August 19, 2026 · Applied Cybernetics Group
Morning Brief — August 19, 2026
Morning Brief — 2026-08-19
1 material breach disclosures, 4 federal patching priority, 10 emerging critical cves, 10 supply chain, 23 ransomware activity, 607 ioc volume, 14 active malware families, 25 multi-source iocs, 1 cross-reference, 4 intel feeds, 12 hand-authored sigma, and 17 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
Alto Ingredients, Inc. (ALTO)
- Filed: 2026-08-07 · CIK 0000778164 · Accession
0001213900-26-086750 - Filing: https://www.sec.gov/Archives/edgar/data/778164/000121390026086750/ea030067001ex10-1.htm
any governmental authority or affected individuals regarding any such incident. There has been no such Breach, and the Company has not been notified of and has no knowledge of any event or condition that would reasonably be expected to result in, any such Breach, except in each case as would not reasonably be expected, individually or in the aggregate, to result in a Material Adverse Effect.
(…
Federal Patching Priority
CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Service Extensions
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
- Added: 2026-08-18 · Federal due: 2026-08-21 · EPSS 99.0th pct (score 0.558) · CVSS 9.8 (CRITICAL) · CWE-415
- ransomware use: Unknown
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-55040 — Microsoft SharePoint
Microsoft SharePoint Weak Authentication Vulnerability
- Added: 2026-08-18 · Federal due: 2026-08-21 · EPSS 89.6th pct (score 0.040) · CVSS 9.1 (CRITICAL) · CWE-1390
- ransomware use: Unknown
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-59310 — Broadcom VMware vCenter
Broadcom VMware vCenter Path Traversal Vulnerability
- Added: 2026-08-18 · Federal due: 2026-08-21 · EPSS 63.9th pct (score 0.011) · CVSS 9.8 (CRITICAL) · CWE-22
- ransomware use: Unknown
Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
CVE-2026-65400 — Apple macOS
Apple macOS Improper Authentication Vulnerability
- Added: 2026-08-18 · Federal due: 2026-08-21 · EPSS 40.4th pct (score 0.005) · CVSS 9.8 (CRITICAL) · CWE-287
- ransomware use: Unknown
Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
Exploit Probability Movers
No CVEs with ≥0.20 EPSS movement in this window.
Emerging Critical CVEs
CVE-2026-76008· CRITICAL (10.0) · 2026-08-19 — A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes…CVE-2026-70921· CRITICAL (10.0) · 2026-08-18 — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticat…CVE-2026-70880· CRITICAL (10.0) · 2026-08-18 — Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability a…CVE-2026-61241· CRITICAL (10.0) · 2026-08-18 — Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allo…CVE-2026-75784· CRITICAL (10.0) · 2026-08-18 — A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument…CVE-2026-73343· CRITICAL (10.0) · 2026-08-18 — Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.CVE-2026-75874· CRITICAL (10.0) · 2026-08-18 — Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.CVE-2026-76004· CRITICAL (9.9) · 2026-08-19 — A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp of the component HTTP Handler. The…CVE-2026-76003· CRITICAL (9.9) · 2026-08-19 — A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based buffe…CVE-2026-75976· CRITICAL (9.9) · 2026-08-19 — A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes stack-based…
Supply Chain
GHSA-hfg8-hc9c-6c3h · CVE-2026-17106 (go)
- HIGH · 2026-08-18
- Affected:
github.com/moby/go-archive - https://github.com/advisories/GHSA-hfg8-hc9c-6c3h
moby/go-archive: Crafted tar archive can write outside the extraction directory
GHSA-7gww-x7fh-jf9j (composer)
- HIGH · CVSS 8.1 · 2026-08-18
- Affected:
