September 19, 2026 · Applied Cybernetics Group
Morning Brief — September 19, 2026
Morning Brief — 2026-09-19
2 material breach disclosures, 3 federal patching priority, 2 exploit probability movers, 10 emerging critical cves, 10 supply chain, 33 ransomware activity, 657 ioc volume, 13 active malware families, 3 multi-source iocs, 2 intel feeds, 18 hand-authored sigma, and 18 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
Nutex Health Inc. (NUTX)
- Filed: 2026-09-11 · CIK 0001479681 · Accession
0001628280-26-061432 - Filing: https://www.sec.gov/Archives/edgar/data/1479681/000162828026061432/materiality_assessmentxupd.htm
Forward-Looking StatementsCertain statements and information included in this press release constitute “forward-looking statements” within the meaning of the Private Securities Litigation Reform Act of 1995. When used in this press release, the words or phrases “will,” “will likely result,” “expected to,” “will continue,” “anticipated,” “estimate,” “projected,” “intend,” “goal,” or similar express…
BOSTON SCIENTIFIC CORP (BSX)
- Filed: 2026-09-08 · CIK 0000885725 · Accession
0000885725-26-000059 - Filing: https://www.sec.gov/Archives/edgar/data/885725/000088572526000059/bsx-20260907.htm
As previously disclosed in a Current Report on Form 8-K filed on August 26, 2026 with the Securities and Exchange Commission, on August 25, 2026, Boston Scientific Corporation (the “Company”) identified a cybersecurity incident that affected certain of its information technology systems and resulted in a global disruption to the Company’s operations. Upon detection, the Company activated its incid…
Federal Patching Priority
CVE-2025-39682 — Linux Kernel
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
- Added: 2026-09-18 · Federal due: 2026-09-21 · EPSS 42.1th pct (score 0.005) · CVSS 9.8 (CRITICAL) · CWE-754
- ransomware use: Unknown
Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we break out of the main processing loop. If the record has already been decrypted…
CVE-2025-39964 — Linux Kernel
Linux Kernel Race Condition Vulnerability
- Added: 2026-09-18 · Federal due: 2026-09-21 · EPSS 25.6th pct (score 0.003) · CVSS 7.8 (HIGH) · CWE-362
- ransomware use: Unknown
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket’s internal state.
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates…
CVE-2026-53266 — Linux Kernel
Linux Kernel Out-of-Bounds Write Vulnerability
- Added: 2026-09-18 · Federal due: 2026-09-21 · EPSS 2.2th pct (score 0.001) · CVSS 8.8 (HIGH) · CWE-787
- ransomware use: Unknown
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking…
Exploit Probability Movers
| CVE | Today | Prev | Δ | In KEV |
|---|---|---|---|---|
CVE-2025-48976 | 0.330 | 0.626 | ▼ 0.297 | |
CVE-2025-48988 | 0.305 | 0.595 | ▼ 0.289 |
Emerging Critical CVEs
CVE-2026-93741· CRITICAL (10.0) · 2026-09-19 — A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in bu…CVE-2026-93740· CRITICAL (10.0) · 2026-09-18 — A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is…CVE-2026-10747· CRITICAL (10.0) · 2026-09-18 — IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to a heap buffer overflow in protocol message processing before authentication.CVE-2025-15399· CRITICAL (10.0) · 2026-09-18 — IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions…CVE-2026-93606· CRITICAL (10.0) · 2026-09-18 — vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape inVMandNodeVM. When an embedder exposes a host API that returns a host-realm Promise, the bridge’s rejection sanitizer (hostPromiseSanitizeReject / ma…CVE-2026-93605· CRITICAL (10.0) · 2026-09-18 — vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and exe…CVE-2026-93603· CRITICAL (10.0) · 2026-09-18 — vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullishthisreceiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function withou…CVE-2026-93742· CRITICAL (9.9) · 2026-09-19 — A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The a…CVE-2026-93739· CRITICAL (9.9) · 2026-09-18 — A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The…CVE-2026-93738· CRITICAL (9.9) · 2026-09-18 — A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The…
Supply Chain
GHSA-jgh3-fggc-mcpm (go)
- HIGH · CVSS 7.6 · 2026-09-18
- Affected:
github.com/obot-platform/obot - https://github.com/advisories/GHSA-jgh3-fggc-mcpm
Obot: Server-Side Request Forgery via remote MCP server URL
GHSA-xwmw-prc4-v3cr (go)
- HIGH · CVSS 8.8 · 2026-09-18
- Affected:
github.com/obot-platform/obot - https://github.com/advisories/GHSA-xwmw-prc4-v3cr
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion
GHSA-9jjc-fw8x-fmwx · CVE-2026-85058 (maven)
- HIGH · CVSS 7.5 · 2026-09-18
- Affected:
io.moquette:moquette-broker - https://github.com/advisories/GHSA-9jjc-fw8x-fmwx
io.moquette:moquette-broker has a Missing Authorization issue
GHSA-xcw4-53cc-hv32 · CVE-2026-59163 (pip)
- CRITICAL · CVSS 9.1 · 2026-09-18
- Affected:
mnemosyne-memory - https://github.com/advisories/GHSA-xcw4-53cc-hv32
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
GHSA-vr5f-w35q-98jp · CVE-2026-63445 (go)
- HIGH · 2026-09-18
- Affected:
github.com/perses/perses - https://github.com/advisories/GHSA-vr5f-w35q-98jp
Perses’s unvalidated project parameter enables filesystem path traversal
GHSA-4227-9989-jrhx · CVE-2026-63199 (go)
- HIGH · 2026-09-18
- Affected:
github.com/perses/perses - https://github.com/advisories/GHSA-4227-9989-jrhx
Perses’s missing authorization in datasource proxy allows cross-scope secret disclosure
GHSA-cjgj-2fwf-4c2w · CVE-2026-63458 (go)
- HIGH · 2026-09-18
- Affected:
github.com/perses/perses - https://github.com/advisories/GHSA-cjgj-2fwf-4c2w
Perses’s project query parameter authorization bypass exposes cross-project resources
GHSA-3753-m2x2-q623 · CVE-2026-91127 (npm)
- HIGH · CVSS 8.2 · 2026-09-18
- Affected:
@file-viewer/doc,msdoc-viewer - https://github.com/advisories/GHSA-3753-m2x2-q623
File Viewer: DOM XSS via unsafe hyperlink schemes in the legacy DOC renderer
GHSA-7q85-xj36-vmfc · CVE-2026-77301 (npm)
- HIGH · CVSS 7.5 · 2026-09-18
- Affected:
adm-zip - https://github.com/advisories/GHSA-7q85-xj36-vmfc
adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
GHSA-p5vg-v7mj-f6q4 · CVE-2026-81505 (go)
- HIGH · 2026-09-18
- Affected:
github.com/frain-dev/convoy - https://github.com/advisories/GHSA-p5vg-v7mj-f6q4
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials
Ransomware Activity
33 new victim postings across 15 groups.
| Group | Victims | Sample |
|---|---|---|
N0n | 10 | Inter (Venezuela’s largest internet provider), PayPal support operations (Transc… |
qilin | 5 | Ascend Com, Ceres Tolvas, Futuro Forestal, Grupo Juste, Inland and Offshore Cont… |
play | 3 | Vista Plastic Solutions, Inglewood Golf, Barrett Mahony Consulting Engineers |
AuditTeam | 2 | kit-e.jp, Paid Victim 192EB2B6AD7B98D9 |
incransom | 2 | www.roancampingholidays.com, www.kendallhunt.com |
lockbit5 | 2 | hygear.com, forus.cl |
Gammax | 1 | Premier Lighting & Controls |
Panzer | 1 | K3G Solutions Brazil |
Spirals | 1 | PITTSRAD |
Vexy Ransomware | 1 | Quy Nhon University |
akira | 1 | Anderson Industries |
anubis | 1 | Quest Group |
emperador | 1 | Cassias MG Government |
rhysida | 1 | MPA Pharma |
securotrop | 1 | Prefix Corp |
IOC Volume
657 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 657 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Active Malware Families
13 malware families active this week (1 corroborated across ≥2 sources), exercising 16 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| AMOS (Atomic macOS Stealer) | stealer | ✓ | 16 | T1005, T1056.002, T1071, T1555.001 |
| Mirai | botnet | — | 1,320 | T1110, T1498, T1499, T1584.005 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 48 | T1219 |
| ClickFix | delivery → | — | 26 | T1059.001, T1204 |
| CoinMiner | miner | — | 13 | T1496 |
| AgentTesla | stealer | — | 11 | T1056.001, T1071, T1114, T1555 |
| ACRStealer | stealer | — | 9 | T1005, T1071, T1555 |
| DDoSAgent | ddos | — | 9 | T1498, T1499 |
| MassLogger | stealer | — | 7 | T1056.001, T1071, T1555 |
| SilverFox | rat | — | 2 | T1059, T1071, T1219 |
| Stealc | stealer | — | 2 | T1005, T1071, T1555 |
| Formbook | stealer | — | 1 | T1005, T1056.001, T1071, T1555 |
| PureLogsStealer | stealer | — | 1 | T1005, T1071, T1555 |
Families marked ”→” are delivery/social-engineering clusters (ClickFix). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
3 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
implantdentistrytx.com | domain | misp + urlhaus | 2026-09-19 |
nova-client.com | domain | misp + urlhaus | 2026-09-19 |
odinclient.com | domain | misp + urlhaus | 2026-09-19 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No SEC × KEV vendor token matches in this window. (This is a heuristic surface, absence is expected most days.)
Intel Feeds
2 IOC feeds updated this run (3,593 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| URLhaus — Malware Distribution URLs | urlhaus | url | 3,435 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 158 | CSV · MISP · STIX |
Hand-Authored Sigma
16 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Host | experimental | https://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml |
| T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Process | experimental | https://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1098.005 Okta Verify Enrollment from a Hypervisor Guest | experimental | https://thrunt.me/sigma/t1098-005-hypervisor-mfa-device-enrollment.yml |
| T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnet | experimental | https://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml |
| T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Container | experimental | https://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml |
| T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml |
| T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml |
| T1557 Okta Authentication or MFA via a Remote-Desktop / Proxy / Tor Tunnel | experimental | https://thrunt.me/sigma/t1557-aitm-cross-asn-session-mfa.yml |
| T1557 Claims Kit First-Party Exfil — X-Enc Single-Letter C2 | experimental | https://thrunt.me/sigma/t1557-claims-kit-single-letter-c2-xenc.yml |
| T1557 Okta Verify SVG Asset Served by a Non-Okta Host | experimental | https://thrunt.me/sigma/t1557-non-okta-host-oktaverify-svg.yml |
| T1557 reCAPTCHA-Skinned Cloudflare Turnstile Gate | experimental | https://thrunt.me/sigma/t1557-recaptcha-skinned-turnstile-gate.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Path | experimental | https://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml |
| T1583.001 Resolution of a ShinyHunters .claims Impersonation Domain | experimental | https://thrunt.me/sigma/t1583-001-claims-registration-conjunction.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
18 of 160 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1573.001 | Symmetric Cryptography | — | 1 | 3 |
T1562 | — | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 8 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.