markcardiff.tech:/daily-intel/2026-08-20.html
Generated: 2026-08-20 08:00:16 UTC
P1: 2
P2: 2
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-20

Generated: 2026-08-20 08:00:16 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=2, P2=2, P3=59, P4=187.
  • Highest-priority item: CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway (P1, source: Rapid7 Blog).
  • 19 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway — Rapid7 Blog; score 107; technologies: Citrix NetScaler.
  • - Overview On August 19, 2026, a security advisory was published for CVE-2026-19490 , a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be…

  • P1 CVE-2026-65811 Power BI Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.

  • P2 CISA: Medusa ransomware hit over 500 critical infrastructure orgs — BleepingComputer Ransomware News; score 57; technologies: none explicitly matched.
  • - The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]

  • P2 RansomLook: Babcock claimed by the gentlemen — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Babcock. Description excerpt: babcock.co.za rocketreach.co/babcock-international-group-africa-profile_b5cda591f42e0b42 Babcock Africa is a leading engineering and…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-19490: CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway — technologies: Citrix NetScaler.
  • P1 CVE-2026-65811: CVE-2026-65811 Power BI Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62705: CVE-2026-62705 Microsoft Brokering File System Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-42912: CVE-2026-42912 Windows Telephony Service Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-65675: CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2020-1173: CVE-2020-1173 Microsoft Power BI Report Server Spoofing Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2021-26859: CVE-2021-26859 Microsoft Power BI Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2021-41372: CVE-2021-41372 Power BI Report Server Spoofing Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2023-21806: CVE-2023-21806 Power BI Report Server Spoofing Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2024-43612: CVE-2024-43612 Power BI Report Server Spoofing Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2024-43481: CVE-2024-43481 Power BI Report Server Spoofing Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-58647: CVE-2026-58647 Microsoft PowerBI Report Server Spoofing Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 CISA: Medusa ransomware hit over 500 critical infrastructure orgs — The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]
  • P2 RansomLook: Babcock claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Babcock. Description excerpt: babcock.co.za rocketreach.co/babcock-international-group-africa-profile_b5cda591f42e0b42…
  • P3 Rogue ransomware affiliate poses as recovery firm to steal payments — A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete…
  • P3 RansomLook: Capgemini Engineering claimed by everest — Public RansomLook extortion-site listing claim. Group: everest. Claimed victim/listing: Capgemini Engineering. Description excerpt: 2 posts - 1h
  • P3 RansomLook: Grupo DT claimed by everest — Public RansomLook extortion-site listing claim. Group: everest. Claimed victim/listing: Grupo DT. Description excerpt: 2 posts - 1h
  • P3 RansomLook: Kingston Technology claimed by everest — Public RansomLook extortion-site listing claim. Group: everest. Claimed victim/listing: Kingston Technology. Description excerpt: 2 posts - 1h
  • P3 RansomLook: Experts Entreprendre claimed by everest — Public RansomLook extortion-site listing claim. Group: everest. Claimed victim/listing: Experts Entreprendre. Description excerpt: 2 posts - 1h
  • P3 RansomLook: Target claimed by xpl0itrs — Public RansomLook extortion-site listing claim. Group: xpl0itrs. Claimed victim/listing: Target. Description excerpt: General merchandise retail
  • P3 RansomLook: usbank.com claimed by lockbit5 — Public RansomLook extortion-site listing claim. Group: lockbit5. Claimed victim/listing: usbank.com. Description excerpt: U.S. Bank is a multinational financial institution that provides banking, lending, payment, and…
  • P3 RansomLook: Grand Ion Delemen Hotel claimed by majinahanashi — Public RansomLook extortion-site listing claim. Group: majinahanashi. Claimed victim/listing: Grand Ion Delemen Hotel. Description excerpt: PUBLICATION SCHEDULED. Publication scheduled: 2026-08-26T16:34:00Z Package: 4.0…
  • P3 RansomLook: The Margo Hotel claimed by majinahanashi — Public RansomLook extortion-site listing claim. Group: majinahanashi. Claimed victim/listing: The Margo Hotel. Description excerpt: PUBLICATION SCHEDULED. Publication scheduled: 2026-08-26T20:49:00Z Package: 4.6 GiB /…
  • P3 RansomLook: Semana claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Semana. Description excerpt: Advertising & Marketing
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=https://cqintzfep6rw6jc9.public.blob.vercel-storage.com/2.bat
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=https://itsmystik.com/dl/deadlock/Loader.exe
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=GuLoader,VIPKeylogger; url=https://drive.google.com/uc?export=download&id=1mVI9h_rV6mptfRqbC3cDNiyfurIAq2tQ
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://112.232.226.68:57370/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=rat,RemcosRAT; url=https://res.cloudinary.com/shsw2tu4/image/upload/v1787199350/img_001530.jpg
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://59.97.253.208:46690/bin.sh
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://60.184.140.145:34890/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://61.53.95.17:59123/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://115.55.236.213:53264/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=http://23.94.145.229/api/v1/ps1/bf57fba60c91af3c5b2a12a00824e554/payload?gk=8548a53bccb76780011e980c89530d41dc9762640a4cc2664b532a045e8dee8b
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=AsyncRAT,exe; url=http://85.203.4.64/client.exe
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-19490`CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewaRapid7 Blog
    cve`CVE-2026-65811`CVE-2026-65811 Power BI Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62705`CVE-2026-62705 Microsoft Brokering File System Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-42912`CVE-2026-42912 Windows Telephony Service Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-65675`CVE-2026-65675 CoPilot Chat Security Feature Bypass VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2020-1173`CVE-2020-1173 Microsoft Power BI Report Server Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2021-26859`CVE-2021-26859 Microsoft Power BI Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2021-41372`CVE-2021-41372 Power BI Report Server Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2023-21806`CVE-2023-21806 Power BI Report Server Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2024-43612`CVE-2024-43612 Power BI Report Server Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2024-43481`CVE-2024-43481 Power BI Report Server Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-58647`CVE-2026-58647 Microsoft PowerBI Report Server Spoofing VulnerabilityMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    hash`9d0b9595b62e70efa9c62d22143bcde3`RansomLook: usbank.com claimed by lockbit5RansomLook Recent Listings
    hash`ce605d864c57ff747e7ecd30b1902f299173d3a000f157f0db042e5176388d4d`RansomLook: sunsea.co.th claimed by krybitRansomLook Recent Listings
    hash`46a64b85d31f0d777b0dc5a91f1600a5e5ae008c53047d5894278928d4da5c2c`RansomLook: www.mestojilemnice.cz claimed by krybitRansomLook Recent Listings
    hash`82b3572f2dadeca89f06a17fd17a8f05f10e23aff09bfc7071d7b6d29e6238e5`RansomLook: automotoresrosedal.com.ar claimed by krybitRansomLook Recent Listings
    hash`b4d8eca0770c757d11f65384178d5b5593c9c56b412f43ceab1594beb5de1669`RansomLook: sipresitalia.it claimed by krybitRansomLook Recent Listings
    hash`5a53eb10748f0117aaad6cba285ba46741fa0ad62a76966d702b51fad300978a`RansomLook: www.hsi.info claimed by krybitRansomLook Recent Listings

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=1 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=40
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=21 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=4 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=120 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.