markcardiff.tech:/daily-intel/2026-08-15.html
Generated: 2026-08-15 08:00:42 UTC
P1: 6
P2: 3
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-15

Generated: 2026-08-15 08:00:42 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=6, P2=3, P3=58, P4=183.
  • Highest-priority item: Metasploit Wrap Up: Lot of summer shells and fit http profiles (P1, source: Rapid7 Blog).
  • 25 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 Metasploit Wrap Up: Lot of summer shells and fit http profiles — Rapid7 Blog; score 107; technologies: SonicWall, WordPress.
  • - This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for…

  • P1 CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability — Microsoft Security Response Center RSS; score 75; technologies: Microsoft Defender.
  • - Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will…

  • P1 CVE-2026-72970 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - The security updates for Powershell have been updated.

  • P1 CVE-2026-50313 Windows NTFS Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Acknowledgement Updated

  • P1 CVE-2026-50523 Microsoft PowerShell Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - The security updates for Powershell have been updated.

  • P2 RansomLook: Pierce Township claimed by rhysida — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: rhysida. Claimed victim/listing: Pierce Township. Description excerpt: Pierce Township Pierce Township is a growing community in Ohio that blends rural charm with suburban living, covering 23.5 square…

  • P2 RansomLook: Avanta Maroc Ex Adecco claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Avanta Maroc Ex Adecco. Description excerpt: avanta.ma rocketreach.co/avanta-maroc-ex-adecco-profile_b7352c87c4297b95 Avanta Maroc, formerly known as Adecco Maroc,…

  • P2 RansomLook: Cityside Homes claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Cityside Homes. Description excerpt: citysidehomes.com zoominfo.com/c/cityside-homes-llc/355153806 Cityside Homes is a new construction home builder based in…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-46300: Metasploit Wrap Up: Lot of summer shells and fit http profiles — technologies: SonicWall, WordPress.
  • P1 CVE-2026-69414: CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability — technologies: Microsoft Defender.
  • P1 CVE-2026-72970: CVE-2026-72970 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-70337: CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-50313: CVE-2026-50313 Windows NTFS Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-50523: CVE-2026-50523 Microsoft PowerShell Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-19560: Chromium: CVE-2026-19560 Use after free in Blink — technologies: not watchlist-specific.
  • P3 CVE-2026-19559: Chromium: CVE-2026-19559 Use after free in HTML — technologies: not watchlist-specific.
  • P3 CVE-2026-19558: Chromium: CVE-2026-19558 Use after free in Extensions — technologies: not watchlist-specific.
  • P3 CVE-2026-19557: Chromium: CVE-2026-19557 Use after free in TabStrip — technologies: not watchlist-specific.
  • P3 CVE-2026-19556: Chromium: CVE-2026-19556 Use after free in V8 — technologies: not watchlist-specific.
  • P3 CVE-2026-62777: CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-61347: CVE-2026-61347 Windows Event Logging Service Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62746: CVE-2026-62746 Win32k Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62755: CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-65671: CVE-2026-65671 Remote Access API Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-68821: CVE-2026-68821 Windows Package Manager Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-59126: CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-59119: CVE-2026-59119 PowerShell Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-32153: CVE-2026-32153 Windows Speech Runtime Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Pierce Township claimed by rhysida — Public RansomLook extortion-site listing claim. Group: rhysida. Claimed victim/listing: Pierce Township. Description excerpt: Pierce Township Pierce Township is a growing community in Ohio that blends rural charm with…
  • P2 RansomLook: Avanta Maroc Ex Adecco claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Avanta Maroc Ex Adecco. Description excerpt: avanta.ma rocketreach.co/avanta-maroc-ex-adecco-profile_b7352c87c4297b95 Avanta…
  • P2 RansomLook: Cityside Homes claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Cityside Homes. Description excerpt: citysidehomes.com zoominfo.com/c/cityside-homes-llc/355153806 Cityside Homes is a new…
  • P3 Shell investigates 'potential incident' after Clop data theft claims — Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...]
  • P3 RansomLook: Interim HealthCare claimed by anubis — Public RansomLook extortion-site listing claim. Group: anubis. Claimed victim/listing: Interim HealthCare. Description excerpt: Home Healthcare Agency & Medical Staffing.
  • P3 RansomLook: FERRARI MANGIMI SRL claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: FERRARI MANGIMI SRL. Description excerpt: Business Services
  • P3 RansomLook: granjarinya.com claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: granjarinya.com. Description excerpt: Headquartered in Albal, Valencia, the family-owned company traces its origins to three…
  • P3 RansomLook: Columbia University Information (Dental) claimed by global secret group — Public RansomLook extortion-site listing claim. Group: global secret group. Claimed victim/listing: Columbia University Information (Dental). Description excerpt: Country: New York, US | Website: columbia.edu | Revenue:…
  • P3 RansomLook: FiferFox Minecraft Server claimed by bluewhale — Public RansomLook extortion-site listing claim. Group: bluewhale. Claimed victim/listing: FiferFox Minecraft Server. Description excerpt: Minecraft Server • 10000 • 3 This is a basic Minecraft Server.
  • P3 RansomLook: Satellite Developer Server claimed by bluewhale — Public RansomLook extortion-site listing claim. Group: bluewhale. Claimed victim/listing: Satellite Developer Server. Description excerpt: Developer • 20000 • 5 A software developer at a company
  • P3 RansomLook: Connell Enterprises LLC claimed by interlock — Public RansomLook extortion-site listing claim. Group: interlock. Claimed victim/listing: Connell Enterprises LLC. Description excerpt: He performs system administration for domain networks but is unable to ensure his…
  • P3 RansomLook: cambrialawfirm.com claimed by inc ransom — Public RansomLook extortion-site listing claim. Group: inc ransom. Claimed victim/listing: cambrialawfirm.com.
  • Malware / infrastructure / abuse feed highlights

