August 27, 2026 · Applied Cybernetics Group
Morning Brief — August 27, 2026
Morning Brief — 2026-08-27
6 federal patching priority, 1 exploit probability movers, 10 emerging critical cves, 10 supply chain, 51 ransomware activity, 667 ioc volume, 14 active malware families, 1 multi-source iocs, 2 intel feeds, 12 hand-authored sigma, and 17 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
No new Item 1.05 8-K filings in this window.
Federal Patching Priority
CVE-2021-23758 — Ajax.NET Professional Ajax.NET Professional
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- Added: 2026-08-26 · Federal due: 2026-09-09 · EPSS 99.8th pct (score 0.891) · CVSS 8.1 (HIGH) · CWE-502
- ransomware use: Unknown
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
CVE-2019-1068 — Microsoft SQL Server
Microsoft SQL Server Remote Code Execution Vulnerability
- Added: 2026-08-26 · Federal due: 2026-08-29 · EPSS 98.7th pct (score 0.447) · CVSS 8.8 (HIGH) · CWE-20
- ransomware use: Unknown
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka ‘Microsoft SQL Server Remote Code Execution Vulnerability’.
CVE-2015-3246 — Red Hat Libuser
Red Hat Libuser Race Condition Vulnerability
- Added: 2026-08-26 · Federal due: 2026-09-09 · EPSS 93.7th pct (score 0.071) · CVSS 5.1 (MEDIUM) · CWE-264, CWE-367
- ransomware use: Unknown
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.
CVE-2022-0995 — Linux Kernel
Linux Kernel Out-of-Bounds Write Vulnerability
- Added: 2026-08-26 · Federal due: 2026-09-09 · EPSS 93.1th pct (score 0.063) · CVSS 7.8 (HIGH) · CWE-787
- ransomware use: Unknown
Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.
CVE-2015-5287 — Red Hat Automatic Bug Reporting Tool
Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
- Added: 2026-08-26 · Federal due: 2026-09-09 · EPSS 88.0th pct (score 0.034) · CVSS 7.8 (HIGH) · CWE-59
- ransomware use: Unknown
Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
- Added: 2026-08-26 · Federal due: 2026-08-29 · EPSS 61.5th pct (score 0.010) · CVSS 9.8 (CRITICAL) · CWE-119
- ransomware use: Unknown
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
Exploit Probability Movers
| CVE | Today | Prev | Δ | In KEV |
|---|---|---|---|---|
CVE-2020-10221 | 0.802 | 0.368 | ▲ 0.435 | ✓ |
Emerging Critical CVEs
CVE-2026-77554· CRITICAL (10.0) · 2026-08-26 — A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device.CVE-2026-77550· CRITICAL (10.0) · 2026-08-26 — A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instanc…CVE-2026-77537· CRITICAL (10.0) · 2026-08-26 — A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.CVE-2026-77553· CRITICAL (9.9) · 2026-08-26 — A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.CVE-2026-77548· CRITICAL (9.9) · 2026-08-26 — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.CVE-2026-77547· CRITICAL (9.9) · 2026-08-26 — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.CVE-2026-77546· CRITICAL (9.9) · 2026-08-26 — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.CVE-2026-77543· CRITICAL (9.9) · 2026-08-26 — A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.CVE-2026-77536· CRITICAL (9.9) · 2026-08-26 — A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or inst…CVE-2026-77534· CRITICAL (9.9) · 2026-08-26 — A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or inst…
Supply Chain
GHSA-7w8c-qgxg-m7jx (composer)
- HIGH · CVSS 7.1 · 2026-08-26
- Affected:
librenms/librenms - https://github.com/advisories/GHSA-7w8c-qgxg-m7jx
LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates
GHSA-2wxc-x7rj-hg8f · CVE-2026-54591 (pip)
- HIGH · CVSS 8.1 · 2026-08-26
- Affected:
asyncssh - https://github.com/advisories/GHSA-2wxc-x7rj-hg8f
asyncssh has SCP Path Traversal to Arbitrary File Write
GHSA-jrw6-7x4q-w25j · CVE-2026-54569 (pip)
- CRITICAL · CVSS 9.8 · 2026-08-26
- Affected:
senaite.core - https://github.com/advisories/GHSA-jrw6-7x4q-w25j
senaite.core Vulnerable to Eval Injection and Missing Authorization
GHSA-w93q-cq9w-58p7 · CVE-2026-54606 (npm)
- HIGH · 2026-08-26
- Affected:
suneditor - https://github.com/advisories/GHSA-w93q-cq9w-58p7
SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed
GHSA-w5fv-7x5q-g8qp · CVE-2026-54563 (go)
- HIGH · CVSS 7.1 · 2026-08-26
- Affected:
github.com/cloudreve/Cloudreve/v4,github.com/cloudreve/Cloudreve/v3 - https://github.com/advisories/GHSA-w5fv-7x5q-g8qp
Cloudreve WebDAV (/dav) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root
GHSA-93qj-5q5v-3c2h (pip)
- CRITICAL · 2026-08-26
- Affected:
pantheon-agents - https://github.com/advisories/GHSA-93qj-5q5v-3c2h
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)
