markcardiff.tech:/daily-intel/2026-08-12.html
Generated: 2026-08-12 08:00:14 UTC
P1: 18
P2: 3
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-12

Generated: 2026-08-12 08:00:14 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=18, P2=3, P3=100, P4=129.
  • Highest-priority item: CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED) (P1, source: Rapid7 Blog).
  • 30 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED) — Rapid7 Blog; score 107; technologies: SharePoint.
  • - Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint…

  • P1 Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) — Rapid7 Blog; score 107; technologies: SharePoint.
  • - Overview On July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept…

  • P1 CVE-2026-63514 Microsoft SharePoint Server Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 100; technologies: SharePoint.
  • - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • P1 CVE-2026-63520 Microsoft SharePoint Server Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 100; technologies: SharePoint.
  • - Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

  • P1 CISA: Microsoft SharePoint flaw now exploited in ransomware attacks — BleepingComputer Ransomware News; score 87; technologies: SharePoint.
  • - CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. [...]

  • P1 Patch Tuesday - August 2026 — Rapid7 Blog; score 82; technologies: SharePoint.
  • - Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to…

  • P1 CVE-2026-57105 Microsoft Office SharePoint Spoofing Vulnerability — Microsoft Security Response Center RSS; score 75; technologies: SharePoint.
  • - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • P1 CVE-2026-62829 Microsoft SharePoint Server Spoofing Vulnerability — Microsoft Security Response Center RSS; score 75; technologies: SharePoint.
  • - Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • P1 CVE-2026-62827 Microsoft SharePoint Server Elevation of Privilege Vulnerability — Microsoft Security Response Center RSS; score 75; technologies: SharePoint.
  • - Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • P1 CVE-2026-62837 Microsoft SharePoint Server Information Disclosure Vulnerability — Microsoft Security Response Center RSS; score 75; technologies: SharePoint.
  • - Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

  • P1 CVE-2026-63512 Microsoft SharePoint Server Tampering Vulnerability — Microsoft Security Response Center RSS; score 75; technologies: SharePoint.
  • - Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.

  • P1 CVE-2026-63516 Microsoft SharePoint Server Spoofing Vulnerability — Microsoft Security Response Center RSS; score 75; technologies: SharePoint.
  • - Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • P1 CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-54113 Remote Procedure Call Denial of Service Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.

  • P1 CVE-2026-54984 Windows Imaging Component Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.

  • P1 CVE-2026-49179 Windows Active Directory Domain Services Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-59113 Visual Studio Code Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

  • P2 US and South Korea warn of Gunra ransomware targeting govt agencies — BleepingComputer Ransomware News; score 57; technologies: none explicitly matched.
  • - U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]

  • P2 Microsoft Patch Tuesday August 2026, (Tue, Aug 11th) — SANS Internet Storm Center; score 54; technologies: none explicitly matched.
  • - This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-55040, CVE-2026-63520: CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED) — technologies: SharePoint.
  • P1 CVE-2026-55040: Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) — technologies: SharePoint.
  • P1 CVE-2026-63514: CVE-2026-63514 Microsoft SharePoint Server Remote Code Execution Vulnerability — technologies: SharePoint.
  • P1 CVE-2026-63520: CVE-2026-63520 Microsoft SharePoint Server Remote Code Execution Vulnerability — technologies: SharePoint.
  • P1 CVE-2026-57105: CVE-2026-57105 Microsoft Office SharePoint Spoofing Vulnerability — technologies: SharePoint.
  • P1 CVE-2026-62829: CVE-2026-62829 Microsoft SharePoint Server Spoofing Vulnerability — technologies: SharePoint.
  • P1 CVE-2026-62827: CVE-2026-62827 Microsoft SharePoint Server Elevation of Privilege Vulnerability — technologies: SharePoint.
  • P1 CVE-2026-62837: CVE-2026-62837 Microsoft SharePoint Server Information Disclosure Vulnerability — technologies: SharePoint.
  • P1 CVE-2026-63512: CVE-2026-63512 Microsoft SharePoint Server Tampering Vulnerability — technologies: SharePoint.
  • P1 CVE-2026-63516: CVE-2026-63516 Microsoft SharePoint Server Spoofing Vulnerability — technologies: SharePoint.
  • P1 CVE-2026-65768: CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-54113: CVE-2026-54113 Remote Procedure Call Denial of Service Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-54984: CVE-2026-54984 Windows Imaging Component Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-49179: CVE-2026-49179 Windows Active Directory Domain Services Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-59113: CVE-2026-59113 Visual Studio Code Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-59124: CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-50472: CVE-2026-50472 Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-56174: CVE-2026-56174 Windows Narrator Braille Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-58650: CVE-2026-58650 Visual Studio Code Security Feature Bypass Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-40375: CVE-2026-40375 Microsoft Dynamics Business Central Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P1 CISA: Microsoft SharePoint flaw now exploited in ransomware attacks — CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. [...]
  • P2 US and South Korea warn of Gunra ransomware targeting govt agencies — U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]
  • P2 RansomLook: QPC Global claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: QPC Global. Description excerpt: Quest Personal Care Global Ltd is a global company specializing in affordable beauty and…
  • P3 DeadLock ransomware uses blockchain to resist infrastructure takedown — The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. [...]
  • P3 RansomLook: Wanted claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Wanted. Description excerpt: Business Services
  • P3 RansomLook: Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano claimed by space bears — Public RansomLook extortion-site listing claim. Group: space bears. Claimed victim/listing: Basso Fedele & Figli S.r.l. (Olio Basso) / Villa Raiano. Description excerpt: Basso Fedele & Figli S.r.l. is a historic Italian…
  • P3 RansomLook: E* claimed by genesis — Public RansomLook extortion-site listing claim. Group: genesis. Claimed victim/listing: E*. Description excerpt: A healthcare organization
  • P3 RansomLook: R...er claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: R...er. Description excerpt: To be announced...
  • P3 RansomLook: G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: G.M.A. GRANDI MARCHE AUTOMOBILI - S.R.L. Description excerpt: Business Services
  • P3 RansomLook: Crown Group claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Crown Group. Description excerpt: Business Services
  • P3 RansomLook: AngMar Companies claimed by interlock — Public RansomLook extortion-site listing claim. Group: interlock. Claimed victim/listing: AngMar Companies. Description excerpt: https://www.angmarcompanies.com/ AngMar is a private organization comprised of numerous…
  • P3 RansomLook: B&B Hydraulik claimed by payload — Public RansomLook extortion-site listing claim. Group: payload. Claimed victim/listing: B&B Hydraulik. Description excerpt: B&B Hydraulik is a German company based in Hattingen that specializes in the development and…
  • Malware / infrastructure / abuse feed highlights

