June 11, 2026 · Applied Cybernetics Group
Morning Brief — June 11, 2026
Morning Brief — 2026-06-11
6 exploit probability movers, 10 emerging critical cves, 10 supply chain, 55 ransomware activity, 1254 ioc volume, 25 multi-source iocs, 4 intel feeds, 1 hand-authored sigma, and 20 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
No new Item 1.05 8-K filings in this window.
Federal Patching Priority
No new KEV additions in this window.
Exploit Probability Movers
| CVE | Today | Prev | Δ | In KEV |
|---|---|---|---|---|
CVE-1999-0512 | 0.659 | 0.004 | ▲ 0.655 | |
CVE-2004-2466 | 0.778 | 0.445 | ▲ 0.333 | |
CVE-2022-1711 | 0.844 | 0.539 | ▲ 0.304 | |
CVE-2026-5073 | 0.245 | 0.001 | ▲ 0.244 | |
CVE-2026-7473 | 0.225 | 0.000 | ▲ 0.224 | ✓ |
CVE-2022-34197 | 0.296 | 0.095 | ▲ 0.201 |
Emerging Critical CVEs
CVE-2026-46695· CRITICAL (10.0) · 2026-06-10 — Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not restrict the kernel capa…CVE-2026-50566· CRITICAL (9.9) · 2026-06-10 — Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a tenant with environments.fission.io create/update R…CVE-2026-50564· CRITICAL (9.9) · 2026-06-10 — Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission’s Environment CRD exposes spec.runtime.podSpe…CVE-2026-50563· CRITICAL (9.9) · 2026-06-10 — Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission’s Container Executor path lets a tenant suppl…CVE-2026-50545· CRITICAL (9.9) · 2026-06-10 — Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Environment.spec.runtime.podSpec / spec.builder.p…CVE-2026-45558· CRITICAL (9.9) · 2026-06-10 — Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoints (POST /api/service/haproxy/<server_id>/section/<section_type> and t…CVE-2026-45556· CRITICAL (9.9) · 2026-06-10 — Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf//<server_ip>/rule/<rule_id>/save accepts a config_file_name form field that is pass… CVE-2026-45552· CRITICAL (9.9) · 2026-06-10 — Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/routes/install/routes.py:…CVE-2026-35273· CRITICAL (9.8) · 2026-06-11 — Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability al…CVE-2026-46614· CRITICAL (9.8) · 2026-06-10 — Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.23.0, the Fission router registers an internal-style route…
Supply Chain
GHSA-78v8-vpjp-cjqh · CVE-2026-47764 (pip)
- HIGH · 2026-06-10
- Affected:
pdm - https://github.com/advisories/GHSA-78v8-vpjp-cjqh
PDM wheel installation leads to Path Traversal via overridden write_to_fs
GHSA-qvv5-jq5g-4cgg · CVE-2026-48063 (npm)
- CRITICAL · 2026-06-10
- Affected:
baileys,@whiskeysockets/baileys,baileys - https://github.com/advisories/GHSA-qvv5-jq5g-4cgg
Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload
GHSA-542p-wvx7-72m4 · CVE-2026-48060 (pip)
- HIGH · CVSS 8.1 · 2026-06-10
- Affected:
litestar - https://github.com/advisories/GHSA-542p-wvx7-72m4
Litestar has HTML Injection Through its CSRF Token
GHSA-cxh2-4639-vmc5 · CVE-2026-47701 (go)
- HIGH · CVSS 7.7 · 2026-06-10
- Affected:
github.com/open-telemetry/opentelemetry-operator - https://github.com/advisories/GHSA-cxh2-4639-vmc5
OpenTelemetry Operator for Kubernetes’s ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth
GHSA-j9rx-rppg-6hh4 · CVE-2026-47253 (go)
- HIGH · CVSS 7.3 · 2026-06-10
- Affected:
github.com/julien040/anyquery - https://github.com/advisories/GHSA-j9rx-rppg-6hh4
Anyquery has Path Traversal through clear_plugin_cache, Allowing Arbitrary Directory Deletion
GHSA-cqgj-h8vf-4w59 · CVE-2025-53114 (maven)
- HIGH · CVSS 7.5 · 2026-06-10
- Affected:
org.cometd.java:cometd-java-server-common,org.cometd.java:cometd-java-server-common,org.cometd.java:cometd-java-server-common - https://github.com/advisories/GHSA-cqgj-h8vf-4w59
Acknowledgement extension out of memory
GHSA-8qhj-4f8c-j8qg · CVE-2026-49396 (go)
- HIGH · CVSS 7.1 · 2026-06-10
- Affected:
github.com/nezhahq/nezha - https://github.com/advisories/GHSA-8qhj-4f8c-j8qg
Nezha has cross-site GET request that can trigger stored cron commands on a victim’s agents
GHSA-mqq6-462x-jxmm · CVE-2026-48031 (go)
- CRITICAL · CVSS 9.1 · 2026-06-10
- Affected:
github.com/dhax/go-base - https://github.com/advisories/GHSA-mqq6-462x-jxmm
Go Restful API Boilerplate: Hardcoded JWT Secret “random” Allows Token Forgery
GHSA-32g3-35g9-wc9g · CVE-2026-48036 (npm)
- HIGH · 2026-06-10
- Affected:
@hulumi/drift - https://github.com/advisories/GHSA-32g3-35g9-wc9g
@hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts
GHSA-2mxr-p26x-mj73 · CVE-2026-48035 (npm)
- HIGH · 2026-06-10
- Affected:
@hulumi/baseline - https://github.com/advisories/GHSA-2mxr-p26x-mj73
@hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened
Ransomware Activity
55 new victim postings across 10 groups.
