September 23, 2026 · Applied Cybernetics Group
Morning Brief — September 23, 2026
Morning Brief — 2026-09-23
1 material breach disclosures, 4 federal patching priority, 20 exploit probability movers, 10 emerging critical cves, 10 supply chain, 32 ransomware activity, 880 ioc volume, 13 active malware families, 3 multi-source iocs, 2 intel feeds, 18 hand-authored sigma, and 18 detection gaps. Sections with no signal are still rendered with an explicit “none in this window” note so absence is visible alongside presence.
Material Breach Disclosures
Nutex Health Inc. (NUTX)
- Filed: 2026-09-11 · CIK 0001479681 · Accession
0001628280-26-061432 - Filing: https://www.sec.gov/Archives/edgar/data/1479681/000162828026061432/materiality_assessmentxupd.htm
Forward-Looking StatementsCertain statements and information included in this press release constitute “forward-looking statements” within the meaning of the Private Securities Litigation Reform Act of 1995. When used in this press release, the words or phrases “will,” “will likely result,” “expected to,” “will continue,” “anticipated,” “estimate,” “projected,” “intend,” “goal,” or similar express…
Federal Patching Priority
CVE-2026-93952 — Arista VeloCloud Orchestrator
Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
- Added: 2026-09-22 · Federal due: 2026-09-25 · EPSS 36.3th pct (score 0.004) · CVSS 10.0 (CRITICAL) · CWE-20
- ransomware use: Unknown
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been…
CVE-2026-85102 — Check Point Multiple Products
Check Point Multiple Products Improper Certificate Validation Vulnerability
- Added: 2026-09-22 · Federal due: 2026-09-25 · EPSS 26.3th pct (score 0.003) · CVSS 9.8 (CRITICAL) · CWE-295
- ransomware use: Unknown
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
CVE-2026-94127 — F5 BIG-IP APM
F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
- Added: 2026-09-22 · Federal due: 2026-09-25 · CVSS 9.8 (CRITICAL) · CWE-122
- ransomware use: Unknown
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected…
CVE-2026-93616 — Check Point Multiple Products
Check Point Multiple Products Path Traversal Vulnerability
- Added: 2026-09-22 · Federal due: 2026-09-25 · CVSS 9.8 (CRITICAL) · CWE-22
- ransomware use: Unknown
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
Exploit Probability Movers
| CVE | Today | Prev | Δ | In KEV |
|---|---|---|---|---|
CVE-2016-3251 | 0.581 | 0.034 | ▲ 0.546 | |
CVE-2017-3191 | 0.625 | 0.141 | ▲ 0.484 | |
CVE-2018-0258 | 0.482 | 0.062 | ▲ 0.420 | |
CVE-2017-9829 | 0.687 | 0.276 | ▲ 0.412 | |
CVE-2018-3924 | 0.441 | 0.030 | ▲ 0.411 | |
CVE-2016-3272 | 0.433 | 0.032 | ▲ 0.401 | |
CVE-2019-7111 | 0.559 | 0.161 | ▲ 0.398 | |
CVE-2016-6603 | 0.870 | 0.488 | ▲ 0.382 | |
CVE-2018-16283 | 0.631 | 0.251 | ▲ 0.379 | |
CVE-2015-5259 | 0.570 | 0.194 | ▲ 0.377 | |
CVE-2017-6343 | 0.603 | 0.228 | ▲ 0.376 | |
CVE-2018-18990 | 0.395 | 0.026 | ▲ 0.369 | |
CVE-2018-11714 | 0.681 | 0.319 | ▲ 0.361 | |
CVE-2017-6360 | 0.661 | 0.305 | ▲ 0.356 | |
CVE-2019-9733 | 0.529 | 0.174 | ▲ 0.355 | |
CVE-2016-4264 | 0.690 | 0.342 | ▲ 0.349 | |
CVE-2018-11139 | 0.429 | 0.775 | ▼ 0.346 | |
CVE-2018-11132 | 0.183 | 0.525 | ▼ 0.342 | |
CVE-2017-14942 | 0.609 | 0.268 | ▲ 0.340 | |
CVE-2018-8033 | 0.257 | 0.596 | ▼ 0.339 |
Emerging Critical CVEs
CVE-2026-96257· CRITICAL (10.0) · 2026-09-23 — A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. Executing a manipulation can lead to stack-based buffer ove…CVE-2026-75745· CRITICAL (10.0) · 2026-09-22 — Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to…CVE-2026-89275· CRITICAL (10.0) · 2026-09-22 — Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code (‘Code Injection’) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could e…CVE-2026-84412· CRITICAL (10.0) · 2026-09-22 — Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code (‘Code Injection’) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could e…CVE-2026-77244· CRITICAL (10.0) · 2026-09-22 — MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a verified user identity and downstream fetcher constructi…CVE-2026-75723· CRITICAL (10.0) · 2026-09-22 — Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execu…CVE-2026-75721· CRITICAL (10.0) · 2026-09-22 — Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code (‘Code Injection’) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could e…CVE-2026-75703· CRITICAL (10.0) · 2026-09-22 — Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code (‘Code Injection’) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could e…CVE-2026-75699· CRITICAL (10.0) · 2026-09-22 — Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code (‘Code Injection’) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could e…CVE-2026-73369· CRITICAL (10.0) · 2026-09-22 — Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code (‘Code Injection’) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could e…
Supply Chain
GHSA-wx4m-69m9-gx3m · CVE-2026-91130 (pip)
- CRITICAL · 2026-09-22
- Affected:
homeassistant - https://github.com/advisories/GHSA-wx4m-69m9-gx3m
Home Assistant: XSS in Statistics Graph Card
GHSA-xj3h-wwxq-gfcj · CVE-2026-77633 (go)
- HIGH · CVSS 7.1 · 2026-09-22
- Affected:
github.com/cloudreve/Cloudreve/v4 - https://github.com/advisories/GHSA-xj3h-wwxq-gfcj
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service
GHSA-4825-p4xm-pcf2 · CVE-2026-94462 (rubygems)
- HIGH · CVSS 7.1 · 2026-09-22
- Affected:
spree_api,spree_api - https://github.com/advisories/GHSA-4825-p4xm-pcf2
Spree: Broken Access Control in PATCH /api/v3/store/carts/:id/associate (IDOR)
GHSA-vv3m-f8x4-7377 · CVE-2026-85740 (pip)
- HIGH · CVSS 7.1 · 2026-09-22
- Affected:
lightrag-hku - https://github.com/advisories/GHSA-vv3m-f8x4-7377
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
GHSA-frch-4w6v-q5xx · CVE-2026-85734 (pip)
- CRITICAL · CVSS 9.1 · 2026-09-22
- Affected:
lightrag-hku - https://github.com/advisories/GHSA-frch-4w6v-q5xx
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
GHSA-vxg7-f2jj-jmqm · CVE-2026-76819 (go)
- HIGH · CVSS 8.6 · 2026-09-22
- Affected:
github.com/projectdiscovery/nuclei/v3 - https://github.com/advisories/GHSA-vxg7-f2jj-jmqm
Nuclei: Arbitrary Code Execution via Goja JavaScript Engine Vulnerability
GHSA-328g-jx67-v94g · CVE-2026-77560 (go)
- HIGH · CVSS 8.1 · 2026-09-22
- Affected:
github.com/tinyauthapp/tinyauth - https://github.com/advisories/GHSA-328g-jx67-v94g
Tinyauth: forward-auth per-app ACL is matched case-sensitively against the (case-insensitive) hostname, letting an authenticated user reach apps they are not on the allowlist for
GHSA-5jpj-293f-rhvj · CVE-2026-62371 (go)
- HIGH · CVSS 8.8 · 2026-09-22
- Affected:
github.com/kubeedge/kubeedge,github.com/kubeedge/kubeedge,github.com/kubeedge/kubeedge - https://github.com/advisories/GHSA-5jpj-293f-rhvj
KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API
GHSA-9vm9-pqxx-x83v · CVE-2026-62369 (go)
- HIGH · CVSS 8.1 · 2026-09-22
- Affected:
github.com/kubeedge/kubeedge,github.com/kubeedge/kubeedge,github.com/kubeedge/kubeedge - https://github.com/advisories/GHSA-9vm9-pqxx-x83v
KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join
GHSA-34fc-gh42-pj53 · CVE-2026-63132 (go)
- CRITICAL · 2026-09-22
- Affected:
github.com/openbao/openbao,github.com/openbao/openbao - https://github.com/advisories/GHSA-34fc-gh42-pj53
OpenBao’s Recovery Mode Vulnerable To Token Leakage via Timing Attack
Ransomware Activity
32 new victim postings across 13 groups.
