July 22, 2026 · Applied Cybernetics Group
Morning Brief — July 22, 2026
Morning Brief — 2026-07-22
2 material breach disclosures, 4 federal patching priority, 10 emerging critical cves, 11 supply chain, 19 ransomware activity, 1340 ioc volume, 1 recent osint events, 17 active malware families, 22 multi-source iocs, 4 intel feeds, 5 hand-authored sigma, and 17 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
River Financial Corp (RVRF)
- Filed: 2026-07-17 · CIK 0001641601 · Accession
0001193125-26-307288 - Filing: https://www.sec.gov/Archives/edgar/data/1641601/000119312526307288/ck0001641601-20260619.htm
As set forth in its Form 8-K filed July 10, 2026, two class action lawsuits were filed relating to the unauthorized threat actor gaining access to the network environment of River Financial Corporation, including River Bank & Trust (together, “River”). A third class action was filed against River on July 10, 2026 and a fourth class action was filed against River on July 16, 2026.
The principal…
River Financial Corp (RVRF)
- Filed: 2026-07-10 · CIK 0001641601 · Accession
0001193125-26-300763 - Filing: https://www.sec.gov/Archives/edgar/data/1641601/000119312526300763/ck0001641601-20260619.htm
Since the date of the original filing, River’s investigation has progressed. River has determined that an unauthorized threat actor accessed portions of its network and removed certain data from its environment. River is working to determine the nature and scope of the information involved, including whether any personally identifiable information was affected. To date, River is not aware of any r…
Federal Patching Priority
CVE-2026-0770 — Langflow Langflow
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
- Added: 2026-07-21 · Federal due: 2026-07-24 · EPSS 95.2th pct (score 0.104) · CVSS 9.8 (CRITICAL) · CWE-829
- ransomware use: Unknown
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The…
CVE-2026-63030 — WordPress Core
WordPress Core Interpretation Conflict Vulnerability
- Added: 2026-07-21 · Federal due: 2026-07-24 · EPSS 94.7th pct (score 0.089) · CVSS 9.8 (CRITICAL) · CWE-436
- ransomware use: Unknown
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
CVE-2021-27137 — DD-WRT DD-WRT
DD-WRT Stack-Based Buffer Overflow Vulnerability
- Added: 2026-07-21 · Federal due: 2026-07-24 · EPSS 91.9th pct (score 0.054) · CVSS 8.1 (HIGH) · CWE-121
- ransomware use: Unknown
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch…
CVE-2026-60137 — WordPress Core
WordPress Core SQL Injection Vulnerability
- Added: 2026-07-21 · Federal due: 2026-08-04 · EPSS 89.5th pct (score 0.040) · CVSS 5.9 (MEDIUM) · CWE-89
- ransomware use: Unknown
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
Exploit Probability Movers
No CVEs with ≥0.20 EPSS movement in this window.
Emerging Critical CVEs
