September 16, 2026 · Applied Cybernetics Group
Morning Brief — September 16, 2026
Morning Brief — 2026-09-16
2 material breach disclosures, 10 emerging critical cves, 10 supply chain, 32 ransomware activity, 696 ioc volume, 16 active malware families, 3 multi-source iocs, 2 intel feeds, 18 hand-authored sigma, and 18 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
Nutex Health Inc. (NUTX)
- Filed: 2026-09-11 · CIK 0001479681 · Accession
0001628280-26-061432 - Filing: https://www.sec.gov/Archives/edgar/data/1479681/000162828026061432/materiality_assessmentxupd.htm
Forward-Looking StatementsCertain statements and information included in this press release constitute “forward-looking statements” within the meaning of the Private Securities Litigation Reform Act of 1995. When used in this press release, the words or phrases “will,” “will likely result,” “expected to,” “will continue,” “anticipated,” “estimate,” “projected,” “intend,” “goal,” or similar express…
BOSTON SCIENTIFIC CORP (BSX)
- Filed: 2026-09-08 · CIK 0000885725 · Accession
0000885725-26-000059 - Filing: https://www.sec.gov/Archives/edgar/data/885725/000088572526000059/bsx-20260907.htm
As previously disclosed in a Current Report on Form 8-K filed on August 26, 2026 with the Securities and Exchange Commission, on August 25, 2026, Boston Scientific Corporation (the “Company”) identified a cybersecurity incident that affected certain of its information technology systems and resulted in a global disruption to the Company’s operations. Upon detection, the Company activated its incid…
Federal Patching Priority
No new KEV additions in this window.
Exploit Probability Movers
No CVEs with ≥0.20 EPSS movement in this window.
Emerging Critical CVEs
CVE-2026-87230· CRITICAL (10.0) · 2026-09-15 — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticat…CVE-2026-83099· CRITICAL (10.0) · 2026-09-15 — Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability al…CVE-2026-83059· CRITICAL (10.0) · 2026-09-15 — Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allo…CVE-2026-83021· CRITICAL (10.0) · 2026-09-15 — Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerabili…CVE-2026-83020· CRITICAL (10.0) · 2026-09-15 — Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitabl…CVE-2026-71133· CRITICAL (10.0) · 2026-09-15 — Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability al…CVE-2026-53710· CRITICAL (10.0) · 2026-09-15 — MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py…CVE-2026-59971· CRITICAL (10.0) · 2026-09-15 — MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport wi…CVE-2026-87172· CRITICAL (9.9) · 2026-09-15 — Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privilege…CVE-2026-83282· CRITICAL (9.9) · 2026-09-15 — Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability al…
Supply Chain
GHSA-2h44-8472-frjj · CVE-2026-61559 (npm)
- CRITICAL · CVSS 9.6 · 2026-09-15
- Affected:
@zereight/mcp-gitlab - https://github.com/advisories/GHSA-2h44-8472-frjj
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
GHSA-vmp7-252j-cwp7 · CVE-2026-61568 (npm)
- CRITICAL · CVSS 9.6 · 2026-09-15
- Affected:
@zereight/mcp-gitlab - https://github.com/advisories/GHSA-vmp7-252j-cwp7
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
GHSA-5648-rgj9-v224 (npm)
- HIGH · CVSS 8.1 · 2026-09-15
- Affected:
@zereight/mcp-gitlab - https://github.com/advisories/GHSA-5648-rgj9-v224
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
GHSA-4595-rvpx-4q34 · CVE-2026-61554 (go)
- HIGH · CVSS 7.5 · 2026-09-15
- Affected:
github.com/jm33-m0/emp3r0r/core - https://github.com/advisories/GHSA-4595-rvpx-4q34
emp3r0r has an unauthenticated HTTP Polling DoS
GHSA-gq9p-f254-h286 · CVE-2026-88975 (maven)
- HIGH · CVSS 7.5 · 2026-09-15
- Affected:
org.http4s:http4s-ember-core_2.13,org.http4s:http4s-ember-core_2.12,org.http4s:http4s-ember-core_3 - https://github.com/advisories/GHSA-gq9p-f254-h286
Http4s: Ember HTTP/2 buffers a frame’s declared payload before checking SETTINGS_MAX_FRAME_SIZE
GHSA-5hq8-qhww-jm7q · CVE-2026-61544 (rust)
- HIGH · 2026-09-15
- Affected:
libp2p-quic - https://github.com/advisories/GHSA-5hq8-qhww-jm7q
libp2p-quic: Remote panic via certificate expiry race during QUIC handshake
GHSA-cp4q-fqw9-4hf6 · CVE-2026-69218 (maven)
- HIGH · CVSS 7.5 · 2026-09-15
- Affected:
org.http4s:http4s-ember-core_2.12,org.http4s:http4s-ember-core_2.13,org.http4s:http4s-ember-core_3 - https://github.com/advisories/GHSA-cp4q-fqw9-4hf6
Http4s Ember HTTP/2: unbounded continuation frame accumulation
GHSA-8f3q-3jmv-7prw · CVE-2026-69213 (maven)
- HIGH · CVSS 7.5 · 2026-09-15
- Affected:
org.http4s:http4s-ember-core_2.12,org.http4s:http4s-ember-core_2.13,org.http4s:http4s-ember-core_3 - https://github.com/advisories/GHSA-8f3q-3jmv-7prw
Http4s Ember HTTP/2 has an unbounded outbound frame queue
GHSA-fm4g-76c9-7w69 · CVE-2026-69208 (maven)
- HIGH · CVSS 7.5 · 2026-09-15
- Affected:
org.http4s:http4s-ember-server_2.12,org.http4s:http4s-ember-server_2.13,org.http4s:http4s-ember-server_3 - https://github.com/advisories/GHSA-fm4g-76c9-7w69
Http4s: DigestAuth nonce map grows unbounded
GHSA-9998-894r-fwvr · CVE-2026-69205 (maven)
- HIGH · CVSS 8.7 · 2026-09-15
- Affected:
org.http4s:http4s-ember-core_3,org.http4s:http4s-ember-core_2.13,org.http4s:http4s-ember-core_2.12 - https://github.com/advisories/GHSA-9998-894r-fwvr
Http4s Ember Transfer-Encoding value parsing (TE.CL / TE.0 request smuggling)
Ransomware Activity
32 new victim postings across 11 groups.
