markcardiff.tech:/daily-intel/2026-08-10.html
Generated: 2026-08-10 08:00:56 UTC
P1: 4
P2: 2
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-10

Generated: 2026-08-10 08:00:56 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=4, P2=2, P3=55, P4=189.
  • Highest-priority item: CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client (P1, source: Microsoft Security Response Center RSS).
  • 28 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client — Microsoft Security Response Center RSS; score 75; technologies: Apache.
  • - Information published.

  • P1 CVE-2026-34501 Apache Portable Runtime Utility: Heap buffer overflow in APR redis client — Microsoft Security Response Center RSS; score 75; technologies: Apache.
  • - Information published.

  • P1 CVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle — Microsoft Security Response Center RSS; score 75; technologies: Apache.
  • - Information published.

  • P1 CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack — Microsoft Security Response Center RSS; score 75; technologies: Apache.
  • - Information published.

  • P2 RansomLook: Lancesoft India claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Lancesoft India. Description excerpt: lancesoft.in zoominfo.com/c/lancesoft-india/547301190 LanceSoft India is a key division of a global workforce solutions and IT…

  • P2 RansomLook: AIMS Group claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: AIMS Group. Description excerpt: aimsgroup.com AIMS Group LLC is a major conglomerate based in Ajman, UAE, established in 2003 with a workforce of thousands. It…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-34502: CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client — technologies: Apache.
  • P1 CVE-2026-34501: CVE-2026-34501 Apache Portable Runtime Utility: Heap buffer overflow in APR redis client — technologies: Apache.
  • P1 CVE-2026-34191: CVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle — technologies: Apache.
  • P1 CVE-2025-49506: CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack — technologies: Apache.
  • P3 CVE-2026-64584: CVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi object — technologies: not watchlist-specific.
  • P3 CVE-2026-64583: CVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown — technologies: not watchlist-specific.
  • P3 CVE-2026-64590: CVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning — technologies: not watchlist-specific.
  • P3 CVE-2026-64577: CVE-2026-64577 gtp: check skb_pull_data() return in gtp1u_send_echo_resp() — technologies: not watchlist-specific.
  • P3 CVE-2026-64567: CVE-2026-64567 btrfs: reject free space cache with more entries than pages — technologies: not watchlist-specific.
  • P3 CVE-2026-64569: CVE-2026-64569 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n — technologies: not watchlist-specific.
  • P3 CVE-2026-64572: CVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error path — technologies: not watchlist-specific.
  • P3 CVE-2026-64576: CVE-2026-64576 nexthop: initialize extack in nh_res_bucket_migrate() — technologies: not watchlist-specific.
  • P3 CVE-2026-64571: CVE-2026-64571 wifi: p54: validate RX frame length in p54_rx_eeprom_readback() — technologies: not watchlist-specific.
  • P3 CVE-2026-64562: CVE-2026-64562 KVM: nVMX: Hide shadow VMCS right after VMCLEAR — technologies: not watchlist-specific.
  • P3 CVE-2026-64564: CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processing — technologies: not watchlist-specific.
  • P3 CVE-2026-64561: CVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages available — technologies: not watchlist-specific.
  • P3 CVE-2026-18839: CVE-2026-18839 Popt-devel: popt-static: size_t underflow in singleoptionhelp — technologies: not watchlist-specific.
  • P3 CVE-2026-71227: CVE-2026-71227 Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return — technologies: not watchlist-specific.
  • P3 CVE-2026-71226: CVE-2026-71226 Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path — technologies: not watchlist-specific.
  • P3 CVE-2026-71225: CVE-2026-71225 Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Lancesoft India claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Lancesoft India. Description excerpt: lancesoft.in zoominfo.com/c/lancesoft-india/547301190 LanceSoft India is a key division…
  • P2 RansomLook: AIMS Group claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: AIMS Group. Description excerpt: aimsgroup.com AIMS Group LLC is a major conglomerate based in Ajman, UAE, established in…
  • P3 RansomLook: Zion Contracting claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Zion Contracting. Description excerpt: zioncontracting.com Zion Contracting LLC is a trusted general contractor based in New…
  • P3 RansomLook: Premier Pigs claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Premier Pigs. Description excerpt: premierpigs.com zoominfo.com/c/premier-pigs/458500816 Grupo Premier Pigs is a family-owned…
  • P3 RansomLook: NTU Alumni Club claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: NTU Alumni Club. Description excerpt: ntualumni.org.sg zoominfo.com/c/ntu-alumni-club/447180090 The NTU Alumni Club is an…
  • P3 RansomLook: Canopy Support Services claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Canopy Support Services. Description excerpt: canopysupport.ca zoominfo.com/c/canopy-support-services/347650822 Canopy…
  • P3 RansomLook: Mikel Coffee claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Mikel Coffee. Description excerpt: mikelcoffee.com zoominfo.com/c/mikel-coffee/456172290 Mikel Coffee Company is a prominent…
