Daily Cyber Threat Intel Brief — 2026-08-25
Generated: 2026-08-25 08:00:45 UTC
Executive summary
Collected 250 recent public-source CTI items for technology-only monitoring.
Priority distribution: P1=4, P2=5, P3=46, P4=195.
Highest-priority item: Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) (P1, source: Rapid7 Blog).
14 public IOC highlights selected for analyst awareness.
Priority technology watch items
P1 Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) — Rapid7 Blog; score 95; technologies: SharePoint.
P1 GitHub release: Nuclei Templates v10.4.8 - Release Notes — ProjectDiscovery Nuclei Templates Releases; score 90; technologies: SharePoint, WordPress.
- ### New Templates Added: `112` | CVEs Added: `101` | First-time contributions: `22` ### 🔥 Release Highlights 🔥 - [CVE-2026-72898] Metabase - Unauthenticated SQL Injection (@0x_Akoko, @pdteam) [critical] (kev) (vKEV) 🔥 - [CVE-2026-71362] Adobe Commerce/Magento…
P1 Hackers target WordPress sites in miniOrange auth bypass attacks — BleepingComputer Ransomware News; score 79; technologies: WordPress.
- Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
P1 CVE-2026-47292 Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability — Microsoft Security Response Center RSS; score 70; technologies: none explicitly matched.
- Affected software updated with new package information.
P2 RansomLook: Criba claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Criba. Description excerpt: (release includes data on Argentina, Uruguay, and other countries, as well as financial documents and client documentation, including a…
P2 RansomLook: Brookview Financial claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Brookview Financial. Description excerpt: (data of many thousands of customers, including credit reports, SSNs, addresses, etc.) Brookview Financial is a boutique…
P2 RansomLook: Wozair claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Wozair. Description excerpt: Wozair specializes in the design, manufacture, and installation of heavy-duty heating, ventilating, and air conditioning (HVAC) products…
P2 RansomLook: Frato claimed by dragonforce — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Frato. Description excerpt: (release includes data for the entire group of companies across all countries of operation, financial documentation, shareholder…
P2 RansomLook: Meridian Forest Services claimed by beast — RansomLook Recent Listings; score 53; technologies: none explicitly matched.
- Public RansomLook extortion-site listing claim. Group: beast. Claimed victim/listing: Meridian Forest Services. Description excerpt: Meridian Forest Services Limited is a progressive natural resource consulting company that offers a range of services…
Newly exploited vulnerabilities / CVE watch
P1 CVE-2026-63520: Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) — technologies: SharePoint.
P1 CVE-2026-57219, CVE-2026-58644, CVE-2026-59774, CVE-2026-63077, CVE-2026-64638, CVE-2026-64849, CVE-2026-71362, CVE-2026-72898: GitHub release: Nuclei Templates v10.4.8 - Release Notes — technologies: SharePoint, WordPress.
P1 CVE-2026-47292: CVE-2026-47292 Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability — technologies: not watchlist-specific.
P3 CVE-2026-65787: CVE-2026-65787 Desktop Window Manager Elevation of Privilege Vulnerability — technologies: not watchlist-specific.
P3 CVE-2026-50661: CVE-2026-50661 Windows BitLocker Security Feature Bypass Vulnerability — technologies: not watchlist-specific.
Ransomware and extortion trend notes
P2 RansomLook: Criba claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Criba. Description excerpt: (release includes data on Argentina, Uruguay, and other countries, as well as financial documents…
P2 RansomLook: Brookview Financial claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Brookview Financial. Description excerpt: (data of many thousands of customers, including credit reports, SSNs, addresses,…
P2 RansomLook: Wozair claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Wozair. Description excerpt: Wozair specializes in the design, manufacture, and installation of heavy-duty heating,…
P2 RansomLook: Frato claimed by dragonforce — Public RansomLook extortion-site listing claim. Group: dragonforce. Claimed victim/listing: Frato. Description excerpt: (release includes data for the entire group of companies across all countries of operation,…
P2 RansomLook: Meridian Forest Services claimed by beast — Public RansomLook extortion-site listing claim. Group: beast. Claimed victim/listing: Meridian Forest Services. Description excerpt: Meridian Forest Services Limited is a progressive natural resource consulting company…
P3 RansomLook: Cosmon claimed by beast — Public RansomLook extortion-site listing claim. Group: beast. Claimed victim/listing: Cosmon. Description excerpt: Cosmon develops agentic artificial intelligence software for mechanical engineering workflows, centered…
P3 RansomLook: Consultores de Seguros claimed by qilin — Public RansomLook extortion-site listing claim. Group: qilin. Claimed victim/listing: Consultores de Seguros. Description excerpt: Insurance
P3 RansomLook: W**s claimed by payoutsking — Public RansomLook extortion-site listing claim. Group: payoutsking. Claimed victim/listing: W**s.
