SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefMonday, August 10, 2026 INTEL CONFIDENCE 76% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Active Scanning Targets Ivanti Connect Secure Gateways | CRITICAL |
|
5 C2 IPs | 8 OTX IOCs | 1 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by active exploitation attempts targeting Ivanti Connect Secure gateways via an unauthenticated remote code execution vulnerability. Additionally, threat actors are leveraging compromised websites to distribute infostealers through fake Google Chrome and Microsoft Edge browser updates. Organizations must also secure exposed Redis instances as automated scanning for unauthenticated database servers continues to surge. |
|
■ CRITICAL STORIES Active Exploitation of Ivanti Connect Secure Gateways Threat actors are actively scanning for and exploiting an unauthenticated remote code execution vulnerability in Ivanti Connect Secure gateways to gain initial access to corporate networks. |
Fake Browser Updates Distribute Infostealer Malware Compromised websites are being used to deliver fake Google Chrome and Microsoft Edge updates, tricking users into executing malicious payloads that steal credentials. |
Automated Scanning Surge Against Exposed Redis Instances Analysts have detected a significant spike in automated scanning targeting unauthenticated Redis servers to execute unauthorized commands and deploy cryptocurrency miners. |
|
■ CVEs IDENTIFIED [CVE-TBD] Ivanti Connect Secure — Unauthenticated Remote Code Execution |
[CVE-TBD] Redis Server — Unauthorized Command Execution via Unauthenticated Access |
|
■ THREAT ACTORS Exploiting Ivanti Connect Secure gateways for initial access and persistence. |
Distributing infostealers via fake browser update campaigns targeting Chrome and Edge users. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Exploitation of Ivanti Connect Secure gateways. |
| T1189 | | Drive-by Compromise | Fake browser updates delivered via compromised websites. |
| T1059 | | Command and Scripting Interpreter | Execution of unauthorized commands on exposed Redis servers. |
|
■ PATCH PRIORITY Ivanti — Connect Secure — Active exploitation of unauthenticated RCE [CVE-TBD] poses immediate compromise risk — SANS ISC |
Redis — Redis Server — Exposed unauthenticated instances are being actively scanned and exploited — SANS ISC |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Apply the latest security patches or vendor-provided workarounds for Ivanti Connect Secure to mitigate the active [CVE-TBD] RCE vulnerability. |
| 2 | [P2] Restrict Redis Server access to trusted internal networks and enable robust authentication to prevent unauthorized command execution. |
| 3 | [P2] Configure endpoint detection and response (EDR) policies to monitor and block anomalous process execution originating from Google Chrome and Microsoft Edge paths. |
| 4 | [P3] Monitor network logs for anomalous outbound traffic from Ivanti Connect Secure gateways to unverified external IP addresses. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |