Threat Hunt Feed (2026-06-12)
BleepingComputer
- Microsoft fixes BitLocker recovery bug on Windows Server 2025 — Thu, 11 Jun 2026 04:44:22 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002), At (T1053.002)
Darkreading
- Phishing Attack Volume Down 20%, but Risk Still Rising — Fri, 12 Jun 2026 00:58:07 GMT
- Matched TTPs: Artificial Intelligence (T1588.007), Vulnerabilities (T1588.006), Cloud Services (T1021.007), Web Services (T1584.006), Phishing (T1566), Exploits (T1588.005), Impersonation (T1656), At (T1053.002)
The Hacker News
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities — Fri, 12 Jun 2026 01:59:23 +0530
- Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Server (T1584.004), Email Addresses (T1589.002), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Python (T1059.006), At (T1053.002)
- ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories — Thu, 11 Jun 2026 18:50:41 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), JavaScript (T1059.007), DNS (T1071.004), Network Devices (T1584.008), Malware (T1588.001), Browser Extensions (T1176.001), Vulnerabilities (T1588.006), SSH (T1021.004), DLL (T1574.001), Domains (T1584.001), Masquerading (T1036), Process Injection (T1055), Server (T1584.004), Email Addresses (T1589.002), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
- OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack — Thu, 11 Jun 2026 15:15:58 +0530
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Python (T1059.006), At (T1053.002)
- GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks — Thu, 11 Jun 2026 11:53:03 +0530
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), At (T1053.002)
- Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE — Wed, 10 Jun 2026 20:30:59 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)