September 15, 2026 · Applied Cybernetics Group
Morning Brief — September 15, 2026
Morning Brief — 2026-09-15
4 material breach disclosures, 1 federal patching priority, 10 emerging critical cves, 3 supply chain, 55 ransomware activity, 794 ioc volume, 16 active malware families, 1 multi-source iocs, 2 intel feeds, 18 hand-authored sigma, and 18 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
Nutex Health Inc. (NUTX)
- Filed: 2026-09-11 · CIK 0001479681 · Accession
0001628280-26-061432 - Filing: https://www.sec.gov/Archives/edgar/data/1479681/000162828026061432/materiality_assessmentxupd.htm
Forward-Looking StatementsCertain statements and information included in this press release constitute “forward-looking statements” within the meaning of the Private Securities Litigation Reform Act of 1995. When used in this press release, the words or phrases “will,” “will likely result,” “expected to,” “will continue,” “anticipated,” “estimate,” “projected,” “intend,” “goal,” or similar express…
BOSTON SCIENTIFIC CORP (BSX)
- Filed: 2026-09-08 · CIK 0000885725 · Accession
0000885725-26-000059 - Filing: https://www.sec.gov/Archives/edgar/data/885725/000088572526000059/bsx-20260907.htm
As previously disclosed in a Current Report on Form 8-K filed on August 26, 2026 with the Securities and Exchange Commission, on August 25, 2026, Boston Scientific Corporation (the “Company”) identified a cybersecurity incident that affected certain of its information technology systems and resulted in a global disruption to the Company’s operations. Upon detection, the Company activated its incid…
Park Dental Partners, Inc. (PARK)
- Filed: 2026-09-01 · CIK 0002069604 · Accession
0001104659-26-104300 - Filing: https://www.sec.gov/Archives/edgar/data/2069604/000110465926104300/park-20260828x8k.htm
On August 28, 2026, Park Dental Partners, Inc. (“we” or the “Company”) identified unauthorized access to its computer network. The Company promptly initiated its incident response protocols, and engaged its external cybersecurity and forensic specialists. The Company is continuing to investigate the nature and scope of this incident, including the scope of any compromise of personal or protected h…
NovoCure Ltd (NVCR)
- Filed: 2026-09-01 · CIK 0001645113 · Accession
0001645113-26-000065 - Filing: https://www.sec.gov/Archives/edgar/data/1645113/000164511326000065/nvcr-20260901.htm
Forward-Looking StatementsIn addition to historical facts or statements of current condition, this press release may contain forward-looking statements. Forward-looking statements provide Novocure’s current expectations or forecasts of future events. These may include statements regarding anticipated scientific progress on its research programs, clinical study progress, development of potential pr…
Federal Patching Priority
CVE-2026-76461 — Cisco Secure Email Gateway
Cisco Secure Email Gateway SQL Injection Vulnerability
- Added: 2026-09-14 · Federal due: 2026-09-17 · CVSS 9.8 (CRITICAL) · CWE-89
- ransomware use: Unknown
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that…
Exploit Probability Movers
No CVEs with ≥0.20 EPSS movement in this window.
Emerging Critical CVEs
CVE-2026-91001· CRITICAL (9.9) · 2026-09-15 — A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/…CVE-2026-16338· CRITICAL (9.9) · 2026-09-14 — IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbitrary file write due to improper validation of file paths.CVE-2026-90937· CRITICAL (9.9) · 2026-09-14 — froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs conta…CVE-2026-65414· CRITICAL (9.8) · 2026-09-14 — An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, vision…CVE-2026-55209· CRITICAL (9.8) · 2026-09-14 — resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata insufficiently validates numeric fields, grid dimensions, keyword sizes, and array indexes while pars…CVE-2026-54334· CRITICAL (9.8) · 2026-09-14 — UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number from GetBits(Sd,…CVE-2026-54333· CRITICAL (9.8) · 2026-09-14 — UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not validate that bit-l…CVE-2026-59178· CRITICAL (9.8) · 2026-09-14 — ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from$ESPHOME_USERNAMEand$ESPHOME_PASSWORD. Earl…CVE-2026-90945· CRITICAL (9.8) · 2026-09-14 — Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to acc…CVE-2026-76443· CRITICAL (9.8) · 2026-09-14 — As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security revi…
Supply Chain
GHSA-vrh8-c9cm-wh8v · CVE-2026-56668 (go)
- HIGH · CVSS 8.1 · 2026-09-14
- Affected:
github.com/zitadel/zitadel - https://github.com/advisories/GHSA-vrh8-c9cm-wh8v
ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange
GHSA-rrxg-g2pf-6hh4 · CVE-2026-59178 (pip)
- CRITICAL · CVSS 9.8 · 2026-09-14
- Affected:
esphome-device-builder - https://github.com/advisories/GHSA-rrxg-g2pf-6hh4
ESPHome Device Builder: Renamed auth env vars silently disable dashboard authentication on upgrade
Exploitation evidence, 7-day window (severity-agnostic — evidence trumps labels):
GHSA-rcr6-4jqh-j84m(CVE-2026-60004, go) · 2026-09-08 — in CISA KEV · EPSS p99.7
Ransomware Activity
55 new victim postings across 14 groups.
