markcardiff.tech:/daily-intel/2026-08-21.html
Generated: 2026-08-21 08:00:17 UTC
P1: 10
P2: 3
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-21

Generated: 2026-08-21 08:00:17 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=10, P2=3, P3=69, P4=168.
  • Highest-priority item: CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability (P1, source: Microsoft Security Response Center RSS).
  • 28 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 100; technologies: Apache.
  • - Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-54118 Microsoft SQL Server Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 82; technologies: none explicitly matched.
  • - The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only.

  • P1 CVE-2026-54117 Microsoft SQL Server Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 82; technologies: none explicitly matched.
  • - The CVSS vector string was update to reflect that an attacker does not require any privileges to successfully exploit this vulnerability (PR:N). This is an informational change only.

  • P1 CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability — Microsoft Security Response Center RSS; score 75; technologies: Microsoft Exchange.
  • - Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

  • P1 CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Corrected the Executive Summary to clarify that the vulnerability affects Windows Device Health Attestation (DHA), not Microsoft Azure Attestation. This is an informational change only.

  • P1 CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated links to security updates. This is an informational change only.

  • P1 CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Added clarifying information to the mitigation. This is an informational change only.

  • P1 CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

  • P1 CVE-2026-61363 Remote Desktop Client Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-69419 Azure Data Manager for Energy Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.

  • P2 Critical Elementor Pro bug exposes WordPress sites to RCE attacks — BleepingComputer Ransomware News; score 67; technologies: WordPress.
  • - A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]

  • P2 RansomLook: Hogan Omidi P.C. claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Hogan Omidi P.C.. Description excerpt: Hogan Omidi, P.C. is a boutique law firm specializing in family law, including divorce, child custody, and property division,…

  • P2 RansomLook: NetExam claimed by emperador — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: emperador. Claimed victim/listing: NetExam. Description excerpt: NetExam (netexam.com) — the website of NetExam LMS+, a US-based SaaS learning management system built for external audiences rather than…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-65770: CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability — technologies: Apache.
  • P1 CVE-2026-54118: CVE-2026-54118 Microsoft SQL Server Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-54117: CVE-2026-54117 Microsoft SQL Server Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-65801: CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege Vulnerability — technologies: Microsoft Exchange.
  • P1 CVE-2026-66802: CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-71331: CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-33824: CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-69836: CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-61363: CVE-2026-61363 Remote Desktop Client Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-69419: CVE-2026-69419 Azure Data Manager for Energy Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62754: CVE-2026-62754 Windows Kerberos Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62834: CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-68789: CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69519: CVE-2026-69519 Azure Stack HCI Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-69851: CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62703: CVE-2026-62703 Windows DWM Core Library Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-65786: CVE-2026-65786 Desktop Window Manager Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-55015: CVE-2026-55015 Microsoft Remote Help Denial of Service Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-55013: CVE-2026-55013 Windows Remote Help Defense Spoofing Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-62728: CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Hogan Omidi P.C. claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Hogan Omidi P.C.. Description excerpt: Hogan Omidi, P.C. is a boutique law firm specializing in family law, including divorce,…
  • P2 RansomLook: NetExam claimed by emperador — Public RansomLook extortion-site listing claim. Group: emperador. Claimed victim/listing: NetExam. Description excerpt: NetExam (netexam.com) — the website of NetExam LMS+, a US-based SaaS learning management system…
  • P3 RansomLook: UOLconsult claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: UOLconsult. Description excerpt: uol-consult.com UOLconsult GmbH is a boutique management consulting firm based in Vienna,…
  • P3 RansomLook: dlp motive claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: dlp motive. Description excerpt: dlp-motive.de dlp motive is a German full-service event technology provider founded in 2007,…
  • P3 RansomLook: AWJ Holding claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: AWJ Holding. Description excerpt: awjholding.com zoominfo.com/c/awj-holding-co/448239448 AWJ Holding Company is a prominent…
  • P3 RansomLook: Lexacaucho claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Lexacaucho. Description excerpt: lexacaucho.com zoominfo.com/c/lexacaucho--laminados-y-extruidos-de-caucho-sac/457170004…
  • P3 RansomLook: LOG Systems claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: LOG Systems. Description excerpt: logsystem.pl zoominfo.com/c/log-systems/372786485 LOG Systems is a Polish software company…
  • P3 RansomLook: Interim HealthCare (Head office) claimed by anubis — Public RansomLook extortion-site listing claim. Group: anubis. Claimed victim/listing: Interim HealthCare (Head office). Description excerpt: Data breach at a major healthcare franchise headquarters.
  • P3 RansomLook: Hitachi High-Tech claimed by coinbase cartel — Public RansomLook extortion-site listing claim. Group: coinbase cartel. Claimed victim/listing: Hitachi High-Tech. Description excerpt: Automation & Materials - $4.7 Billion
  • P3 RansomLook: D... claimed by leakeddata — Public RansomLook extortion-site listing claim. Group: leakeddata. Claimed victim/listing: D.... Description excerpt: To be announced...
  • P3 RansomLook: Frisian Flag Indonesia claimed by panzer — Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Frisian Flag Indonesia. Description excerpt: Frisian Flag Indonesia specializes in high-quality dairy products, including sweetened…
  • P3 RansomLook: Ayuntamiento de Velilla de San Antonio claimed by kairos — Public RansomLook extortion-site listing claim. Group: kairos. Claimed victim/listing: Ayuntamiento de Velilla de San Antonio. Description excerpt: El Ayuntamiento de Velilla de San Antonio es el organismo oficial de…
  • Malware / infrastructure / abuse feed highlights

