August 25, 2026 · Applied Cybernetics Group
Morning Brief — August 25, 2026
Morning Brief — 2026-08-25
1 federal patching priority, 20 exploit probability movers, 10 emerging critical cves, 4 supply chain, 27 ransomware activity, 587 ioc volume, 21 active malware families, 2 multi-source iocs, 2 intel feeds, 12 hand-authored sigma, and 17 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
No new Item 1.05 8-K filings in this window.
Federal Patching Priority
CVE-2026-21962 — Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
- Added: 2026-08-24 · Federal due: 2026-08-27 · EPSS 98.6th pct (score 0.432) · CVSS 10.0 (CRITICAL) · CWE-284
- ransomware use: Unknown
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
Exploit Probability Movers
| CVE | Today | Prev | Δ | In KEV |
|---|---|---|---|---|
CVE-2026-48908 | 0.148 | 0.881 | ▼ 0.733 | ✓ |
CVE-2026-63077 | 0.847 | 0.120 | ▲ 0.727 | ✓ |
CVE-2026-72898 | 0.792 | 0.104 | ▲ 0.688 | ✓ |
CVE-2026-45659 | 0.761 | 0.099 | ▲ 0.662 | ✓ |
CVE-2026-15410 | 0.118 | 0.763 | ▼ 0.646 | ✓ |
CVE-2026-48939 | 0.197 | 0.825 | ▼ 0.628 | ✓ |
CVE-2026-56291 | 0.146 | 0.761 | ▼ 0.615 | ✓ |
CVE-2026-20896 | 0.028 | 0.624 | ▼ 0.596 | |
CVE-2026-48282 | 0.424 | 0.992 | ▼ 0.569 | ✓ |
CVE-2016-3251 | 0.581 | 0.034 | ▲ 0.546 | |
CVE-2026-56290 | 0.304 | 0.833 | ▼ 0.529 | ✓ |
CVE-2026-6875 | 0.776 | 0.267 | ▲ 0.508 | |
CVE-2017-3191 | 0.625 | 0.141 | ▲ 0.484 | |
CVE-2026-59310 | 0.459 | 0.024 | ▲ 0.435 | ✓ |
CVE-2018-0258 | 0.494 | 0.064 | ▲ 0.430 | |
CVE-2026-27771 | 0.014 | 0.431 | ▼ 0.417 | |
CVE-2017-9829 | 0.687 | 0.276 | ▲ 0.412 | |
CVE-2018-3924 | 0.441 | 0.030 | ▲ 0.411 | |
CVE-2016-3272 | 0.433 | 0.032 | ▲ 0.401 | |
CVE-2025-71257 | 0.446 | 0.052 | ▲ 0.394 |
Emerging Critical CVEs
CVE-2026-32559· CRITICAL (9.9) · 2026-08-24 — Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.CVE-2026-66897· CRITICAL (9.9) · 2026-08-24 — A path traversal vulnerability in LXD’s instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. Whe…CVE-2026-78568· CRITICAL (9.8) · 2026-08-25 — The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the ex…CVE-2026-63586· CRITICAL (9.8) · 2026-08-25 — The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell…CVE-2026-78477· CRITICAL (9.8) · 2026-08-25 — The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator…CVE-2026-13214· CRITICAL (9.8) · 2026-08-25 — The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request from the central system, the handler copied the attacker-controlled…CVE-2026-78676· CRITICAL (9.8) · 2026-08-25 — GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files w…CVE-2026-56710· CRITICAL (9.8) · 2026-08-25 — Grav Login plugin versions before 1.0.16 fail to validate the target account’s privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on…CVE-2026-56705· CRITICAL (9.8) · 2026-08-25 — Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parame…CVE-2026-78267· CRITICAL (9.8) · 2026-08-24 — Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Supply Chain
GHSA-jm48-m3rr-9hgg · CVE-2026-55477 (go)
- HIGH · CVSS 7.2 · 2026-08-24
- Affected:
github.com/mhsanaei/3x-ui/v3,github.com/mhsanaei/3x-ui/v2 - https://github.com/advisories/GHSA-jm48-m3rr-9hgg
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
GHSA-8jj7-4v57-frf5 · CVE-2026-54623 (pip)
- HIGH · CVSS 7.1 · 2026-08-24
- Affected:
django-cms - https://github.com/advisories/GHSA-8jj7-4v57-frf5
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
GHSA-5x78-73v4-xg6w (rust)
- HIGH · 2026-08-24
- Affected:
postgres-protocol - https://github.com/advisories/GHSA-5x78-73v4-xg6w
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
GHSA-w2x5-gv52-9ccv · CVE-2026-54049 (maven)
- HIGH · CVSS 8.7 · 2026-08-24
- Affected:
org.sakaiproject.conversations:sakai-conversations-impl,org.sakaiproject.kernel:sakai-kernel-impl,org.sakaiproject.rubrics:rubrics-impl - https://github.com/advisories/GHSA-w2x5-gv52-9ccv
Sakai Conversations has a Stored XSS Issue
Ransomware Activity
27 new victim postings across 12 groups.
