August 29, 2026 · Applied Cybernetics Group
Morning Brief — August 29, 2026
Morning Brief — 2026-08-29
20 exploit probability movers, 10 emerging critical cves, 10 supply chain, 36 ransomware activity, 634 ioc volume, 16 active malware families, 3 multi-source iocs, 2 intel feeds, 12 hand-authored sigma, and 17 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
No new Item 1.05 8-K filings in this window.
Federal Patching Priority
No new KEV additions in this window.
Exploit Probability Movers
| CVE | Today | Prev | Δ | In KEV |
|---|---|---|---|---|
CVE-2016-3251 | 0.034 | 0.581 | ▼ 0.546 | |
CVE-2017-3191 | 0.141 | 0.625 | ▼ 0.484 | |
CVE-2018-0258 | 0.064 | 0.494 | ▼ 0.430 | |
CVE-2017-9829 | 0.276 | 0.687 | ▼ 0.412 | |
CVE-2018-3924 | 0.030 | 0.441 | ▼ 0.411 | |
CVE-2016-3272 | 0.032 | 0.433 | ▼ 0.401 | |
CVE-2019-7111 | 0.156 | 0.541 | ▼ 0.386 | |
CVE-2016-6603 | 0.488 | 0.870 | ▼ 0.382 | |
CVE-2018-16283 | 0.251 | 0.631 | ▼ 0.379 | |
CVE-2015-5259 | 0.194 | 0.570 | ▼ 0.377 | |
CVE-2017-6343 | 0.228 | 0.603 | ▼ 0.376 | |
CVE-2018-18990 | 0.026 | 0.395 | ▼ 0.369 | |
CVE-2018-11714 | 0.319 | 0.681 | ▼ 0.361 | |
CVE-2017-6360 | 0.305 | 0.661 | ▼ 0.356 | |
CVE-2019-9733 | 0.174 | 0.529 | ▼ 0.355 | |
CVE-2016-4264 | 0.342 | 0.690 | ▼ 0.349 | |
CVE-2018-11139 | 0.775 | 0.429 | ▲ 0.346 | |
CVE-2018-11132 | 0.525 | 0.183 | ▲ 0.342 | |
CVE-2017-14942 | 0.268 | 0.609 | ▼ 0.340 | |
CVE-2018-8033 | 0.596 | 0.257 | ▲ 0.339 |
Emerging Critical CVEs
CVE-2026-54745· CRITICAL (10.0) · 2026-08-28 — Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability th…CVE-2026-82222· CRITICAL (10.0) · 2026-08-28 — Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection.
This issue affects GiveWP: from n/a through 4.16.7.1.
CVE-2026-19295· CRITICAL (9.9) · 2026-08-28 — IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wra…CVE-2026-18527· CRITICAL (9.9) · 2026-08-28 — IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can…CVE-2026-55634· CRITICAL (9.9) · 2026-08-28 — Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import ac…CVE-2026-55565· CRITICAL (9.9) · 2026-08-28 — Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern i…CVE-2026-19286· CRITICAL (9.8) · 2026-08-28 — IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.CVE-2026-82329· CRITICAL (9.8) · 2026-08-28 — JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.CVE-2026-82277· CRITICAL (9.8) · 2026-08-28 — Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, A…CVE-2026-82266· CRITICAL (9.8) · 2026-08-28 — Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create an…
Supply Chain
GHSA-ffg3-p8fm-mjx2 · CVE-2026-55830 (pip)
- HIGH · CVSS 8.3 · 2026-08-28
- Affected:
RestrictedPython - https://github.com/advisories/GHSA-ffg3-p8fm-mjx2
RestrictedPython guard hooks can be shadowed via positional-only arguments
GHSA-j5g3-42wp-gqm3 · CVE-2026-55843 (composer)
- HIGH · CVSS 6.5 · 2026-08-28
- Affected:
snipe/snipe-it - https://github.com/advisories/GHSA-j5g3-42wp-gqm3
Snipe-IT has an Improper Privilege Management issue
GHSA-5v29-34h8-v68r · CVE-2026-55848 (maven)
- HIGH · CVSS 8.6 · 2026-08-28
- Affected:
org.mapfish.print:print-lib,org.mapfish:print.print-servlet,org.mapfish.print:print-lib - https://github.com/advisories/GHSA-5v29-34h8-v68r
MapFish Print has XXE that allows reading arbitrary files of certain types
GHSA-334q-h5g3-fpxv · CVE-2026-55784 (go)
- HIGH · CVSS 7.5 · 2026-08-28
- Affected:
github.com/free5gc/ausf - https://github.com/advisories/GHSA-334q-h5g3-fpxv
free5GC AUSF authentication contexts can be overwritten by concurrent requests for the same SUPI
GHSA-56wq-x3wv-3ff4 · CVE-2026-55874 (go)
- HIGH · CVSS 7.7 · 2026-08-28
- Affected:
github.com/seaweedfs/seaweedfs - https://github.com/advisories/GHSA-56wq-x3wv-3ff4
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
GHSA-gqr6-r77p-c2pj · CVE-2026-55841 (maven)
- HIGH · CVSS 7.5 · 2026-08-28
- Affected:
org.graylog2:graylog2-server,org.graylog2:graylog2-server,org.graylog2:graylog2-server - https://github.com/advisories/GHSA-gqr6-r77p-c2pj
Fortigate syslog message parser can be exploited to modify or delete fields from the original message
GHSA-mrpp-v6pg-p54x · CVE-2026-55764 (go)
- HIGH · 2026-08-28
- Affected:
github.com/klever-io/klever-go - https://github.com/advisories/GHSA-mrpp-v6pg-p54x
klever-go: SFT add-quantity int64 overflow bypasses a finite per-nonce MaxSupply
GHSA-x626-fcwx-f5pc · CVE-2026-55761 (go)
- HIGH · CVSS 5.9 · 2026-08-28
- Affected:
github.com/portainer/portainer,github.com/portainer/portainer - https://github.com/advisories/GHSA-x626-fcwx-f5pc
Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances
GHSA-v358-wf77-39xv · CVE-2026-55763 (go)
- HIGH · 2026-08-28
- Affected:
github.com/klever-io/klever-go - https://github.com/advisories/GHSA-v358-wf77-39xv
klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits
GHSA-hr6j-w4mw-g9mj · CVE-2026-55484 (go)
- HIGH · CVSS 7.5 · 2026-08-28
- Affected:
github.com/guno1928/alos-http - https://github.com/advisories/GHSA-hr6j-w4mw-g9mj
alos-http has unauthenticated remote DoS: malformed path starting with ”?” triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server
Ransomware Activity
36 new victim postings across 19 groups.