| Group | Victims | Sample |
|---|---|---|
safepay | 9 | marlinhvac.com, neumerkel-gmbh.de, triniticaring.org, laconcepcion.com.mx, meter… |
qilin | 7 | Aarsleff, Taurus Ibérica, Montana Civil Contractors, Resolve Law Group, ADM, Inc… |
Storm | 3 | McCarthy Tire Service, PANTHERx Rare, Insight Credit Union |
akira | 3 | Pilot Precision, Lazyboyz, Southern California Telephone Company |
dragonforce | 2 | Community Property Management, Owen Leigh Optometry |
interlock | 2 | Springfield Public Schools, City of Fort Smith Arkansas |
metaencryptor | 2 | SFA Engineering Corporation, Nippon Steel Corporation |
Dark Project | 1 | Cumar Marble & Granite |
Vexy Ransomware | 1 | Hashimoto Jimuki |
arcusmedia | 1 | Asada Sarapiqu |
insomnia | 1 | Wiggins, Childs, Pantazis, Fisher, & Goldfarb LLC |
IOC Volume
696 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 696 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Active Malware Families
16 malware families active this week (0 corroborated across ≥2 sources), exercising 19 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| Mirai | botnet | — | 1,315 | T1110, T1498, T1499, T1584.005 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 26 | T1219 |
| AgentTesla | stealer | — | 25 | T1056.001, T1071, T1114, T1555 |
| ClickFix | delivery → | — | 24 | T1059.001, T1204 |
| ACRStealer | stealer | — | 12 | T1005, T1071, T1555 |
| CoinMiner | miner | — | 12 | T1496 |
| DDoSAgent | ddos | — | 9 | T1498, T1499 |
| AMOS (Atomic macOS Stealer) | stealer | — | 8 | T1005, T1056.002, T1071, T1555.001 |
| MassLogger | stealer | — | 8 | T1056.001, T1071, T1555 |
| Amadey | loader → | — | 5 | T1071, T1105, T1547 |
| SilverFox | rat | — | 4 | T1059, T1071, T1219 |
| Stealc | stealer | — | 4 | T1005, T1071, T1555 |
| Formbook | stealer | — | 3 | T1005, T1056.001, T1071, T1555 |
| GuLoader | loader → | — | 3 | T1027, T1071, T1105 |
| PureLogsStealer | stealer | — | 1 | T1005, T1071, T1555 |
| XWorm | rat | — | 1 | T1056.001, T1071 |
Families marked ”→” are delivery/social-engineering clusters (ClickFix, Amadey, GuLoader). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
3 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
38.55.99.215 | ip-src | misp + urlhaus | 2026-09-16 |
nova-client.com | domain | misp + urlhaus | 2026-09-16 |
odinclient.com | domain | misp + urlhaus | 2026-09-16 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No SEC × KEV vendor token matches in this window. (This is a heuristic surface, absence is expected most days.)
Intel Feeds
2 IOC feeds updated this run (3,213 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| URLhaus — Malware Distribution URLs | urlhaus | url | 3,058 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 155 | CSV · MISP · STIX |
Hand-Authored Sigma
16 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Host | experimental | https://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml |
| T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Process | experimental | https://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1098.005 Okta Verify Enrollment from a Hypervisor Guest | experimental | https://thrunt.me/sigma/t1098-005-hypervisor-mfa-device-enrollment.yml |
| T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnet | experimental | https://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml |
| T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Container | experimental | https://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml |
| T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml |
| T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml |
| T1557 Okta Authentication or MFA via a Remote-Desktop / Proxy / Tor Tunnel | experimental | https://thrunt.me/sigma/t1557-aitm-cross-asn-session-mfa.yml |
| T1557 Claims Kit First-Party Exfil — X-Enc Single-Letter C2 | experimental | https://thrunt.me/sigma/t1557-claims-kit-single-letter-c2-xenc.yml |
| T1557 Okta Verify SVG Asset Served by a Non-Okta Host | experimental | https://thrunt.me/sigma/t1557-non-okta-host-oktaverify-svg.yml |
| T1557 reCAPTCHA-Skinned Cloudflare Turnstile Gate | experimental | https://thrunt.me/sigma/t1557-recaptcha-skinned-turnstile-gate.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Path | experimental | https://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml |
| T1583.001 Resolution of a ShinyHunters .claims Impersonation Domain | experimental | https://thrunt.me/sigma/t1583-001-claims-registration-conjunction.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
18 of 160 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1573.001 | Symmetric Cryptography | — | 1 | 3 |
T1562 | — | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 8 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.