librenms/librenms - https://github.com/advisories/GHSA-7gww-x7fh-jf9j
LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page
GHSA-pxmc-2ffp-8j67 · CVE-2026-71417 (pip)
- HIGH · CVSS 7.3 · 2026-08-18
- Affected:
lemur - https://github.com/advisories/GHSA-pxmc-2ffp-8j67
Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it
GHSA-cfh6-pv5c-38jv · CVE-2026-71308 (pip)
- HIGH · CVSS 8.1 · 2026-08-18
- Affected:
lemur - https://github.com/advisories/GHSA-cfh6-pv5c-38jv
Lemur: Unchecked replaces[] lets any user silence notifications and hijack auto-rotation for arbitrary certificates
GHSA-6c8m-q6g9-vrw3 · CVE-2026-71307 (pip)
- HIGH · CVSS 7.7 · 2026-08-18
- Affected:
lemur - https://github.com/advisories/GHSA-6c8m-q6g9-vrw3
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
GHSA-v5rc-cpwc-cfpr · CVE-2026-71303 (pip)
- HIGH · CVSS 7.7 · 2026-08-18
- Affected:
lemur - https://github.com/advisories/GHSA-v5rc-cpwc-cfpr
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v — ACME authority update endpoint allows non-admin to replace acme_url with internal IP, bypassing allowlist
GHSA-xpmj-wjcp-6pww · CVE-2026-70666 (pip)
- HIGH · CVSS 7.4 · 2026-08-18
- Affected:
lemur - https://github.com/advisories/GHSA-xpmj-wjcp-6pww
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
GHSA-7788-ghfq-c6mh · CVE-2026-62988 (composer)
- CRITICAL · CVSS 9.0 · 2026-08-18
- Affected:
froxlor/froxlor - https://github.com/advisories/GHSA-7788-ghfq-c6mh
Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints
GHSA-w27m-rmmf-g5w4 · CVE-2026-54348 (composer)
- HIGH · CVSS 7.2 · 2026-08-18
- Affected:
froxlor/froxlor - https://github.com/advisories/GHSA-w27m-rmmf-g5w4
Froxlor: Second-Order SQL Injection via Admins.add ipaddress Parameter Allows Full Database Exfiltration
GHSA-43gm-9rr3-cx7g · CVE-2026-54347 (composer)
- HIGH · CVSS 8.7 · 2026-08-18
- Affected:
froxlor/froxlor - https://github.com/advisories/GHSA-43gm-9rr3-cx7g
Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover
Ransomware Activity
23 new victim postings across 13 groups.
| Group | Victims | Sample |
|---|---|---|
thegentlemen | 5 | Euroscreen, CRASL, Senvest Capital, Roadvision Systems, Babcock |
direwolf | 4 | Photon Health, Inc., InfoFlo CRM, PayUp, Lifesum |
incransom | 3 | SpearFin Ltd, ssf-int.com ssf-ing.de, nyklawfirm.com nyk.ae |
SilentRansomGroup | 2 | Troutman Pepper Locke, T… P… L… |
Storm | 1 | American Contractors Insurance Group |
akira | 1 | Borchert & LaSpina |
dragonforce | 1 | R & D Machine and Engineering |
gunra | 1 | BOMOHSA |
play | 1 | Coltrane Systems |
qilin | 1 | Berlin Brandenburgische Wohnungsbaugenossenschaft |
securotrop | 1 | ADL Embedded Solutions |
shinyhunters | 1 | Logitech/ Streamlabs |
threeam | 1 | mecasem.org |
IOC Volume
607 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 607 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Active Malware Families
14 malware families active this week (0 corroborated across ≥2 sources), exercising 19 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| Mirai | botnet | — | 1,180 | T1110, T1498, T1499, T1584.005 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 54 | T1219 |
| AgentTesla | stealer | — | 21 | T1056.001, T1071, T1114, T1555 |
| AMOS (Atomic macOS Stealer) | stealer | — | 10 | T1005, T1056.002, T1071, T1555.001 |
| ClickFix | delivery → | — | 10 | T1059.001, T1204 |
| DDoSAgent | ddos | — | 9 | T1498, T1499 |
| XWorm | rat | — | 9 | T1056.001, T1071 |
| CoinMiner | miner | — | 7 | T1496 |
| GuLoader | loader → | — | 6 | T1027, T1071, T1105 |
| Formbook | stealer | — | 5 | T1005, T1056.001, T1071, T1555 |
| Phorpiex | botnet | — | 5 | T1071, T1486, T1566 |
| ACRStealer | stealer | — | 2 | T1005, T1071, T1555 |