| Group | Victims | Sample |
|---|---|---|
qilin | 7 | Alter Consultores Legales, Newton County School System, DigiGround, Tramigo, Cos… |
global | 4 | Vigilia, Hangzhou Qihan Biotech Co., Ltd., Shanghai Tunnel Engineering Co Ltd, A… |
akira | 3 | Alumax, BEPeterson, JRT Mechanical |
shinyhunters | 3 | McKesson Corporation, Elekta AB, Jack Henry & Associates |
Doommageddon | 2 | SITTNAK Lojistik A.Ş., Akpera Gayrimenkul Yatırım A.Ş. |
chaos | 2 | corematerials.com, macallister.com |
iah6477 | 2 | swagelok, trc-companies |
rhysida | 2 | Valley Health Team, Berlin, Germany |
Orova | 1 | South Pacific Hotel Limited |
Panzer | 1 | Directorate-General for Education |
ShadowByt3$ | 1 | BayView Real Estate |
emperador | 1 | Hanwha Renewables |
incransom | 1 | Oilquip Inc |
lockbit5 | 1 | apatpa.com |
lynx | 1 | cutlercapital |
majinahanashi | 1 | MONTCAU |
moneymessage | 1 | ProCare |
payoutsking | 1 | H.W. Lochner |
unsafe | 1 | amzur.com |
IOC Volume
634 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 634 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Active Malware Families
16 malware families active this week (0 corroborated across ≥2 sources), exercising 17 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| Mirai | botnet | — | 1,065 | T1110, T1498, T1499, T1584.005 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 49 | T1219 |
| ClickFix | delivery → | — | 25 | T1059.001, T1204 |
| AgentTesla | stealer | — | 17 | T1056.001, T1071, T1114, T1555 |
| CoinMiner | miner | — | 11 | T1496 |
| Formbook | stealer | — | 8 | T1005, T1056.001, T1071, T1555 |
| PureLogsStealer | stealer | — | 7 | T1005, T1071, T1555 |
| XWorm | rat | — | 7 | T1056.001, T1071 |
| Stealc | stealer | — | 5 | T1005, T1071, T1555 |
| DDoSAgent | ddos | — | 4 | T1498, T1499 |
| ClearFake | delivery → | — | 2 | T1059.001, T1189, T1204 |
| GuLoader | loader → | — | 2 | T1027, T1071, T1105 |
| SilverFox | rat | — | 2 | T1059, T1071, T1219 |
| AsyncRAT | rat | — | 1 | T1056.001, T1059.001, T1071, T1219 |
| Lumma | stealer | — | 1 | T1005, T1071, T1555 |
| MassLogger | stealer | — | 1 | T1056.001, T1071, T1555 |
Families marked ”→” are delivery/social-engineering clusters (ClickFix, ClearFake, GuLoader). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
3 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
cryptovectorhub1.lol | domain | misp + urlhaus | 2026-08-29 |
hypercorevector4.lol | domain | misp + urlhaus | 2026-08-29 |
iploglab.store | domain | misp + urlhaus | 2026-08-29 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No recent SEC filings to cross-reference.
Intel Feeds
2 IOC feeds updated this run (2,922 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| URLhaus — Malware Distribution URLs | urlhaus | url | 2,761 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 161 | CSV · MISP · STIX |
Hand-Authored Sigma
10 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Host | experimental | https://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml |
| T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Process | experimental | https://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnet | experimental | https://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml |
| T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Container | experimental | https://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml |
| T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml |
| T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Path | experimental | https://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
17 of 155 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1562 | — | — | 0 | 3 |
T1573.001 | Symmetric Cryptography | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 7 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.