Daily Cyber Threat Intel Brief — 2026-08-13
Generated: 2026-08-13 08:00:44 UTC
Executive summary
Priority technology watch items
- Updated an acknowledgement. This is an informational change only.
- Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. [...]
- Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. [...]
- Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...]
- North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]
- Updated an acknowledgement. This is an informational change only.
- Updated an acknowledgement. This is an informational change only.
- Updated the build numbers. This is an informational update only.
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-62913` | CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-71362` | Hackers exploit critical Adobe Commerce flaw to hijack customer accounts | BleepingComputer Ransomware News |
| cve | `CVE-2026-68820` | Lazarus hackers exploited Windows zero-day to target defense firms | BleepingComputer Ransomware News |
| cve | `CVE-2026-68815` | CVE-2026-68815 Microsoft Excel Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50655` | CVE-2026-50655 Microsoft Windows Media Foundation Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2022-41127` | CVE-2022-41127 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Prem | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62696` | CVE-2026-62696 Windows Program Compatibility Assistant Service Elevation of Privilege Vuln | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62747` | CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-70348` | CVE-2026-70348 Windows Management Services Denial of Service Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50687` | CVE-2026-50687 Windows Win32k Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-58538` | CVE-2026-58538 Windows Bluetooth Service Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50476` | CVE-2026-50476 Windows Network Connections Service Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-42976` | CVE-2026-42976 Remote Access Management service/API (RPC server) Elevation of Privilege Vu | Microsoft Security Response Center RSS |
| ipv4 | `151.241.154.105` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| ipv4 | `185.29.10.11` | URLhaus: malware_download URL observed (online) | URLhaus Recent URLs |
| ipv4 | `31.77.227.130` | URLhaus: malware_download URL observed (online) | URLhaus Recent URLs |
| ipv4 | `31.56.209.189` | URLhaus: malware_download URL observed (online) | URLhaus Recent URLs |
| hash | `4d82f9fb62bdc9deb6a11133591c63fc1d6347d3` | RansomLook: (DISCLOSED)City of Beacon claimed by ransomhouse | RansomLook Recent Listings |