  • P3 Kimwolf v7: An Evolution of the Kimwolf Botnet — Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42 .
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,base64-loader,CoinMiner,Encoded,xmrig; url=http://31.77.227.130:6556/ok
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,base64-loader,CoinMiner,Encoded,xmrig; url=http://31.56.209.189:6556/ok
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,base64-loader,CoinMiner,Encoded,xmrig; url=http://joker.aec944b68370194a50.link:6556/ok
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://5.182.210.174/a7a53e
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://5.182.210.174/1ad6dd
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://5.182.210.174/73c8e4
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://5.182.210.174/2059d3
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://5.182.210.174/a12c22
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://5.182.210.174/cabc7a
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://5.182.210.174/878e23
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-55040`CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)Rapid7 Blog
    cve`CVE-2026-63520`CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)Rapid7 Blog
    cve`CVE-2026-63514`CVE-2026-63514 Microsoft SharePoint Server Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-57105`CVE-2026-57105 Microsoft Office SharePoint Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62829`CVE-2026-62829 Microsoft SharePoint Server Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62827`CVE-2026-62827 Microsoft SharePoint Server Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62837`CVE-2026-62837 Microsoft SharePoint Server Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-63512`CVE-2026-63512 Microsoft SharePoint Server Tampering VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-63516`CVE-2026-63516 Microsoft SharePoint Server Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-65768`CVE-2026-65768 Microsoft Teams Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-54113`CVE-2026-54113 Remote Procedure Call Denial of Service VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-54984`CVE-2026-54984 Windows Imaging Component Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-49179`CVE-2026-49179 Windows Active Directory Domain Services Remote Code Execution VulnerabilitMicrosoft Security Response Center RSS
    cve`CVE-2026-59113`CVE-2026-59113 Visual Studio Code Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-59124`CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution VulneMicrosoft Security Response Center RSS
    cve`CVE-2026-50472`CVE-2026-50472 Windows LUA File Virtualization Filter Driver Elevation of Privilege VulnerMicrosoft Security Response Center RSS
    cve`CVE-2026-56174`CVE-2026-56174 Windows Narrator Braille Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-58650`CVE-2026-58650 Visual Studio Code Security Feature Bypass VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-40375`CVE-2026-40375 Microsoft Dynamics Business Central Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-58612`CVE-2026-58612 PowerShell Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-47299`CVE-2026-47299 Azure Monitor Agent Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-47285`CVE-2026-47285 Visual Studio Code Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-6727`CVE-2026-6727 MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-59127`CVE-2026-59127 Windows Installer Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-59128`CVE-2026-59128 Windows Encrypting File System (EFS) Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-59133`CVE-2026-59133 Microsoft High Performance Computing (HPC) Pack Elevation of Privilege VulnMicrosoft Security Response Center RSS
    cve`CVE-2026-59130`CVE-2026-59130 AMD Zen Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2024-57888`CVE-2024-57888 workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECMicrosoft Security Response Center RSS
    cve`CVE-2024-57795`CVE-2024-57795 RDMA/rxe: Remove the direct link to net_deviceMicrosoft Security Response Center RSS
    cve`CVE-2026-3087`CVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPsMicrosoft Security Response Center RSS

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=36
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=31 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=1 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=120 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.