markcardiff.tech:/daily-intel/2026-08-22.html
Generated: 2026-08-22 08:00:14 UTC
P1: 3
P2: 3
Items: 250

Daily Cyber Threat Intel Brief — 2026-08-22

Generated: 2026-08-22 08:00:14 UTC

Executive summary

  • Collected 250 recent public-source CTI items for technology-only monitoring.
  • Priority distribution: P1=3, P2=3, P3=118, P4=126.
  • Highest-priority item: CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability (P1, source: Microsoft Security Response Center RSS).
  • 10 public IOC highlights selected for analyst awareness.
  • Priority technology watch items

  • P1 CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-64903 Microsoft Office Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P1 CVE-2026-55134 Microsoft Word Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
  • - Updated an acknowledgement. This is an informational change only.

  • P2 RansomLook: Coming soon claimed by rhysida — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: rhysida. Claimed victim/listing: Coming soon. Description excerpt: Coming soon Total capacity 5.79 TBLegal/Complaints/Offenses 77,939 OWi proceedings, lawsuits, legal opinionsFinance 55,553 Budget,…

  • P2 RansomLook: First Commerce LLC claimed by pear — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: pear. Claimed victim/listing: First Commerce LLC. Description excerpt: Privately held real estate investment and development company

  • P2 RansomLook: Hogan Omidi P.C. claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
  • - Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Hogan Omidi P.C.. Description excerpt: Hogan Omidi, P.C. is a boutique law firm specializing in family law, including divorce, child custody, and property division,…

    Newly exploited vulnerabilities / CVE watch

  • P1 CVE-2026-68801: CVE-2026-68801 Microsoft Excel Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-64903: CVE-2026-64903 Microsoft Office Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P1 CVE-2026-55134: CVE-2026-55134 Microsoft Word Remote Code Execution Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-64899: CVE-2026-64899 Microsoft Office Information Disclosure Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-70335: CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-58547: CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-49183: CVE-2026-49183 Windows Clipboard Server Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-32202: CVE-2026-32202 Windows Shell Spoofing Vulnerability — technologies: not watchlist-specific.
  • P3 CVE-2026-54981: CVE-2026-54981 Visual Studio Code Python Extension Security Feature Bypass Vulnerability — technologies: not watchlist-specific.
  • Ransomware and extortion trend notes

  • P2 RansomLook: Coming soon claimed by rhysida — Public RansomLook extortion-site listing claim. Group: rhysida. Claimed victim/listing: Coming soon. Description excerpt: Coming soon Total capacity 5.79 TBLegal/Complaints/Offenses 77,939 OWi proceedings, lawsuits,…
  • P2 RansomLook: First Commerce LLC claimed by pear — Public RansomLook extortion-site listing claim. Group: pear. Claimed victim/listing: First Commerce LLC. Description excerpt: Privately held real estate investment and development company
  • P2 RansomLook: Hogan Omidi P.C. claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Hogan Omidi P.C.. Description excerpt: Hogan Omidi, P.C. is a boutique law firm specializing in family law, including divorce,…
  • P3 RansomLook: holzmarkt chemnitz claimed by space bears — Public RansomLook extortion-site listing claim. Group: space bears. Claimed victim/listing: holzmarkt chemnitz. Description excerpt: Holzmarkt Chemnitz is a specialized retail store for building materials and wood…
  • P3 RansomLook: Freelom claimed by space bears — Public RansomLook extortion-site listing claim. Group: space bears. Claimed victim/listing: Freelom. Description excerpt: Freelom.net s.r.o. is a Czech internet service provider and IT company based in Lomnice nad…
  • P3 RansomLook: CRI Electric claimed by rhysida — Public RansomLook extortion-site listing claim. Group: rhysida. Claimed victim/listing: CRI Electric. Description excerpt: CRI Electric CRI Electric is a veteran-owned business based in San Antonio, providing…
  • P3 RansomLook: Victory Personal Care, Inc claimed by nightspire — Public RansomLook extortion-site listing claim. Group: nightspire. Claimed victim/listing: Victory Personal Care, Inc.
  • P3 RansomLook: RCOP1 claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: RCOP1.
  • P3 RansomLook: REPORT QUEUE STALLED claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: REPORT QUEUE STALLED. Description excerpt: report-generator: 3 jobs failed validation (RCGEN1, RCSSTI, RCSSTI2). Manual…
  • P3 RansomLook: PAYOUT AUDIT - ACTION REQUIRED claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: PAYOUT AUDIT - ACTION REQUIRED. Description excerpt: Automated audit could not reconcile 2 wallet entries. Regenerate…
  • P3 RansomLook: Meridian Logistics Group claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: Meridian Logistics Group. Description excerpt: Full network image staged. ERP exports, dispatch DB and payroll archives…
  • P3 RansomLook: RCLIFE1 claimed by the gentlemen — Public RansomLook extortion-site listing claim. Group: the gentlemen. Claimed victim/listing: RCLIFE1. Description excerpt: =24)clearInterval(t)},15000);">
  • Malware / infrastructure / abuse feed highlights

