Applied Cybernetics Group
Threat intel → detection pipeline
Tuesday, July 14, 2026
Data as of 20:11 UTC

Morning Brief — 2026-06-11

6 exploit probability movers, 10 emerging critical cves, 10 supply chain, 55 ransomware activity, 1254 ioc volume, 25 multi-source iocs, 4 intel feeds, 1 hand-authored sigma, and 20 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.

Material Breach Disclosures

No new Item 1.05 8-K filings in this window.

Federal Patching Priority

No new KEV additions in this window.

Exploit Probability Movers

CVETodayPrevΔIn KEV
CVE-1999-05120.6590.004▲ 0.655
CVE-2004-24660.7780.445▲ 0.333
CVE-2022-17110.8440.539▲ 0.304
CVE-2026-50730.2450.001▲ 0.244
CVE-2026-74730.2250.000▲ 0.224
CVE-2022-341970.2960.095▲ 0.201

Emerging Critical CVEs

Supply Chain

GHSA-78v8-vpjp-cjqh · CVE-2026-47764 (pip)

PDM wheel installation leads to Path Traversal via overridden write_to_fs

GHSA-qvv5-jq5g-4cgg · CVE-2026-48063 (npm)

Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload

GHSA-542p-wvx7-72m4 · CVE-2026-48060 (pip)

Litestar has HTML Injection Through its CSRF Token

GHSA-cxh2-4639-vmc5 · CVE-2026-47701 (go)

OpenTelemetry Operator for Kubernetes’s ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth

GHSA-j9rx-rppg-6hh4 · CVE-2026-47253 (go)

Anyquery has Path Traversal through clear_plugin_cache, Allowing Arbitrary Directory Deletion

GHSA-cqgj-h8vf-4w59 · CVE-2025-53114 (maven)

Acknowledgement extension out of memory

GHSA-8qhj-4f8c-j8qg · CVE-2026-49396 (go)

Nezha has cross-site GET request that can trigger stored cron commands on a victim’s agents

GHSA-mqq6-462x-jxmm · CVE-2026-48031 (go)

Go Restful API Boilerplate: Hardcoded JWT Secret “random” Allows Token Forgery

GHSA-32g3-35g9-wc9g · CVE-2026-48036 (npm)

@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts

GHSA-2mxr-p26x-mj73 · CVE-2026-48035 (npm)

@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened

Ransomware Activity

55 new victim postings across 10 groups.

GroupVictimsSample
lockbit526centralromana.com.do, shougang.com.pe, stahlwille.nl, lbreng.com.br, santoinacio…
qilin17Bitek System, AltaVista Strategic Partners, Plaxen & Adler, Miller & Zois, Iliff…
akira3Port Air Express, The Midland Theatre, Associated Investor Services
krybit2libertyinsurance.com.ph, PROBE, S.A. DE C.V
play2Mundt and Associates, Rainbow Distributors USA
incransom1FIZA
lamashtu1PatayaFood
shinyhunters1Notice
spacebears1Cattani
worldleaks1Reliance Group

IOC Volume

1254 new IOCs in this window. By source:

SourceCount
urlhaus1050
misp204

Recent OSINT Events

No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).

Multi-Source IOCs

25 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.

IOCTypeSourcesLast seen
cloud55file.ccdomainmisp + urlhaus2026-06-11
edgeviewruntime.comdomainmisp + urlhaus2026-06-11
friendly-trifle-f3e6f0.netlify.appdomainmisp + urlhaus2026-06-11
host4file.ccdomainmisp + urlhaus2026-06-11
hubsecure.infodomainmisp + urlhaus2026-06-11
photo-62454.cfddomainmisp + urlhaus2026-06-11
04gzr1uh.alternatifdekorasyon.comdomainmisp + urlhaus2026-06-11
0frduisp.cloud-meridian.digitaldomainmisp + urlhaus2026-06-11
0gmqmb12.orbitaldockingmodule.digitaldomainmisp + urlhaus2026-06-11
0h5smwzp.network-forge.digitaldomainmisp + urlhaus2026-06-11
0nwfyg62.onja1bet.comdomainmisp + urlhaus2026-06-11
0q9bvoqh.telemetry-vault.digitaldomainmisp + urlhaus2026-06-11
0u9irsk6.luxerabet10.comdomainmisp + urlhaus2026-06-11
0zfu07h8.audioattenuatorschematic.digitaldomainmisp + urlhaus2026-06-11
102.220.160.85ip-dstmisp + urlhaus2026-06-11
107.182.128.214ip-dstmisp + urlhaus2026-06-11
107.182.128.215ip-dstmisp + urlhaus2026-06-11
107.182.128.217ip-dstmisp + urlhaus2026-06-11
107.182.128.220ip-dstmisp + urlhaus2026-06-11
107.182.128.221ip-dstmisp + urlhaus2026-06-11
107.182.128.222ip-dstmisp + urlhaus2026-06-11
107.182.128.67ip-dstmisp + urlhaus2026-06-11
107.182.128.69ip-dstmisp + urlhaus2026-06-11
107.182.128.70ip-dstmisp + urlhaus2026-06-11
107.182.128.74ip-dstmisp + urlhaus2026-06-11

MISP × KEV Correlation

No MISP events in this window referenced a CVE.

Cross-Reference

No recent SEC filings to cross-reference.

Intel Feeds

4 IOC feeds updated this run (11,418 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.

FeedSourceTypeCountDownloads
MISP — Suspicious Domainsmispdomain5,000CSV · MISP · STIX
MISP — Flagged IPsmispip1,099CSV · MISP · STIX
URLhaus — Malware Distribution URLsurlhausurl4,579CSV · MISP · STIX
URLhaus — Malware Distribution Domainsurlhausdomain740CSV · MISP · STIX

Hand-Authored Sigma

1 hand-authored TTP rule (1 production-ready, 0 scaffolds) live at https://thrunt.me/sigma/manifest.json.

RuleStatusYAML
T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaignreadyhttps://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml

Detection Gaps

20 of 155 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.

TechniqueNameMISPKEV CVEs
T1608.001Upload Malware011
T1011Exfiltration Over Other Network Medium04
T1497Virtualization/Sandbox Evasion04
T1037Boot or Logon Initialization Scripts03
T1573.001Symmetric Cryptography03
T1001Data Obfuscation02
T1499.002Service Exhaustion Flood02
T1530Data from Cloud Storage02
T1584.005Botnet02
T1592Gather Victim Host Information02

…and 10 more below the cut — full list on the rollup.

Pipeline Health

All feeds healthy.


Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).

Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.