| PhantomStealer | stealer | — | 2 | T1005, T1555 |
| PureLogsStealer | stealer | — | 1 | T1005, T1071, T1555 |
Families marked ”→” are delivery/social-engineering clusters (ClickFix, GuLoader). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
25 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
01ejjpa2.behtarin-site-shartbandi.com | domain | misp + urlhaus | 2026-08-19 |
1s3hqwvr.varzeshlife.ir | domain | misp + urlhaus | 2026-08-19 |
2gfxwchj.emeraldualzone.com | domain | misp + urlhaus | 2026-08-19 |
2zm9lhlg.groeschelcompany.com | domain | misp + urlhaus | 2026-08-19 |
47ytdzjs.economywindowsparts.com | domain | misp + urlhaus | 2026-08-19 |
4gfsvs7l.jennyrussianbluepalace.com | domain | misp + urlhaus | 2026-08-19 |
7wzfqmf9.behtarin-site-shartbandi.com | domain | misp + urlhaus | 2026-08-19 |
a6du2gsx.fit2leadconference.com | domain | misp + urlhaus | 2026-08-19 |
aethersyncmatrix5.lol | domain | misp + urlhaus | 2026-08-19 |
bcmej6hr.goodlifelakerentals.com | domain | misp + urlhaus | 2026-08-19 |
bhrbc90m.fredcoplumbingpros.com | domain | misp + urlhaus | 2026-08-19 |
botnet.botnet.xd.67.flightleaks.xyz | domain | misp + urlhaus | 2026-08-19 |
cryptomeshforge10.lol | domain | misp + urlhaus | 2026-08-19 |
cryptomeshforge5.lol | domain | misp + urlhaus | 2026-08-19 |
dnrlgtwo.frizzhairforecast.com | domain | misp + urlhaus | 2026-08-19 |
dwvygj31.dermatologycongress.org | domain | misp + urlhaus | 2026-08-19 |
ea168jci.customhomebuildersplainfield.com | domain | misp + urlhaus | 2026-08-19 |
ewyjl357.flashhomebuyerskc.com | domain | misp + urlhaus | 2026-08-19 |
fby6y3nd.illuigiitaliancuisine.com | domain | misp + urlhaus | 2026-08-19 |
g1wgxqj5.nextbahis.one | domain | misp + urlhaus | 2026-08-19 |
h51ee0ex.emeraldualzone.com | domain | misp + urlhaus | 2026-08-19 |
hag0wqv7.estrelamardedetizadora.com | domain | misp + urlhaus | 2026-08-19 |
hypercorevector9.lol | domain | misp + urlhaus | 2026-08-19 |
iahg2idr.evansunitedspringcarnivalsherman.com | domain | misp + urlhaus | 2026-08-19 |
ijm1e9p4.chrisbrownstlouis.com | domain | misp + urlhaus | 2026-08-19 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
Alto Ingredients, Inc. (filed 2026-08-07)
Token match on alto against KEV vendor/product strings. This is a heuristic — verify before treating as attribution.
CVE-2026-0257— Palo Alto Networks PAN-OS (added 2026-05-29)
Intel Feeds
4 IOC feeds updated this run (8,084 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| MISP — Suspicious Domains | misp | domain | 5,000 | CSV · MISP · STIX |
| MISP — Flagged IPs | misp | ip | 83 | CSV · MISP · STIX |
| URLhaus — Malware Distribution URLs | urlhaus | url | 2,941 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 60 | CSV · MISP · STIX |
Hand-Authored Sigma
10 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Host | experimental | https://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml |
| T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Process | experimental | https://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnet | experimental | https://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml |
| T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Container | experimental | https://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml |
| T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml |
| T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Path | experimental | https://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
17 of 157 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1562 | — | — | 0 | 3 |
T1573.001 | Symmetric Cryptography | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 7 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.