September 5, 2026 · Applied Cybernetics Group
Morning Brief — September 5, 2026
Morning Brief — 2026-09-05
3 material breach disclosures, 1 federal patching priority, 1 exploit probability movers, 10 emerging critical cves, 10 supply chain, 20 ransomware activity, 455 ioc volume, 17 active malware families, 2 intel feeds, 12 hand-authored sigma, and 18 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
Park Dental Partners, Inc. (PARK)
- Filed: 2026-09-01 · CIK 0002069604 · Accession
0001104659-26-104300 - Filing: https://www.sec.gov/Archives/edgar/data/2069604/000110465926104300/park-20260828x8k.htm
On August 28, 2026, Park Dental Partners, Inc. (“we” or the “Company”) identified unauthorized access to its computer network. The Company promptly initiated its incident response protocols, and engaged its external cybersecurity and forensic specialists. The Company is continuing to investigate the nature and scope of this incident, including the scope of any compromise of personal or protected h…
NovoCure Ltd (NVCR)
- Filed: 2026-09-01 · CIK 0001645113 · Accession
0001645113-26-000065 - Filing: https://www.sec.gov/Archives/edgar/data/1645113/000164511326000065/nvcr-20260901.htm
Forward-Looking StatementsIn addition to historical facts or statements of current condition, this press release may contain forward-looking statements. Forward-looking statements provide Novocure’s current expectations or forecasts of future events. These may include statements regarding anticipated scientific progress on its research programs, clinical study progress, development of potential pr…
Nutex Health Inc. (NUTX)
- Filed: 2026-08-31 · CIK 0001479681 · Accession
0001628280-26-059602 - Filing: https://www.sec.gov/Archives/edgar/data/1479681/000162828026059602/nutx-20260831.htm
remediation of the incident. Readers are cautioned that these forward-looking statements are not guarantees of future events or outcomes and they should not be unduly relied on, as they are based on information available to the Company and on management’s current beliefs and expectations as of the date of this Current Report on Form 8-K and are therefore inherently uncertain and subject to risks,…
Federal Patching Priority
CVE-2026-85046 — Google Chromium V8
Google Chromium V8 Type Confusion Vulnerability
- Added: 2026-09-04 · Federal due: 2026-09-18 · EPSS 38.4th pct (score 0.005) · CVSS 8.8 (HIGH) · CWE-843
- ransomware use: Unknown
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Exploit Probability Movers
| CVE | Today | Prev | Δ | In KEV |
|---|---|---|---|---|
CVE-2026-48710 | 0.363 | 0.110 | ▲ 0.252 | ✓ |
Emerging Critical CVEs
CVE-2024-11080· CRITICAL (9.8) · 2026-09-05 — The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file…CVE-2026-83627· CRITICAL (9.8) · 2026-09-05 — The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/cl…CVE-2026-13447· CRITICAL (9.8) · 2026-09-05 — The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelp…CVE-2026-75430· CRITICAL (9.8) · 2026-09-04 — PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.CVE-2026-31020· CRITICAL (9.8) · 2026-09-04 — In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja…CVE-2026-44402· CRITICAL (9.8) · 2026-09-04 — Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading…CVE-2026-18658· CRITICAL (9.8) · 2026-09-04 — IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database…CVE-2026-85696· CRITICAL (9.8) · 2026-09-04 — SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with she…CVE-2026-85688· CRITICAL (9.8) · 2026-09-04 — TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-conten…CVE-2026-85672· CRITICAL (9.8) · 2026-09-04 — zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler…
Supply Chain
GHSA-7q9c-hpx7-9cwm (npm)
- HIGH · CVSS 7.5 · 2026-09-04
- Affected:
@typespec/spector - https://github.com/advisories/GHSA-7q9c-hpx7-9cwm
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
GHSA-rh53-xvx2-j327 · CVE-2026-73842 (go)
- CRITICAL · CVSS 9.0 · 2026-09-04
- Affected:
github.com/openchoreo/openchoreo,github.com/openchoreo/openchoreo,github.com/openchoreo/openchoreo - https://github.com/advisories/GHSA-rh53-xvx2-j327
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
GHSA-h4v5-crx2-3cv4 · CVE-2026-72793 (go)
- HIGH · CVSS 8.6 · 2026-09-04
- Affected:
github.com/siyuan-note/siyuan/kernel - https://github.com/advisories/GHSA-h4v5-crx2-3cv4
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
GHSA-h6w7-xxcf-w2mq · CVE-2026-72795 (go)
- HIGH · CVSS 8.6 · 2026-09-04
- Affected:
github.com/siyuan-note/siyuan/kernel - https://github.com/advisories/GHSA-h6w7-xxcf-w2mq
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
GHSA-34fj-mwm6-fjfg · CVE-2026-72794 (go)
- HIGH · CVSS 8.6 · 2026-09-04
- Affected:
github.com/siyuan-note/siyuan/kernel - https://github.com/advisories/GHSA-34fj-mwm6-fjfg
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
