markcardiff.tech:/daily-intel/2026-08-11.html
Generated: 2026-08-11 08:00:16 UTC
P1: 2
P2: 6
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-11

Generated: 2026-08-11 08:00:16 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=2, P2=6, P3=149, P4=93.
  • Highest-priority item: CVE-2021-34474 Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability (P1, source: Microsoft Security Response Center RSS).
  • 30 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2021-34474 Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated the build numbers. This is an informational update only.

  • P1 CVE-2026-50309 Windows NTFS Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P2 CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs — BleepingComputer Ransomware News; score 62; technologies: SonicWall.
  • - CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]

  • P2 RansomLook: HIGEN MOTOR(critical data) claimed by qilin — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: HIGEN MOTOR(critical data). Description excerpt: Industrial Machinery & Equipment

  • P2 RansomLook: One Vision Imaging claimed by akira — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: akira. Claimed victim/listing: One Vision Imaging. Description excerpt: One Vision Imaging are a team that are passionate about the process of photographic printing and framing. This is why we started…

  • P2 RansomLook: i4 Solutions claimed by akira — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: akira. Claimed victim/listing: i4 Solutions. Description excerpt: i4 Solutions has created thousands of Websites for companies all over the world! i4 Solutions creates custom websites and prides itself…

  • P2 RansomLook: Southern Metals claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Southern Metals. Description excerpt: E-commerce | Charlotte, North Carolina, United States | Southern Metals Company, based in Charlotte, NC, specializes in the recycling…

  • P2 RansomLook: TRP International claimed by storm — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: TRP International. Description excerpt: E-commerce | Elkhart, Indiana, United States | TRP International, LLC specializes in the distribution of high-quality components for…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2021-34474: CVE-2021-34474 Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-50309: CVE-2026-50309 Windows NTFS Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2024-57888: CVE-2024-57888 workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECLAIM worker — technologies: not watchlist-specific.
  • P3 CVE-2024-57795: CVE-2024-57795 RDMA/rxe: Remove the direct link to net_device — technologies: not watchlist-specific.
  • P3 CVE-2026-3087: CVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs — technologies: not watchlist-specific.
  • P3 CVE-2024-57857: CVE-2024-57857 RDMA/siw: Remove direct link to net_device — technologies: not watchlist-specific.
  • P3 CVE-2024-57899: CVE-2024-57899 wifi: mac80211: fix mbss changed flags corruption on 32 bit systems — technologies: not watchlist-specific.
  • P3 CVE-2025-21629: CVE-2025-21629 net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets — technologies: not watchlist-specific.
  • P3 CVE-2024-57893: CVE-2024-57893 ALSA: seq: oss: Fix races at processing SysEx messages — technologies: not watchlist-specific.
  • P3 CVE-2025-21682: CVE-2025-21682 eth: bnxt: always recalculate features after XDP clearing, fix null-deref — technologies: not watchlist-specific.
  • P3 CVE-2024-52005: CVE-2024-52005 The sideband payload is passed unfiltered to the terminal in git — technologies: not watchlist-specific.