CVE-2026-60644· CRITICAL (10.0) · 2026-07-21 — Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Web Content Management). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerabilit…CVE-2026-60389· CRITICAL (10.0) · 2026-07-21 — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability al…CVE-2026-60379· CRITICAL (10.0) · 2026-07-21 — Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability al…CVE-2026-60365· CRITICAL (10.0) · 2026-07-21 — Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). The supported version that is affected is 15.1.1.0.0…CVE-2026-60360· CRITICAL (10.0) · 2026-07-21 — Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unaut…CVE-2026-60358· CRITICAL (10.0) · 2026-07-21 — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability al…CVE-2026-60217· CRITICAL (10.0) · 2026-07-21 — Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability…CVE-2026-47056· CRITICAL (10.0) · 2026-07-21 — Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows una…CVE-2026-61242· CRITICAL (9.9) · 2026-07-21 — Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low pri…CVE-2026-61239· CRITICAL (9.9) · 2026-07-21 — Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable vulnerability allows una…
Supply Chain
GHSA-v2hh-gcrm-f6hx · CVE-2026-16221 (npm)
- HIGH · CVSS 7.5 · 2026-07-21
- Affected:
fast-uri,fast-uri,fast-uri - https://github.com/advisories/GHSA-v2hh-gcrm-f6hx
fast-uri vulnerable to host confusion via literal backslash authority delimiter
GHSA-f88m-g3jw-g9cj (npm)
- HIGH · 2026-07-21
- Affected:
sharp - https://github.com/advisories/GHSA-f88m-g3jw-g9cj
sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
GHSA-8r6m-32jq-jx6q (npm)
- HIGH · 2026-07-21
- Affected:
fast-xml-parser - https://github.com/advisories/GHSA-8r6m-32jq-jx6q
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits
GHSA-rwj8-pgh3-r573 (pip)
- HIGH · CVSS 7.5 · 2026-07-21
- Affected:
gitpython - https://github.com/advisories/GHSA-rwj8-pgh3-r573
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GHSA-hrxh-6v49-42gf (go)
- HIGH · 2026-07-21
- Affected:
google.golang.org/grpc - https://github.com/advisories/GHSA-hrxh-6v49-42gf
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
GHSA-r7wm-3cxj-wff9 (maven)
- HIGH · 2026-07-21
- Affected:
com.fasterxml.jackson.core:jackson-core,com.fasterxml.jackson.core:jackson-core,com.fasterxml.jackson.core:jackson-core - https://github.com/advisories/GHSA-r7wm-3cxj-wff9
jackson-core: Async parser maxNumberLength bypass via chunked digit accumulation (incomplete fix for GHSA-72hv-8253-57qq)
GHSA-gx3v-q759-g323 · CVE-2026-20779 (go)
- HIGH · CVSS 7.1 · 2026-07-21
- Affected:
code.gitea.io/gitea - https://github.com/advisories/GHSA-gx3v-q759-g323
Gitea: TOTP TOCTOU race on web 2FA paths + missing replay check on Basic-Auth X-Gitea-OTP surface
GHSA-g9g6-qhrc-p3qc · CVE-2026-58422 (go)
- HIGH · 2026-07-21
- Affected:
code.gitea.io/gitea - https://github.com/advisories/GHSA-g9g6-qhrc-p3qc
Gitea: Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts
GHSA-44qc-pgvp-wx7v · CVE-2026-58419 (go)
- HIGH · CVSS 7.5 · 2026-07-21
- Affected:
code.gitea.io/gitea - https://github.com/advisories/GHSA-44qc-pgvp-wx7v
Gitea: Notification API leaks private issue metadata after access revocation
GHSA-v73x-hx65-6pf4 · CVE-2026-25038 (go)
- HIGH · CVSS 7.5 · 2026-07-21
- Affected:
code.gitea.io/gitea - https://github.com/advisories/GHSA-v73x-hx65-6pf4
Gitea: Unauthorized Access to Labels of Private Organizations
Exploitation evidence, 7-day window (severity-agnostic — evidence trumps labels):
GHSA-8qw8-rq86-9pc2(CVE-2026-27771, go) · 2026-07-17 — EPSS p98.5
Ransomware Activity
19 new victim postings across 10 groups.