| Group | Victims | Sample |
|---|---|---|
settra | 6 | universalautogroup.com, namtheun2.com, lakebeverage.com, quantummarketing-group.… |
SilentRansomGroup | 5 | W… B…, Clark Hill, B…, Cozen O’Connor, W… |
akira | 3 | Coe Press Equipment, TDMI, DI.C.S.EL. S.R.L. |
medusalocker | 3 | Aokkef, Seznam, Abv |
qilin | 3 | The Fifty/50, Textile City, Columbus Informatica |
AuditTeam | 2 | vit.ac.in, Pr***IT |
Booba Project | 2 | Tulare Western High School, GOTTHELF |
shinyhunters | 2 | Fresenius Medical Care, PSA - READ THIS NOW |
titan | 2 | Grupo Hospifar S.R.L., Sherman Chan, DDS, Inc. |
N0n | 1 | AFRICA-TECH (IT services / document processing) |
anubis | 1 | Gaedke & Partner Steuerberatung |
emperador | 1 | RECEITA FEDERAL DO BRASIL |
kairos | 1 | Krapf Group |
IOC Volume
880 new IOCs in this window. By source:
| Source | Count |
|---|---|
urlhaus | 880 |
Recent OSINT Events
No curated MISP events in this window (bulk-IOC contributions tallied in IOC Volume).
Active Malware Families
13 malware families active this week (1 corroborated across ≥2 sources), exercising 17 ATT&CK techniques. Family is the unit, not the indicator: the raw IOCs are drill-down evidence below, not the signal.
| Family | Type | Corrob. | IOCs | Techniques (✗ = coverage gap) |
|---|---|---|---|---|
| AMOS (Atomic macOS Stealer) | stealer | ✓ | 12 | T1005, T1056.002, T1071, T1555.001 |
| Mirai | botnet | — | 1,913 | T1110, T1498, T1499, T1584.005 |
| ClickFix | delivery → | — | 26 | T1059.001, T1204 |
| ConnectWise ScreenConnect (abuse) | rmm-abuse | — | 25 | T1219 |
| CoinMiner | miner | — | 10 | T1496 |
| AgentTesla | stealer | — | 9 | T1056.001, T1071, T1114, T1555 |
| ClearFake | delivery → | — | 2 | T1059.001, T1189, T1204 |
| MassLogger | stealer | — | 2 | T1056.001, T1071, T1555 |
| SilverFox | rat | — | 2 | T1059, T1071, T1219 |
| DDoSAgent | ddos | — | 1 | T1498, T1499 |
| Formbook | stealer | — | 1 | T1005, T1056.001, T1071, T1555 |
| Lumma | stealer | — | 1 | T1005, T1071, T1555 |
| Stealc | stealer | — | 1 | T1005, T1071, T1555 |
Families marked ”→” are delivery/social-engineering clusters (ClickFix, ClearFake). Their technique mappings are the delivery chain — downstream behavior is payload-dependent, so they don’t open a hard coverage gap on their own.
Multi-Source IOCs
3 IOCs flagged by 2+ independent sources this window — the highest-confidence signal the cross-feed corpus produces.
| IOC | Type | Sources | Last seen |
|---|---|---|---|
amc-us.mprevive.com | domain | misp + urlhaus | 2026-09-23 |
implantdentistrytx.com | domain | misp + urlhaus | 2026-09-23 |
webhook.site | domain | misp + urlhaus | 2026-09-23 |
MISP × KEV Correlation
No MISP events in this window referenced a CVE.
Cross-Reference
No SEC × KEV vendor token matches in this window. (This is a heuristic surface, absence is expected most days.)
Intel Feeds
2 IOC feeds updated this run (4,233 indicators total) — each available as CSV, MISP JSON, and STIX 2.1. Subscribe at https://thrunt.me/intel/manifest.json.
| Feed | Source | Type | Count | Downloads |
|---|---|---|---|---|
| URLhaus — Malware Distribution URLs | urlhaus | url | 4,148 | CSV · MISP · STIX |
| URLhaus — Malware Distribution Domains | urlhaus | domain | 85 | CSV · MISP · STIX |
Hand-Authored Sigma
16 production-ready TTP rules (+2 scaffolds in the authoring queue) live at https://thrunt.me/sigma/manifest.json. Subscribe via https://thrunt.me/sigma/rules.lock.json (content-hash churn) or pull all with https://thrunt.me/sigma/rules.tar.gz.