  • P3 CVE-2024-57895: CVE-2024-57895 ksmbd: set ATTR_CTIME flags when setting mtime — technologies: not watchlist-specific.
  • P3 CVE-2025-37931: CVE-2025-37931 btrfs: adjust subpage bit start based on sectorsize — technologies: not watchlist-specific.
  • P3 CVE-2025-37961: CVE-2025-37961 ipvs: fix uninit-value for saddr in do_output_route4 — technologies: not watchlist-specific.
  • P3 CVE-2025-37856: CVE-2025-37856 btrfs: harden block_group::bg_list against list_del() races — technologies: not watchlist-specific.
  • P3 CVE-2025-37945: CVE-2025-37945 net: phy: allow MDIO bus PM ops to start/stop state machine for phylink-controlled PHY — technologies: not watchlist-specific.
  • P3 CVE-2024-57898: CVE-2024-57898 wifi: cfg80211: clear link ID from bitmap during link delete after clean up — technologies: not watchlist-specific.
  • P3 CVE-2025-37903: CVE-2025-37903 drm/amd/display: Fix slab-use-after-free in hdcp — technologies: not watchlist-specific.
  • P3 CVE-2025-37853: CVE-2025-37853 drm/amdkfd: debugfs hang_hws skip GPU with MES — technologies: not watchlist-specific.
  • P3 CVE-2025-37852: CVE-2025-37852 drm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create() — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs — CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]
  • P2 RansomLook: HIGEN MOTOR(critical data) claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: HIGEN MOTOR(critical data). Description excerpt: Industrial Machinery & Equipment
  • P2 RansomLook: One Vision Imaging claimed by akira — Public RansomLook extortion-site listing claim. Group: akira. Claimed victim/listing: One Vision Imaging. Description excerpt: One Vision Imaging are a team that are passionate about the process of photographic printing…
  • P2 RansomLook: i4 Solutions claimed by akira — Public RansomLook extortion-site listing claim. Group: akira. Claimed victim/listing: i4 Solutions. Description excerpt: i4 Solutions has created thousands of Websites for companies all over the world! i4 Solutions…
  • P2 RansomLook: Southern Metals claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Southern Metals. Description excerpt: E-commerce | Charlotte, North Carolina, United States | Southern Metals Company, based in…
  • P2 RansomLook: TRP International claimed by storm — Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: TRP International. Description excerpt: E-commerce | Elkhart, Indiana, United States | TRP International, LLC specializes in the…
  • P3 New StormEncryptor ransomware used by former Medusa affiliate — A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]
  • P3 RansomLook: FREYWILLE claimed by aurora — Public RansomLook extortion-site listing claim. Group: aurora. Claimed victim/listing: FREYWILLE. Description excerpt: FREYWILLE — the Austrian luxury fire-enamel jewelry house with 70+ boutiques across Europe, the…
  • P3 RansomLook: Cleaver-Brooks claimed by anubis — Public RansomLook extortion-site listing claim. Group: anubis. Claimed victim/listing: Cleaver-Brooks. Description excerpt: Major data breach at a leading industrial manufacturer.
  • P3 RansomLook: Turner claimed by payoutsking — Public RansomLook extortion-site listing claim. Group: payoutsking. Claimed victim/listing: Turner.
  • P3 RansomLook: BigSpark claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: BigSpark.
  • P3 RansomLook: Consolidated Medical Practices of Memphis claimed by genesis — Public RansomLook extortion-site listing claim. Group: genesis. Claimed victim/listing: Consolidated Medical Practices of Memphis. Description excerpt: A healthcare organization
  • Malware / infrastructure / abuse feed highlights