| Group | Victims | Sample |
|---|---|---|
lockbit5 | 26 | centralromana.com.do, shougang.com.pe, stahlwille.nl, lbreng.com.br, santoinacio… |
qilin | 17 | Bitek System, AltaVista Strategic Partners, Plaxen & Adler, Miller & Zois, Iliff… |
akira | 3 | Port Air Express, The Midland Theatre, Associated Investor Services |
krybit | 2 | libertyinsurance.com.ph, PROBE, S.A. DE C.V |
play | 2 | Mundt and Associates, Rainbow Distributors USA |
incransom | 1 | FIZA |
lamashtu | 1 | PatayaFood |
shinyhunters | 1 | Notice |
spacebears | 1 | Cattani |
worldleaks | 1 | Reliance Group |
IOC Volume
1254 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 1050 |
misp | 204 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Multi-Source IOCs
25 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
cloud55file.cc | domain | misp + urlhaus | 2026-06-11 |
edgeviewruntime.com | domain | misp + urlhaus | 2026-06-11 |
friendly-trifle-f3e6f0.netlify.app | domain | misp + urlhaus | 2026-06-11 |
host4file.cc | domain | misp + urlhaus | 2026-06-11 |
hubsecure.info | domain | misp + urlhaus | 2026-06-11 |
photo-62454.cfd | domain | misp + urlhaus | 2026-06-11 |
04gzr1uh.alternatifdekorasyon.com | domain | misp + urlhaus | 2026-06-11 |
0frduisp.cloud-meridian.digital | domain | misp + urlhaus | 2026-06-11 |
0gmqmb12.orbitaldockingmodule.digital | domain | misp + urlhaus | 2026-06-11 |
0h5smwzp.network-forge.digital | domain | misp + urlhaus | 2026-06-11 |
0nwfyg62.onja1bet.com | domain | misp + urlhaus | 2026-06-11 |
0q9bvoqh.telemetry-vault.digital | domain | misp + urlhaus | 2026-06-11 |
0u9irsk6.luxerabet10.com | domain | misp + urlhaus | 2026-06-11 |
0zfu07h8.audioattenuatorschematic.digital | domain | misp + urlhaus | 2026-06-11 |
102.220.160.85 | ip-dst | misp + urlhaus | 2026-06-11 |
107.182.128.214 | ip-dst | misp + urlhaus | 2026-06-11 |
107.182.128.215 | ip-dst | misp + urlhaus | 2026-06-11 |
107.182.128.217 | ip-dst | misp + urlhaus | 2026-06-11 |
107.182.128.220 | ip-dst | misp + urlhaus | 2026-06-11 |
107.182.128.221 | ip-dst | misp + urlhaus | 2026-06-11 |
107.182.128.222 | ip-dst | misp + urlhaus | 2026-06-11 |
107.182.128.67 | ip-dst | misp + urlhaus | 2026-06-11 |
107.182.128.69 | ip-dst | misp + urlhaus | 2026-06-11 |
107.182.128.70 | ip-dst | misp + urlhaus | 2026-06-11 |
107.182.128.74 | ip-dst | misp + urlhaus | 2026-06-11 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No recent SEC filings to cross-reference.
Intel Feeds
4 IOC feeds updated this run (11,418 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| MISP — Suspicious Domains | misp | domain | 5,000 | CSV · MISP · STIX |
| MISP — Flagged IPs | misp | ip | 1,099 | CSV · MISP · STIX |
| URLhaus — Malware Distribution URLs | urlhaus | url | 4,579 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 740 | CSV · MISP · STIX |
Hand-Authored Sigma
1 hand-authored TTP rule (1 production-ready, 0 scaffolds) live at https://thrunt.me/sigma/manifest.json.
| Rule | Status | YAML |
|---|---|---|
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | ready | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
Detection Gaps
20 of 155 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | MISP | KEV CVEs |
|---|---|---|---|
T1608.001 | Upload Malware | 0 | 11 |
T1011 | Exfiltration Over Other Network Medium | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | 0 | 4 |
T1037 | Boot or Logon Initialization Scripts | 0 | 3 |
T1573.001 | Symmetric Cryptography | 0 | 3 |
T1001 | Data Obfuscation | 0 | 2 |
T1499.002 | Service Exhaustion Flood | 0 | 2 |
T1530 | Data from Cloud Storage | 0 | 2 |
T1584.005 | Botnet | 0 | 2 |
T1592 | Gather Victim Host Information | 0 | 2 |
…and 10 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.