Applied Cybernetics Group
Threat intel → detection pipeline
Friday, September 18, 2026
Data as of 13:09 UTC

Morning Brief — 2026-08-27

6 federal patching priority, 1 exploit probability movers, 10 emerging critical cves, 10 supply chain, 51 ransomware activity, 667 ioc volume, 14 active malware families, 1 multi-source iocs, 2 intel feeds, 12 hand-authored sigma, and 17 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.

Material Breach Disclosures

No new Item 1.05 8-K filings in this window.

Federal Patching Priority

CVE-2021-23758 — Ajax.NET Professional Ajax.NET Professional

Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

CVE-2019-1068 — Microsoft SQL Server

Microsoft SQL Server Remote Code Execution Vulnerability

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka ‘Microsoft SQL Server Remote Code Execution Vulnerability’.

CVE-2015-3246 — Red Hat Libuser

Red Hat Libuser Race Condition Vulnerability

Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

CVE-2022-0995 — Linux Kernel

Linux Kernel Out-of-Bounds Write Vulnerability

Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.

An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

CVE-2015-5287 — Red Hat Automatic Bug Reporting Tool

Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability

Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.

CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway

Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

Exploit Probability Movers

CVETodayPrevΔIn KEV
CVE-2020-102210.8020.368▲ 0.435

Emerging Critical CVEs

Supply Chain

GHSA-7w8c-qgxg-m7jx (composer)

LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates

GHSA-2wxc-x7rj-hg8f · CVE-2026-54591 (pip)

asyncssh has SCP Path Traversal to Arbitrary File Write

GHSA-jrw6-7x4q-w25j · CVE-2026-54569 (pip)

senaite.core Vulnerable to Eval Injection and Missing Authorization

GHSA-w93q-cq9w-58p7 · CVE-2026-54606 (npm)

SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed

GHSA-w5fv-7x5q-g8qp · CVE-2026-54563 (go)

Cloudreve WebDAV (/dav) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root

GHSA-93qj-5q5v-3c2h (pip)

Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise)

GHSA-8h6h-x5pq-56fq · CVE-2026-54511 (npm)

@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys

GHSA-f63g-88cj-hjf9 · CVE-2026-54550 (maven)

IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries

GHSA-79gf-7frw-68m9 · CVE-2026-54523 (go)

Kyverno’s NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated — background controller creates RoleBindings in any namespace including kube-system

GHSA-vmm3-xgcx-67hm · CVE-2026-54556 (maven)

http4s has HTTP/2 Denial of Service with Ember Backend

Ransomware Activity

51 new victim postings across 14 groups.

GroupVictimsSample
krybit12finodayacapital.com, cgcgabon.com, karkinos.in, ferretornillos.gt, www.sankovn.c…
SilentRansomGroup8Q… E…, N… M…, S… P…, K… M…, H… K…, H… L…, C… O…, A..…
qilin8Sanatorio Modelo de Caseros, KenEp Resources, Metal Conversions, California Truc…
medusalocker5Jgsee, Servifruit, Hungry Lion, Qualisteel, Health
thegentlemen5Party Rental, TEC Container, Verbux, Espinos, Incolur
akira3Gill Rock Drill, Oral and Maxillofacial Surgery, PA-ID
AiLock2Morgan Services, Hamilton
iah64772proampac, mat-holdings-inc
AuditTeam1Demidov Steel Group
Eclipse1Simplex Engineering
abyss1MEMSIC
aurora1ERPIS LLC
emperador1Capitol Mechanics
pear1NEXT LEVEL MEDICAL, LLC

IOC Volume

667 new IOCs in this window. By source:

SourceCount
urlhaus667

Recent OSINT Events

No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).

Active Malware Families

14 malware families active this week (0 corroborated across ≥2 sources), exercising 15 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.

FamilyTypeCorrob.IOCsTechniques (✗ = coverage gap)
Miraibotnet814T1110, T1498, T1499, T1584.005
ConnectWise ScreenConnect (abuse)rmm-abuse54T1219
ClickFixdelivery →23T1059.001, T1204
AgentTeslastealer15T1056.001, T1071, T1114, T1555
Formbookstealer11T1005, T1056.001, T1071, T1555
PureLogsStealerstealer10T1005, T1071, T1555
XWormrat10T1056.001, T1071
CoinMinerminer5T1496
DDoSAgentddos4T1498, T1499
Stealcstealer4T1005, T1071, T1555
ClearFakedelivery →2T1059.001, T1189, T1204
MassLoggerstealer2T1056.001, T1071, T1555
PureHVNCrat1T1071, T1113
Vidarstealer1T1005, T1071, T1555

Families marked ”→” are delivery/social-engineering clusters (ClickFix, ClearFake). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.

Multi-Source IOCs

1 IOC flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.

IOCTypeSourcesLast seen
iploglab.storedomainmisp + urlhaus2026-08-27

MISP × KEV Correlation

No MISP events in this window referenced a CVE.

Cross-Reference

No recent SEC filings to cross-reference.

Intel Feeds

2 IOC feeds updated this run (2,737 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.

FeedSourceTypeCountDownloads
URLhaus — Malware Distribution URLsurlhausurl2,576CSV · MISP · STIX
URLhaus — Malware Distribution Domainsurlhausdomain161CSV · MISP · STIX

Hand-Authored Sigma

10 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.

RuleStatusYAML
T1037 Boot or Logon Initialization Scripts — Linux Init Script Modificationexperimentalhttps://thrunt.me/sigma/t1037-linux-init-script-modification.yml
T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Hostexperimentalhttps://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml
T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Processexperimentalhttps://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml
T1098.004 Account Manipulation — SSH Authorized Keys File Modificationexperimentalhttps://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml
T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnetexperimentalhttps://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml
T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Containerexperimentalhttps://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml
T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Executionexperimentalhttps://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml
T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Executionexperimentalhttps://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml
T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaignexperimentalhttps://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml
T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Pathexperimentalhttps://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml
T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Accessdrafthttps://thrunt.meundefined
T1530 Data from Cloud Storage — Detectiondrafthttps://thrunt.meundefined

Detection Gaps

17 of 156 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.

TechniqueNameActive familiesMISPKEV
T1011Exfiltration Over Other Network Medium04
T1497Virtualization/Sandbox Evasion04
T156203
T1573.001Symmetric Cryptography03
T1001Data Obfuscation02
T1499.002Service Exhaustion Flood02
T1530Data from Cloud Storage02
T1562.00102
T1003.008/etc/passwd and /etc/shadow01
T1070.00101

…and 7 more below the cut — full list on the rollup.

Pipeline Health

All feeds healthy.


Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).

Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.