  • P3 The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications — Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. The post The Permanent Threat: Analyzing Aeternum’s…
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,iloveboats-st,mirai,ua-wget; url=https://iloveboats.st/disconnectraw.x86_64
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,iloveboats-st,mirai,ua-wget; url=https://iloveboats.st/disconnectraw.x86_64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,quietsurfwi-help,ua-wget; url=https://quietsurfwi.help/disconnectraw.mipsel
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai,quietsurfwi-help,ua-wget; url=https://quietsurfwi.help/disconnectraw.mipsel
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mail-quietsurfwi-help,mirai,ua-wget; url=https://mail.quietsurfwi.help/mipsel
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mail-quietsurfwi-help,mirai,ua-wget; url=https://mail.quietsurfwi.help/killbotx.x86_64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,iloveboats-st,sh,ua-wget; url=https://iloveboats.st/k.sh
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,iloveboats-st,mirai,ua-wget; url=https://iloveboats.st/x86_64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mail-quietsurfwi-help,mirai,ua-wget; url=https://mail.quietsurfwi.help/disconnectraw.x86_64
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mail-quietsurfwi-help,mirai,ua-wget; url=https://mail.quietsurfwi.help/disconnectraw.arm4
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2021-34474`CVE-2021-34474 Microsoft Dynamics 365 Business Central Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50309`CVE-2026-50309 Windows NTFS Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2024-57888`CVE-2024-57888 workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECMicrosoft Security Response Center RSS
    cve`CVE-2024-57795`CVE-2024-57795 RDMA/rxe: Remove the direct link to net_deviceMicrosoft Security Response Center RSS
    cve`CVE-2026-3087`CVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPsMicrosoft Security Response Center RSS
    cve`CVE-2024-57857`CVE-2024-57857 RDMA/siw: Remove direct link to net_deviceMicrosoft Security Response Center RSS
    cve`CVE-2024-57899`CVE-2024-57899 wifi: mac80211: fix mbss changed flags corruption on 32 bit systemsMicrosoft Security Response Center RSS
    cve`CVE-2025-21629`CVE-2025-21629 net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packetsMicrosoft Security Response Center RSS
    cve`CVE-2024-57893`CVE-2024-57893 ALSA: seq: oss: Fix races at processing SysEx messagesMicrosoft Security Response Center RSS
    cve`CVE-2025-21682`CVE-2025-21682 eth: bnxt: always recalculate features after XDP clearing, fix null-derefMicrosoft Security Response Center RSS
    cve`CVE-2024-52005`CVE-2024-52005 The sideband payload is passed unfiltered to the terminal in gitMicrosoft Security Response Center RSS
    cve`CVE-2024-57895`CVE-2024-57895 ksmbd: set ATTR_CTIME flags when setting mtimeMicrosoft Security Response Center RSS
    cve`CVE-2025-37931`CVE-2025-37931 btrfs: adjust subpage bit start based on sectorsizeMicrosoft Security Response Center RSS
    cve`CVE-2025-37961`CVE-2025-37961 ipvs: fix uninit-value for saddr in do_output_route4Microsoft Security Response Center RSS
    cve`CVE-2025-37856`CVE-2025-37856 btrfs: harden block_group::bg_list against list_del() racesMicrosoft Security Response Center RSS
    cve`CVE-2025-37945`CVE-2025-37945 net: phy: allow MDIO bus PM ops to start/stop state machine for phylink-conMicrosoft Security Response Center RSS
    cve`CVE-2024-57898`CVE-2024-57898 wifi: cfg80211: clear link ID from bitmap during link delete after clean upMicrosoft Security Response Center RSS
    cve`CVE-2025-37903`CVE-2025-37903 drm/amd/display: Fix slab-use-after-free in hdcpMicrosoft Security Response Center RSS
    cve`CVE-2025-37853`CVE-2025-37853 drm/amdkfd: debugfs hang_hws skip GPU with MESMicrosoft Security Response Center RSS
    cve`CVE-2025-37852`CVE-2025-37852 drm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_creatMicrosoft Security Response Center RSS
    cve`CVE-2025-37849`CVE-2025-37849 KVM: arm64: Tear down vGIC on failed vCPU creationMicrosoft Security Response Center RSS
    cve`CVE-2025-37842`CVE-2025-37842 spi: fsl-qspi: use devm function instead of driver removeMicrosoft Security Response Center RSS
    cve`CVE-2025-37877`CVE-2025-37877 iommu: Clear iommu-dma ops on cleanupMicrosoft Security Response Center RSS
    cve`CVE-2025-37884`CVE-2025-37884 bpf: Fix deadlock between rcu_tasks_trace and event_mutex.Microsoft Security Response Center RSS
    cve`CVE-2025-37879`CVE-2025-37879 9p/net: fix improper handling of bogus negative read/write repliesMicrosoft Security Response Center RSS
    cve`CVE-2025-37878`CVE-2025-37878 perf/core: Fix WARN_ON(!ctx) in __free_event() for partial initMicrosoft Security Response Center RSS
    cve`CVE-2025-37920`CVE-2025-37920 xsk: Fix race condition in AF_XDP generic RX pathMicrosoft Security Response Center RSS
    cve`CVE-2026-40417`CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege VulnerabilitMicrosoft Security Response Center RSS
    cve`CVE-2025-29821`CVE-2025-29821 Microsoft Dynamics Business Central Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2024-21380`CVE-2024-21380 Microsoft Dynamics Business Central/NAV Information Disclosure VulnerabilitMicrosoft Security Response Center RSS

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=33
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=25 fetched=25
  • NVD Recent CVEs: ok new=21 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=1 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=107 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.