| Group | Victims | Sample |
|---|---|---|
thegentlemen | 30 | ACA Pescara, Hattiesburg Eye Clinic, Indic, Aurora Technologies, Goteborgsregion… |
qilin | 6 | Geieg, Foremost Mfg, Winston Contracting, LLC, RoadEx America, Minmer Global, Vi… |
lockbit5 | 3 | tpi.tw, comune.robeccosulnaviglio.mi.it, httoy.fi |
Booba Project | 2 | Mestechkin Law Group P.C., Atlas Ocean Voyages |
Eclipse | 2 | Dublin City Schools GA, Rosello et Fils |
chaos | 2 | glasfloss.com, steelhausinc.com |
genesis | 2 | Bernath & Rosenberg, Dorfman Abrams Music, P.C |
insomnia | 2 | Metropolitan Community Health Services, Massey, Stotser & Nichols |
AuditTeam | 1 | Ne***ox |
Panzer | 1 | Honda (Peru) |
ShadowByt3$ | 1 | HandyTrac (Greystar Litchfield Park, AZ) |
anubis | 1 | Better Accounting Solutions |
iah6477 | 1 | veritiv |
unsafe | 1 | geekybunch.com |
IOC Volume
794 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 794 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Active Malware Families
16 malware families active this week (0 corroborated across ≥2 sources), exercising 19 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| Mirai | botnet | — | 1,301 | T1110, T1498, T1499, T1584.005 |
| ClickFix | delivery → | — | 29 | T1059.001, T1204 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 26 | T1219 |
| AgentTesla | stealer | — | 24 | T1056.001, T1071, T1114, T1555 |
| ACRStealer | stealer | — | 12 | T1005, T1071, T1555 |
| CoinMiner | miner | — | 10 | T1496 |
| AMOS (Atomic macOS Stealer) | stealer | — | 8 | T1005, T1056.002, T1071, T1555.001 |
| DDoSAgent | ddos | — | 6 | T1498, T1499 |
| MassLogger | stealer | — | 6 | T1056.001, T1071, T1555 |
| Amadey | loader → | — | 5 | T1071, T1105, T1547 |
| GuLoader | loader → | — | 4 | T1027, T1071, T1105 |
| Stealc | stealer | — | 4 | T1005, T1071, T1555 |
| Formbook | stealer | — | 3 | T1005, T1056.001, T1071, T1555 |
| SilverFox | rat | — | 2 | T1059, T1071, T1219 |
| PureLogsStealer | stealer | — | 1 | T1005, T1071, T1555 |
| XWorm | rat | — | 1 | T1056.001, T1071 |
Families marked ”→” are delivery/social-engineering clusters (ClickFix, Amadey, GuLoader). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
1 IOC flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
38.55.99.215 | ip-src | misp + urlhaus | 2026-09-15 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No SEC × KEV vendor token matches in this window. (This is a heuristic surface, absence is expected most days.)
Intel Feeds
2 IOC feeds updated this run (3,135 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| URLhaus — Malware Distribution URLs | urlhaus | url | 3,016 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 119 | CSV · MISP · STIX |
Hand-Authored Sigma
16 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Host | experimental | https://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml |
| T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Process | experimental | https://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1098.005 Okta Verify Enrollment from a Hypervisor Guest | experimental | https://thrunt.me/sigma/t1098-005-hypervisor-mfa-device-enrollment.yml |
| T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnet | experimental | https://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml |
| T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Container | experimental | https://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml |
| T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml |
| T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml |
| T1557 Okta Authentication or MFA via a Remote-Desktop / Proxy / Tor Tunnel | experimental | https://thrunt.me/sigma/t1557-aitm-cross-asn-session-mfa.yml |
| T1557 Claims Kit First-Party Exfil — X-Enc Single-Letter C2 | experimental | https://thrunt.me/sigma/t1557-claims-kit-single-letter-c2-xenc.yml |
| T1557 Okta Verify SVG Asset Served by a Non-Okta Host | experimental | https://thrunt.me/sigma/t1557-non-okta-host-oktaverify-svg.yml |
| T1557 reCAPTCHA-Skinned Cloudflare Turnstile Gate | experimental | https://thrunt.me/sigma/t1557-recaptcha-skinned-turnstile-gate.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Path | experimental | https://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml |
| T1583.001 Resolution of a ShinyHunters .claims Impersonation Domain | experimental | https://thrunt.me/sigma/t1583-001-claims-registration-conjunction.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
18 of 160 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1573.001 | Symmetric Cryptography | — | 1 | 3 |
T1562 | — | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 8 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.