P3 RansomLook: Government of Vojvodina claimed by panzer — Public RansomLook extortion-site listing claim. Group: panzer. Claimed victim/listing: Government of Vojvodina. Description excerpt: The Provincial Government of Vojvodina is focused on enhancing economic and academic…
P3 RansomLook: lagegepesca.it claimed by safepay — Public RansomLook extortion-site listing claim. Group: safepay. Claimed victim/listing: lagegepesca.it. Description excerpt: Based in Lallio, near Bergamo in Lombardy, the company traces its origins to 1957, when Santo…
P3 RansomLook: Furnished Quarters claimed by dark project — Public RansomLook extortion-site listing claim. Group: dark project. Claimed victim/listing: Furnished Quarters. Description excerpt: The company "Furnished Quarters" was the victim of a successful cyberattack, as a…
P3 RansomLook: Design-Aire Engineering, INC claimed by dark project — Public RansomLook extortion-site listing claim. Group: dark project. Claimed victim/listing: Design-Aire Engineering, INC. Description excerpt: Design-Aire Engineering, INC has suffered a cyberattack on its service…
Malware / infrastructure / abuse feed highlights
P3 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=HijackLoader; url=https://zcalton.com/UTODYIBG.msi
P3 Feodo Tracker: 1 recommended botnet C2 IPs listed — Public Feodo Tracker recommended IP blocklist snapshot. Sample: 50.16.16.211
P3 DOUBLECUP's PNG Payload, (Mon, Aug 24th) — New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up. It doesn&#;x26;#;39;t use real steganography:
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://1.171.9.127:34273/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://66.212.186.197:40907/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://1.171.9.127:34273/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://39.74.97.181:45160/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=Mozi; url=http://115.57.82.47:57033/i
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=exe,opendir; url=http://91.92.47.41/adobe/rem.exe
P4 URLhaus: malware_download URL observed (offline) — Public URLhaus recent URL. Threat=malware_download; tags=exe,opendir; url=http://91.92.47.41/adobe/adobe.exe
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,arm,elf,mirai,Mozi; url=http://36.69.95.117:55652/bin.sh
P4 URLhaus: malware_download URL observed (online) — Public URLhaus recent URL. Threat=malware_download; tags=32-bit,elf,mips,Mozi; url=http://42.178.212.5:52315/bin.sh
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-63520` | Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) | Rapid7 Blog |
| cve | `CVE-2026-57219` | GitHub release: Nuclei Templates v10.4.8 - Release Notes | ProjectDiscovery Nuclei Templates Releases |
| cve | `CVE-2026-58644` | GitHub release: Nuclei Templates v10.4.8 - Release Notes | ProjectDiscovery Nuclei Templates Releases |
| cve | `CVE-2026-59774` | GitHub release: Nuclei Templates v10.4.8 - Release Notes | ProjectDiscovery Nuclei Templates Releases |
| cve | `CVE-2026-63077` | GitHub release: Nuclei Templates v10.4.8 - Release Notes | ProjectDiscovery Nuclei Templates Releases |
| cve | `CVE-2026-64638` | GitHub release: Nuclei Templates v10.4.8 - Release Notes | ProjectDiscovery Nuclei Templates Releases |
| cve | `CVE-2026-64849` | GitHub release: Nuclei Templates v10.4.8 - Release Notes | ProjectDiscovery Nuclei Templates Releases |
| cve | `CVE-2026-71362` | GitHub release: Nuclei Templates v10.4.8 - Release Notes | ProjectDiscovery Nuclei Templates Releases |
| cve | `CVE-2026-72898` | GitHub release: Nuclei Templates v10.4.8 - Release Notes | ProjectDiscovery Nuclei Templates Releases |
| cve | `CVE-2026-47292` | CVE-2026-47292 Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-65787` | CVE-2026-65787 Desktop Window Manager Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50661` | CVE-2026-50661 Windows BitLocker Security Feature Bypass Vulnerability | Microsoft Security Response Center RSS |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| hash | `94e954f9fa4095799dede0c689e6d6b51ddddaff16d44b75cf49ba265dc3a79a` | RansomLook: resi.com claimed by krybit | RansomLook Recent Listings |
Defensive takeaways
Prioritize patch/exposure review for CISA KEV or actively exploited items touching the technology watchlist.
Treat public PoC or Nuclei-template activity as a signal to validate internet-facing exposure and logging, not as standalone proof of exploitation.
Use IOC highlights as short-lived hunting pivots; prefer behavior and vulnerable-asset validation over broad permanent blocking.
Sources checked
BleepingComputer Ransomware News: ok new=0 fetched=15
CISA Known Exploited Vulnerabilities: ok new=0 fetched=38
Cisco Talos Blog: ok new=0 fetched=15
Feodo Tracker Recommended Blocklist: ok new=0 fetched=1
Huntress Blog: ok new=0 fetched=25
Microsoft Security Response Center RSS: ok new=0 fetched=25
NVD Recent CVEs: ok new=16 fetched=80
ProjectDiscovery Nuclei Templates Releases: ok new=0 fetched=10
RansomLook Recent Listings: ok new=1 fetched=50
Rapid7 Blog: ok new=0 fetched=20
SANS Internet Storm Center: ok new=0 fetched=10
Sophos X-Ops: ok new=0 fetched=15
The DFIR Report: ok new=0 fetched=10
URLhaus Recent URLs: ok new=71 fetched=120
Unit 42 Threat Research: ok new=0 fetched=15
Limitations
Public/open-source collection only; no paid feeds, customer watchlists, credential dumps, or direct dark-web interaction.
Technology-only matching can miss relevant items that do not name a tracked product explicitly.
Ransomware victim claims are actor/source claims unless independently corroborated.
IOC highlights are publicly sourced and should be validated before enforcement in production controls.