Applied Cybernetics Group
Threat intel → detection pipeline
Friday, September 18, 2026
Data as of 13:09 UTC

Morning Brief — 2026-08-20

1 material breach disclosures, 1 federal patching priority, 3 exploit probability movers, 10 emerging critical cves, 11 supply chain, 45 ransomware activity, 709 ioc volume, 18 active malware families, 3 multi-source iocs, 1 cross-reference, 4 intel feeds, 12 hand-authored sigma, and 17 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.

Material Breach Disclosures

Alto Ingredients, Inc. (ALTO)

any governmental authority or affected individuals regarding any such incident. There has been no such Breach, and the Company has not been notified of and has no knowledge of any event or condition that would reasonably be expected to result in, any such Breach, except in each case as would not reasonably be expected, individually or in the aggregate, to result in a Material Adverse Effect.

(…

Federal Patching Priority

CVE-2026-64849 — MLflow MLflow

MLflow Server-Side Request Forgery Vulnerability

MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated…

Exploit Probability Movers

CVETodayPrevΔIn KEV
CVE-2018-117140.6810.354▲ 0.327
CVE-2026-338240.7790.558▲ 0.220
CVE-2019-10030300.9690.756▲ 0.213

Emerging Critical CVEs

Supply Chain

GHSA-rxjr-6c9q-h67x · CVE-2026-63188 (npm)

logto-tunnel serves files outside —experience-path via path traversal

GHSA-vwg3-w8w3-pc79 · CVE-2026-62673 (composer)

Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems

GHSA-3hgv-jr5j-cg9x · CVE-2026-55694 (composer)

Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover

GHSA-wf6j-gr27-g7ch · CVE-2024-45747 (maven)

GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates

GHSA-p77j-g7h5-r2vw (pip)

GeoLens’s authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GHSA-45ph-gxxr-gwgw · CVE-2026-53966 (maven)

XWiki Platform Live Data Live Table Connector has privilege escalation from edit to script right through Live Data editing

GHSA-7m52-jw36-44r3 · CVE-2026-53965 (composer)

MCP PHP SDK: client HttpTransport SSE buffer (sseBuffer .= chunk) grows unbounded when server withholds the event delimiter

GHSA-w47q-945m-q9pc · CVE-2026-53964 (pip)

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

GHSA-2xhg-73j7-rrgx · CVE-2026-53957 (npm)

Contentful MCP Server: export_space/import_space tools pass LLM-controlled host/proxy args to CMA client, redirecting server PAT to attacker-controlled endpoint

GHSA-9gmc-jqmh-3rvm · CVE-2026-53951 (pip)

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

Exploitation evidence, 7-day window (severity-agnostic — evidence trumps labels):

Ransomware Activity

45 new victim postings across 14 groups.

GroupVictimsSample
qilin13Questronix, Provite, Trends And Concepts, Semana, Thrifty Building Supply, Estec…
krybit5sunsea.co.th, www.mestojilemnice.cz, automotoresrosedal.com.ar, sipresitalia.it,…
settra5wcmanagement.info, alphanumeric.com, am-bition.jp, grecosteel.com, makfreight.co…
everest4Kingston Technology, Experts Entreprendre, Grupo DT, Capgemini Engineering
incransom4BANGKOKCABLE, UNIPLASTICS.COM, CDGARVINLAW, EXEL
Deadlock3JP Molyneux Studio, UFOC, Global Terminal Services
coinbasecartel2Crowe, Advanced Engineering Consultants
insomnia2Aurora Health Management, ***********
xpl0itrs2Target, Mihuru
Helix1Delek US
Orova1DL HOLDINGS GROUP
akira1Ericksen Krentel
interlock1Southeastern Oklahoma State University
nightspire1Vi***** Pe****** C***, Inc

IOC Volume

709 new IOCs in this window. By source:

SourceCount
urlhaus709

Recent OSINT Events

No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).

Active Malware Families

18 malware families active this week (0 corroborated across ≥2 sources), exercising 21 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.

FamilyTypeCorrob.IOCsTechniques (✗ = coverage gap)
Miraibotnet1,202T1110, T1498, T1499, T1584.005
ConnectWise ScreenConnect (abuse)rmm-abuse89T1219
AgentTeslastealer23T1056.001, T1071, T1114, T1555
ClickFixdelivery →18T1059.001, T1204
AsyncRATrat9T1056.001, T1059.001, T1071, T1219
DDoSAgentddos9T1498, T1499
Remcosrat9T1056.001, T1071, T1113
CoinMinerminer8T1496
Formbookstealer5T1005, T1056.001, T1071, T1555
XWormrat5T1056.001, T1071
Phorpiexbotnet4T1071, T1486, T1566
GuLoaderloader →3T1027, T1071, T1105
PhantomStealerstealer3T1005, T1555
PureLogsStealerstealer3T1005, T1071, T1555
ACRStealerstealer2T1005, T1071, T1555
Vidarstealer2T1005, T1071, T1555
AMOS (Atomic macOS Stealer)stealer1T1005, T1056.002, T1071, T1555.001
njRATrat1T1056.001, T1059.003, T1071, T1219

Families marked ”→” are delivery/social-engineering clusters (ClickFix, GuLoader). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.

Multi-Source IOCs

3 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.

IOCTypeSourcesLast seen
botnet.botnet.xd.67.flightleaks.xyzdomainmisp + urlhaus2026-08-20
cryptomeshforge10.loldomainmisp + urlhaus2026-08-20
hypercorevector5.loldomainmisp + urlhaus2026-08-20

MISP × KEV Correlation

No MISP events in this window referenced a CVE.

Cross-Reference

Alto Ingredients, Inc. (filed 2026-08-07)

Token match on alto against KEV vendor/product strings. This is a heuristic — verify before treating as attribution.

Intel Feeds

4 IOC feeds updated this run (8,269 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.

FeedSourceTypeCountDownloads
MISP — Suspicious Domainsmispdomain5,000CSV · MISP · STIX
MISP — Flagged IPsmispip27CSV · MISP · STIX
URLhaus — Malware Distribution URLsurlhausurl3,145CSV · MISP · STIX
URLhaus — Malware Distribution Domainsurlhausdomain97CSV · MISP · STIX

Hand-Authored Sigma

10 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.

RuleStatusYAML
T1037 Boot or Logon Initialization Scripts — Linux Init Script Modificationexperimentalhttps://thrunt.me/sigma/t1037-linux-init-script-modification.yml
T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Hostexperimentalhttps://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml
T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Processexperimentalhttps://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml
T1098.004 Account Manipulation — SSH Authorized Keys File Modificationexperimentalhttps://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml
T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnetexperimentalhttps://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml
T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Containerexperimentalhttps://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml
T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Executionexperimentalhttps://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml
T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Executionexperimentalhttps://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml
T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaignexperimentalhttps://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml
T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Pathexperimentalhttps://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml
T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Accessdrafthttps://thrunt.meundefined
T1530 Data from Cloud Storage — Detectiondrafthttps://thrunt.meundefined

Detection Gaps

17 of 158 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.

TechniqueNameActive familiesMISPKEV
T1011Exfiltration Over Other Network Medium04
T1497Virtualization/Sandbox Evasion04
T156203
T1573.001Symmetric Cryptography03
T1001Data Obfuscation02
T1499.002Service Exhaustion Flood02
T1530Data from Cloud Storage02
T1562.00102
T1003.008/etc/passwd and /etc/shadow01
T1070.00101

…and 7 more below the cut — full list on the rollup.

Pipeline Health

All feeds healthy.


Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).

Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.