Daily Cyber Threat Intel Brief — 2026-08-15
Generated: 2026-08-15 08:00:42 UTC
Executive summary
Priority technology watch items
- This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for…
- Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will…
- Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- The security updates for Powershell have been updated.
- Acknowledgement Updated
- The security updates for Powershell have been updated.
- Public RansomLook extortion-site listing claim. Group: rhysida. Claimed victim/listing: Pierce Township. Description excerpt: Pierce Township Pierce Township is a growing community in Ohio that blends rural charm with suburban living, covering 23.5 square…
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Avanta Maroc Ex Adecco. Description excerpt: avanta.ma rocketreach.co/avanta-maroc-ex-adecco-profile_b7352c87c4297b95 Avanta Maroc, formerly known as Adecco Maroc,…
- Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Cityside Homes. Description excerpt: citysidehomes.com zoominfo.com/c/cityside-homes-llc/355153806 Cityside Homes is a new construction home builder based in…
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-46300` | Metasploit Wrap Up: Lot of summer shells and fit http profiles | Rapid7 Blog |
| cve | `CVE-2026-69414` | CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-72970` | CVE-2026-72970 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-70337` | CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50313` | CVE-2026-50313 Windows NTFS Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50523` | CVE-2026-50523 Microsoft PowerShell Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-19560` | Chromium: CVE-2026-19560 Use after free in Blink | Microsoft Security Response Center RSS |
| cve | `CVE-2026-19559` | Chromium: CVE-2026-19559 Use after free in HTML | Microsoft Security Response Center RSS |
| cve | `CVE-2026-19558` | Chromium: CVE-2026-19558 Use after free in Extensions | Microsoft Security Response Center RSS |
| cve | `CVE-2026-19557` | Chromium: CVE-2026-19557 Use after free in TabStrip | Microsoft Security Response Center RSS |
| cve | `CVE-2026-19556` | Chromium: CVE-2026-19556 Use after free in V8 | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62777` | CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-61347` | CVE-2026-61347 Windows Event Logging Service Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62746` | CVE-2026-62746 Win32k Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62755` | CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-65671` | CVE-2026-65671 Remote Access API Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-68821` | CVE-2026-68821 Windows Package Manager Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-59126` | CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-59119` | CVE-2026-59119 PowerShell Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-32153` | CVE-2026-32153 Windows Speech Runtime Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-48566` | CVE-2026-48566 Windows DWM Core Library Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-70338` | CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability | Microsoft Security Response Center RSS |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| ipv4 | `166.0.192.57` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| hash | `90beb8a335c0d7625ee2d3a0f21b5eee7bd0fc9a` | RansomLook: (DISCLOSED)PCL Holding claimed by ransomhouse | RansomLook Recent Listings |