Applied Cybernetics Group
Threat intel → detection pipeline
Tuesday, July 14, 2026
Data as of 20:11 UTC
Today’s figurescomputed 20:11:34 UTC
Coverage gaps
14
KEV CVEs mapped
419
Techniques w/ signal
155
Active families · 7d
202 corrob.
Multi-source IOCs · 7d
15
GHSA exploit evidence · 7d
0none this window

Signal × coverage → gap · recomputed daily

Detection rules for techniques that are exploited and undetected — computed daily from live intel, not asserted.

Of the 155 ATT&CK techniques showing live exploitation signal this window, 14 have no community detection coverage. The gap is computed — CISA KEV, EPSS, MISP OSINT, ransomware leak sites and SEC 8-K filings, crossed against the SigmaHQ rule index — and it is where thrunt authors.

Lead · the daily brief briefs/2026-06-11

Morning brief — June 11, 2026: 9 of 15 sections carry signal

6 exploit probability movers, 10 emerging critical cves, 10 supply chain, 55 ransomware activity, 1254 ioc volume, 25 multi-source iocs, 4 intel feeds, 1 hand-authored sigma, and 20 detection gaps.

Cross-referenced  1,385 entries this window across material breaches, federal patching priority, exploit-probability movers, emerging CVEs, ransomware, IOC volume, OSINT, MISP×KEV correlation, hand-authored Sigma and the detection-gap ledger. Read the brief →

The gap ledger · exploited, undetected 14 open · full map

Fourteen techniques show live signal and zero community rules

T1497 Virtualization/Sandbox Evasion· T1573.001 Symmetric Cryptography· T1499.002 Service Exhaustion Flood· T1530 Data from Cloud Storage· T1003.008 /etc/passwd and /etc/shadow· T1491.002 External Defacement· T1498.001 Direct Network Flood· T1602 Data from Configuration Repository· T1071.002 File Transfer Protocols· T1011 Exfiltration Over Other Network Medium· T1001 Data Obfuscation· T1542.005 TFTP Boot· T1114.002 Remote Email Collection· T1601 Modify System Image

3 former gaps now carry hand-authored thrunt rules: T1037, T1098.004 and T1566.002 — the queue below is the rest of the ledger, scored and waiting.

The Sigma desk 3 rules in production · all TLP:CLEAR
  • T1037 · persistence · experimental · level medium · file_event/linux · 2026-06-11

    Boot or Logon Initialization Scripts — Linux Init Script Modification

    Creation or modification of legacy init-system entry points (/etc/rc.local, /etc/init.d/, /etc/rc*.d/). Adversaries plant scripts there for root-context execution at boot — old-school, still routinely effective on servers and appliances that keep sysvinit compatibility.

  • T1098.004 · persistence · experimental · level medium · file_event/linux · 2026-06-11

    Account Manipulation — SSH Authorized Keys File Modification

    Creation or modification of an SSH authorized_keys file. Adversaries add their own public key to maintain persistent access after initial compromise — a one-line write that survives credential rotation and (on many estates) every patch cycle.

  • T1566.002 · initial access · experimental · level medium · sms/mobile · 2026-06-10

    Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign

    Smishing campaign targeting hotel customers in Luxembourg. The CIRCL MISP event lists six SMS sender phone numbers (NL/UK/ID country codes) that delivered the lure linking to a credential-harvesting page.

Every rule publishes with its live intel context — the KEV CVEs, EPSS scores and family activity that justified authoring it. Rules ship as Sigma YAML, TLP:CLEAR, CC BY 4.0. The desk →

The corpus four surfaces, rebuilt daily

ATT&CK

155

techniques with live signal

14 exploited-and-undetected gaps · 135 community-covered · 21 lit by active family telemetry.

KEV

1,638

exploited CVEs in catalog

329 with known ransomware use · 419 mapped to ATT&CK techniques via CTID.

SEC 8-K

70

material-incident filings

Form 8-K Item 1.05 disclosures from EDGAR full-text search — breach reality as reported to shareholders.

Ransomware

1,036

victim postings tracked

70 active groups tracked on leak sites in 2026 · leak-site postings, year-bucketed.

Material disclosures SEC EDGAR · Form 8-K Item 1.05
  • River Financial CorpRVRFfiled 2026-07-10Since the date of the original filing, River's investigation has progressed. River has determined that an unauthorized threat actor accessed…
  • River Financial CorpRVRFfiled 2026-07-06Since the date of the original filing, River’s investigation has progressed. River has reason to believe that certain data was potentially impacted…
  • NAVIENT CORPJSMfiled 2026-07-02On June 8, 2026, the Company became aware of a cybersecurity incident involving a third‑party law firm (the “Firm”) that provides services to the…
  • AdaptHealth Corp.AHCOfiled 2026-07-02AdaptHealth Corp. (the “Company”) is investigating a security incident whereby a threat actor gained unauthorized access to Company systems and…
  • River Financial CorpRVRFfiled 2026-06-25On or about June 16, 2026, an unauthorized threat actor gained access to the network environment of River Financial Corporation, including River…

Excerpts verbatim from filings, truncated. 70 filings tracked. All disclosures →