Threat Hunt Feed (2026-05-22)
Hacker News: Best
- AI is just unauthorised plagiarism at a bigger scale — Thu, 21 May 2026 13:38:12 +0000
- Matched TTPs: At (T1053.002)
Krebs on Security
- Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada — Thu, 21 May 2026 21:50:25 +0000
- Matched TTPs: Botnet (T1584.005), Domains (T1584.001), Email Addresses (T1589.002), At (T1053.002)
BleepingComputer
- Google accidentally exposed details of unfixed Chromium flaw — Thu, 21 May 2026 14:13:50 -0400
- Matched TTPs: JavaScript (T1059.007), Malware (T1588.001), Hardware (T1592.001), Botnet (T1584.005), Tool (T1588.002), Software (T1592.002), At (T1053.002)
- Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet — Thu, 21 May 2026 10:00:10 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Social Media Accounts (T1585.001), Domains (T1584.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Chinese hackers target telcos with new Linux, Windows malware — Thu, 21 May 2026 10:00:00 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), DLL (T1574.001), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Python (T1059.006), At (T1053.002)
- Flipper One project needs community help to build open Linux platform — Thu, 21 May 2026 07:00:00 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
- Microsoft warns of new Defender zero-days exploited in attacks — Thu, 21 May 2026 03:49:48 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Cloud Services (T1021.007), Tool (T1588.002), Software (T1592.002)
Darkreading
- Fake Android Apps Commit Carrier Billing Fraud for Premium Services — Wed, 20 May 2026 20:35:35 GMT
- Matched TTPs: JavaScript (T1059.007), Malware (T1588.001), Vulnerabilities (T1588.006), Email Accounts (T1585.002), Masquerading (T1036), Browser Session Hijacking (T1185), Phishing (T1566), Software (T1592.002), At (T1053.002)
The Hacker News
- Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor — Thu, 21 May 2026 19:47:09 +0530
- Matched TTPs: IP Addresses (T1590.005), Rootkit (T1014), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Web Shell (T1505.003), Server (T1584.004), Proxy (T1090), Social Media (T1593.001), At (T1053.002)
- ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories — Thu, 21 May 2026 17:22:14 +0530
- Matched TTPs: Keylogging (T1056.001), Sharepoint (T1213.002), Artificial Intelligence (T1588.007), IP Addresses (T1590.005), Rootkit (T1014), JavaScript (T1059.007), DNS (T1071.004), Malware (T1588.001), Databases (T1213.006), Vulnerabilities (T1588.006), SSH (T1021.004), Domains (T1584.001), Server (T1584.004), Email Addresses (T1589.002), Proxy (T1090), Mshta (T1218.005), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Multi-Factor Authentication (T1556.006), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Impersonation (T1656), Python (T1059.006), At (T1053.002)
- Microsoft Warns of Two Actively Exploited Defender Vulnerabilities — Thu, 21 May 2026 16:25:57 +0530
- Matched TTPs: Rootkit (T1014), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Server (T1584.004), Social Media (T1593.001)
- When Identity is the Attack Path — Thu, 21 May 2026 16:00:00 +0530
- Matched TTPs: Rootkit (T1014), DNS (T1071.004), Malware (T1588.001), Databases (T1213.006), Vulnerabilities (T1588.006), Server (T1584.004), Tool (T1588.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)