markcardiff.tech:/daily-intel/2026-08-19.html
Generated: 2026-08-19 08:00:14 UTC
P1: 2
P2: 9
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-19

Generated: 2026-08-19 08:00:13 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=2, P2=9, P3=38, P4=201.
  • Highest-priority item: CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability (P1, source: Microsoft Security Response Center RSS).
  • 7 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Acknowledgement Updated

  • P1 CVE-2026-56642 Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated the Security Updates table by removing an affected software entry. No user action is required. This is an informational change only.

  • P2 CISA: Windows Task Host flaw now exploited by ransomware gangs — BleepingComputer Ransomware News; score 57; technologies: none explicitly matched.
  • - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. [...]

  • P2 RansomLook: Babcock claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Babcock. Description excerpt: babcock.co.za rocketreach.co/babcock-international-group-africa-profile_b5cda591f42e0b42 Babcock Africa is a leading engineering and…

  • P2 RansomLook: R & D Machine and Engineering claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: R & D Machine and Engineering. Description excerpt: &D Machine and Engineering, LLC specializes in CNC machining of precision metal components primarily for the…

  • P2 RansomLook: Brinks Home claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Brinks Home. Description excerpt: Over 4.9 million Salesforce records containing some PII was compromised. The Company failed to reach an agreement with us despite…

  • P2 RansomLook: Alcon, Inc. claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Alcon, Inc.. Description excerpt: Over 25 million Salesforce records containing some PII was compromised. The Company failed to reach an agreement with us despite our…

  • P2 RansomLook: Questel SAS claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Questel SAS. Description excerpt: Over 21 million Salesforce records containing some PII and 147GB+ of internal corporate data was compromised. The Company failed to…

  • P2 RansomLook: Sharecare, Inc. claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Sharecare, Inc.. Description excerpt: This Company data was published due to them hiring a very incompetent and unskilled negotiator. If you choose incompetency to…

  • P2 RansomLook: Baxter International, Inc. claimed by shinyhunters — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Baxter International, Inc.. Description excerpt: Over 7.1M Salesforce records containing some PII was compromised. This is a final warning to reach out by 17 Aug 2026…

  • P2 RansomLook: Prefeitura Municipal de Arcos claimed by emperador — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: emperador. Claimed victim/listing: Prefeitura Municipal de Arcos. Description excerpt: We hold complete, unrestricted access to your internal infrastructure. All servers, databases, emails, and admin…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-65791: CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-56642: CVE-2026-56642 Microsoft Fabric Data Warehouse Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-47632: CVE-2026-47632 Azure Connected Machine Agent Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-24301: CVE-2026-24301 Microsoft Copilot Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-50419: CVE-2026-50419 Windows Kernel Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 CISA: Windows Task Host flaw now exploited by ransomware gangs — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.…
  • P2 RansomLook: Babcock claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Babcock. Description excerpt: babcock.co.za rocketreach.co/babcock-international-group-africa-profile_b5cda591f42e0b42…
  • P2 RansomLook: R & D Machine and Engineering claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: R & D Machine and Engineering. Description excerpt: &D Machine and Engineering, LLC specializes in CNC machining of precision…
  • P2 RansomLook: Brinks Home claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Brinks Home. Description excerpt: Over 4.9 million Salesforce records containing some PII was compromised. The Company failed…
  • P2 RansomLook: Alcon, Inc. claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Alcon, Inc.. Description excerpt: Over 25 million Salesforce records containing some PII was compromised. The Company failed…
  • P2 RansomLook: Questel SAS claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Questel SAS. Description excerpt: Over 21 million Salesforce records containing some PII and 147GB+ of internal corporate data…
  • P2 RansomLook: Sharecare, Inc. claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Sharecare, Inc.. Description excerpt: This Company data was published due to them hiring a very incompetent and unskilled…
  • P2 RansomLook: Baxter International, Inc. claimed by shinyhunters — Public RansomLook extortion-site listing claim. Group: shinyhunters. Claimed victim/listing: Baxter International, Inc.. Description excerpt: Over 7.1M Salesforce records containing some PII was compromised. This is a…
  • P2 RansomLook: Prefeitura Municipal de Arcos claimed by emperador — Public RansomLook extortion-site listing claim. Group: emperador. Claimed victim/listing: Prefeitura Municipal de Arcos. Description excerpt: We hold complete, unrestricted access to your internal infrastructure. All…
  • P3 Clop created custom web shell for Windchill data theft attacks — A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal…
  • P3 RansomLook: Photon Health, Inc. claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: Photon Health, Inc..
  • P3 RansomLook: InfoFlo CRM claimed by direwolf — Public RansomLook extortion-site listing claim. Group: direwolf. Claimed victim/listing: InfoFlo CRM.
  • Malware / infrastructure / abuse feed highlights

  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://115.49.94.7:42242/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://222.137.172.144:33777/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://59.97.252.25:32934/i
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://167.86.99.169/iran.aarch64
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://219.157.246.145:56603/bin.sh
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://18.236.12.51/bins/chud.m68k
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://18.236.12.51/bins/chud.arm6
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://18.236.12.51/bins/chud.arm7
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://18.236.12.51/bins/chud.x86_64
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://18.236.12.51/bins/chud.ppc
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://18.236.12.51/bins/chud.arc
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-65791`CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-56642`CVE-2026-56642 Microsoft Fabric Data Warehouse Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-47632`CVE-2026-47632 Azure Connected Machine Agent Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-24301`CVE-2026-24301 Microsoft Copilot Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-50419`CVE-2026-50419 Windows Kernel Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`57062565054198fe38b978e436e845577c1cb295`RansomLook: (DISCLOSED)Alya Construtora claimed by ransomhouseRansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=39
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=62 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=1 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=64 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.