July 30, 2026 · Applied Cybernetics Group
Morning Brief — July 30, 2026
Morning Brief — 2026-07-30
3 material breach disclosures, 1 federal patching priority, 8 exploit probability movers, 10 emerging critical cves, 10 supply chain, 30 ransomware activity, 1437 ioc volume, 13 active malware families, 25 multi-source iocs, 4 intel feeds, 5 hand-authored sigma, and 17 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
UPBOUND GROUP, INC. (UPBD)
- Filed: 2026-07-22 · CIK 0000933036 · Accession
0001193125-26-310605 - Filing: https://www.sec.gov/Archives/edgar/data/933036/000119312526310605/upbd-20260721.htm
Caution Concerning Forward-Looking Statements
This Current Report on Form 8-K contains “forward-looking statements” within the meaning of the Private Securities Litigation Reform Act of 1995. Such forward-looking statements involve risks and uncertainties, including statements regarding our understanding of the event and its potential impacts. Factors that could cause or contribute to material…
CID Holdco, Inc. (DAIC)
- Filed: 2026-07-22 · CIK 0002033770 · Accession
0001213900-26-080208 - Filing: https://www.sec.gov/Archives/edgar/data/2033770/000121390026080208/ea029882601ex10-1.htm
any written notice from any governmental authority alleging any material violation of applicable cybersecurity or data privacy laws that remains unresolved. To the Company’s knowledge, there are no pending or threatened claims, investigations or proceedings by any governmental authority relating to any material cybersecurity incident or any material violation of applicable cybersecurity or d…
River Financial Corp (RVRF)
- Filed: 2026-07-17 · CIK 0001641601 · Accession
0001193125-26-307288 - Filing: https://www.sec.gov/Archives/edgar/data/1641601/000119312526307288/ck0001641601-20260619.htm
As set forth in its Form 8-K filed July 10, 2026, two class action lawsuits were filed relating to the unauthorized threat actor gaining access to the network environment of River Financial Corporation, including River Bank & Trust (together, “River”). A third class action was filed against River on July 10, 2026 and a fourth class action was filed against River on July 16, 2026.
The principal…
Federal Patching Priority
CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC)
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
- Added: 2026-07-29 · Federal due: 2026-08-01 · CVSS 5.3 (MEDIUM) · CWE-259
- ransomware use: Unknown
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this…
Exploit Probability Movers
| CVE | Today | Prev | Δ | In KEV |
|---|---|---|---|---|
CVE-2026-16232 | 0.700 | 0.127 | ▲ 0.573 | ✓ |
CVE-2007-2815 | 0.719 | 0.392 | ▲ 0.327 | |
CVE-2026-48907 | 0.559 | 0.830 | ▼ 0.271 | ✓ |
CVE-2000-0884 | 0.706 | 0.453 | ▲ 0.252 | |
CVE-2002-0079 | 0.712 | 0.460 | ▲ 0.252 | |
CVE-2000-0630 | 0.667 | 0.450 | ▲ 0.217 | |
CVE-2000-0886 | 0.670 | 0.457 | ▲ 0.214 | |
CVE-2000-0457 | 0.506 | 0.298 | ▲ 0.208 |
Emerging Critical CVEs
CVE-2026-48449· CRITICAL (10.0) · 2026-07-30 — Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user inte…CVE-2026-67429· CRITICAL (10.0) · 2026-07-29 — Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its…CVE-2026-16326· CRITICAL (10.0) · 2026-07-29 — In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client’s Consul authentication token to be used for subsequent requests from other clients. T…CVE-2026-54735· CRITICAL (10.0) · 2026-07-29 — Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into outbound reques…CVE-2026-58162· CRITICAL (10.0) · 2026-07-29 — The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 throu…
