markcardiff.tech:/daily-intel/2026-08-18.html
Generated: 2026-08-18 08:00:15 UTC
P1: 6
P2: 7
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-18

Generated: 2026-08-18 08:00:15 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=6, P2=7, P3=42, P4=195.
  • Highest-priority item: CVE-2025-62593: Ray-Project Ray added to CISA KEV (P1, source: CISA Known Exploited Vulnerabilities).
  • 14 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2025-62593: Ray-Project Ray added to CISA KEV — CISA Known Exploited Vulnerabilities; score 107; technologies: none explicitly matched.
  • - Ray-Project Ray Code Injection Vulnerability. Known exploited vulnerability. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes)…

  • P1 CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 100; technologies: Windows Server.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Acknowledgement Updated

  • P1 CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Acknowledgement Updated

  • P1 CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Acknowledgement Updated

  • P1 CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Acknowledgement Updated

  • P2 Microsoft working on Defender patch for ShieldBreak zero-day — BleepingComputer Ransomware News; score 62; technologies: none explicitly matched.
  • - Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-69414. [...]

  • P2 RansomLook: Brinks Home claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Brinks Home. Description excerpt: Over 4.9 million Salesforce records containing some PII was compromised. The Company failed to reach an agreement with us despite…

  • P2 RansomLook: Alcon, Inc. claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Alcon, Inc.. Description excerpt: Over 25 million Salesforce records containing some PII was compromised. The Company failed to reach an agreement with us despite our…

  • P2 RansomLook: Questel SAS claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Questel SAS. Description excerpt: Over 21 million Salesforce records containing some PII and 147GB+ of internal corporate data was compromised. The Company failed to…

  • P2 RansomLook: Sharecare, Inc. claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Sharecare, Inc.. Description excerpt: This Company data was published due to them hiring a very incompetent and unskilled negotiator. If you choose incompetency to…

  • P2 RansomLook: Baxter International, Inc. claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Baxter International, Inc.. Description excerpt: Over 7.1M Salesforce records containing some PII was compromised. This is a final warning to reach out by 17 Aug 2026…

  • P2 RansomLook: Vermont XCenter claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Vermont XCenter. Description excerpt: A Vermont coloca seus clientes estrategicamente no Centro das Decisões, pois entende que o cliente deve estar no Centro das…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2025-62593: CVE-2025-62593: Ray-Project Ray added to CISA KEV — technologies: not watchlist-specific.
  • P1 CVE-2026-56188: CVE-2026-56188 Windows Server Network driver Remote Code Execution Vulnerability — technologies: Windows Server.
  • P1 CVE-2026-66807: CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-63519: CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-63513: CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-63518: CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P2 CVE-2026-69414: Microsoft working on Defender patch for ShieldBreak zero-day — technologies: not watchlist-specific.
  • P3 CVE-2026-62722: CVE-2026-62722 Microsoft Brokering File System Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-54121: Certighost and the Privilege Hiding in Your Certificate Authority — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Brinks Home claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Brinks Home. Description excerpt: Over 4.9 million Salesforce records containing some PII was compromised. The Company failed…
  • P2 RansomLook: Alcon, Inc. claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Alcon, Inc.. Description excerpt: Over 25 million Salesforce records containing some PII was compromised. The Company failed…
  • P2 RansomLook: Questel SAS claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Questel SAS. Description excerpt: Over 21 million Salesforce records containing some PII and 147GB+ of internal corporate data…
  • P2 RansomLook: Sharecare, Inc. claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Sharecare, Inc.. Description excerpt: This Company data was published due to them hiring a very incompetent and unskilled…
  • P2 RansomLook: Baxter International, Inc. claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Baxter International, Inc.. Description excerpt: Over 7.1M Salesforce records containing some PII was compromised. This is a…
  • P2 RansomLook: Vermont XCenter claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Vermont XCenter. Description excerpt: A Vermont coloca seus clientes estrategicamente no Centro das Decisões, pois entende que…
  • P3 Philips and GE investigating Clop ransomware data theft claims — Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]
  • P3 RansomLook: Lumenis Ltd. claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Lumenis Ltd.. Description excerpt: Over 1.1 million records containing some PII of customers/employees and 177GB+ of internal…
  • P3 RansomLook: Metabase claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Metabase. Description excerpt: :P
  • P3 RansomLook: NOTICE OF WARNING claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: NOTICE OF WARNING. Description excerpt: We are currently experiencing an influx of volume. More leaks are on their way. Kindly…
  • P3 RansomLook: Carhartt, Inc. claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Carhartt, Inc.. Description excerpt: Our demand for this Company was $3.3 million. The Company reached out. However, The…
  • P3 RansomLook: Cook Medical LLC claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Cook Medical LLC. Description excerpt: Customer data, employee data, and other internal corporate data was compromised. The…
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=974b6b4ed30ddaa4b6f4ec27976e52d8,dropped-by-remus; url=https://thu-iphone-07.cfd/TispciphraLoader.exe
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=elf,iot; url=http://176.65.139.194/loader
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://37.54.31.40:58523/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://37.54.31.40:58523/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://123.11.69.200:37705/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=mirai; url=http://200.115.102.246:58251/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://109.171.67.100:40657/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://123.129.132.69:54242/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=mirai; url=http://200.115.102.246:58251/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://196.189.98.77:59901/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://117.208.42.53:55830/i
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2025-62593`CVE-2025-62593: Ray-Project Ray added to CISA KEVCISA Known Exploited Vulnerabilities
    hash`70e7c72780bdec075dba6cad1afe0832772bfe09`CVE-2025-62593: Ray-Project Ray added to CISA KEVCISA Known Exploited Vulnerabilities
    cve`CVE-2026-56188`CVE-2026-56188 Windows Server Network driver Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-66807`CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-63519`CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-63513`CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-63518`CVE-2026-63518 Microsoft Office Word Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69414`Microsoft working on Defender patch for ShieldBreak zero-dayBleepingComputer Ransomware News
    cve`CVE-2026-62722`CVE-2026-62722 Microsoft Brokering File System Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-54121`Certighost and the Privilege Hiding in Your Certificate AuthorityBleepingComputer Ransomware News
    hash`974b6b4ed30ddaa4b6f4ec27976e52d8`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    ipv4`176.65.139.194`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs
    hash`22d6afc5026ed606ba20dd5f2860e718`RansomLook: terra-petra.com claimed by lockbit5RansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=35
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=80 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=12 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=82 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.