| Group | Victims | Sample |
|---|---|---|
nova | 5 | Marpatech, Canal 9 Litoral, La Financière d’Orion (finorion), Tèrra Aventura, Ko… |
akira | 2 | Novasport s.r.o., Finer & Finer |
chaos | 2 | issvc.com, argonautms.com |
dragonforce | 2 | Koshkaryan Law Group, One Community FCU |
play | 2 | Tax MT, Kreysler & Associates |
qilin | 2 | Evergreen Title, RehaVital Gesundheitsservice GmbH |
morpheus | 1 | Kyowa Singapore Pte Ltd |
ransomhouse | 1 | Nichirei |
settra | 1 | downies.com |
titan | 1 | PERTINENT HEALTHCARE BUSINESS SOLUTIONS PRIVATE LIMITED |
IOC Volume
1340 new IOCs in this window. By source:
| Source | Count |
|---|---|
misp | 807 |
urlhaus | 533 |
Recent OSINT Events
MoustachedBouncer: Espionage against foreign diplomats in Belarus
- Date: 2023-07-21 · Threat: low · Org: ESET
- Signal: 0 actionable IOCs (of 4 attributes) · https://www.circl.lu/doc/misp/feed-osint/ea593018-b2e9-4e7e-8da9-cc20a751e3f6.json
Active Malware Families
17 malware families active this week (2 corroborated across ≥2 sources), exercising 20 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| ClearFake | delivery → | ✓ | 1,185 | T1059.001, T1189, T1204 |
| ClickFix | delivery → | ✓ | 22 | T1059.001, T1204 |
| Mirai | botnet | — | 516 | T1110, T1498, T1499, T1584.005 |
| PhantomStealer | stealer | — | 16 | T1005, T1555 |
| CoinMiner | miner | — | 14 | T1496 |
| AgentTesla | stealer | — | 11 | T1056.001, T1071, T1114, T1555 |
| XWorm | rat | — | 11 | T1056.001, T1071 |
| GuLoader | loader → | — | 6 | T1027, T1071, T1105 |
| AsyncRAT | rat | — | 4 | T1056.001, T1059.001, T1071, T1219 |
| Formbook | stealer | — | 4 | T1005, T1056.001, T1071, T1555 |
| Stealc | stealer | — | 4 | T1005, T1071, T1555 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 3 | T1219 |
| ACRStealer | stealer | — | 2 | T1005, T1071, T1555 |
| MassLogger | stealer | — | 2 | T1056.001, T1071, T1555 |
| Phorpiex | botnet | — | 2 | T1071, T1486, T1566 |
| Amadey | loader → | — | 1 | T1071, T1105, T1547 |
| njRAT | rat | — | 1 | T1056.001, T1059.003, T1071, T1219 |
Families marked ”→” are delivery/social-engineering clusters (ClearFake, ClickFix, GuLoader, Amadey). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
22 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
46.183.25.232 | ip-dst | misp + urlhaus | 2026-07-22 |
193.41.226.161 | ip-dst | misp + urlhaus | 2026-07-22 |
2.59.133.148 | ip-dst | misp + urlhaus | 2026-07-22 |
23.27.180.36 | ip-src | misp + urlhaus | 2026-07-22 |
31.76.252.47 | ip-dst | misp + urlhaus | 2026-07-22 |
45.135.193.114 | ip-dst | misp + urlhaus | 2026-07-22 |
95.216.64.240 | ip-src | misp + urlhaus | 2026-07-22 |
cdn.defenders.workers.dev | domain | misp + urlhaus | 2026-07-22 |
datastream-hub.christmas | domain | misp + urlhaus | 2026-07-22 |
gardenworkflowhub.garden | domain | misp + urlhaus | 2026-07-22 |
impur-treacheryperepelitsa.wiki | domain | misp + urlhaus | 2026-07-22 |
leconto.lol | domain | misp + urlhaus | 2026-07-22 |
nexrogcapital.xyz | domain | misp + urlhaus | 2026-07-22 |
nextjs2385.ngrok.io | domain | misp + urlhaus | 2026-07-22 |
recaptcha.boit.cloud | domain | misp + urlhaus | 2026-07-22 |
subterranean-mineral-map.garden | domain | misp + urlhaus | 2026-07-22 |
svganchordev.net | domain | misp + urlhaus | 2026-07-22 |
zapier-logos.s3.amazonaws.com | domain | misp + urlhaus | 2026-07-22 |
103.101.85.173 | ip-dst | misp + urlhaus | 2026-07-17 |
dev1-revitavive.com | domain | misp + urlhaus | 2026-07-17 |
slotmy-send.tech | domain | misp + urlhaus | 2026-07-17 |
stg1-swaggrhockey.com | domain | misp + urlhaus | 2026-07-17 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No SEC × KEV vendor token matches in this window. (This is a heuristic surface, absence is expected most days.)
Intel Feeds
4 IOC feeds updated this run (6,890 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| MISP — Suspicious Domains | misp | domain | 2,853 | CSV · MISP · STIX |
| MISP — Flagged IPs | misp | ip | 130 | CSV · MISP · STIX |
| URLhaus — Malware Distribution URLs | urlhaus | url | 3,297 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 610 | CSV · MISP · STIX |
Hand-Authored Sigma
3 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
17 of 155 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1562 | — | — | 0 | 3 |
T1573.001 | Symmetric Cryptography | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 7 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.