CVE-2026-58046· CRITICAL (9.9) · 2026-07-30 — Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.CVE-2026-54680· CRITICAL (9.9) · 2026-07-29 — Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings su…CVE-2026-7849· CRITICAL (9.8) · 2026-07-30 — Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.CVE-2026-44108· CRITICAL (9.8) · 2026-07-30 — Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible,…CVE-2026-44104· CRITICAL (9.8) · 2026-07-30 — The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modifi…
Supply Chain
GHSA-xvg2-cgv6-6h7v (go)
- HIGH · 2026-07-29
- Affected:
github.com/tinfoil-factory/netfoil - https://github.com/advisories/GHSA-xvg2-cgv6-6h7v
netfoil: Incorrect block responses could lead to localhost traffic
GHSA-mjqf-28ph-426h · CVE-2026-54680 (go)
- CRITICAL · CVSS 9.9 · 2026-07-29
- Affected:
github.com/kube-logging/logging-operator - https://github.com/advisories/GHSA-mjqf-28ph-426h
Logging operator has Fluentd configuration injection that allows remote code execution
GHSA-jq8w-8q2f-ffm9 · CVE-2026-54693 (go)
- HIGH · 2026-07-29
- Affected:
github.com/zitadel/zitadel,github.com/zitadel/zitadel,github.com/zitadel/zitadel - https://github.com/advisories/GHSA-jq8w-8q2f-ffm9
ZITADEL Users Can Self-Verify Email/Phone via API
GHSA-7h3g-4w2f-fj2f · CVE-2026-54727 (pip)
- HIGH · CVSS 8.2 · 2026-07-29
- Affected:
proot-distro - https://github.com/advisories/GHSA-7h3g-4w2f-fj2f
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
GHSA-9xq3-3fqg-4vg7 · CVE-2026-54574 (pip)
- HIGH · CVSS 8.2 · 2026-07-29
- Affected:
proot-distro - https://github.com/advisories/GHSA-9xq3-3fqg-4vg7
proot-distro install has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
GHSA-4vmm-5qvc-w5p7 · CVE-2026-55651 (composer)
- HIGH · CVSS 7.1 · 2026-07-29
- Affected:
alextselegidis/easyappointments - https://github.com/advisories/GHSA-4vmm-5qvc-w5p7
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure
GHSA-m4x6-gwgp-4pm7 · CVE-2026-11393 (npm)
- HIGH · CVSS 9.0 · 2026-07-29
- Affected:
@aws/agentcore,@aws/agentcore,@aws/agentcore - https://github.com/advisories/GHSA-m4x6-gwgp-4pm7
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
GHSA-4p3g-4hcj-wpvx · CVE-2026-54735 (go)
- CRITICAL · CVSS 10.0 · 2026-07-29
- Affected:
github.com/prebid/prebid-server/v4,github.com/prebid/prebid-server/v3,github.com/prebid/prebid-server/v2 - https://github.com/advisories/GHSA-4p3g-4hcj-wpvx
prebid-server’s request forgery vulnerability allows for possible host environment data extraction
GHSA-qcxp-gm7m-4j5v · CVE-2026-50559 (maven)
- HIGH · CVSS 7.5 · 2026-07-29
- Affected:
io.quarkus:quarkus-vertx-http,io.quarkus:quarkus-vertx-http,io.quarkus:quarkus-vertx-http - https://github.com/advisories/GHSA-qcxp-gm7m-4j5v
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities
GHSA-655f-mp8p-96gv · CVE-2026-49755 (erlang)
- HIGH · 2026-07-29
- Affected:
req - https://github.com/advisories/GHSA-655f-mp8p-96gv
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
Ransomware Activity
30 new victim postings across 12 groups.
