Applied Cybernetics Group
Threat intel → detection pipeline
Tuesday, July 14, 2026
Data as of 20:11 UTC

Morning Brief — 2026-06-10

3 federal patching priority, 4 exploit probability movers, 10 emerging critical cves, 5 supply chain, 22 ransomware activity, 34671 ioc volume, 1 recent osint events, 25 multi-source iocs, 4 intel feeds, and 1 hand-authored sigma. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.

Material Breach Disclosures

No new Item 1.05 8-K filings in this window.

Federal Patching Priority

CVE-2026-20245 — Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of…

CVE-2026-11645 — Google Chromium V8

Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-7473 — Arista Extensible Operating System

Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability

Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.

On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not…

Exploit Probability Movers

CVETodayPrevΔIn KEV
CVE-2026-422710.6080.041▲ 0.567
CVE-2012-100560.5770.368▲ 0.209
CVE-2011-100090.6860.484▲ 0.202
CVE-2022-447270.2070.005▲ 0.202

Emerging Critical CVEs

Supply Chain

GHSA-jvc5-6g7q-c843 · CVE-2026-48030 (composer)

Pheditor: OS Command Injection in terminal handler via unsanitized ‘dir’ parameter

GHSA-7qjx-gp9h-65qj (go)

Dex: Token-exchange endpoint is missing AllowedConnectors enforcement

GHSA-833p-95jq-929q · CVE-2026-8469 (erlang)

PhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)

GHSA-55hg-8qxv-qj4p · CVE-2026-8467 (erlang)

PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground

GHSA-w7jw-789q-3m8p · CVE-2026-9277 (npm)

shell-quote quote() does not escape newlines in object .op values

Ransomware Activity

22 new victim postings across 13 groups.

GroupVictimsSample
pear4K & E Distributing, Bayou Electrical Services, National Health Fund, Alpha IT
worldleaks4Apollo Pipes, GDL Transport, M1xchange, Centra Sota Cooperative
akira3Spray Equipment & Service Center, Rockaway River Country Club, SMPC Architects
PrinzEugen2Spratley’s of Mortimer, Spratley’s
chaos1airespring.com
dragonforce1Sayre Associates
embargo1Auburn Electrical Construction Company
fulcrumsec1Global Schools Foundation
insomnia1Mid-Cumberland Human Resource Agency
morpheus1HDFC FUND
shinyhunters1nottingham.ac.uk
spacebears1Lösing Filtertechnik
termite1Cal Fresh

IOC Volume

34671 new IOCs in this window. By source:

SourceCount
misp33915
urlhaus756

Recent OSINT Events

Phishing Campaign Targeting Hotel Customers in Luxembourg

Multi-Source IOCs

25 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.

IOCTypeSourcesLast seen
04gzr1uh.alternatifdekorasyon.comdomainmisp + urlhaus2026-06-10
1822jtv8.betwoonuyelik.comdomainmisp + urlhaus2026-06-10
1djqvowq.iaap2019.comdomainmisp + urlhaus2026-06-10
1v55nk51.irantennis.betdomainmisp + urlhaus2026-06-10
2os894vl.betfire90.betdomainmisp + urlhaus2026-06-10
3i8e3aty.ef90bet.comdomainmisp + urlhaus2026-06-10
3p1x6btm.1xbet90.betdomainmisp + urlhaus2026-06-10
4lm4v3bu.bet404.gamesdomainmisp + urlhaus2026-06-10
4ly606b9.aftabsport.irdomainmisp + urlhaus2026-06-10
4q4880m7.bwin90.betdomainmisp + urlhaus2026-06-10
5ay2qa01.electriccrash.betdomainmisp + urlhaus2026-06-10
6dg7sjam.bet404farsi.comdomainmisp + urlhaus2026-06-10
6go1tq9f.takbet90.betdomainmisp + urlhaus2026-06-10
6ju7fjjz.bordoo.betdomainmisp + urlhaus2026-06-10
6vk8lpd5.betball90.casinodomainmisp + urlhaus2026-06-10
7aaxg4kb.betbatis.comdomainmisp + urlhaus2026-06-10
7g5swyfn.bazipoop.comdomainmisp + urlhaus2026-06-10
8i927m8y.bcgamefarsi.comdomainmisp + urlhaus2026-06-10
8vjdfz8n.basketballiran.betdomainmisp + urlhaus2026-06-10
afdaqyu.yasbet.casinodomainmisp + urlhaus2026-06-10
ageqour.hit4bet1.comdomainmisp + urlhaus2026-06-10
aknkoyw.homa.betdomainmisp + urlhaus2026-06-10
amcbvlw.bordbet.casinodomainmisp + urlhaus2026-06-10
atnvjyj.emroze.betdomainmisp + urlhaus2026-06-10
bagkqzj.zeppelin.betdomainmisp + urlhaus2026-06-10

MISP × KEV Correlation

No MISP events in this window referenced a CVE.

Cross-Reference

No recent SEC filings to cross-reference.

Intel Feeds

4 IOC feeds updated this run (11,045 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.

FeedSourceTypeCountDownloads
MISP — Suspicious Domainsmispdomain5,000CSV · MISP · STIX
MISP — Flagged IPsmispip1,082CSV · MISP · STIX
URLhaus — Malware Distribution URLsurlhausurl4,301CSV · MISP · STIX
URLhaus — Malware Distribution Domainsurlhausdomain662CSV · MISP · STIX

Hand-Authored Sigma

1 hand-authored TTP rule live at https://thrunt.me/sigma/manifest.json.

RuleYAML
T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaignhttps://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml

Pipeline Health

All feeds healthy.


Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).

Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.