June 10, 2026 · Applied Cybernetics Group
Morning Brief — June 10, 2026
Morning Brief — 2026-06-10
3 federal patching priority, 4 exploit probability movers, 10 emerging critical cves, 5 supply chain, 22 ransomware activity, 34671 ioc volume, 1 recent osint events, 25 multi-source iocs, 4 intel feeds, and 1 hand-authored sigma. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
No new Item 1.05 8-K filings in this window.
Federal Patching Priority
CVE-2026-20245 — Cisco Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
- Added: 2026-06-09 · Federal due: 2026-06-23 · EPSS 24.2th pct (score 0.001) · CVSS 7.8 (HIGH) · CWE-116
- ransomware use: Unknown
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of…
CVE-2026-11645 — Google Chromium V8
Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
- Added: 2026-06-09 · Federal due: 2026-06-23 · EPSS 23.6th pct (score 0.001) · CVSS 8.8 (HIGH) · CWE-787, CWE-125
- ransomware use: Unknown
Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7473 — Arista Extensible Operating System
Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
- Added: 2026-06-09 · Federal due: 2026-06-23 · EPSS 8.7th pct (score 0.000) · CVSS 5.8 (MEDIUM) · CWE-1023
- ransomware use: Unknown
Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when the switch incorrectly decapsulate and forwards other unexpected tunneled packet with a destination IP matching its configured decapsulation IP.
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet with a destination IP matching its configured decapsulation IP. This occurs because the switch does not…
Exploit Probability Movers
| CVE | Today | Prev | Δ | In KEV |
|---|---|---|---|---|
CVE-2026-42271 | 0.608 | 0.041 | ▲ 0.567 | ✓ |
CVE-2012-10056 | 0.577 | 0.368 | ▲ 0.209 | |
CVE-2011-10009 | 0.686 | 0.484 | ▲ 0.202 | |
CVE-2022-44727 | 0.207 | 0.005 | ▲ 0.202 |
Emerging Critical CVEs
CVE-2026-48303· CRITICAL (10.0) · 2026-06-09 — Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation o…CVE-2026-47938· CRITICAL (10.0) · 2026-06-09 — Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require…CVE-2026-10520· CRITICAL (10.0) · 2026-06-09 — An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code executionCVE-2026-10523· CRITICAL (9.9) · 2026-06-09 — An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full admi…CVE-2026-30141· CRITICAL (9.8) · 2026-06-09 — An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via a crafted GIF fil…CVE-2026-10045· CRITICAL (9.8) · 2026-06-09 — Shenzhen Kangda Xin Intelligent Network Technology Company’s router, model DR300, version 2.1.2.121, contains hardcoded login credentials and has telnet enabled by default on WAN and LAN interfaces. These vulnerabilities…CVE-2026-49841· CRITICAL (9.8) · 2026-06-09 — FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, the mod_vert…CVE-2026-47643· CRITICAL (9.8) · 2026-06-09 — External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.CVE-2026-47291· CRITICAL (9.8) · 2026-06-09 — Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.CVE-2026-45657· CRITICAL (9.8) · 2026-06-09 — Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
Supply Chain
GHSA-jvc5-6g7q-c843 · CVE-2026-48030 (composer)
- CRITICAL · CVSS 9.9 · 2026-06-09
- Affected:
pheditor/pheditor - https://github.com/advisories/GHSA-jvc5-6g7q-c843
Pheditor: OS Command Injection in terminal handler via unsanitized ‘dir’ parameter
GHSA-7qjx-gp9h-65qj (go)
- HIGH · CVSS 8.7 · 2026-06-09
- Affected:
github.com/dexidp/dex - https://github.com/advisories/GHSA-7qjx-gp9h-65qj
Dex: Token-exchange endpoint is missing AllowedConnectors enforcement
GHSA-833p-95jq-929q · CVE-2026-8469 (erlang)
- HIGH · 2026-06-09
- Affected:
phoenix_storybook - https://github.com/advisories/GHSA-833p-95jq-929q
PhoenixStorybook: Unbounded atom creation from LiveView event params (atom-table DoS)
GHSA-55hg-8qxv-qj4p · CVE-2026-8467 (erlang)
- CRITICAL · 2026-06-09
- Affected:
phoenix_storybook - https://github.com/advisories/GHSA-55hg-8qxv-qj4p
PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground
GHSA-w7jw-789q-3m8p · CVE-2026-9277 (npm)
- CRITICAL · CVSS 8.1 · 2026-06-09
- Affected:
shell-quote - https://github.com/advisories/GHSA-w7jw-789q-3m8p
shell-quote quote() does not escape newlines in object .op values
Ransomware Activity
22 new victim postings across 13 groups.
