Daily Cyber Threat Intel Brief — 2026-08-17
Generated: 2026-08-17 08:00:15 UTC
Executive summary
Priority technology watch items
- Public URLhaus recent URL. Threat=malware_download; tags=botnet,bruteforce,iran,mirai,ssh; url=http://31.77.227.119/cat.sh
- Public URLhaus recent URL. Threat=malware_download; tags=botnet,bruteforce,iran,mirai,ssh; url=http://31.77.227.119/iran.armv7l
- Public RansomLook extortion-site listing claim. Group: emperador. Claimed victim/listing: Albania's official national teacher training portal.. Description excerpt: Albania’s official national teacher training portal provides centralized professional…
- Public RansomLook extortion-site listing claim. Group: emperador. Claimed victim/listing: Albania's Official National Teacher Training Portal. Description excerpt: Albania’s official national teacher training portal provides centralized professional…
- Public RansomLook extortion-site listing claim. Group: eclipse. Claimed victim/listing: Moscord. Description excerpt: Moscord is a digital marketplace that connects buyers and sellers in the maritime industry, offering a platform for various suppliers to…
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| ipv4 | `31.77.227.119` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| cve | `CVE-2026-65769` | CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-57104` | CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-65767` | CVE-2026-65767 Microsoft Teams for Android Spoofing Vulnerability | Microsoft Security Response Center RSS |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| ipv4 | `31.77.227.115` | URLhaus: malware_download URL observed (online) | URLhaus Recent URLs |
| hash | `dbe106197da13620f53ed5f2481b1970` | RansomLook: actua.fr claimed by lockbit5 | RansomLook Recent Listings |
| hash | `7c703831ffe8b0b9761a08710d0af29d` | RansomLook: dupouy-associes.fr claimed by lockbit5 | RansomLook Recent Listings |
| hash | `9a49a287d3e0d4a993de4fa5bd968a44` | RansomLook: agricolagalbusera.it claimed by lockbit5 | RansomLook Recent Listings |
| hash | `29cde1b97f982e6e9517920e9b8ca365` | RansomLook: tecosim.com claimed by lockbit5 | RansomLook Recent Listings |
| hash | `56802155da7ca00b8af929049da5fcf1` | RansomLook: vgrn.de claimed by lockbit5 | RansomLook Recent Listings |