| Group | Victims | Sample |
|---|---|---|
Booba Project | 4 | Davroc, Chernyy & Associates, Country-Wide Insurance, Federis Abogados |
Dark Project | 4 | The Liberty Group, Jones, Little & Co., CPAs, LLP, Design-Aire Engineering, INC,… |
dragonforce | 4 | Frato, Criba, Brookview Financial, Wozair |
qilin | 3 | Consultores de Seguros, Coldfish Seafood, A&E + SMA Design |
Deadlock | 2 | SHAHEEN LAW GROUP PLC - Richmond, Virginia, USA, FBC |
Panzer | 2 | Government of Vojvodina, Senvibe |
arcusmedia | 2 | ManagementPro, Mark’Techno |
beast | 2 | Cosmon, Meridian Forest Services |
akira | 1 | Bihl |
blackwater | 1 | www.ptesm.com |
incransom | 1 | FFKR Architects |
safepay | 1 | lagegepesca.it |
IOC Volume
587 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 587 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Active Malware Families
21 malware families active this week (0 corroborated across ≥2 sources), exercising 20 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| Mirai | botnet | — | 782 | T1110, T1498, T1499, T1584.005 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 83 | T1219 |
| ClickFix | delivery → | — | 17 | T1059.001, T1204 |
| AgentTesla | stealer | — | 10 | T1056.001, T1071, T1114, T1555 |
| AsyncRAT | rat | — | 9 | T1056.001, T1059.001, T1071, T1219 |
| Remcos | rat | — | 9 | T1056.001, T1071, T1113 |
| PureLogsStealer | stealer | — | 8 | T1005, T1071, T1555 |
| CoinMiner | miner | — | 5 | T1496 |
| Formbook | stealer | — | 5 | T1005, T1056.001, T1071, T1555 |
| DDoSAgent | ddos | — | 4 | T1498, T1499 |
| Phorpiex | botnet | — | 4 | T1071, T1486, T1566 |
| XWorm | rat | — | 4 | T1056.001, T1071 |
| GuLoader | loader → | — | 3 | T1027, T1071, T1105 |
| Vidar | stealer | — | 3 | T1005, T1071, T1555 |
| ACRStealer | stealer | — | 2 | T1005, T1071, T1555 |
| ClearFake | delivery → | — | 2 | T1059.001, T1189, T1204 |
| MassLogger | stealer | — | 2 | T1056.001, T1071, T1555 |
| Stealc | stealer | — | 2 | T1005, T1071, T1555 |
| njRAT | rat | — | 1 | T1056.001, T1059.003, T1071, T1219 |
| PhantomStealer | stealer | — | 1 | T1005, T1555 |
| PureHVNC | rat | — | 1 | T1071, T1113 |
Families marked ”→” are delivery/social-engineering clusters (ClickFix, GuLoader, ClearFake). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
2 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
cryptomeshforge10.lol | domain | misp + urlhaus | 2026-08-25 |
hypercorevector5.lol | domain | misp + urlhaus | 2026-08-25 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No recent SEC filings to cross-reference.
Intel Feeds
2 IOC feeds updated this run (2,840 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| URLhaus — Malware Distribution URLs | urlhaus | url | 2,692 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 148 | CSV · MISP · STIX |
Hand-Authored Sigma
10 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Host | experimental | https://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml |
| T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Process | experimental | https://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnet | experimental | https://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml |
| T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Container | experimental | https://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml |
| T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml |
| T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Path | experimental | https://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
17 of 156 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1562 | — | — | 0 | 3 |
T1573.001 | Symmetric Cryptography | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 7 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.