September 14, 2026 · Applied Cybernetics Group
Morning Brief — September 14, 2026
Morning Brief — 2026-09-14
5 material breach disclosures, 1 exploit probability movers, 10 emerging critical cves, 1 supply chain, 9 ransomware activity, 667 ioc volume, 15 active malware families, 1 multi-source iocs, 2 intel feeds, 18 hand-authored sigma, and 18 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
Nutex Health Inc. (NUTX)
- Filed: 2026-09-11 · CIK 0001479681 · Accession
0001628280-26-061432 - Filing: https://www.sec.gov/Archives/edgar/data/1479681/000162828026061432/materiality_assessmentxupd.htm
Forward-Looking StatementsCertain statements and information included in this press release constitute “forward-looking statements” within the meaning of the Private Securities Litigation Reform Act of 1995. When used in this press release, the words or phrases “will,” “will likely result,” “expected to,” “will continue,” “anticipated,” “estimate,” “projected,” “intend,” “goal,” or similar express…
BOSTON SCIENTIFIC CORP (BSX)
- Filed: 2026-09-08 · CIK 0000885725 · Accession
0000885725-26-000059 - Filing: https://www.sec.gov/Archives/edgar/data/885725/000088572526000059/bsx-20260907.htm
As previously disclosed in a Current Report on Form 8-K filed on August 26, 2026 with the Securities and Exchange Commission, on August 25, 2026, Boston Scientific Corporation (the “Company”) identified a cybersecurity incident that affected certain of its information technology systems and resulted in a global disruption to the Company’s operations. Upon detection, the Company activated its incid…
Park Dental Partners, Inc. (PARK)
- Filed: 2026-09-01 · CIK 0002069604 · Accession
0001104659-26-104300 - Filing: https://www.sec.gov/Archives/edgar/data/2069604/000110465926104300/park-20260828x8k.htm
On August 28, 2026, Park Dental Partners, Inc. (“we” or the “Company”) identified unauthorized access to its computer network. The Company promptly initiated its incident response protocols, and engaged its external cybersecurity and forensic specialists. The Company is continuing to investigate the nature and scope of this incident, including the scope of any compromise of personal or protected h…
NovoCure Ltd (NVCR)
- Filed: 2026-09-01 · CIK 0001645113 · Accession
0001645113-26-000065 - Filing: https://www.sec.gov/Archives/edgar/data/1645113/000164511326000065/nvcr-20260901.htm
Forward-Looking StatementsIn addition to historical facts or statements of current condition, this press release may contain forward-looking statements. Forward-looking statements provide Novocure’s current expectations or forecasts of future events. These may include statements regarding anticipated scientific progress on its research programs, clinical study progress, development of potential pr…
Nutex Health Inc. (NUTX)
- Filed: 2026-08-31 · CIK 0001479681 · Accession
0001628280-26-059602 - Filing: https://www.sec.gov/Archives/edgar/data/1479681/000162828026059602/nutx-20260831.htm
remediation of the incident. Readers are cautioned that these forward-looking statements are not guarantees of future events or outcomes and they should not be unduly relied on, as they are based on information available to the Company and on management’s current beliefs and expectations as of the date of this Current Report on Form 8-K and are therefore inherently uncertain and subject to risks,…
Federal Patching Priority
No new KEV additions in this window.
Exploit Probability Movers
| CVE | Today | Prev | Δ | In KEV |
|---|---|---|---|---|
CVE-2023-36757 | 0.369 | 0.686 | ▼ 0.317 |
Emerging Critical CVEs
CVE-2026-81648· CRITICAL (10.0) · 2026-09-13 — The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting ar…CVE-2026-90699· CRITICAL (9.9) · 2026-09-14 — A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack…CVE-2026-90693· CRITICAL (9.9) · 2026-09-14 — A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer overflow. Remote expl…CVE-2026-90692· CRITICAL (9.9) · 2026-09-14 — A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the component Dynamic DNS IPv6 Settings. The manipulation of the argument IPv6Address/Hostname results in stac…CVE-2026-90680· CRITICAL (9.9) · 2026-09-14 — A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAd…CVE-2026-90608· CRITICAL (9.9) · 2026-09-14 — A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buff…CVE-2026-90607· CRITICAL (9.9) · 2026-09-14 — A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results i…CVE-2026-90606· CRITICAL (9.9) · 2026-09-14 — A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument sta…CVE-2026-90605· CRITICAL (9.9) · 2026-09-14 — A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6ad…CVE-2026-82787· CRITICAL (9.8) · 2026-09-14 — Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.
