September 1, 2026 · Applied Cybernetics Group
Morning Brief — September 1, 2026
Morning Brief — 2026-09-01
1 material breach disclosures, 2 federal patching priority, 10 emerging critical cves, 4 supply chain, 67 ransomware activity, 522 ioc volume, 19 active malware families, 3 multi-source iocs, 2 intel feeds, 12 hand-authored sigma, and 18 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
Nutex Health Inc. (NUTX)
- Filed: 2026-08-31 · CIK 0001479681 · Accession
0001628280-26-059602 - Filing: https://www.sec.gov/Archives/edgar/data/1479681/000162828026059602/nutx-20260831.htm
remediation of the incident. Readers are cautioned that these forward-looking statements are not guarantees of future events or outcomes and they should not be unduly relied on, as they are based on information available to the Company and on management’s current beliefs and expectations as of the date of this Current Report on Form 8-K and are therefore inherently uncertain and subject to risks,…
Federal Patching Priority
CVE-2026-82078 — PaperCut NG/MF
PaperCut NG/MF Unsafe Reflection Vulnerability
- Added: 2026-08-31 · Federal due: 2026-09-14 · EPSS 38.3th pct (score 0.005) · CVSS 9.1 (CRITICAL) · CWE-470
- ransomware use: Unknown
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on…
CVE-2026-81578 — PaperCut NG/MF
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
- Added: 2026-08-31 · Federal due: 2026-09-14 · EPSS 32.4th pct (score 0.004) · CVSS 9.8 (CRITICAL) · CWE-305
- ransomware use: Unknown
PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
Exploit Probability Movers
No CVEs with ≥0.20 EPSS movement in this window.
Emerging Critical CVEs
CVE-2026-82971· CRITICAL (10.0) · 2026-08-31 — A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command i…CVE-2026-81780· CRITICAL (10.0) · 2026-08-31 — Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.CVE-2026-81779· CRITICAL (10.0) · 2026-08-31 — Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted.
This issue affects Newspapers X: from 1.0.46 through 1.0.48.
CVE-2026-82970· CRITICAL (10.0) · 2026-08-31 — Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files.
This issue affects WP Cookie Notice for GDPR, CCPA & ePriv…
CVE-2026-82695· CRITICAL (10.0) · 2026-08-31 — A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack ca…CVE-2026-82694· CRITICAL (10.0) · 2026-08-31 — A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The att…CVE-2026-82693· CRITICAL (10.0) · 2026-08-31 — A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authenticat…CVE-2026-83772· CRITICAL (9.9) · 2026-09-01 — A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipula…CVE-2026-83524· CRITICAL (9.9) · 2026-08-31 — A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component Sy…CVE-2026-82954· CRITICAL (9.9) · 2026-08-31 — A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of t…
Supply Chain
GHSA-67mx-6wf2-92xp · CVE-2026-71415 (composer)
- HIGH · 2026-08-31
- Affected:
getkirby/cms - https://github.com/advisories/GHSA-67mx-6wf2-92xp
Kirby: File upload permissions are not checked during processing of chunk data
GHSA-9vx2-j98c-p72w · CVE-2026-75594 (composer)
- HIGH · 2026-08-31
- Affected:
getkirby/cms,getkirby/cms - https://github.com/advisories/GHSA-9vx2-j98c-p72w
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
GHSA-gr94-w7qr-f4j3 · CVE-2026-59724 (npm)
- HIGH · CVSS 7.5 · 2026-08-31
- Affected:
engine.io - https://github.com/advisories/GHSA-gr94-w7qr-f4j3
Socket.IO: Engine.IO WebTransport SID DoS
GHSA-8x3q-jpjh-qh5c · CVE-2026-81889 (composer)
- HIGH · CVSS 8.6 · 2026-08-31
- Affected:
studio-42/elfinder - https://github.com/advisories/GHSA-8x3q-jpjh-qh5c
elFinder: SSRF protection bypass via DNS rebinding in the fsock_get_contents() fallback
Ransomware Activity
67 new victim postings across 21 groups.
