Daily Cyber Threat Intel Brief — 2026-08-14
Generated: 2026-08-14 08:00:15 UTC
Executive summary
Priority technology watch items
- A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]
- Acknowledgement Updated
- Removed Linux and macOS products from the Affected Software table. This is an informational change only.
- Removed Linux and macOS products from the Affected Software table. This is an informational change only.
- Acknowledgement Updated
- Updated the CVE title, changed the security impact from Denial of Service to Remote Code Execution, changed the severity from Important to Critical, updated the CVSS score from 5.9 to 8.1, and corrected the severity and impact entries in the Security Updates…
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Avanta Maroc Ex Adecco. Description excerpt: avanta.ma rocketreach.co/avanta-maroc-ex-adecco-profile_b7352c87c4297b95 Avanta Maroc, formerly known as Adecco Maroc,…
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Cityside Homes. Description excerpt: citysidehomes.com zoominfo.com/c/cityside-homes-llc/355153806 Cityside Homes is a new construction home builder based in…
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: GB Group S.A. Description excerpt: GB Group is one of Haiti’s largest private industrial and trading conglomerates. Headquartered in Port-au-Prince, it operates across…
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-59310` | Critical VMware vCenter RCE flaw exploited for reverse SSH access | BleepingComputer Ransomware News |
| cve | `CVE-2026-50461` | CVE-2026-50461 Windows NTFS Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62897` | CVE-2026-62897 .NET Framework Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-70354` | CVE-2026-70354 .NET Core Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64906` | CVE-2026-64906 Microsoft Access Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-65796` | CVE-2026-65796 Windows iSCSI Target Service Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-61346` | CVE-2026-61346 Windows Graphics Kernel Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62695` | CVE-2026-62695 Windows Storage Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-61359` | CVE-2026-61359 Windows Storage Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-66804` | CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62688` | CVE-2026-62688 Windows MIDI Service Module Elevation of Privileges Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-44814` | CVE-2026-44814 Windows DWM Core Library Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-45597` | CVE-2026-45597 Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulne | Microsoft Security Response Center RSS |
| cve | `CVE-2026-45593` | CVE-2026-45593 Windows SDK Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-45592` | CVE-2026-45592 Windows Internet (wininet.dll) Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50298` | CVE-2026-50298 Windows Spaceport.sys Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50342` | CVE-2026-50342 Windows MIDI Service Module Elevation of Privileges Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-49798` | CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50383` | CVE-2026-50383 Windows Print Spooler Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50387` | CVE-2026-50387 Windows GDI Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62902` | CVE-2026-62902 .NET Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62871` | CVE-2026-62871 .NET Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62886` | CVE-2026-62886 .NET Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62898` | CVE-2026-62898 Microsoft QUIC Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| ipv4 | `151.241.154.105` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| hash | `aad4bac321edc26a8cd977642358607beb7c7262` | RansomLook: (DISCLOSED)TECHVENTURES BANK S.A. claimed by ransomhouse | RansomLook Recent Listings |