| Group | Victims | Sample |
|---|---|---|
thegentlemen | 9 | Promatrix, Malaysian Nuclear Agency, Delkart Industries Pvt, ETA Technology Pvt,… |
qilin | 8 | Byonyks, Prenisac, Excel Consultores, Affinity Capital, Adpo, servitelco, Orimar… |
aurora | 3 | Van Eijck International Car Rescue, Evosys Laser GmbH, Pyramid Analytics B.V. |
Black X | 2 | sanaa hospital, Tong Kong E & E Sdn Bhd (95907X) |
Section9 | 1 | ****.com.pa |
akira | 1 | Northwood Country Club |
gunra | 1 | Siam Stabilizers and Chemicals Co., Ltd. / SSC |
incransom | 1 | harwal.net |
insomnia | 1 | Sky Solutions |
kairos | 1 | Warwick Fabrics |
morpheus | 1 | Yue Ki Industrial |
spacebears | 1 | StellarRAD Systems |
IOC Volume
1437 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 1111 |
misp | 326 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Active Malware Families
13 malware families active this week (1 corroborated across ≥2 sources), exercising 17 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| Mirai | botnet | ✓ | 904 | T1110, T1498, T1499, T1584.005 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 71 | T1219 |
| XWorm | rat | — | 19 | T1056.001, T1071 |
| ClickFix | delivery → | — | 15 | T1059.001, T1204 |
| DDoSAgent | ddos | — | 14 | T1498, T1499 |
| CoinMiner | miner | — | 4 | T1496 |
| PhantomStealer | stealer | — | 4 | T1005, T1555 |
| ACRStealer | stealer | — | 3 | T1005, T1071, T1555 |
| AgentTesla | stealer | — | 3 | T1056.001, T1071, T1114, T1555 |
| Stealc | stealer | — | 3 | T1005, T1071, T1555 |
| AMOS (Atomic macOS Stealer) | stealer | — | 2 | T1005, T1056.002, T1071, T1555.001 |
| Formbook | stealer | — | 2 | T1005, T1056.001, T1071, T1555 |
| Phorpiex | botnet | — | 2 | T1071, T1486, T1566 |
Families marked ”→” are delivery/social-engineering clusters (ClickFix). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
25 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
103.193.173.199 | ip-dst | misp + urlhaus | 2026-07-30 |
9qdbp5gv.bet90forward.win | domain | misp + urlhaus | 2026-07-30 |
airyvineic.help | domain | misp + urlhaus | 2026-07-30 |
amse.senorgyros.com | domain | misp + urlhaus | 2026-07-30 |
auai.bet90forward.win | domain | misp + urlhaus | 2026-07-30 |
axoo.colg1.org | domain | misp + urlhaus | 2026-07-30 |
btlbbyxf.bet90forward.win | domain | misp + urlhaus | 2026-07-30 |
bwimlqru.jetbet.download | domain | misp + urlhaus | 2026-07-30 |
cdba.bet90forward.win | domain | misp + urlhaus | 2026-07-30 |
cdnorigin.net | domain | misp + urlhaus | 2026-07-30 |
cqjeqfltg.fg777jbg.net | domain | misp + urlhaus | 2026-07-30 |
dsdvsvqgy.jetbet.download | domain | misp + urlhaus | 2026-07-30 |
dvjmeze.yan303.com | domain | misp + urlhaus | 2026-07-30 |
eikgcqyt.onjabet1.com | domain | misp + urlhaus | 2026-07-30 |
fazv.jadoobet.pro | domain | misp + urlhaus | 2026-07-30 |
fnvr.casinomhub.bet | domain | misp + urlhaus | 2026-07-30 |
glmm.colg1.org | domain | misp + urlhaus | 2026-07-30 |
hdqzc.casinomhub.bet | domain | misp + urlhaus | 2026-07-30 |
hzzgoxjvb.pdfbama.com | domain | misp + urlhaus | 2026-07-30 |
i0wrocb4.bet90forward.win | domain | misp + urlhaus | 2026-07-30 |
inasa.pdfbama.com | domain | misp + urlhaus | 2026-07-30 |
izehzccr.bet90forward.win | domain | misp + urlhaus | 2026-07-30 |
jppxuuhae.imagederm.com | domain | misp + urlhaus | 2026-07-30 |
klca.hieliao-app.com | domain | misp + urlhaus | 2026-07-30 |
konr.domirunway.com | domain | misp + urlhaus | 2026-07-30 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No SEC × KEV vendor token matches in this window. (This is a heuristic surface, absence is expected most days.)
Intel Feeds
4 IOC feeds updated this run (8,682 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| MISP — Suspicious Domains | misp | domain | 5,000 | CSV · MISP · STIX |
| MISP — Flagged IPs | misp | ip | 194 | CSV · MISP · STIX |
| URLhaus — Malware Distribution URLs | urlhaus | url | 3,379 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 109 | CSV · MISP · STIX |
Hand-Authored Sigma
3 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
17 of 157 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1562 | — | — | 0 | 3 |
T1573.001 | Symmetric Cryptography | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 7 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.