  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=elf,iot; url=http://166.0.192.57/loader
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=exe,MintsLoader; url=http://nodemetrics3379.com/update/exe
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=54e64e,dropped-by-amadey; url=http://91.92.242.236/files-129312398/files/file_865135af23551105.exe
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://222.139.192.15:47283/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://117.223.140.197:37526/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://27.217.139.36:39257/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://117.223.140.197:37526/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://110.36.22.249:44558/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://110.39.228.78:44625/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://116.76.206.254:50342/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://125.41.6.205:46320/i
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-46300`Metasploit Wrap Up: Lot of summer shells and fit http profilesRapid7 Blog
    cve`CVE-2026-69414`CVE-2026-69414 Microsoft Defender Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-72970`CVE-2026-72970 Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-70337`CVE-2026-70337 Microsoft PowerShell Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50313`CVE-2026-50313 Windows NTFS Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50523`CVE-2026-50523 Microsoft PowerShell Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-19560`Chromium: CVE-2026-19560 Use after free in BlinkMicrosoft Security Response Center RSS
    cve`CVE-2026-19559`Chromium: CVE-2026-19559 Use after free in HTMLMicrosoft Security Response Center RSS
    cve`CVE-2026-19558`Chromium: CVE-2026-19558 Use after free in ExtensionsMicrosoft Security Response Center RSS
    cve`CVE-2026-19557`Chromium: CVE-2026-19557 Use after free in TabStripMicrosoft Security Response Center RSS
    cve`CVE-2026-19556`Chromium: CVE-2026-19556 Use after free in V8Microsoft Security Response Center RSS
    cve`CVE-2026-62777`CVE-2026-62777 Windows License Manager Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-61347`CVE-2026-61347 Windows Event Logging Service Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62746`CVE-2026-62746 Win32k Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62755`CVE-2026-62755 Windows DHCP Client Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-65671`CVE-2026-65671 Remote Access API Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-68821`CVE-2026-68821 Windows Package Manager Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-59126`CVE-2026-59126 Windows Event Logging Service Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-59119`CVE-2026-59119 PowerShell Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-32153`CVE-2026-32153 Windows Speech Runtime Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-48566`CVE-2026-48566 Windows DWM Core Library Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-70338`CVE-2026-70338 Microsoft PowerShell Security Feature Bypass VulnerabilityMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    ipv4`166.0.192.57`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    hash`90beb8a335c0d7625ee2d3a0f21b5eee7bd0fc9a`RansomLook: (DISCLOSED)PCL Holding claimed by ransomhouseRansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=35
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=45 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=1 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: error: syntax error: line 1, column 0
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=48 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.