Daily Cyber Threat Intel Brief — 2026-08-21
Generated: 2026-08-21 08:00:17 UTC
Executive summary
Priority technology watch items
- Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
- The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only.
- The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only.
- Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
- Corrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only.
- Updated links to security updates. This is an informational change only.
- Added clarifying information to the mitigation. This is an informational change only.
- Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
- Updated an acknowledgement. This is an informational change only.
- Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
- A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Hogan Omidi P.C.. Description excerpt: Hogan Omidi, P.C. is a boutique law firm specializing in family law, including divorce, child custody, and property division,…
- Public RansomLook extortion-site listing claim. Group: emperador. Claimed victim/listing: NetExam. Description excerpt: NetExam (netexam.com) — the website of NetExam LMS+, a US-based SaaS learning management system built for external audiences rather than…
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-65770` | CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerabi | Microsoft Security Response Center RSS |
| cve | `CVE-2026-54118` | CVE-2026-54118 Microsoft SQL Server Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-54117` | CVE-2026-54117 Microsoft SQL Server Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-65801` | CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-66802` | CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-71331` | CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-33824` | CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Executio | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69836` | CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-61363` | CVE-2026-61363 Remote Desktop Client Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69419` | CVE-2026-69419 Azure Data Manager for Energy Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62754` | CVE-2026-62754 Windows Kerberos Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62834` | CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-68789` | CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69519` | CVE-2026-69519 Azure Stack HCI Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-69851` | CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62703` | CVE-2026-62703 Windows DWM Core Library Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-65786` | CVE-2026-65786 Desktop Window Manager Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-55015` | CVE-2026-55015 Microsoft Remote Help Denial of Service Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-55013` | CVE-2026-55013 Windows Remote Help Defense Spoofing Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62728` | CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-70105` | CVE-2026-70105 Microsoft Word Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-63509` | CVE-2026-63509 Microsoft Fabric Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-65816` | CVE-2026-65816 Azure Arc Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-66309` | CVE-2026-66309 Azure SQL Database Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-66800` | CVE-2026-66800 Azure Data Factory Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-68782` | CVE-2026-68782 Azure SQL Database Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| ipv4 | `178.132.198.200` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |