September 17, 2026 · Applied Cybernetics Group
Morning Brief — September 17, 2026
Morning Brief — 2026-09-17
2 material breach disclosures, 3 federal patching priority, 10 emerging critical cves, 10 supply chain, 26 ransomware activity, 860 ioc volume, 15 active malware families, 3 multi-source iocs, 2 intel feeds, 18 hand-authored sigma, and 18 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
Nutex Health Inc. (NUTX)
- Filed: 2026-09-11 · CIK 0001479681 · Accession
0001628280-26-061432 - Filing: https://www.sec.gov/Archives/edgar/data/1479681/000162828026061432/materiality_assessmentxupd.htm
Forward-Looking StatementsCertain statements and information included in this press release constitute “forward-looking statements” within the meaning of the Private Securities Litigation Reform Act of 1995. When used in this press release, the words or phrases “will,” “will likely result,” “expected to,” “will continue,” “anticipated,” “estimate,” “projected,” “intend,” “goal,” or similar express…
BOSTON SCIENTIFIC CORP (BSX)
- Filed: 2026-09-08 · CIK 0000885725 · Accession
0000885725-26-000059 - Filing: https://www.sec.gov/Archives/edgar/data/885725/000088572526000059/bsx-20260907.htm
As previously disclosed in a Current Report on Form 8-K filed on August 26, 2026 with the Securities and Exchange Commission, on August 25, 2026, Boston Scientific Corporation (the “Company”) identified a cybersecurity incident that affected certain of its information technology systems and resulted in a global disruption to the Company’s operations. Upon detection, the Company activated its incid…
Federal Patching Priority
CVE-2026-58704 — Google Pixel
Google Pixel Improper Authorization Vulnerability
- Added: 2026-09-16 · Federal due: 2026-09-19 · EPSS 1.6th pct (score 0.001) · CVSS 8.8 (HIGH) · CWE-285, CWE-693
- ransomware use: Unknown
Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-76460 — Cisco Identity Services Engine
Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
- Added: 2026-09-16 · Federal due: 2026-09-19 · CVSS 10.0 (CRITICAL) · CWE-648
- ransomware use: Unknown
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized…
CVE-2026-87886 — Acronis Backup
Acronis Backup Incorrect Default Permissions Vulnerability
- Added: 2026-09-16 · Federal due: 2026-09-19 · CWE-276
- ransomware use: Unknown
Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.
Exploit Probability Movers
No CVEs with ≥0.20 EPSS movement in this window.
Emerging Critical CVEs
CVE-2026-76423· CRITICAL (10.0) · 2026-09-16 — A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device.
This vulnerability is due to the REST API web service…
CVE-2026-20192· CRITICAL (10.0) · 2026-09-16 — As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensiv…CVE-2026-20130· CRITICAL (10.0) · 2026-09-16 — As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensi…CVE-2026-73456· CRITICAL (10.0) · 2026-09-16 — Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code exec…CVE-2026-70416· CRITICAL (10.0) · 2026-09-16 — Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote exec…CVE-2026-73453· CRITICAL (10.0) · 2026-09-16 — An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Ru…CVE-2026-20332· CRITICAL (9.9) · 2026-09-16 — As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management C…CVE-2026-20330· CRITICAL (9.9) · 2026-09-16 — As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management C…CVE-2026-20329· CRITICAL (9.9) · 2026-09-16 — As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management C…CVE-2026-20325· CRITICAL (9.9) · 2026-09-16 — As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software…
Supply Chain
GHSA-mxm6-v9r6-r94c · CVE-2026-63671 (npm)
- HIGH · CVSS 8.1 · 2026-09-16
- Affected:
@nuxtjs/mdc - https://github.com/advisories/GHSA-mxm6-v9r6-r94c
@nuxtjs/mdc’s URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration
GHSA-9pj6-vhgr-3mwh · CVE-2026-63128 (rust)
- HIGH · CVSS 7.5 · 2026-09-16
- Affected:
rmcp - https://github.com/advisories/GHSA-9pj6-vhgr-3mwh
RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP server transport leads to remote denial-of-service
GHSA-33f5-2c5q-wgwj · CVE-2026-63127 (rust)
- HIGH · CVSS 8.2 · 2026-09-16
- Affected:
rmcp - https://github.com/advisories/GHSA-33f5-2c5q-wgwj
RMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata Discovery
GHSA-7prp-2623-8g45 · CVE-2026-61599 (pip)
- HIGH · 2026-09-16
- Affected:
djust - https://github.com/advisories/GHSA-7prp-2623-8g45
djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path
GHSA-c7c5-5j6r-q957 · CVE-2026-61596 (pip)
- HIGH · CVSS 7.1 · 2026-09-16
- Affected:
djust - https://github.com/advisories/GHSA-c7c5-5j6r-q957
djust has broken object-level access control (IDOR)
GHSA-xhhm-f6hp-2qwj · CVE-2026-61594 (pip)
- CRITICAL · CVSS 9.1 · 2026-09-16
- Affected:
djust - https://github.com/advisories/GHSA-xhhm-f6hp-2qwj
djust has an authorization bypass on the WebSocket/SSE mount path
GHSA-c67v-vqrp-m5wj · CVE-2026-61591 (pip)
- HIGH · CVSS 8.1 · 2026-09-16
- Affected:
djust - https://github.com/advisories/GHSA-c67v-vqrp-m5wj
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
GHSA-f795-p5jw-j6g2 · CVE-2026-61592 (pip)
- HIGH · CVSS 7.4 · 2026-09-16
- Affected:
djust - https://github.com/advisories/GHSA-f795-p5jw-j6g2
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
GHSA-r2pf-9cw4-5j65 · CVE-2026-68904 (npm)
- HIGH · CVSS 7.0 · 2026-09-16
- Affected:
node-opcua-transport,node-opcua-client,node-opcua - https://github.com/advisories/GHSA-r2pf-9cw4-5j65
node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - Resource Exhaustion
GHSA-pg97-jvmf-qfvc · CVE-2026-61593 (pip)
- HIGH · CVSS 8.1 · 2026-09-16
- Affected:
djust - https://github.com/advisories/GHSA-pg97-jvmf-qfvc
djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session
Ransomware Activity
26 new victim postings across 13 groups.