| Group | Victims | Sample |
|---|---|---|
pear | 4 | K & E Distributing, Bayou Electrical Services, National Health Fund, Alpha IT |
worldleaks | 4 | Apollo Pipes, GDL Transport, M1xchange, Centra Sota Cooperative |
akira | 3 | Spray Equipment & Service Center, Rockaway River Country Club, SMPC Architects |
PrinzEugen | 2 | Spratley’s of Mortimer, Spratley’s |
chaos | 1 | airespring.com |
dragonforce | 1 | Sayre Associates |
embargo | 1 | Auburn Electrical Construction Company |
fulcrumsec | 1 | Global Schools Foundation |
insomnia | 1 | Mid-Cumberland Human Resource Agency |
morpheus | 1 | HDFC FUND |
shinyhunters | 1 | nottingham.ac.uk |
spacebears | 1 | Lösing Filtertechnik |
termite | 1 | Cal Fresh |
IOC Volume
34671 new IOCs in this window. By source:
| Source | Count |
|---|---|
misp | 33915 |
urlhaus | 756 |
Recent OSINT Events
Phishing Campaign Targeting Hotel Customers in Luxembourg
- Date: 2026-06-01 · Threat: high · Org: CIRCL
- Signal: 0 actionable IOCs (of 6 attributes) · https://www.circl.lu/doc/misp/feed-osint/10a94632-a0a1-4062-a3a5-95fe321ae045.json
Multi-Source IOCs
25 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
04gzr1uh.alternatifdekorasyon.com | domain | misp + urlhaus | 2026-06-10 |
1822jtv8.betwoonuyelik.com | domain | misp + urlhaus | 2026-06-10 |
1djqvowq.iaap2019.com | domain | misp + urlhaus | 2026-06-10 |
1v55nk51.irantennis.bet | domain | misp + urlhaus | 2026-06-10 |
2os894vl.betfire90.bet | domain | misp + urlhaus | 2026-06-10 |
3i8e3aty.ef90bet.com | domain | misp + urlhaus | 2026-06-10 |
3p1x6btm.1xbet90.bet | domain | misp + urlhaus | 2026-06-10 |
4lm4v3bu.bet404.games | domain | misp + urlhaus | 2026-06-10 |
4ly606b9.aftabsport.ir | domain | misp + urlhaus | 2026-06-10 |
4q4880m7.bwin90.bet | domain | misp + urlhaus | 2026-06-10 |
5ay2qa01.electriccrash.bet | domain | misp + urlhaus | 2026-06-10 |
6dg7sjam.bet404farsi.com | domain | misp + urlhaus | 2026-06-10 |
6go1tq9f.takbet90.bet | domain | misp + urlhaus | 2026-06-10 |
6ju7fjjz.bordoo.bet | domain | misp + urlhaus | 2026-06-10 |
6vk8lpd5.betball90.casino | domain | misp + urlhaus | 2026-06-10 |
7aaxg4kb.betbatis.com | domain | misp + urlhaus | 2026-06-10 |
7g5swyfn.bazipoop.com | domain | misp + urlhaus | 2026-06-10 |
8i927m8y.bcgamefarsi.com | domain | misp + urlhaus | 2026-06-10 |
8vjdfz8n.basketballiran.bet | domain | misp + urlhaus | 2026-06-10 |
afdaqyu.yasbet.casino | domain | misp + urlhaus | 2026-06-10 |
ageqour.hit4bet1.com | domain | misp + urlhaus | 2026-06-10 |
aknkoyw.homa.bet | domain | misp + urlhaus | 2026-06-10 |
amcbvlw.bordbet.casino | domain | misp + urlhaus | 2026-06-10 |
atnvjyj.emroze.bet | domain | misp + urlhaus | 2026-06-10 |
bagkqzj.zeppelin.bet | domain | misp + urlhaus | 2026-06-10 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No recent SEC filings to cross-reference.
Intel Feeds
4 IOC feeds updated this run (11,045 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| MISP — Suspicious Domains | misp | domain | 5,000 | CSV · MISP · STIX |
| MISP — Flagged IPs | misp | ip | 1,082 | CSV · MISP · STIX |
| URLhaus — Malware Distribution URLs | urlhaus | url | 4,301 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 662 | CSV · MISP · STIX |
Hand-Authored Sigma
1 hand-authored TTP rule live at https://thrunt.me/sigma/manifest.json.
| Rule | YAML |
|---|---|
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.