| Group | Victims | Sample |
|---|---|---|
krybit | 14 | seashellhospital.com, uicc.org, tum.com.mx, www.alphaplantes.com, reignwoodpark.… |
BrainCipher | 8 | icot.es, aeiconsultants.com, syc.es, Adviesbureau De Beuckelaer BV, ahadandco.co… |
settra | 8 | manhattanloft.co.uk, zonarsystems.com, diversifiedbodyandpaint.com, howardlumber… |
incransom | 5 | New Century Ophthalmology Group, zummocorp.com, www.lichtvision.com, www.renoref… |
play | 4 | MEQ, Figgins Family Wine Estates, KRC Machine Tool Solutions, Meteor Group |
ZaWoo | 3 | zenithtechnology.co.nz, fes-sport.de, esopartnerscpa.com |
akira | 3 | KFZ-MEISTERBETRIEB JOST GmbH, Gale Credit Union, WEMS |
everest | 3 | Rise UP, VIVOTEK, Italtel Peru |
qilin | 3 | Commission de la construction du Quebec, Inmac, Allied Recycling |
Orova | 2 | ASYS Corporation, Fu Sheng Industrial Co., Ltd |
lockbit5 | 2 | svfcu.org, hoaattorneys.com |
nightspire | 2 | Easyoga, Truckworx |
thegentlemen | 2 | EP Manufacturing Bhd, Saudi Consulting Services SAUD CONSULT |
Falcon | 1 | Hayward Holdings |
Global Secret Group | 1 | R L Fine Chem Pvt. Ltd. |
Wallstreet | 1 | Cedar County Memorial Hospital |
aurora | 1 | Ishbia & Gagleard, P.C. |
insomnia | 1 | Metro Tulsa Foot |
interlock | 1 | Super Systems Inc |
majinahanashi | 1 | TERRACOM & MONTCAU |
medusalocker | 1 | Lawter |
IOC Volume
522 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 522 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Active Malware Families
19 malware families active this week (0 corroborated across ≥2 sources), exercising 21 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| Mirai | botnet | — | 1,368 | T1110, T1498, T1499, T1584.005 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 48 | T1219 |
| AgentTesla | stealer | — | 25 | T1056.001, T1071, T1114, T1555 |
| ClickFix | delivery → | — | 21 | T1059.001, T1204 |
| CoinMiner | miner | — | 12 | T1496 |
| PureLogsStealer | stealer | — | 11 | T1005, T1071, T1555 |
| Formbook | stealer | — | 8 | T1005, T1056.001, T1071, T1555 |
| XWorm | rat | — | 7 | T1056.001, T1071 |
| AsyncRAT | rat | — | 6 | T1056.001, T1059.001, T1071, T1219 |
| SilverFox | rat | — | 6 | T1059, T1071, T1219 |
| AMOS (Atomic macOS Stealer) | stealer | — | 5 | T1005, T1056.002, T1071, T1555.001 |
| Stealc | stealer | — | 5 | T1005, T1071, T1555 |
| DDoSAgent | ddos | — | 4 | T1498, T1499 |
| ClearFake | delivery → | — | 2 | T1059.001, T1189, T1204 |
| GuLoader | loader → | — | 2 | T1027, T1071, T1105 |
| NetSupport Manager (abuse) | rmm-abuse | — | 2 | T1219 |
| Phorpiex | botnet | — | 2 | T1071, T1486, T1566 |
| Lumma | stealer | — | 1 | T1005, T1071, T1555 |
| MassLogger | stealer | — | 1 | T1056.001, T1071, T1555 |
Families marked ”→” are delivery/social-engineering clusters (ClickFix, ClearFake, GuLoader). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
3 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
cryptovectorhub1.lol | domain | misp + urlhaus | 2026-09-01 |
hypercorevector4.lol | domain | misp + urlhaus | 2026-09-01 |
iploglab.store | domain | misp + urlhaus | 2026-09-01 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No SEC × KEV vendor token matches in this window. (This is a heuristic surface, absence is expected most days.)
Intel Feeds
2 IOC feeds updated this run (2,905 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| URLhaus — Malware Distribution URLs | urlhaus | url | 2,783 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 122 | CSV · MISP · STIX |
Hand-Authored Sigma
10 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Host | experimental | https://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml |
| T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Process | experimental | https://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnet | experimental | https://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml |
| T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Container | experimental | https://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml |
| T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml |
| T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Path | experimental | https://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
18 of 160 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1573.001 | Symmetric Cryptography | — | 1 | 3 |
T1562 | — | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 8 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.