  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=botnet,download,malware,sh; url=http://178.132.198.200/payload_v10.sh
  • P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=None; url=https://itsmystik.com/dl/deadlock/Loader.exe
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://91.192.81.41:8080/arm
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://91.192.81.41:8080/arm5
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://91.192.81.41:8080/mpsl
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://91.192.81.41:8080/arm7
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://91.192.81.41:8080/m68k
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://91.192.81.41:8080/x86_32
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://91.192.81.41:8080/ppc440
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://91.192.81.41:8080/mips
  • P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ua-wget; url=http://91.192.81.41:8080/sh4
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-65770`CVE-2026-65770 Azure Managed Instance for Apache Cassandra Remote Code Execution VulnerabiMicrosoft Security Response Center RSS
    cve`CVE-2026-54118`CVE-2026-54118 Microsoft SQL Server Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-54117`CVE-2026-54117 Microsoft SQL Server Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-65801`CVE-2026-65801 Microsoft Exchange Online Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-66802`CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-71331`CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-33824`CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code ExecutioMicrosoft Security Response Center RSS
    cve`CVE-2026-69836`CVE-2026-69836 Microsoft Entra ID Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-61363`CVE-2026-61363 Remote Desktop Client Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69419`CVE-2026-69419 Azure Data Manager for Energy Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62754`CVE-2026-62754 Windows Kerberos Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62834`CVE-2026-62834 Azure Data Factory Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-68789`CVE-2026-68789 Azure SQL Database Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69519`CVE-2026-69519 Azure Stack HCI Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-69851`CVE-2026-69851 Microsoft Entra ID Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62703`CVE-2026-62703 Windows DWM Core Library Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-65786`CVE-2026-65786 Desktop Window Manager Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-55015`CVE-2026-55015 Microsoft Remote Help Denial of Service VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-55013`CVE-2026-55013 Windows Remote Help Defense Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-62728`CVE-2026-62728 Windows Common Log File System Driver Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-70105`CVE-2026-70105 Microsoft Word Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-63509`CVE-2026-63509 Microsoft Fabric Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-65816`CVE-2026-65816 Azure Arc Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-66309`CVE-2026-66309 Azure SQL Database Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-66800`CVE-2026-66800 Azure Data Factory Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-68782`CVE-2026-68782 Azure SQL Database Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist
    ipv4`178.132.198.200`URLhaus: malware_download URL observed (offline)URLhaus Recent URLs

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=0 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=42
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=3 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=6 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=53 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.