Supply Chain
No high/critical GHSA advisories in the 24h window — exploitation-evidence hits below.
Exploitation evidence, 7-day window (severity-agnostic — evidence trumps labels):
GHSA-rcr6-4jqh-j84m(CVE-2026-60004, go) · 2026-09-08 — in CISA KEV · EPSS p99.7
Ransomware Activity
9 new victim postings across 5 groups.
| Group | Victims | Sample |
|---|---|---|
AuditTeam | 3 | Paid Victim F9CF4B639CAC1B18, Paid Victim FDC699DE3A112669, vi***in |
qilin | 3 | Alicotrans, Gilco Scaffolding, CARIDRO VAL DE LOIRE |
Panzer | 1 | Cerámicas Kantu |
emperador | 1 | Navitrans |
krybit | 1 | www.kashkha.com |
IOC Volume
667 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 667 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Active Malware Families
15 malware families active this week (0 corroborated across ≥2 sources), exercising 17 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| Mirai | botnet | — | 1,277 | T1110, T1498, T1499, T1584.005 |
| ClickFix | delivery → | — | 23 | T1059.001, T1204 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 22 | T1219 |
| AgentTesla | stealer | — | 18 | T1056.001, T1071, T1114, T1555 |
| ACRStealer | stealer | — | 9 | T1005, T1071, T1555 |
| CoinMiner | miner | — | 8 | T1496 |
| DDoSAgent | ddos | — | 6 | T1498, T1499 |
| Amadey | loader → | — | 5 | T1071, T1105, T1547 |
| Formbook | stealer | — | 4 | T1005, T1056.001, T1071, T1555 |
| GuLoader | loader → | — | 4 | T1027, T1071, T1105 |
| MassLogger | stealer | — | 4 | T1056.001, T1071, T1555 |
| PureLogsStealer | stealer | — | 4 | T1005, T1071, T1555 |
| Stealc | stealer | — | 4 | T1005, T1071, T1555 |
| SilverFox | rat | — | 2 | T1059, T1071, T1219 |
| XWorm | rat | — | 1 | T1056.001, T1071 |
Families marked ”→” are delivery/social-engineering clusters (ClickFix, Amadey, GuLoader). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
1 IOC flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
38.55.99.215 | ip-src | misp + urlhaus | 2026-09-14 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No SEC × KEV vendor token matches in this window. (This is a heuristic surface, absence is expected most days.)
Intel Feeds
2 IOC feeds updated this run (3,075 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| URLhaus — Malware Distribution URLs | urlhaus | url | 2,982 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 93 | CSV · MISP · STIX |
Hand-Authored Sigma
16 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Host | experimental | https://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml |
| T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Process | experimental | https://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1098.005 Okta Verify Enrollment from a Hypervisor Guest | experimental | https://thrunt.me/sigma/t1098-005-hypervisor-mfa-device-enrollment.yml |
| T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnet | experimental | https://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml |
| T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Container | experimental | https://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml |
| T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml |
| T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml |
| T1557 Okta Authentication or MFA via a Remote-Desktop / Proxy / Tor Tunnel | experimental | https://thrunt.me/sigma/t1557-aitm-cross-asn-session-mfa.yml |
| T1557 Claims Kit First-Party Exfil — X-Enc Single-Letter C2 | experimental | https://thrunt.me/sigma/t1557-claims-kit-single-letter-c2-xenc.yml |
| T1557 Okta Verify SVG Asset Served by a Non-Okta Host | experimental | https://thrunt.me/sigma/t1557-non-okta-host-oktaverify-svg.yml |
| T1557 reCAPTCHA-Skinned Cloudflare Turnstile Gate | experimental | https://thrunt.me/sigma/t1557-recaptcha-skinned-turnstile-gate.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Path | experimental | https://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml |
| T1583.001 Resolution of a ShinyHunters .claims Impersonation Domain | experimental | https://thrunt.me/sigma/t1583-001-claims-registration-conjunction.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
18 of 158 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1573.001 | Symmetric Cryptography | — | 1 | 3 |
T1562 | — | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 8 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.