Threat Hunt Feed (2026-05-02)
Hacker News: Best
- Police Have Used License Plate Readers at Least 14x to Stalk Romantic Interests — Fri, 01 May 2026 16:17:55 +0000
- Matched TTPs: At (T1053.002)
- Show HN: WhatCable, a tiny menu bar app for inspecting USB-C cables — Fri, 01 May 2026 08:43:45 +0000
- Matched TTPs: Keychain (T1555.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- LinkedIn is scanning browser extensions — Thu, 30 Apr 2026 19:40:20 +0000
- Matched TTPs: JavaScript (T1059.007), Hardware (T1592.001), Browser Extensions (T1176.001), Tool (T1588.002), Software (T1592.002), At (T1053.002)
- For Linux kernel vulnerabilities, there is no heads-up to distributions — Thu, 30 Apr 2026 16:43:47 +0000
- Matched TTPs: Pluggable Authentication Modules (T1556.003), Password Cracking (T1110.002), Vulnerabilities (T1588.006), Server (T1584.004), Code Repositories (T1213.003), Software (T1592.002)
- Honker – Durable queues, streams, pub/sub, and cron scheduler in a SQLite file — Thu, 30 Apr 2026 14:43:02 +0000
- Matched TTPs: Cron (T1053.003), Python (T1059.006)
BleepingComputer
- Story retracted — Fri, 01 May 2026 12:26:28 -0400
- Matched TTPs: At (T1053.002)
Darkreading
- If AI’s So Smart, Why Does It Keep Deleting Production Databases? — Fri, 01 May 2026 14:39:55 GMT
- Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Databases (T1213.006), Vulnerabilities (T1588.006), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
The Hacker News
- 30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign — Fri, 01 May 2026 23:39:00 +0530
- Matched TTPs: Malware (T1588.001), Browser Extensions (T1176.001), Vulnerabilities (T1588.006), Masquerading (T1036), Server (T1584.004), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft — Fri, 01 May 2026 15:13:00 +0530
- Matched TTPs: Malware (T1588.001), Browser Extensions (T1176.001), Vulnerabilities (T1588.006), SSH (T1021.004), Server (T1584.004), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)