchlist-specific.
  • P3 CVE-2026-71225: CVE-2026-71225 Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P3 RansomLook: studiotibaldi.it claimed by krybit — Public RansomLook extortion-site listing claim. Group: krybit. Claimed victim/listing: studiotibaldi.it. Description excerpt: Studio Associato Tibaldi is an Italian professional firm based in Rome, founded over 40 years…
  • P3 RansomLook: Lucidmotors claimed by sovcali — Public RansomLook extortion-site listing claim. Group: sovcali. Claimed victim/listing: Lucidmotors. Description excerpt: The complete engineering archive of Lucid Motors and eShocan is now available: 5.078 terabytes of…
  • P3 RansomLook: Daily Trust claimed by panzer — Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Daily Trust. Description excerpt: Daily Trust is a Nigerian news organization that provides breaking news, investigative stories,…
  • P3 RansomLook: Impact Centre Chrétien claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Impact Centre Chrétien. Description excerpt: Business Services
  • P3 RansomLook: Clausing claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Clausing. Description excerpt: Food & Beverage
  • P3 RansomLook: CLLS Co Ltd claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: CLLS Co Ltd. Description excerpt: Industrial Machinery & Equipment
  • P3 RansomLook: Louisville Bar Association claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: Louisville Bar Association.
  • P3 RansomLook: Rutan & Tucker, LLP claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Rutan & Tucker, LLP. Description excerpt: Founded in 1909 and headquartered in Costa Mesa, California, Rutan & Tucker, LLP. is a…
  • P3 RansomLook: Floyd Skeren Manukian Langevin, LLP claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Floyd Skeren Manukian Langevin, LLP. Description excerpt: Floyd Skeren Manukian Langevin, LLP is a multi-service law firm with…
  • P3 RansomLook: Ropers Majeski PC claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Ropers Majeski PC. Description excerpt: For more than 75 years, Ropers Majeski has provided high-quality legal advice to a wide…
  • P3 RansomLook: Farella Braun + Martel LLP claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Farella Braun + Martel LLP. Description excerpt: They offered $520,000 to keep the data from being published. Farella Braun +…
  • P3 RansomLook: Sandberg Phoenix claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Sandberg Phoenix. Description excerpt: Over 45 years providing superior legal services to clients of every size throughout the…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ua-curl; url=https://quick-load.vercel.app/api/settings/bootstraplinux
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=fake-software,gaming-lure,github,Loader; url=https://github.com/ThreadColonelSouk/release/releases/download/release/release.zip
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=fake-software,gaming-lure,github,Loader; url=https://github.com/Shapecluneedle/jubilant-engine/releases/download/exec/payd.exe
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=fake-software,gaming-lure,github,Loader,SheetRAT; url=https://github.com/Shapecluneedle/jubilant-engine/releases/download/exec/payl.exe
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=fake-software,gaming-lure,github,Loader; url=https://github.com/BlackSuite999/Fishstrap-Roblox-2026/releases/download/release/Release.v.1.3.8.zip
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=fake-software,gaming-lure,github,Loader; url=https://github.com/CoopeRlOq9/Project-Zomboid-Build-42-Map/releases/download/release/Release.v.1.3.8.zip
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=fake-software,gaming-lure,github,Loader; url=https://github.com/Alomonohom6/stalzone-cheat-2026/releases/download/release/Release.v.3.1.4.zip
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=fake-software,gaming-lure,github,Loader; url=https://github.com/AlinRight93/stalzone-tools-cheat-2026/releases/download/release/Stalzone.v1.6.by.Kernel.Labs.zip
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=fake-software,gaming-lure,github,Loader; url=https://github.com/BeamChunin42/jennymod-installer/releases/download/latest/JennyMod.zip
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,jkqhdbbbqwiujkaz-hopto-org,mirai,ua-wget; url=http://jkqhdbbbqwiujkaz.hopto.org/nz/nz.arm
