Daily Cyber Threat Intel Brief — 2026-08-22
Generated: 2026-08-22 08:00:14 UTC
Executive summary
Collected 250 recent public-source CTI items for technology-only monitoring.
Priority distribution: P1=3, P2=3, P3=118, P4=126.
Highest-priority item: CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability (P1, source: Microsoft Security Response Center RSS).
10 public IOC highlights selected for analyst awareness.
Priority technology watch items
P1 CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Updated an acknowledgement. This is an informational change only.
P1 CVE-2026-64903 Microsoft Office Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Updated an acknowledgement. This is an informational change only.
P1 CVE-2026-55134 Microsoft Word Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Updated an acknowledgement. This is an informational change only.
P2 RansomLook: Coming soon claimed by rhysida — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: rhysida. Claimed victim/listing: Coming soon. Description excerpt: Coming soon Total capacity 5.79 TBLegal/Complaints/Offenses 77,939 OWi proceedings, lawsuits, legal opinionsFinance 55,553 Budget,…
P2 RansomLook: First Commerce LLC claimed by pear — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: pear. Claimed victim/listing: First Commerce LLC. Description excerpt: Privately held real estate investment and development company
P2 RansomLook: Hogan Omidi P.C. claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Hogan Omidi P.C.. Description excerpt: Hogan Omidi, P.C. is a boutique law firm specializing in family law, including divorce, child custody, and property division,…
Newly exploited vulnerabilities / CVE watch
P1 CVE-2026-68801: CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability — technologies: not watchlist-specific.
P1 CVE-2026-64903: CVE-2026-64903 Microsoft Office Remote Code Execution Vulnerability — technologies: not watchlist-specific.
P1 CVE-2026-55134: CVE-2026-55134 Microsoft Word Remote Code Execution Vulnerability — technologies: not watchlist-specific.
P3 CVE-2026-64899: CVE-2026-64899 Microsoft Office Information Disclosure Vulnerability — technologies: not watchlist-specific.
P3 CVE-2026-70335: CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
P3 CVE-2026-58547: CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
P3 CVE-2026-49183: CVE-2026-49183 Windows Clipboard Server Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
P3 CVE-2026-32202: CVE-2026-32202 Windows Shell Spoofing Vulnerability — technologies: not watchlist-specific.
P3 CVE-2026-54981: CVE-2026-54981 Visual Studio Code Python Extension Security Feature Bypass Vulnerability — technologies: not watchlist-specific.
Ransomware and extortion trend notes
P2 RansomLook: Coming soon claimed by rhysida — Public RansomLook extortion-site listing claim. Group: rhysida. Claimed victim/listing: Coming soon. Description excerpt: Coming soon Total capacity 5.79 TBLegal/Complaints/Offenses 77,939 OWi proceedings, lawsuits,…
P2 RansomLook: First Commerce LLC claimed by pear — Public RansomLook extortion-site listing claim. Group: pear. Claimed victim/listing: First Commerce LLC. Description excerpt: Privately held real estate investment and development company
P2 RansomLook: Hogan Omidi P.C. claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Hogan Omidi P.C.. Description excerpt: Hogan Omidi, P.C. is a boutique law firm specializing in family law, including divorce,…
P3 RansomLook: holzmarkt chemnitz claimed by space bears — Public RansomLook extortion-site listing claim. Group: space bears. Claimed victim/listing: holzmarkt chemnitz. Description excerpt: Holzmarkt Chemnitz is a specialized retail store for building materials and wood…
P3 RansomLook: Freelom claimed by space bears — Public RansomLook extortion-site listing claim. Group: space bears. Claimed victim/listing: Freelom. Description excerpt: Freelom.net s.r.o. is a Czech internet service provider and IT company based in Lomnice nad…
P3 RansomLook: CRI Electric claimed by rhysida — Public RansomLook extortion-site listing claim. Group: rhysida. Claimed victim/listing: CRI Electric. Description excerpt: CRI Electric CRI Electric is a veteran-owned business based in San Antonio, providing…
P3 RansomLook: Victory Personal Care, Inc claimed by nightspire — Public RansomLook extortion-site listing claim. Group: nightspire. Claimed victim/listing: Victory Personal Care, Inc.
P3 RansomLook: RCOP1 claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: RCOP1.
P3 RansomLook: REPORT QUEUE STALLED claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: REPORT QUEUE STALLED. Description excerpt: report-generator: 3 jobs failed validation (RCGEN1, RCSSTI, RCSSTI2). Manual…
P3 RansomLook: PAYOUT AUDIT - ACTION REQUIRED claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: PAYOUT AUDIT - ACTION REQUIRED. Description excerpt: Automated audit could not reconcile 2 wallet entries. Regenerate…
P3 RansomLook: Meridian Logistics Group claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Meridian Logistics Group. Description excerpt: Full network image staged. ERP exports, dispatch DB and payroll archives…
P3 RansomLook: RCLIFE1 claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: RCLIFE1. Description excerpt: =24)clearInterval(t)},15000);">
Malware / infrastructure / abuse feed highlights
P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ClickOnce,DRASTOK,fakegame,Loader,stealer; url=https://drastok.xyz/installer/Application%20Files/Drastok_1_0_0_223/Drastok.dll.deploy
P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ClickOnce,DRASTOK,fakegame,Loader,stealer; url=https://drastok.xyz/installer/Drastok.application
P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
P3 New SynkLoader malware pushed in Microsoft Teams phishing campaign — A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://61.52.45.140:49405/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://125.47.87.135:56962/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://125.41.75.183:52478/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://115.55.130.187:46359/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://182.122.199.106:34085/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://61.52.45.140:49405/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://115.48.146.190:54106/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://125.41.75.183:52478/bin.sh
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-68801` | CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64903` | CVE-2026-64903 Microsoft Office Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-55134` | CVE-2026-55134 Microsoft Word Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-64899` | CVE-2026-64899 Microsoft Office Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-70335` | CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-58547` | CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege V | Microsoft Security Response Center RSS |
| cve | `CVE-2026-49183` | CVE-2026-49183 Windows Clipboard Server Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-32202` | CVE-2026-32202 Windows Shell Spoofing Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-54981` | CVE-2026-54981 Visual Studio Code Python Extension Security Feature Bypass Vulnerability | Microsoft Security Response Center RSS |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
Defensive takeaways
Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
Sources checked
BleepingComputer Ransomware News: ok new=1 fetched=15
CISA Known Exploited Vulnerabilities: ok new=0 fetched=39
Cisco Talos Blog: ok new=0 fetched=15
Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
Huntress Blog: ok new=0 fetched=25
Microsoft Security Response Center RSS: ok new=0 fetched=25
NVD Recent CVEs: ok new=60 fetched=80
ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
RansomLook Recent Listings: ok new=4 fetched=50
Rapid7 Blog: ok new=0 fetched=20
SANS Internet Storm Center: ok new=0 fetched=10
Sophos X-Ops: ok new=0 fetched=15
The DFIR Report: ok new=0 fetched=10
URLhaus Recent URLs: ok new=49 fetched=120
Unit 42 Threat Research: ok new=0 fetched=15
Limitations
Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
Technology-only matching can miss relevant items that do not name a tracked product explicitly.
Ransomware victim claims are actor/source claims unless independently corroborated.
IOC highlights are publicly sourced and should be validated before enforcement in production controls.