markcardiff.tech:/daily-intel/2026-08-14.html
Generated: 2026-08-14 08:00:15 UTC
P1: 6
P2: 3
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-14

Generated: 2026-08-14 08:00:15 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=6, P2=3, P3=102, P4=139.
  • Highest-priority item: Critical VMware vCenter RCE flaw exploited for reverse SSH access (P1, source: BleepingComputer Ransomware News).
  • 27 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 Critical VMware vCenter RCE flaw exploited for reverse SSH access — BleepingComputer Ransomware News; score 74; technologies: none explicitly matched.
  • - A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...]

  • P1 CVE-2026-50461 Windows NTFS Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Acknowledgement Updated

  • P1 CVE-2026-62897 .NET Framework Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Removed Linux and macOS products from the Affected Software table. This is an informational change only.

  • P1 CVE-2026-70354 .NET Core Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Removed Linux and macOS products from the Affected Software table. This is an informational change only.

  • P1 CVE-2026-64906 Microsoft Access Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Acknowledgement Updated

  • P1 CVE-2026-65796 Windows iSCSI Target Service Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated the CVE title, changed the security impact from Denial of Service to Remote Code Execution, changed the severity from Important to Critical, updated the CVSS score from 5.9 to 8.1, and corrected the severity and impact entries in the Security Updates…

  • P2 RansomLook: Avanta Maroc Ex Adecco claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Avanta Maroc Ex Adecco. Description excerpt: avanta.ma rocketreach.co/avanta-maroc-ex-adecco-profile_b7352c87c4297b95 Avanta Maroc, formerly known as Adecco Maroc,…

  • P2 RansomLook: Cityside Homes claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Cityside Homes. Description excerpt: citysidehomes.com zoominfo.com/c/cityside-homes-llc/355153806 Cityside Homes is a new construction home builder based in…