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,jkqhdbbbqwiujkaz-hopto-org,mirai,ua-wget; url=http://jkqhdbbbqwiujkaz.hopto.org/nz/nz.arm7
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-34502`CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached clieMicrosoft Security Response Center RSS
    cve`CVE-2026-34501`CVE-2026-34501 Apache Portable Runtime Utility: Heap buffer overflow in APR redis clientMicrosoft Security Response Center RSS
    cve`CVE-2026-34191`CVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracleMicrosoft Security Response Center RSS
    cve`CVE-2025-49506`CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timiMicrosoft Security Response Center RSS
    cve`CVE-2026-64584`CVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi objectMicrosoft Security Response Center RSS
    cve`CVE-2026-64583`CVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardownMicrosoft Security Response Center RSS
    cve`CVE-2026-64590`CVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warningMicrosoft Security Response Center RSS
    cve`CVE-2026-64577`CVE-2026-64577 gtp: check skb_pull_data() return in gtp1u_send_echo_resp()Microsoft Security Response Center RSS
    cve`CVE-2026-64567`CVE-2026-64567 btrfs: reject free space cache with more entries than pagesMicrosoft Security Response Center RSS
    cve`CVE-2026-64569`CVE-2026-64569 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=nMicrosoft Security Response Center RSS
    cve`CVE-2026-64572`CVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error pathMicrosoft Security Response Center RSS
    cve`CVE-2026-64576`CVE-2026-64576 nexthop: initialize extack in nh_res_bucket_migrate()Microsoft Security Response Center RSS
    cve`CVE-2026-64571`CVE-2026-64571 wifi: p54: validate RX frame length in p54_rx_eeprom_readback()Microsoft Security Response Center RSS
    cve`CVE-2026-64562`CVE-2026-64562 KVM: nVMX: Hide shadow VMCS right after VMCLEARMicrosoft Security Response Center RSS
    cve`CVE-2026-64564`CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processingMicrosoft Security Response Center RSS
    cve`CVE-2026-64561`CVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages availablMicrosoft Security Response Center RSS
    cve`CVE-2026-18839`CVE-2026-18839 Popt-devel: popt-static: size_t underflow in singleoptionhelpMicrosoft Security Response Center RSS
    cve`CVE-2026-71227`CVE-2026-71227 Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all()Microsoft Security Response Center RSS
    cve`CVE-2026-71226`CVE-2026-71226 Libkcapi: memory corruption via uncanceled aio requests on error in libkcapMicrosoft Security Response Center RSS
    cve`CVE-2026-71225`CVE-2026-71225 Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes ciMicrosoft Security Response Center RSS
    cve`CVE-2026-54876`CVE-2026-54876 Client-Side Memory Leak in OCSP Response CheckingMicrosoft Security Response Center RSS
    cve`CVE-2026-68082`CVE-2026-68082 libceph: fix two unsafe bare decodes in decode_lockers()Microsoft Security Response Center RSS
    cve`CVE-2026-68081`CVE-2026-68081 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest sMicrosoft Security Response Center RSS
    cve`CVE-2026-47243`CVE-2026-47243 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofsMicrosoft Security Response Center RSS
    cve`CVE-2026-64676`CVE-2026-64676 Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted hostMicrosoft Security Response Center RSS
    cve`CVE-2026-55995`CVE-2026-55995 Double-free in the iSNS attribute decoder in open-iscsiMicrosoft Security Response Center RSS
    cve`CVE-2026-44944`CVE-2026-44944 iscsiuio control-socket authentication bypass in open-iscsiMicrosoft Security Response Center RSS
    cve`CVE-2026-44943`CVE-2026-44943 remote limited file-write as root via discovery in open-iscsiMicrosoft Security Response Center RSS
    cve`CVE-2026-6879`CVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index PredicatesMicrosoft Security Response Center RSS
    cve`CVE-2026-32597`CVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violaMicrosoft Security Response Center RSS

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=35
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=25 fetched=25
  • NVD Recent CVEs: ok new=39 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=64 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.