September 22, 2026 · Applied Cybernetics Group
Morning Brief — September 22, 2026
Morning Brief — 2026-09-22
2 material breach disclosures, 1 federal patching priority, 20 exploit probability movers, 10 emerging critical cves, 3 supply chain, 28 ransomware activity, 1195 ioc volume, 12 active malware families, 3 multi-source iocs, 2 intel feeds, 18 hand-authored sigma, and 18 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
Nutex Health Inc. (NUTX)
- Filed: 2026-09-11 · CIK 0001479681 · Accession
0001628280-26-061432 - Filing: https://www.sec.gov/Archives/edgar/data/1479681/000162828026061432/materiality_assessmentxupd.htm
Forward-Looking StatementsCertain statements and information included in this press release constitute “forward-looking statements” within the meaning of the Private Securities Litigation Reform Act of 1995. When used in this press release, the words or phrases “will,” “will likely result,” “expected to,” “will continue,” “anticipated,” “estimate,” “projected,” “intend,” “goal,” or similar express…
BOSTON SCIENTIFIC CORP (BSX)
- Filed: 2026-09-08 · CIK 0000885725 · Accession
0000885725-26-000059 - Filing: https://www.sec.gov/Archives/edgar/data/885725/000088572526000059/bsx-20260907.htm
As previously disclosed in a Current Report on Form 8-K filed on August 26, 2026 with the Securities and Exchange Commission, on August 25, 2026, Boston Scientific Corporation (the “Company”) identified a cybersecurity incident that affected certain of its information technology systems and resulted in a global disruption to the Company’s operations. Upon detection, the Company activated its incid…
Federal Patching Priority
CVE-2026-7273 — Zyxel GS1900 Series Switches
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
- Added: 2026-09-21 · Federal due: 2026-09-24 · EPSS 24.6th pct (score 0.003) · CVSS 8.8 (HIGH) · CWE-121
- ransomware use: Unknown
Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
Exploit Probability Movers
| CVE | Today | Prev | Δ | In KEV |
|---|---|---|---|---|
CVE-2016-3251 | 0.034 | 0.581 | ▼ 0.546 | |
CVE-2017-3191 | 0.141 | 0.625 | ▼ 0.484 | |
CVE-2026-58644 | 0.609 | 0.159 | ▲ 0.451 | ✓ |
CVE-2018-0258 | 0.062 | 0.482 | ▼ 0.420 | |
CVE-2017-9829 | 0.276 | 0.687 | ▼ 0.412 | |
CVE-2018-3924 | 0.030 | 0.441 | ▼ 0.411 | |
CVE-2016-3272 | 0.032 | 0.433 | ▼ 0.401 | |
CVE-2019-7111 | 0.161 | 0.559 | ▼ 0.398 | |
CVE-2016-6603 | 0.488 | 0.870 | ▼ 0.382 | |
CVE-2018-16283 | 0.251 | 0.631 | ▼ 0.379 | |
CVE-2015-5259 | 0.194 | 0.570 | ▼ 0.377 | |
CVE-2017-6343 | 0.228 | 0.603 | ▼ 0.376 | |
CVE-2018-18990 | 0.026 | 0.395 | ▼ 0.369 | |
CVE-2018-11714 | 0.319 | 0.681 | ▼ 0.361 | |
CVE-2017-6360 | 0.305 | 0.661 | ▼ 0.356 | |
CVE-2019-9733 | 0.174 | 0.529 | ▼ 0.355 | |
CVE-2016-4264 | 0.342 | 0.690 | ▼ 0.349 | |
CVE-2018-11139 | 0.775 | 0.429 | ▲ 0.346 | |
CVE-2018-11132 | 0.525 | 0.183 | ▲ 0.342 | |
CVE-2017-14942 | 0.268 | 0.609 | ▼ 0.340 |
Emerging Critical CVEs
CVE-2026-93952· CRITICAL (10.0) · 2026-09-22 — VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confi…CVE-2026-94493· CRITICAL (10.0) · 2026-09-22 — A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in missing authentica…CVE-2026-77521· CRITICAL (10.0) · 2026-09-21 — MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding…CVE-2026-79920· CRITICAL (9.9) · 2026-09-21 — Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py wi…CVE-2026-19658· CRITICAL (9.8) · 2026-09-22 — The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input . This makes it possible for unauthenticated attackers to in…CVE-2026-13355· CRITICAL (9.8) · 2026-09-22 — The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-fro…CVE-2026-85751· CRITICAL (9.8) · 2026-09-21 — Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a clie…CVE-2026-94301· CRITICAL (9.8) · 2026-09-21 — The fix for CVE-2026-47065/ZDRES-232 (“resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy”), released on 2026-06-02 and announced as “Fully addressed” in MINA 2.2.8, 2.1.13 and 2.…CVE-2026-58491· CRITICAL (9.3) · 2026-09-21 — Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso…CVE-2026-79916· CRITICAL (9.1) · 2026-09-21 — MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields that _update_aws_credent…
Supply Chain
GHSA-pxcx-fv34-x9p5 · CVE-2026-61628 (go)
- HIGH · CVSS 8.1 · 2026-09-21
- Affected:
github.com/lucasdillmann/nginx-ignition - https://github.com/advisories/GHSA-pxcx-fv34-x9p5
nginx ignition has Unauthenticated Admin Account Creation via Onboarding Race Condition
GHSA-jr34-h97m-9hpx · CVE-2026-61629 (go)
- HIGH · CVSS 7.5 · 2026-09-21
- Affected:
github.com/lucasdillmann/nginx-ignition - https://github.com/advisories/GHSA-jr34-h97m-9hpx
nginx ignition has ParseAcceptLanguage _ separator bypass that enables ~75x CPU amplification via Accept-Language header in i18nMiddleware
GHSA-phg3-3g28-wq9v · CVE-2026-61687 (go)
- HIGH · CVSS 7.1 · 2026-09-21
- Affected:
hatchet - https://github.com/advisories/GHSA-phg3-3g28-wq9v
Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState
Ransomware Activity
28 new victim postings across 16 groups.
