Threat Hunt Feed (2026-05-05)
Hacker News: Best
- How OpenAI delivers low-latency voice AI at scale — Mon, 04 May 2026 19:42:47 +0000
- Matched TTPs: Network Topology (T1590.004), Server (T1584.004), Tool (T1588.002), Credentials (T1589.001), At (T1053.002)
- Talking to strangers at the gym — Mon, 04 May 2026 11:41:02 +0000
- Matched TTPs: At (T1053.002)
- Agentic Coding Is a Trap — Sun, 03 May 2026 22:52:07 +0000
- Matched TTPs: Trap (T1546.005), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Python (T1059.006), At (T1053.002)
BleepingComputer
- Amazon SES increasingly abused in phishing to evade detection — Mon, 04 May 2026 16:03:28 -0400
- Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Hardware (T1592.001), Tool (T1588.002), Phishing (T1566), Multi-Factor Authentication (T1556.006), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), At (T1053.002)
- Backdoored PyTorch Lightning package drops credential stealer — Mon, 04 May 2026 13:15:27 -0400
- Matched TTPs: JavaScript (T1059.007), Malware (T1588.001), Hardware (T1592.001), Cloud Services (T1021.007), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
- Progress warns of critical MOVEit Automation auth bypass flaw — Mon, 04 May 2026 08:18:57 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), At (T1053.002)
Darkreading
- RMM Tools Fuel Stealthy Phishing Campaign — Mon, 04 May 2026 20:56:34 GMT
- Matched TTPs: Malware (T1588.001), Databases (T1213.006), Vulnerabilities (T1588.006), Tool (T1588.002), Phishing (T1566), Software (T1592.002), At (T1053.002)
- Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability — Mon, 04 May 2026 19:14:14 GMT
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Databases (T1213.006), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), At (T1053.002)
- Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia — Mon, 04 May 2026 14:39:26 GMT
- Matched TTPs: Malware (T1588.001), Databases (T1213.006), Vulnerabilities (T1588.006), Phishing (T1566), Software (T1592.002), Python (T1059.006), At (T1053.002)
The Hacker News
- Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools — Mon, 04 May 2026 23:36:00 +0530
- Matched TTPs: Malware (T1588.001), Windows Service (T1543.003), Vulnerabilities (T1588.006), Server (T1584.004), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
- Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass — Mon, 04 May 2026 22:04:00 +0530
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Server (T1584.004), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
- ⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More — Mon, 04 May 2026 19:53:00 +0530
- Matched TTPs: Screen Capture (T1113), Keylogging (T1056.001), Artificial Intelligence (T1588.007), JavaScript (T1059.007), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Email Accounts (T1585.002), Domains (T1584.001), Masquerading (T1036), Control Panel (T1218.002), Server (T1584.004), Email Addresses (T1589.002), Proxy (T1090), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Multi-Factor Authentication (T1556.006), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Email Bombing (T1667), Impersonation (T1656), Python (T1059.006), At (T1053.002)
- Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia — Mon, 04 May 2026 17:27:00 +0530
- Matched TTPs: JavaScript (T1059.007), Malware (T1588.001), Vulnerabilities (T1588.006), Server (T1584.004), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Python (T1059.006), At (T1053.002)
- Global Crackdown Arrests 276, Shuts 9 Crypto Scam Centers, Seizes $701M — Mon, 04 May 2026 11:29:00 +0530
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Phishing (T1566), Lua (T1059.011), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Impersonation (T1656), At (T1053.002)