GHSA-8h6h-x5pq-56fq · CVE-2026-54511 (npm)
- HIGH · CVSS 8.6 · 2026-08-26
- Affected:
@logtape/syslog,@logtape/syslog,@logtape/syslog - https://github.com/advisories/GHSA-8h6h-x5pq-56fq
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys
GHSA-f63g-88cj-hjf9 · CVE-2026-54550 (maven)
- HIGH · CVSS 7.4 · 2026-08-26
- Affected:
org.codehaus.izpack:izpack-installer - https://github.com/advisories/GHSA-f63g-88cj-hjf9
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries
GHSA-79gf-7frw-68m9 · CVE-2026-54523 (go)
- CRITICAL · CVSS 9.6 · 2026-08-26
- Affected:
github.com/kyverno/kyverno - https://github.com/advisories/GHSA-79gf-7frw-68m9
Kyverno’s NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated — background controller creates RoleBindings in any namespace including kube-system
GHSA-vmm3-xgcx-67hm · CVE-2026-54556 (maven)
- HIGH · 2026-08-26
- Affected:
org.http4s:http4s-ember-core_2.12,org.http4s:http4s-ember-core_2.13,org.http4s:http4s-ember-core_3 - https://github.com/advisories/GHSA-vmm3-xgcx-67hm
http4s has HTTP/2 Denial of Service with Ember Backend
Ransomware Activity
51 new victim postings across 14 groups.
| Group | Victims | Sample |
|---|---|---|
krybit | 12 | finodayacapital.com, cgcgabon.com, karkinos.in, ferretornillos.gt, www.sankovn.c… |
SilentRansomGroup | 8 | Q… E…, N… M…, S… P…, K… M…, H… K…, H… L…, C… O…, A..… |
qilin | 8 | Sanatorio Modelo de Caseros, KenEp Resources, Metal Conversions, California Truc… |
medusalocker | 5 | Jgsee, Servifruit, Hungry Lion, Qualisteel, Health |
thegentlemen | 5 | Party Rental, TEC Container, Verbux, Espinos, Incolur |
akira | 3 | Gill Rock Drill, Oral and Maxillofacial Surgery, PA-ID |
AiLock | 2 | Morgan Services, Hamilton |
iah6477 | 2 | proampac, mat-holdings-inc |
AuditTeam | 1 | Demidov Steel Group |
Eclipse | 1 | Simplex Engineering |
abyss | 1 | MEMSIC |
aurora | 1 | ERPIS LLC |
emperador | 1 | Capitol Mechanics |
pear | 1 | NEXT LEVEL MEDICAL, LLC |
IOC Volume
667 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 667 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Active Malware Families
14 malware families active this week (0 corroborated across ≥2 sources), exercising 15 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| Mirai | botnet | — | 814 | T1110, T1498, T1499, T1584.005 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 54 | T1219 |
| ClickFix | delivery → | — | 23 | T1059.001, T1204 |
| AgentTesla | stealer | — | 15 | T1056.001, T1071, T1114, T1555 |
| Formbook | stealer | — | 11 | T1005, T1056.001, T1071, T1555 |
| PureLogsStealer | stealer | — | 10 | T1005, T1071, T1555 |
| XWorm | rat | — | 10 | T1056.001, T1071 |
| CoinMiner | miner | — | 5 | T1496 |
| DDoSAgent | ddos | — | 4 | T1498, T1499 |
| Stealc | stealer | — | 4 | T1005, T1071, T1555 |
| ClearFake | delivery → | — | 2 | T1059.001, T1189, T1204 |
| MassLogger | stealer | — | 2 | T1056.001, T1071, T1555 |
| PureHVNC | rat | — | 1 | T1071, T1113 |
| Vidar | stealer | — | 1 | T1005, T1071, T1555 |
Families marked ”→” are delivery/social-engineering clusters (ClickFix, ClearFake). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
1 IOC flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
iploglab.store | domain | misp + urlhaus | 2026-08-27 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No recent SEC filings to cross-reference.
Intel Feeds
2 IOC feeds updated this run (2,737 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| URLhaus — Malware Distribution URLs | urlhaus | url | 2,576 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 161 | CSV · MISP · STIX |
Hand-Authored Sigma
10 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Host | experimental | https://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml |
| T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Process | experimental | https://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnet | experimental | https://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml |
| T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Container | experimental | https://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml |
| T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml |
| T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Path | experimental | https://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
17 of 156 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1562 | — | — | 0 | 3 |
T1573.001 | Symmetric Cryptography | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 7 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.