| Rule | Status | YAML |
|---|---|---|
| T1037 Boot or Logon Initialization Scripts — Linux Init Script Modification | experimental | https://thrunt.me/sigma/t1037-linux-init-script-modification.yml |
| T1055 Process Injection — Rundll32 Spawning Explorer as an Injection Host | experimental | https://thrunt.me/sigma/t1055-rundll32-spawning-explorer-injection.yml |
| T1071.004 DNS-over-HTTPS Resolution from a Non-Browser Process | experimental | https://thrunt.me/sigma/t1071-004-doh-resolver-non-browser-c2.yml |
| T1098.004 Account Manipulation — SSH Authorized Keys File Modification | experimental | https://thrunt.me/sigma/t1098-004-ssh-authorized-keys-write.yml |
| T1098.005 Okta Verify Enrollment from a Hypervisor Guest | experimental | https://thrunt.me/sigma/t1098-005-hypervisor-mfa-device-enrollment.yml |
| T1102.001 Dead Drop Resolver — EtherHiding Payload Retrieval from BNB Smart Chain Testnet | experimental | https://thrunt.me/sigma/t1102-001-etherhiding-bsc-testnet-dead-drop.yml |
| T1195.002 Compromise Software Supply Chain — Malicious Google Tag Manager Container | experimental | https://thrunt.me/sigma/t1195-002-unapproved-gtm-container-injection.yml |
| T1204.004 Malicious Copy and Paste — ClickFix macOS Terminal Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-macos-terminal-execution.yml |
| T1204.004 Malicious Copy and Paste — ClickFix Run Dialog Execution | experimental | https://thrunt.me/sigma/t1204-004-clickfix-run-dialog-execution.yml |
| T1557 Okta Authentication or MFA via a Remote-Desktop / Proxy / Tor Tunnel | experimental | https://thrunt.me/sigma/t1557-aitm-cross-asn-session-mfa.yml |
| T1557 Claims Kit First-Party Exfil — X-Enc Single-Letter C2 | experimental | https://thrunt.me/sigma/t1557-claims-kit-single-letter-c2-xenc.yml |
| T1557 Okta Verify SVG Asset Served by a Non-Okta Host | experimental | https://thrunt.me/sigma/t1557-non-okta-host-oktaverify-svg.yml |
| T1557 reCAPTCHA-Skinned Cloudflare Turnstile Gate | experimental | https://thrunt.me/sigma/t1557-recaptcha-skinned-turnstile-gate.yml |
| T1566.002 Spearphishing Link — Luxembourg Hospitality SMS Phishing Campaign | experimental | https://thrunt.me/sigma/t1566-002-luxembourg-hospitality-sms-phish.yml |
| T1574.002 DLL Side-Loading — Signed javac.exe Loading jli.dll from a User-Writable Path | experimental | https://thrunt.me/sigma/t1574-002-signed-javac-sideload-jli.yml |
| T1583.001 Resolution of a ShinyHunters .claims Impersonation Domain | experimental | https://thrunt.me/sigma/t1583-001-claims-registration-conjunction.yml |
| T1003.008 OS Credential Dumping — /etc/shadow and /etc/gshadow Access | draft | https://thrunt.meundefined |
| T1530 Data from Cloud Storage — Detection | draft | https://thrunt.meundefined |
Detection Gaps
18 of 160 techniques with corpus signal have zero detection coverage — no SigmaHQ community rule, no thrunt rule. This is the hand-authoring queue; the live view is at https://thrunt.me/corpus/attck/.
| Technique | Name | Active families | MISP | KEV |
|---|---|---|---|---|
T1011 | Exfiltration Over Other Network Medium | — | 0 | 4 |
T1497 | Virtualization/Sandbox Evasion | — | 0 | 4 |
T1573.001 | Symmetric Cryptography | — | 1 | 3 |
T1562 | — | — | 0 | 3 |
T1001 | Data Obfuscation | — | 0 | 2 |
T1499.002 | Service Exhaustion Flood | — | 0 | 2 |
T1530 | Data from Cloud Storage | — | 0 | 2 |
T1562.001 | — | — | 0 | 2 |
T1003.008 | /etc/passwd and /etc/shadow | — | 0 | 1 |
T1070.001 | — | — | 0 | 1 |
…and 8 more below the cut — full list on the rollup.
Pipeline Health
All feeds healthy.
Sources: SEC EDGAR (public domain), CISA Known Exploited Vulnerabilities (public domain), FIRST.org EPSS (per ToS), NIST NVD (public domain), GitHub Security Advisories (per ToS), abuse.ch URLhaus (CC0, attribution), ransomware.live (per ToS), MITRE ATT&CK (CC BY 4.0).
Published by Applied Cybernetics Group via thrunt.me. Heuristic cross-references are labelled as such; verify before action.