Daily Cyber Threat Intel Brief — 2026-08-11
Generated: 2026-08-11 08:00:16 UTC
Executive summary
Priority technology watch items
- Updated the build numbers. This is an informational update only.
- Updated an acknowledgement. This is an informational change only.
- CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]
- Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: HIGEN MOTOR(critical data). Description excerpt: Industrial Machinery & Equipment
- Public RansomLook extortion-site listing claim. Group: akira. Claimed victim/listing: One Vision Imaging. Description excerpt: One Vision Imaging are a team that are passionate about the process of photographic printing and framing. This is why we started…
- Public RansomLook extortion-site listing claim. Group: akira. Claimed victim/listing: i4 Solutions. Description excerpt: i4 Solutions has created thousands of Websites for companies all over the world! i4 Solutions creates custom websites and prides itself…
- Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: Southern Metals. Description excerpt: E-commerce | Charlotte, North Carolina, United States | Southern Metals Company, based in Charlotte, NC, specializes in the recycling…
- Public RansomLook extortion-site listing claim. Group: storm. Claimed victim/listing: TRP International. Description excerpt: E-commerce | Elkhart, Indiana, United States | TRP International, LLC specializes in the distribution of high-quality components for…
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2021-34474` | CVE-2021-34474 Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50309` | CVE-2026-50309 Windows NTFS Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2024-57888` | CVE-2024-57888 workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_REC | Microsoft Security Response Center RSS |
| cve | `CVE-2024-57795` | CVE-2024-57795 RDMA/rxe: Remove the direct link to net_device | Microsoft Security Response Center RSS |
| cve | `CVE-2026-3087` | CVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs | Microsoft Security Response Center RSS |
| cve | `CVE-2024-57857` | CVE-2024-57857 RDMA/siw: Remove direct link to net_device | Microsoft Security Response Center RSS |
| cve | `CVE-2024-57899` | CVE-2024-57899 wifi: mac80211: fix mbss changed flags corruption on 32 bit systems | Microsoft Security Response Center RSS |
| cve | `CVE-2025-21629` | CVE-2025-21629 net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets | Microsoft Security Response Center RSS |
| cve | `CVE-2024-57893` | CVE-2024-57893 ALSA: seq: oss: Fix races at processing SysEx messages | Microsoft Security Response Center RSS |
| cve | `CVE-2025-21682` | CVE-2025-21682 eth: bnxt: always recalculate features after XDP clearing, fix null-deref | Microsoft Security Response Center RSS |
| cve | `CVE-2024-52005` | CVE-2024-52005 The sideband payload is passed unfiltered to the terminal in git | Microsoft Security Response Center RSS |
| cve | `CVE-2024-57895` | CVE-2024-57895 ksmbd: set ATTR_CTIME flags when setting mtime | Microsoft Security Response Center RSS |
| cve | `CVE-2025-37931` | CVE-2025-37931 btrfs: adjust subpage bit start based on sectorsize | Microsoft Security Response Center RSS |
| cve | `CVE-2025-37961` | CVE-2025-37961 ipvs: fix uninit-value for saddr in do_output_route4 | Microsoft Security Response Center RSS |
| cve | `CVE-2025-37856` | CVE-2025-37856 btrfs: harden block_group::bg_list against list_del() races | Microsoft Security Response Center RSS |
| cve | `CVE-2025-37945` | CVE-2025-37945 net: phy: allow MDIO bus PM ops to start/stop state machine for phylink-con | Microsoft Security Response Center RSS |
| cve | `CVE-2024-57898` | CVE-2024-57898 wifi: cfg80211: clear link ID from bitmap during link delete after clean up | Microsoft Security Response Center RSS |
| cve | `CVE-2025-37903` | CVE-2025-37903 drm/amd/display: Fix slab-use-after-free in hdcp | Microsoft Security Response Center RSS |
| cve | `CVE-2025-37853` | CVE-2025-37853 drm/amdkfd: debugfs hang_hws skip GPU with MES | Microsoft Security Response Center RSS |
| cve | `CVE-2025-37852` | CVE-2025-37852 drm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_creat | Microsoft Security Response Center RSS |
| cve | `CVE-2025-37849` | CVE-2025-37849 KVM: arm64: Tear down vGIC on failed vCPU creation | Microsoft Security Response Center RSS |
| cve | `CVE-2025-37842` | CVE-2025-37842 spi: fsl-qspi: use devm function instead of driver remove | Microsoft Security Response Center RSS |
| cve | `CVE-2025-37877` | CVE-2025-37877 iommu: Clear iommu-dma ops on cleanup | Microsoft Security Response Center RSS |
| cve | `CVE-2025-37884` | CVE-2025-37884 bpf: Fix deadlock between rcu_tasks_trace and event_mutex. | Microsoft Security Response Center RSS |
| cve | `CVE-2025-37879` | CVE-2025-37879 9p/net: fix improper handling of bogus negative read/write replies | Microsoft Security Response Center RSS |
| cve | `CVE-2025-37878` | CVE-2025-37878 perf/core: Fix WARN_ON(!ctx) in __free_event() for partial init | Microsoft Security Response Center RSS |
| cve | `CVE-2025-37920` | CVE-2025-37920 xsk: Fix race condition in AF_XDP generic RX path | Microsoft Security Response Center RSS |
| cve | `CVE-2026-40417` | CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerabilit | Microsoft Security Response Center RSS |
| cve | `CVE-2025-29821` | CVE-2025-29821 Microsoft Dynamics Business Central Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2024-21380` | CVE-2024-21380 Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerabilit | Microsoft Security Response Center RSS |