| Group | Victims | Sample |
|---|---|---|
metaencryptor | 6 | Astemo, Ltd., Hudson MD Group, LLC, Bruker Corporation, Flex Ltd, HyVision Syste… |
Storm | 3 | The Money Store, TrueCore Behavioral Solutions, Manroc Developments |
termite | 3 | Sealcon, TruAmerica Multifamily, theLender |
Global Secret Group | 2 | Allied Supply Co., Kjla |
nightspire | 2 | 360 Consulenza S.r.l., Spo**** Schools |
play | 2 | Metallco, Hurley |
Doommageddon | 1 | Charlottesville Police Department |
N0n | 1 | FinSoft (Kolibri retail back-office software) |
SilentRansomGroup | 1 | Hogan Lovells Cadwalader |
akira | 1 | Prestige Management |
anubis | 1 | Summa Gold |
moneymessage | 1 | U.S. Electrical Services and Wiedenbach Brown |
qilin | 1 | Telrad Networks |
secp0 | 1 | NAI Earle Furman |
thegentlemen | 1 | Grupolider |
unsafe | 1 | kyyba.com |
IOC Volume
1195 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 1195 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Active Malware Families
12 malware families active this week (1 corroborated across ≥2 sources), exercising 16 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| AMOS (Atomic macOS Stealer) | stealer | ✓ | 12 | T1005, T1056.002, T1071, T1555.001 |
| Mirai | botnet | — | 1,742 | T1110, T1498, T1499, T1584.005 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 26 | T1219 |
| ClickFix | delivery → | — | 25 | T1059.001, T1204 |
| CoinMiner | miner | — | 14 | T1496 |
| MassLogger | stealer | — | 4 | T1056.001, T1071, T1555 |
| SilverFox | rat | — | 4 | T1059, T1071, T1219 |
| DDoSAgent | ddos | — | 2 | T1498, T1499 |
| AgentTesla | stealer | — | 1 | T1056.001, T1071, T1114, T1555 |
| Formbook | stealer | — | 1 | T1005, T1056.001, T1071, T1555 |
| Lumma | stealer | — | 1 | T1005, T1071, T1555 |
| Stealc | stealer | — | 1 | T1005, T1071, T1555 |
Families marked ”→” are delivery/social-engineering clusters (ClickFix). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
3 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
implantdentistrytx.com | domain | misp + urlhaus | 2026-09-22 |
nova-client.com | domain | misp + urlhaus | 2026-09-22 |
odinclient.com | domain | misp + urlhaus | 2026-09-22 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No SEC × KEV vendor token matches in this window. (This is a heuristic surface, absence is expected most days.)
Intel Feeds
2 IOC feeds updated this run (4,131 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| URLhaus — Malware Distribution URLs | urlhaus | url | 4,027 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 104 | CSV · MISP · STIX |
Hand-Authored Sigma
16 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Host | experimental | https://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml |
| T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Process | experimental | https://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1098.005 Okta Verify Enrollment from a Hypervisor Guest | experimental | https://thrunt.me/sigma/t1098-005-hypervisor-mfa-device-enrollment.yml |
| T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnet | experimental | https://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml |
| T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Container | experimental | https://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml |
| T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml |
| T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml |
| T1557 Okta Authentication or MFA via a Remote-Desktop / Proxy / Tor Tunnel | experimental | https://thrunt.me/sigma/t1557-aitm-cross-asn-session-mfa.yml |
| T1557 Claims Kit First-Party Exfil — X-Enc Single-Letter C2 | experimental | https://thrunt.me/sigma/t1557-claims-kit-single-letter-c2-xenc.yml |
| T1557 Okta Verify SVG Asset Served by a Non-Okta Host | experimental | https://thrunt.me/sigma/t1557-non-okta-host-oktaverify-svg.yml |
| T1557 reCAPTCHA-Skinned Cloudflare Turnstile Gate | experimental | https://thrunt.me/sigma/t1557-recaptcha-skinned-turnstile-gate.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Path | experimental | https://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml |
| T1583.001 Resolution of a ShinyHunters .claims Impersonation Domain | experimental | https://thrunt.me/sigma/t1583-001-claims-registration-conjunction.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
18 of 160 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1573.001 | Symmetric Cryptography | — | 1 | 3 |
T1562 | — | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 8 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.