Applied Cybernetics Group
Threat intel → detection pipeline
Tuesday, July 14, 2026
Data as of 20:11 UTC

Independent security research. Local pipeline. Primary sources, credited per entry.

Applied Cybernetics Group is an independent security-research practice. ThreatPipeline, the engine behind thrunt.me, runs locally — no managed pipeline, no third-party data broker. Every signal here was fetched from a primary source we credit on the sources page.

Why

Your endpoint console reports 5,000 vulnerabilities. This corpus tells you which handful are actually being exploited this week — KEV membership, exploit-probability percentile, multi-source IOC corroboration, ATT&CK technique mapping — and where detection coverage stands. Collection is a solved problem. The work is the control valve: correlation, prioritization, and saying explicitly which signal deserves an analyst's morning. Feeds are plain files over HTTPS, built to plug directly into a pipeline — no accounts, no API keys, no SaaS between you and the data.

What's published

One brief per day: material breach disclosures, federal patching priority (KEV × EPSS), exploit-probability movers, emerging critical CVEs, supply-chain advisories, ransomware activity, IOC volume, and cross-references when an entity in one feed appears in another. When a section has no signal, it still renders with an explicit "none in this window" note — calibration matters as much as signal. Permanent corpus surfaces live at /corpus/; intel feeds at /intel/; detection rules at /sigma/.

What's not

No trackers. No analytics. No third-party fonts. No comments. No newsletter signup. No paywall.

Follow

The brief feed is at /feed.xml. Corpus updates on every brief publish. Read-only; the source links per entry are the canonical references.