GHSA-mfrj-v65r-979c · CVE-2026-72798 (go)
- HIGH · CVSS 8.6 · 2026-09-04
- Affected:
github.com/siyuan-note/siyuan/kernel - https://github.com/advisories/GHSA-mfrj-v65r-979c
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
GHSA-848m-r628-vrxw · CVE-2026-63735 (rust)
- HIGH · CVSS 8.1 · 2026-09-04
- Affected:
surrealdb - https://github.com/advisories/GHSA-848m-r628-vrxw
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
GHSA-gx45-xrj5-g6c4 · CVE-2026-75911 (rust)
- HIGH · CVSS 7.8 · 2026-09-04
- Affected:
deepseek-tui,deepseek-tui,codewhale-tui - https://github.com/advisories/GHSA-gx45-xrj5-g6c4
CodeWhale: Project config allow_shell override enables arbitrary shell command execution via cloned repository
GHSA-wrj3-vj8c-784f · CVE-2026-75858 (rust)
- HIGH · CVSS 7.8 · 2026-09-04
- Affected:
deepseek-tui,deepseek-tui,codewhale-tui - https://github.com/advisories/GHSA-wrj3-vj8c-784f
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user’s approval policy (RCE)
GHSA-c6mw-8xh8-gpq6 · CVE-2026-75912 (rust)
- HIGH · CVSS 7.4 · 2026-09-04
- Affected:
deepseek-tui,deepseek-tui,codewhale-tui - https://github.com/advisories/GHSA-c6mw-8xh8-gpq6
CodeWhale: Argument Injection in git_blame Tool Allows Arbitrary File Read Without Approval
Ransomware Activity
20 new victim postings across 12 groups.
| Group | Victims | Sample |
|---|---|---|
Vexy Ransomware | 3 | Palsana Enviro (PEPL), Annapurna Fashion, Sancity Soft Touch |
lockbit5 | 3 | pscindustries.com, kalahealth.eu, huisartsencentrumkleiniterson.nl |
akira | 2 | Stransky Heiz-Mess-Regeltechnik GmbH, Worrell |
pear | 2 | EdgeChem Jamaica Limited, Kovo Healthtech Corp |
qilin | 2 | AP CAPITAL PARTNERS LIMITED, Commission de la construction du Quebec (CCQ) |
spacebears | 2 | D-MAX Engineering, Inc, Sports Endeavors |
BlackLocks | 1 | 광명산업(주) |
DYSPHOR1A | 1 | MBT Telecom |
SilentRansomGroup | 1 | H… C… |
direwolf | 1 | Wolfram Research |
emperador | 1 | Judicial Branch of the Province of Jujuy |
tridentlocker | 1 | SouthernCarlson |
IOC Volume
455 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 455 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Active Malware Families
17 malware families active this week (0 corroborated across ≥2 sources), exercising 19 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| Mirai | botnet | — | 1,308 | T1110, T1498, T1499, T1584.005 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 50 | T1219 |
| DDoSAgent | ddos | — | 10 | T1498, T1499 |
| PureLogsStealer | stealer | — | 9 | T1005, T1071, T1555 |
| CoinMiner | miner | — | 8 | T1496 |
| AgentTesla | stealer | — | 7 | T1056.001, T1071, T1114, T1555 |
| AsyncRAT | rat | — | 7 | T1056.001, T1059.001, T1071, T1219 |
| ClickFix | delivery → | — | 7 | T1059.001, T1204 |
| AMOS (Atomic macOS Stealer) | stealer | — | 5 | T1005, T1056.002, T1071, T1555.001 |
| Phorpiex | botnet | — | 4 | T1071, T1486, T1566 |
| SilverFox | rat | — | 4 | T1059, T1071, T1219 |
| DCRat | rat | — | 2 | T1056.001, T1059.001, T1071, T1219 |
| NetSupport Manager (abuse) | rmm-abuse | — | 2 | T1219 |
| Stealc | stealer | — | 2 | T1005, T1071, T1555 |
| Vidar | stealer | — | 2 | T1005, T1071, T1555 |
| QuasarRAT | rat | — | 1 | T1056.001, T1059.001, T1071, T1219 |
| Remcos | rat | — | 1 | T1056.001, T1071, T1113 |
Families marked ”→” are delivery/social-engineering clusters (ClickFix). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
No IOCs corroborated across multiple sources in this window. Each feed reported uniquely.
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No SEC × KEV vendor token matches in this window. (This is a heuristic surface, absence is expected most days.)
Intel Feeds
2 IOC feeds updated this run (3,036 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| URLhaus — Malware Distribution URLs | urlhaus | url | 2,964 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 72 | CSV · MISP · STIX |
Hand-Authored Sigma
10 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Host | experimental | https://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml |
| T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Process | experimental | https://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnet | experimental | https://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml |
| T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Container | experimental | https://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml |
| T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml |
| T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Path | experimental | https://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
18 of 161 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1573.001 | Symmetric Cryptography | — | 1 | 3 |
T1562 | — | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 8 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.