Daily Cyber Threat Intel Brief — 2026-08-18
Generated: 2026-08-18 08:00:15 UTC
Executive summary
Collected 250 recent public-source CTI items for technology-only monitoring.
Priority distribution: P1=6, P2=7, P3=42, P4=195.
Highest-priority item: CVE-2025-62593: Ray-Project Ray added to CISA KEV (P1, source: CISA Known Exploited Vulnerabilities).
14 public IOC highlights selected for analyst awareness.
Priority technology watch items
P1 CVE-2025-62593: Ray-Project Ray added to CISA KEV — CISA Known Exploited Vulnerabilities; score 107; technologies: none explicitly matched.
- Ray-Project Ray Code Injection Vulnerability. Known exploited vulnerability. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes)…
P1 CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 100; technologies: Windows Server.
- Updated an acknowledgement. This is an informational change only.
P1 CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Acknowledgement Updated
P1 CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Acknowledgement Updated
P1 CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Acknowledgement Updated
P1 CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Acknowledgement Updated
P2 Microsoft working on Defender patch for ShieldBreak zero-day — BleepingComputer Ransomware News; score 62; technologies: none explicitly matched.
- Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-69414. [...]
P2 RansomLook: Brinks Home claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Brinks Home. Description excerpt: Over 4.9 million Salesforce records containing some PII was compromised. The Company failed to reach an agreement with us despite…
P2 RansomLook: Alcon, Inc. claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Alcon, Inc.. Description excerpt: Over 25 million Salesforce records containing some PII was compromised. The Company failed to reach an agreement with us despite our…
P2 RansomLook: Questel SAS claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Questel SAS. Description excerpt: Over 21 million Salesforce records containing some PII and 147GB+ of internal corporate data was compromised. The Company failed to…
P2 RansomLook: Sharecare, Inc. claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Sharecare, Inc.. Description excerpt: This Company data was published due to them hiring a very incompetent and unskilled negotiator. If you choose incompetency to…
P2 RansomLook: Baxter International, Inc. claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Baxter International, Inc.. Description excerpt: Over 7.1M Salesforce records containing some PII was compromised. This is a final warning to reach out by 17 Aug 2026…
P2 RansomLook: Vermont XCenter claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Vermont XCenter. Description excerpt: A Vermont coloca seus clientes estrategicamente no Centro das Decisões, pois entende que o cliente deve estar no Centro das…
Newly exploited vulnerabilities / CVE watch
P1 CVE-2025-62593: CVE-2025-62593: Ray-Project Ray added to CISA KEV — technologies: not watchlist-specific.
P1 CVE-2026-56188: CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability — technologies: Windows Server.
P1 CVE-2026-66807: CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability — technologies: not watchlist-specific.
P1 CVE-2026-63519: CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability — technologies: not watchlist-specific.
P1 CVE-2026-63513: CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability — technologies: not watchlist-specific.
P1 CVE-2026-63518: CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability — technologies: not watchlist-specific.
P2 CVE-2026-69414: Microsoft working on Defender patch for ShieldBreak zero-day — technologies: not watchlist-specific.
P3 CVE-2026-62722: CVE-2026-62722 Microsoft Brokering File System Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
P3 CVE-2026-54121: Certighost and the Privilege Hiding in Your Certificate Authority — technologies: not watchlist-specific.
