September 18, 2026 · Applied Cybernetics Group
Morning Brief — September 18, 2026
Morning Brief — 2026-09-18
2 material breach disclosures, 10 emerging critical cves, 10 supply chain, 38 ransomware activity, 631 ioc volume, 14 active malware families, 2 multi-source iocs, 2 intel feeds, 18 hand-authored sigma, and 18 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
Nutex Health Inc. (NUTX)
- Filed: 2026-09-11 · CIK 0001479681 · Accession
0001628280-26-061432 - Filing: https://www.sec.gov/Archives/edgar/data/1479681/000162828026061432/materiality_assessmentxupd.htm
Forward-Looking StatementsCertain statements and information included in this press release constitute “forward-looking statements” within the meaning of the Private Securities Litigation Reform Act of 1995. When used in this press release, the words or phrases “will,” “will likely result,” “expected to,” “will continue,” “anticipated,” “estimate,” “projected,” “intend,” “goal,” or similar express…
BOSTON SCIENTIFIC CORP (BSX)
- Filed: 2026-09-08 · CIK 0000885725 · Accession
0000885725-26-000059 - Filing: https://www.sec.gov/Archives/edgar/data/885725/000088572526000059/bsx-20260907.htm
As previously disclosed in a Current Report on Form 8-K filed on August 26, 2026 with the Securities and Exchange Commission, on August 25, 2026, Boston Scientific Corporation (the “Company”) identified a cybersecurity incident that affected certain of its information technology systems and resulted in a global disruption to the Company’s operations. Upon detection, the Company activated its incid…
Federal Patching Priority
No new KEV additions in this window.
Exploit Probability Movers
No CVEs with ≥0.20 EPSS movement in this window.
Emerging Critical CVEs
CVE-2026-69843· CRITICAL (10.0) · 2026-09-18 — Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.CVE-2026-62874· CRITICAL (10.0) · 2026-09-18 — Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.CVE-2026-85889· CRITICAL (10.0) · 2026-09-17 — Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.CVE-2026-83944· CRITICAL (10.0) · 2026-09-17 — Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.CVE-2026-70200· CRITICAL (10.0) · 2026-09-17 — Improper limitation of a pathname to a restricted directory (‘path traversal’) in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.CVE-2026-69865· CRITICAL (10.0) · 2026-09-17 — Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.CVE-2026-69399· CRITICAL (10.0) · 2026-09-17 — Azure Arc Elevation of Privilege VulnerabilityCVE-2026-54734· CRITICAL (10.0) · 2026-09-17 — Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or…CVE-2026-92960· CRITICAL (10.0) · 2026-09-17 — vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: [’*’] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to…CVE-2026-92956· CRITICAL (10.0) · 2026-09-17 — vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a defaultnew VM()sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host…
Supply Chain
GHSA-r94f-hx44-8jqf · CVE-2026-72819 (composer)
- HIGH · CVSS 8.8 · 2026-09-17
- Affected:
getgrav/grav - https://github.com/advisories/GHSA-r94f-hx44-8jqf
Grav CMS vulnerable to remote code execution via .zip file upload
GHSA-xhfv-7758-r9hx · CVE-2026-75837 (composer)
- HIGH · CVSS 9.1 · 2026-09-17
- Affected:
getgrav/grav - https://github.com/advisories/GHSA-xhfv-7758-r9hx
Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin
GHSA-f8wv-xp27-6gq7 · CVE-2026-75827 (composer)
- CRITICAL · CVSS 8.8 · 2026-09-17
- Affected:
getgrav/grav - https://github.com/advisories/GHSA-f8wv-xp27-6gq7
Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write
GHSA-vfmf-q6x9-cw96 · CVE-2026-75828 (composer)
- CRITICAL · CVSS 8.7 · 2026-09-17
- Affected:
getgrav/grav - https://github.com/advisories/GHSA-vfmf-q6x9-cw96
Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS
GHSA-4v9q-p283-qc2m · CVE-2026-74907 (composer)
- HIGH · CVSS 5.9 · 2026-09-17
- Affected:
getgrav/grav - https://github.com/advisories/GHSA-4v9q-p283-qc2m
Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in plugin-asset-map.php Static Asset Server (index.php)
GHSA-jq29-c7v8-rg55 · CVE-2026-72695 (composer)
- HIGH · CVSS 8.1 · 2026-09-17
- Affected:
getgrav/grav - https://github.com/advisories/GHSA-jq29-c7v8-rg55
Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
GHSA-9gm5-9rfh-m6vx · CVE-2026-86003 (go)
- HIGH · CVSS 7.5 · 2026-09-17
- Affected:
github.com/coredns/coredns - https://github.com/advisories/GHSA-9gm5-9rfh-m6vx
CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
GHSA-x424-64qh-5j54 · CVE-2026-84997 (composer)
- HIGH · CVSS 7.5 · 2026-09-17
- Affected:
react/http - https://github.com/advisories/GHSA-x424-64qh-5j54
react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU
GHSA-mrg3-qvqr-jw29 · CVE-2026-82399 (go)
- HIGH · CVSS 7.5 · 2026-09-17
- Affected:
github.com/coredns/coredns - https://github.com/advisories/GHSA-mrg3-qvqr-jw29
CoreDNS: Unauthenticated memory exhaustion in custom transports
GHSA-gq9c-wmrm-5hvr · CVE-2026-81876 (maven)
- HIGH · CVSS 7.5 · 2026-09-17
- Affected:
ca.uhn.hapi.fhir:org.hl7.fhir.r5,ca.uhn.hapi.fhir:org.hl7.fhir.validation,ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli - https://github.com/advisories/GHSA-gq9c-wmrm-5hvr
HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service
Ransomware Activity
38 new victim postings across 16 groups.