| Group | Victims | Sample |
|---|---|---|
AuditTeam | 6 | palletshop, Wise IT, buben, dg.ac.kr, gownet.net, krimax.org |
qilin | 4 | Reddrop Group, In The Company of Huskies, Thorndale Foundation, Thema Foundries |
akira | 3 | Blossomland Accounting, Bee Maid Honey, Manders |
Wallstreet | 2 | Odyssey Charter School, Inc., Roshd Sanat |
emperador | 2 | RDA MOTORS S.P.A., SEVENOAKS s.r.o. |
incransom | 2 | www.appliancefactory.com, www.diarco.com.ar |
Panzer | 1 | Nielsen Design |
ShadowByt3$ | 1 | HandyTrac Greystar AZ WARNING |
arcusmedia | 1 | ARDA |
blacknevas | 1 | Optimum First Mortgage (Pear’s acting group’s promotional blog) |
kairos | 1 | Leisure Coast Kitchens |
ransomhouse | 1 | Namibian Defence Force |
shinyhunters | 1 | Qi**** |
IOC Volume
860 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 860 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Active Malware Families
15 malware families active this week (0 corroborated across ≥2 sources), exercising 19 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| Mirai | botnet | — | 1,332 | T1110, T1498, T1499, T1584.005 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 39 | T1219 |
| ClickFix | delivery → | — | 21 | T1059.001, T1204 |
| AgentTesla | stealer | — | 17 | T1056.001, T1071, T1114, T1555 |
| CoinMiner | miner | — | 13 | T1496 |
| ACRStealer | stealer | — | 12 | T1005, T1071, T1555 |
| DDoSAgent | ddos | — | 9 | T1498, T1499 |
| AMOS (Atomic macOS Stealer) | stealer | — | 8 | T1005, T1056.002, T1071, T1555.001 |
| Amadey | loader → | — | 5 | T1071, T1105, T1547 |
| MassLogger | stealer | — | 5 | T1056.001, T1071, T1555 |
| SilverFox | rat | — | 4 | T1059, T1071, T1219 |
| Stealc | stealer | — | 4 | T1005, T1071, T1555 |
| Formbook | stealer | — | 2 | T1005, T1056.001, T1071, T1555 |
| GuLoader | loader → | — | 2 | T1027, T1071, T1105 |
| PureLogsStealer | stealer | — | 1 | T1005, T1071, T1555 |
Families marked ”→” are delivery/social-engineering clusters (ClickFix, Amadey, GuLoader). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
3 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
38.55.99.215 | ip-src | misp + urlhaus | 2026-09-17 |
nova-client.com | domain | misp + urlhaus | 2026-09-17 |
odinclient.com | domain | misp + urlhaus | 2026-09-17 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No SEC × KEV vendor token matches in this window. (This is a heuristic surface, absence is expected most days.)
Intel Feeds
2 IOC feeds updated this run (3,418 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| URLhaus — Malware Distribution URLs | urlhaus | url | 3,273 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 145 | CSV · MISP · STIX |
Hand-Authored Sigma
16 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Host | experimental | https://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml |
| T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Process | experimental | https://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1098.005 Okta Verify Enrollment from a Hypervisor Guest | experimental | https://thrunt.me/sigma/t1098-005-hypervisor-mfa-device-enrollment.yml |
| T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnet | experimental | https://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml |
| T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Container | experimental | https://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml |
| T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml |
| T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml |
| T1557 Okta Authentication or MFA via a Remote-Desktop / Proxy / Tor Tunnel | experimental | https://thrunt.me/sigma/t1557-aitm-cross-asn-session-mfa.yml |
| T1557 Claims Kit First-Party Exfil — X-Enc Single-Letter C2 | experimental | https://thrunt.me/sigma/t1557-claims-kit-single-letter-c2-xenc.yml |
| T1557 Okta Verify SVG Asset Served by a Non-Okta Host | experimental | https://thrunt.me/sigma/t1557-non-okta-host-oktaverify-svg.yml |
| T1557 reCAPTCHA-Skinned Cloudflare Turnstile Gate | experimental | https://thrunt.me/sigma/t1557-recaptcha-skinned-turnstile-gate.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Path | experimental | https://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml |
| T1583.001 Resolution of a ShinyHunters .claims Impersonation Domain | experimental | https://thrunt.me/sigma/t1583-001-claims-registration-conjunction.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
18 of 160 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1573.001 | Symmetric Cryptography | — | 1 | 3 |
T1562 | — | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 8 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.