  • P2 RansomLook: GB Group S.A claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: GB Group S.A. Description excerpt: GB Group is one of Haiti’s largest private industrial and trading conglomerates. Headquartered in Port-au-Prince, it operates across…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-59310: Critical VMware vCenter RCE flaw exploited for reverse SSH access — technologies: not watchlist-specific.
  • P1 CVE-2026-50461: CVE-2026-50461 Windows NTFS Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-62897: CVE-2026-62897 .NET Framework Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-70354: CVE-2026-70354 .NET Core Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-64906: CVE-2026-64906 Microsoft Access Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-65796: CVE-2026-65796 Windows iSCSI Target Service Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-61346: CVE-2026-61346 Windows Graphics Kernel Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62695: CVE-2026-62695 Windows Storage Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-61359: CVE-2026-61359 Windows Storage Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-66804: CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-65796: CVE-2026-65796 Windows iSCSI Target Service Denial of Service Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62688: CVE-2026-62688 Windows MIDI Service Module Elevation of Privileges Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-44814: CVE-2026-44814 Windows DWM Core Library Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-45597: CVE-2026-45597 Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-45593: CVE-2026-45593 Windows SDK Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-45592: CVE-2026-45592 Windows Internet (wininet.dll) Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-50298: CVE-2026-50298 Windows Spaceport.sys Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-50342: CVE-2026-50342 Windows MIDI Service Module Elevation of Privileges Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-49798: CVE-2026-49798 Windows Kernel Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-50383: CVE-2026-50383 Windows Print Spooler Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Avanta Maroc Ex Adecco claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Avanta Maroc Ex Adecco. Description excerpt: avanta.ma rocketreach.co/avanta-maroc-ex-adecco-profile_b7352c87c4297b95 Avanta…
  • P2 RansomLook: Cityside Homes claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Cityside Homes. Description excerpt: citysidehomes.com zoominfo.com/c/cityside-homes-llc/355153806 Cityside Homes is a new…
  • P2 RansomLook: GB Group S.A claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: GB Group S.A. Description excerpt: GB Group is one of Haiti’s largest private industrial and trading conglomerates.…
  • P3 Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt — An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]
  • P3 RansomLook: Lercher Werkzeugbau claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Lercher Werkzeugbau. Description excerpt: Industrial Machinery & Equipment
  • P3 RansomLook: 3f claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: 3f. Description excerpt: Membership Organizations
  • P3 RansomLook: PenLink claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: PenLink. Description excerpt: Software
  • P3 RansomLook: EKEPIS claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: EKEPIS. Description excerpt: ekepis.gr rocketreach.co/ekepis-ethniko-kentro-pistopoiisis-domon-profile_b6d46b6ac7408ffe…
  • P3 RansomLook: Megalaser Industria Metalurgica LTDA claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Megalaser Industria Metalurgica LTDA. Description excerpt: megalaser.com.br…
  • P3 RansomLook: Community Connections claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Community Connections. Description excerpt: comconnections.org zoominfo.com/c/community-connections-inc/350834294 Community…
  • P3 RansomLook: Acli claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Acli. Description excerpt: acli.it zoominfo.com/c/acli/372618594 ACLI (Christian Associations of Italian Workers) is a major…
  • P3 RansomLook: Vector Two Technology claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Vector Two Technology. Description excerpt: vtt.com.br zoominfo.com/c/vtt/372441609 VTT is a pioneering Brazilian technology…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=exe,MintsLoader; url=http://nodemetrics3379.com/update/exe
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://botnet.botnet.xd.67.flightleaks.xyz/wd1337
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://u87yy3f87b23f8293bfg83bgu94.bombamodzik.xyz/wd1337
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://botnet.botnet.xd.67.flightleaks.xyz/log
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://botnet.botnet.xd.67.flightleaks.xyz/wd1337
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://u87yy3f87b23f8293bfg83bgu94.bombamodzik.xyz/wd1337
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://botnet.botnet.xd.67.flightleaks.xyz/log
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://botnet.botnet.xd.67.flightleaks.xyz/proot
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://botnet.botnet.xd.67.flightleaks.xyz/Error84
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://botnet.botnet.xd.67.flightleaks.xyz/Error84
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnetdomain,elf,mirai; url=http://botnet.botnet.xd.67.flightleaks.xyz/proot
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-59310`Critical VMware vCenter RCE flaw exploited for reverse SSH accessBleepingComputer Ransomware News
    cve`CVE-2026-50461`CVE-2026-50461 Windows NTFS Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62897`CVE-2026-62897 .NET Framework Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-70354`CVE-2026-70354 .NET Core Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-64906`CVE-2026-64906 Microsoft Access Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-65796`CVE-2026-65796 Windows iSCSI Target Service Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-61346`CVE-2026-61346 Windows Graphics Kernel Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62695`CVE-2026-62695 Windows Storage Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-61359`CVE-2026-61359 Windows Storage Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-66804`CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62688`CVE-2026-62688 Windows MIDI Service Module Elevation of Privileges VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-44814`CVE-2026-44814 Windows DWM Core Library Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-45597`CVE-2026-45597 Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege VulneMicrosoft Security Response Center RSS
    cve`CVE-2026-45593`CVE-2026-45593 Windows SDK Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-45592`CVE-2026-45592 Windows Internet (wininet.dll) Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50298`CVE-2026-50298 Windows Spaceport.sys Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50342`CVE-2026-50342 Windows MIDI Service Module Elevation of Privileges VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-49798`CVE-2026-49798 Windows Kernel Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50383`CVE-2026-50383 Windows Print Spooler Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50387`CVE-2026-50387 Windows GDI Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62902`CVE-2026-62902 .NET Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62871`CVE-2026-62871 .NET Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62886`CVE-2026-62886 .NET Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62898`CVE-2026-62898 Microsoft QUIC Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    ipv4`151.241.154.105`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    hash`aad4bac321edc26a8cd977642358607beb7c7262`RansomLook: (DISCLOSED)TECHVENTURES BANK S.A. claimed by ransomhouseRansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=35
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=22 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=19 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=120 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.