markcardiff.tech:/daily-intel/2026-08-13.html
Generated: 2026-08-13 08:00:44 UTC
P1: 8
P2: 0
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-13

Generated: 2026-08-13 08:00:44 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=8, P2=0, P3=79, P4=163.
  • Highest-priority item: CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability (P1, source: Microsoft Security Response Center RSS).
  • 19 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 100; technologies: Microsoft Exchange.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 Hackers leverage new Microsoft SharePoint exploit in attacks — BleepingComputer Ransomware News; score 79; technologies: SharePoint.
  • - Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. [...]

  • P1 New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges — BleepingComputer Ransomware News; score 79; technologies: Microsoft Defender.
  • - Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates. [...]

  • P1 Hackers exploit critical Adobe Commerce flaw to hijack customer accounts — BleepingComputer Ransomware News; score 74; technologies: none explicitly matched.
  • - Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...]

  • P1 Lazarus hackers exploited Windows zero-day to target defense firms — BleepingComputer Ransomware News; score 74; technologies: none explicitly matched.
  • - North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]

  • P1 CVE-2026-68815 Microsoft Excel Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-50655 Microsoft Windows Media Foundation Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2022-41127 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated the build numbers. This is an informational update only.

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-62913: CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability — technologies: Microsoft Exchange.
  • P1 CVE-2026-71362: Hackers exploit critical Adobe Commerce flaw to hijack customer accounts — technologies: not watchlist-specific.
  • P1 CVE-2026-68820: Lazarus hackers exploited Windows zero-day to target defense firms — technologies: not watchlist-specific.
  • P1 CVE-2026-68815: CVE-2026-68815 Microsoft Excel Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-50655: CVE-2026-50655 Microsoft Windows Media Foundation Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2022-41127: CVE-2022-41127 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62696: CVE-2026-62696 Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62747: CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-70348: CVE-2026-70348 Windows Management Services Denial of Service Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-50687: CVE-2026-50687 Windows Win32k Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-58538: CVE-2026-58538 Windows Bluetooth Service Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-50476: CVE-2026-50476 Windows Network Connections Service Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-42976: CVE-2026-42976 Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P3 RansomLook: eas** claimed by nightspire — Public RansomLook extortion-site listing claim. Group: nightspire. Claimed victim/listing: eas**.
  • P3 RansomLook: Riker Danzig Scherer Hyland & Perretti claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Riker Danzig Scherer Hyland & Perretti. Description excerpt: Founded in 1882, Riker Danzig Scherer Hyland & Perretti is a law…
  • P3 RansomLook: Xpress Tech claimed by panzer — Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Xpress Tech. Description excerpt: Xpress Tech is a leading B2B iGaming aggregation platform established in 2015 under Softquo…
  • P3 RansomLook: Hightech Signs claimed by kairos — Public RansomLook extortion-site listing claim. Group: kairos. Claimed victim/listing: Hightech Signs. Description excerpt: Hightech Signs, Inc. is a full-service sign shop located in Charlottesville, Virginia,…
  • P3 RansomLook: gamaus.com claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: gamaus.com.
  • P3 RansomLook: Riker Danzig LLP claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: Riker Danzig LLP. Description excerpt: To be announced...
  • P3 RansomLook: Tianji Auto Care Service Company claimed by nightspire — Public RansomLook extortion-site listing claim. Group: nightspire. Claimed victim/listing: Tianji Auto Care Service Company.
  • P3 RansomLook: Safeware claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Safeware. Description excerpt: safewareinc.com Safeware Inc. is a national leader providing safety and security solutions for…
  • P3 RansomLook: United Association Local Union 345 claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: United Association Local Union 345. Description excerpt: Membership Organizations
  • P3 RansomLook: D...s claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: D...s. Description excerpt: To be announced...
  • P3 RansomLook: stuartandassociates.com claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: stuartandassociates.com.
  • P3 RansomLook: BEDC.COM.AU claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: BEDC.COM.AU.
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=GuLoader,rat,RemcosRAT; url=http://151.241.154.105:8888/1/ueyasmgyetaq241.mwn
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=GuLoader,rat,RemcosRAT; url=http://151.241.154.105:8888/1/iokasg181fteasmm.nce
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=AgentTesla,ascii,Encoded,GuLoader; url=http://185.29.10.11/Menneskevrdige.csv
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=AgentTesla,encrypted,GuLoader; url=http://185.29.10.11/ePSDxHP52.bin
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,base64-loader,CoinMiner,Encoded,xmrig; url=http://31.77.227.130:6556/ok
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,base64-loader,CoinMiner,Encoded,xmrig; url=http://31.56.209.189:6556/ok
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,base64-loader,CoinMiner,Encoded,xmrig; url=http://joker.aec944b68370194a50.link:6556/ok
  • P3 Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI, (Wed, Aug 12th) — In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how…
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://182.127.64.81:42389/bin.sh
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ascii,Formbook,powershell,ps1; url=http://178.16.53.176/DV/ojkcrypted.ps1
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=AgentTesla,ascii,powershell,ps1; url=https://frtkvnpa.xyz/crypted.ps1
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-62913`CVE-2026-62913 Microsoft Exchange Server Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-71362`Hackers exploit critical Adobe Commerce flaw to hijack customer accountsBleepingComputer Ransomware News
    cve`CVE-2026-68820`Lazarus hackers exploited Windows zero-day to target defense firmsBleepingComputer Ransomware News
    cve`CVE-2026-68815`CVE-2026-68815 Microsoft Excel Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50655`CVE-2026-50655 Microsoft Windows Media Foundation Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2022-41127`CVE-2022-41127 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On PremMicrosoft Security Response Center RSS
    cve`CVE-2026-62696`CVE-2026-62696 Windows Program Compatibility Assistant Service Elevation of Privilege VulnMicrosoft Security Response Center RSS
    cve`CVE-2026-62747`CVE-2026-62747 Windows Device Association Service Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-70348`CVE-2026-70348 Windows Management Services Denial of Service VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50687`CVE-2026-50687 Windows Win32k Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-58538`CVE-2026-58538 Windows Bluetooth Service Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50476`CVE-2026-50476 Windows Network Connections Service Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-42976`CVE-2026-42976 Remote Access Management service/API (RPC server) Elevation of Privilege VuMicrosoft Security Response Center RSS
    ipv4`151.241.154.105`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    ipv4`185.29.10.11`URLhaus: malware_download URL observed (online)URLhaus Recent URLs
    ipv4`31.77.227.130`URLhaus: malware_download URL observed (online)URLhaus Recent URLs
    ipv4`31.56.209.189`URLhaus: malware_download URL observed (online)URLhaus Recent URLs
    hash`4d82f9fb62bdc9deb6a11133591c63fc1d6347d3`RansomLook: (DISCLOSED)City of Beacon claimed by ransomhouseRansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=36
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=52 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=0 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=74 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.