  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ClickOnce,DRASTOK,fakegame,Loader,stealer; url=https://drastok.xyz/installer/Application%20Files/Drastok_1_0_0_223/Drastok.dll.deploy
  • P3 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=ClickOnce,DRASTOK,fakegame,Loader,stealer; url=https://drastok.xyz/installer/Drastok.application
  • P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
  • P3 New SynkLoader malware pushed in Microsoft Teams phishing campaign — A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://61.52.45.140:49405/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://125.47.87.135:56962/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://125.41.75.183:52478/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://115.55.130.187:46359/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://182.122.199.106:34085/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://61.52.45.140:49405/bin.sh
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://115.48.146.190:54106/i
  • P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://125.41.75.183:52478/bin.sh
  • IOC highlights

    TypeValueContextSource
    cve`CVE-2026-68801`CVE-2026-68801 Microsoft Excel Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-64903`CVE-2026-64903 Microsoft Office Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-55134`CVE-2026-55134 Microsoft Word Remote Code Execution VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-64899`CVE-2026-64899 Microsoft Office Information Disclosure VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-70335`CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-58547`CVE-2026-58547 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege VMicrosoft Security Response Center RSS
    cve`CVE-2026-49183`CVE-2026-49183 Windows Clipboard Server Elevation of Privilege VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-32202`CVE-2026-32202 Windows Shell Spoofing VulnerabilityMicrosoft Security Response Center RSS
    cve`CVE-2026-54981`CVE-2026-54981 Visual Studio Code Python Extension Security Feature Bypass VulnerabilityMicrosoft Security Response Center RSS
    ipv4`50.16.16.211`Feodo Tracker: 1 recommended botnet C2 IPs listedFeodo Tracker Recommended Blocklist

    Defensive takeaways

  • Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
  • Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
  • Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
  • Sources checked

  • BleepingComputer Ransomware News: ok new=1 fetched=15
  • CISA Known Exploited Vulnerabilities: ok new=0 fetched=39
  • Cisco Talos Blog: ok new=0 fetched=15
  • Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
  • Huntress Blog: ok new=0 fetched=25
  • Microsoft Security Response Center RSS: ok new=0 fetched=25
  • NVD Recent CVEs: ok new=60 fetched=80
  • ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
  • RansomLook Recent Listings: ok new=4 fetched=50
  • Rapid7 Blog: ok new=0 fetched=20
  • SANS Internet Storm Center: ok new=0 fetched=10
  • Sophos X-Ops: ok new=0 fetched=15
  • The DFIR Report: ok new=0 fetched=10
  • URLhaus Recent URLs: ok new=49 fetched=120
  • Unit 42 Threat Research: ok new=0 fetched=15
  • Limitations

  • Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
  • Technology-only matching can miss relevant items that do not name a tracked product explicitly.
  • Ransomware victim claims are actor/source claims unless independently corroborated.
  • IOC highlights are publicly sourced and should be validated before enforcement in production controls.