Ransomware and extortion trend notes
P2 RansomLook: Brinks Home claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Brinks Home. Description excerpt: Over 4.9 million Salesforce records containing some PII was compromised. The Company failed…
P2 RansomLook: Alcon, Inc. claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Alcon, Inc.. Description excerpt: Over 25 million Salesforce records containing some PII was compromised. The Company failed…
P2 RansomLook: Questel SAS claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Questel SAS. Description excerpt: Over 21 million Salesforce records containing some PII and 147GB+ of internal corporate data…
P2 RansomLook: Sharecare, Inc. claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Sharecare, Inc.. Description excerpt: This Company data was published due to them hiring a very incompetent and unskilled…
P2 RansomLook: Baxter International, Inc. claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Baxter International, Inc.. Description excerpt: Over 7.1M Salesforce records containing some PII was compromised. This is a…
P2 RansomLook: Vermont XCenter claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Vermont XCenter. Description excerpt: A Vermont coloca seus clientes estrategicamente no Centro das Decisões, pois entende que…
P3 Philips and GE investigating Clop ransomware data theft claims — Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]
P3 RansomLook: Lumenis Ltd. claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Lumenis Ltd.. Description excerpt: Over 1.1 million records containing some PII of customers/employees and 177GB+ of internal…
P3 RansomLook: Metabase claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Metabase. Description excerpt: :P
P3 RansomLook: NOTICE OF WARNING claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: NOTICE OF WARNING. Description excerpt: We are currently experiencing an influx of volume. More leaks are on their way. Kindly…
P3 RansomLook: Carhartt, Inc. claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Carhartt, Inc.. Description excerpt: Our demand for this Company was $3.3 million. The Company reached out. However, The…
P3 RansomLook: Cook Medical LLC claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Cook Medical LLC. Description excerpt: Customer data, employee data, and other internal corporate data was compromised. The…
Malware / infrastructure / abuse feed highlights
P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=974b6b4ed30ddaa4b6f4ec27976e52d8,dropped-by-remus; url=https://thu-iphone-07.cfd/TispciphraLoader.exe
P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=elf,iot; url=http://176.65.139.194/loader
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://37.54.31.40:58523/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://37.54.31.40:58523/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://123.11.69.200:37705/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=mirai; url=http://200.115.102.246:58251/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://109.171.67.100:40657/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://123.129.132.69:54242/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=mirai; url=http://200.115.102.246:58251/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://196.189.98.77:59901/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://117.208.42.53:55830/i
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2025-62593` | CVE-2025-62593: Ray-Project Ray added to CISA KEV | CISA Known Exploited Vulnerabilities |
| hash | `70e7c72780bdec075dba6cad1afe0832772bfe09` | CVE-2025-62593: Ray-Project Ray added to CISA KEV | CISA Known Exploited Vulnerabilities |
| cve | `CVE-2026-56188` | CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-66807` | CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-63519` | CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-63513` | CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-63518` | CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69414` | Microsoft working on Defender patch for ShieldBreak zero-day | BleepingComputer Ransomware News |
| cve | `CVE-2026-62722` | CVE-2026-62722 Microsoft Brokering File System Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-54121` | Certighost and the Privilege Hiding in Your Certificate Authority | BleepingComputer Ransomware News |
| hash | `974b6b4ed30ddaa4b6f4ec27976e52d8` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| ipv4 | `176.65.139.194` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| hash | `22d6afc5026ed606ba20dd5f2860e718` | RansomLook: terra-petra.com claimed by lockbit5 | RansomLook Recent Listings |
Defensive takeaways
Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
Sources checked
BleepingComputer Ransomware News: ok new=0 fetched=15
CISA Known Exploited Vulnerabilities: ok new=0 fetched=35
Cisco Talos Blog: ok new=0 fetched=15
Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
Huntress Blog: ok new=0 fetched=25
Microsoft Security Response Center RSS: ok new=0 fetched=25
NVD Recent CVEs: ok new=80 fetched=80
ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
RansomLook Recent Listings: ok new=12 fetched=50
Rapid7 Blog: ok new=0 fetched=20
SANS Internet Storm Center: ok new=0 fetched=10
Sophos X-Ops: ok new=0 fetched=15
The DFIR Report: ok new=0 fetched=10
URLhaus Recent URLs: ok new=82 fetched=120
Unit 42 Threat Research: ok new=0 fetched=15
Limitations
Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
Technology-only matching can miss relevant items that do not name a tracked product explicitly.
Ransomware victim claims are actor/source claims unless independently corroborated.
IOC highlights are publicly sourced and should be validated before enforcement in production controls.