| Group | Victims | Sample |
|---|---|---|
settra | 6 | rottner-tresor.at, naturesplus.com, pacificabs.com, fchhotels.com, budgetms.com,… |
Storm | 5 | American Casting Company, Johnson Investment Counsel, First Secure Community Ban… |
qilin | 4 | Vigatec, Invincible GG, Techwise, The Gran Hotel Ingles |
BrainCipher | 3 | hoyletanner.com, aecom.com, xpera.ca |
Panzer | 3 | Universitt Hamburg, Inovapy, Stim |
akira | 3 | Practice Management (maximizedrevenue.com), Vetta, Javep Chevrolet |
metaencryptor | 3 | Beckman Coulter, Inc, AECOM, Promantra, Inc |
EndZone | 2 | Accela.com, AT&T |
krybit | 2 | www.harputyapi.com, www.diakonie-apolda.de |
SilentRansomGroup | 1 | C… |
Spirals | 1 | ANYTHINGIT |
Vexy Ransomware | 1 | STP Fashion Lab |
chaos | 1 | expresspros.com |
incransom | 1 | Silicon Integrated Systems |
killsec | 1 | Giti Corp |
ransomhouse | 1 | Pertamina |
IOC Volume
631 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 631 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Active Malware Families
14 malware families active this week (0 corroborated across ≥2 sources), exercising 18 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| Mirai | botnet | — | 1,307 | T1110, T1498, T1499, T1584.005 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 43 | T1219 |
| ClickFix | delivery → | — | 25 | T1059.001, T1204 |
| ACRStealer | stealer | — | 12 | T1005, T1071, T1555 |
| CoinMiner | miner | — | 12 | T1496 |
| AgentTesla | stealer | — | 11 | T1056.001, T1071, T1114, T1555 |
| AMOS (Atomic macOS Stealer) | stealer | — | 11 | T1005, T1056.002, T1071, T1555.001 |
| DDoSAgent | ddos | — | 9 | T1498, T1499 |
| MassLogger | stealer | — | 7 | T1056.001, T1071, T1555 |
| Amadey | loader → | — | 5 | T1071, T1105, T1547 |
| SilverFox | rat | — | 4 | T1059, T1071, T1219 |
| Stealc | stealer | — | 4 | T1005, T1071, T1555 |
| Formbook | stealer | — | 1 | T1005, T1056.001, T1071, T1555 |
| PureLogsStealer | stealer | — | 1 | T1005, T1071, T1555 |
Families marked ”→” are delivery/social-engineering clusters (ClickFix, Amadey). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
2 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
nova-client.com | domain | misp + urlhaus | 2026-09-18 |
odinclient.com | domain | misp + urlhaus | 2026-09-18 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No SEC × KEV vendor token matches in this window. (This is a heuristic surface, absence is expected most days.)
Intel Feeds
2 IOC feeds updated this run (3,455 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| URLhaus — Malware Distribution URLs | urlhaus | url | 3,299 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 156 | CSV · MISP · STIX |
Hand-Authored Sigma
16 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Host | experimental | https://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml |
| T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Process | experimental | https://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1098.005 Okta Verify Enrollment from a Hypervisor Guest | experimental | https://thrunt.me/sigma/t1098-005-hypervisor-mfa-device-enrollment.yml |
| T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnet | experimental | https://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml |
| T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Container | experimental | https://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml |
| T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml |
| T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml |
| T1557 Okta Authentication or MFA via a Remote-Desktop / Proxy / Tor Tunnel | experimental | https://thrunt.me/sigma/t1557-aitm-cross-asn-session-mfa.yml |
| T1557 Claims Kit First-Party Exfil — X-Enc Single-Letter C2 | experimental | https://thrunt.me/sigma/t1557-claims-kit-single-letter-c2-xenc.yml |
| T1557 Okta Verify SVG Asset Served by a Non-Okta Host | experimental | https://thrunt.me/sigma/t1557-non-okta-host-oktaverify-svg.yml |
| T1557 reCAPTCHA-Skinned Cloudflare Turnstile Gate | experimental | https://thrunt.me/sigma/t1557-recaptcha-skinned-turnstile-gate.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Path | experimental | https://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml |
| T1583.001 Resolution of a ShinyHunters .claims Impersonation Domain | experimental | https://thrunt.me/sigma/t1583-001-claims-registration-conjunction.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
18 of 160 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1573.001 | Symmetric Cryptography | — | 1 | 3 |
T1562 | — | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 8 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.