  • P3 RansomLook: Zion Construction claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Zion Construction. Description excerpt: zionconstructioninc.com Zion Construction Inc is a reputable general contracting and…
  • P3 RansomLook: Hong Kong Baptist University claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Hong Kong Baptist University. Description excerpt: hkbu.edu.hk zoominfo.com/c/hong-kong-baptist-university/429650952 Hong…
  • P3 RansomLook: Eva Care claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Eva Care. Description excerpt: evacare.com rocketreach.co/eva-care-profile_b7a227f8c53b4785 Eva Care Group is a healthcare…
  • P3 RansomLook: (DISCLOSED)Nichirei claimed by ransomhouse — Public RansomLook extortion-site listing claim. Group: ransomhouse. Claimed victim/listing: (DISCLOSED)Nichirei.
  • P3 RansomLook: PharmaEssentia claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: PharmaEssentia. Description excerpt: pharmaessentia.com zoominfo.com/c/pharmaessentia-corp/145441146 PharmaEssentia is a…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=connectwise; url=https://fkoqonr2vgbsw7qu.public.blob.vercel-storage.com/data.msi
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://5.182.210.174/4c1687
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://5.182.210.174/9b9d62
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://5.182.210.174/ff9728
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://5.182.210.174/688c63
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://5.182.210.174/6be5c4
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://5.182.210.174/8fedf4
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://5.182.210.174/0cda73
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://5.182.210.174/a05a88
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://5.182.210.174/e89cd9
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://129.121.110.105/ytEr
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-34502`CVE-2026-34502 Apache Portable Runtime Utility: Heap buffer overflow in APR memcached clieMicrosoft Security Response Center RSS
    cve`CVE-2026-34501`CVE-2026-34501 Apache Portable Runtime Utility: Heap buffer overflow in APR redis clientMicrosoft Security Response Center RSS
    cve`CVE-2026-34191`CVE-2026-34191 Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracleMicrosoft Security Response Center RSS
    cve`CVE-2025-49506`CVE-2025-49506 Apache Portable Runtime Utility: apr_password_validate() vulnerable to timiMicrosoft Security Response Center RSS
    cve`CVE-2026-64584`CVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi objectMicrosoft Security Response Center RSS
    cve`CVE-2026-64583`CVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardownMicrosoft Security Response Center RSS
    cve`CVE-2026-64590`CVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warningMicrosoft Security Response Center RSS
    cve`CVE-2026-64577`CVE-2026-64577 gtp: check skb_pull_data() return in gtp1u_send_echo_resp()Microsoft Security Response Center RSS
    cve`CVE-2026-64567`CVE-2026-64567 btrfs: reject free space cache with more entries than pagesMicrosoft Security Response Center RSS
    cve`CVE-2026-64569`CVE-2026-64569 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=nMicrosoft Security Response Center RSS
    cve`CVE-2026-64572`CVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error pathMicrosoft Security Response Center RSS
    cve`CVE-2026-64576`CVE-2026-64576 nexthop: initialize extack in nh_res_bucket_migrate()Microsoft Security Response Center RSS
    cve`CVE-2026-64571`CVE-2026-64571 wifi: p54: validate RX frame length in p54_rx_eeprom_readback()Microsoft Security Response Center RSS
    cve`CVE-2026-64562`CVE-2026-64562 KVM: nVMX: Hide shadow VMCS right after VMCLEARMicrosoft Security Response Center RSS
    cve`CVE-2026-64564`CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processingMicrosoft Security Response Center RSS
    cve`CVE-2026-64561`CVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages availablMicrosoft Security Response Center RSS
    cve`CVE-2026-18839`CVE-2026-18839 Popt-devel: popt-static: size_t underflow in singleoptionhelpMicrosoft Security Response Center RSS
    cve`CVE-2026-71227`CVE-2026-71227 Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all()Microsoft Security Response Center RSS
    cve`CVE-2026-71226`CVE-2026-71226 Libkcapi: memory corruption via uncanceled aio requests on error in libkcapMicrosoft Security Response Center RSS
    cve`CVE-2026-71225`CVE-2026-71225 Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes ciMicrosoft Security Response Center RSS
    cve`CVE-2026-54876`CVE-2026-54876 Client-Side Memory Leak in OCSP Response CheckingMicrosoft Security Response Center RSS
    cve`CVE-2026-68082`CVE-2026-68082 libceph: fix two unsafe bare decodes in decode_lockers()Microsoft Security Response Center RSS
    cve`CVE-2026-68081`CVE-2026-68081 KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest sMicrosoft Security Response Center RSS
    cve`CVE-2026-47243`CVE-2026-47243 Kata guest escape: runtime-rs guest-root to host-root escape via virtiofsMicrosoft Security Response Center RSS
    cve`CVE-2026-64676`CVE-2026-64676 Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted hostMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`342598281928417826db8ac5d4efb9ee97cc7a8e`RansomLook: (DISCLOSED)Nichirei claimed by ransomhouseRansomLook Recent Listings
    hash`39b1b6646b2110e79ac532e169720824c3d842d02ce0c61e95658835ac24d084`RansomLook: studiotibaldi.it claimed by krybitRansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=33
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=30 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=120 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.