Threat Hunt Feed (2026-06-19)
Hacker News: Best
- I found 10k GitHub repositories distributing Trojan malware — Thu, 18 Jun 2026 11:45:43 +0000
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Search Engines (T1593.002), At (T1053.002)
- Hospitals and universities repurposing drugs at lower cost — Thu, 18 Jun 2026 10:33:22 +0000
- Matched TTPs: At (T1053.002)
- AMD silently removes memory encryption from consumer Ryzen CPUs — Thu, 18 Jun 2026 08:08:00 +0000
- Matched TTPs: Artificial Intelligence (T1588.007), Bootkit (T1542.003), Malware (T1588.001), Hardware (T1592.001), Firmware (T1592.003), Software (T1592.002), Exploits (T1588.005), At (T1053.002)
- Local Qwen isn’t a worse Opus, it’s a different tool — Thu, 18 Jun 2026 03:04:20 +0000
- Matched TTPs: Serverless (T1584.007), Hardware (T1592.001), Server (T1584.004), Trap (T1546.005), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Python (T1059.006), At (T1053.002), Compression (T1027.015)
- Tesco moving 40k server workloads off VMware amid Broadcom’s abusive conduct — Wed, 17 Jun 2026 21:00:53 +0000
- Matched TTPs: Hardware (T1592.001), Server (T1584.004), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
Krebs on Security
- ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm — Thu, 18 Jun 2026 17:37:58 +0000
- Matched TTPs: Screen Capture (T1113), IP Addresses (T1590.005), Malware (T1588.001), Botnet (T1584.005), Domains (T1584.001), Search Engines (T1593.002), Proxy (T1090), Software (T1592.002), At (T1053.002)
BleepingComputer
- USB worm spreads crypto-stealing malware via Windows shortcut files — Thu, 18 Jun 2026 12:20:06 -0400
- Matched TTPs: Scheduled Task (T1053.005), JavaScript (T1059.007), Malware (T1588.001), Hardware (T1592.001), Private Keys (T1552.004), Proxy (T1090), PowerShell (T1059.001), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp — Thu, 18 Jun 2026 09:25:47 -0400
- Matched TTPs: JavaScript (T1059.007), Malware (T1588.001), Hardware (T1592.001), Botnet (T1584.005), Domains (T1584.001), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- F5 issues out-of-band patches for critical NGINX vulnerabilities — Thu, 18 Jun 2026 07:33:00 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001)
- Microsoft fixes Windows Server 2016 security update failures — Thu, 18 Jun 2026 06:14:20 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001)
Darkreading
- Novo Nordisk Breach Exposes Software Development Pipeline Risk — Thu, 18 Jun 2026 20:05:47 GMT
- Matched TTPs: Vulnerabilities (T1588.006), Code Repositories (T1213.003), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Get Out of Security Debt by Tackling the Exposure Problem — Thu, 18 Jun 2026 13:00:00 GMT
- Matched TTPs: Vulnerabilities (T1588.006), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), At (T1053.002)
The Hacker News
- F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution — Thu, 18 Jun 2026 23:02:14 +0530
- Matched TTPs: Rootkit (T1014), Vulnerabilities (T1588.006), Server (T1584.004), Proxy (T1090), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), At (T1053.002)
- ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories — Thu, 18 Jun 2026 20:57:54 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), Rootkit (T1014), JavaScript (T1059.007), DNS (T1071.004), Malvertising (T1583.008), DNS Server (T1584.002), Keychain (T1555.001), Malware (T1588.001), Browser Extensions (T1176.001), Vulnerabilities (T1588.006), DLL (T1574.001), Clipboard Data (T1115), Password Managers (T1555.005), AppleScript (T1059.002), Domains (T1584.001), Process Injection (T1055), Server (T1584.004), Email Addresses (T1589.002), Search Engines (T1593.002), Proxy (T1090), Web Services (T1584.006), Phishing (T1566), Encrypted Channel (T1573), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Impersonation (T1656), Python (T1059.006), Kerberoasting (T1558.003), DCSync (T1003.006), At (T1053.002)
- Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2 — Thu, 18 Jun 2026 20:00:42 +0530
- Matched TTPs: Screen Capture (T1113), Rootkit (T1014), Malware (T1588.001), Vulnerabilities (T1588.006), Private Keys (T1552.004), Server (T1584.004), Proxy (T1090), PowerShell (T1059.001), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Hidden Window (T1564.003), At (T1053.002)
- 145 Mastra npm Packages Compromised via Hijacked Contributor Account — Wed, 17 Jun 2026 13:08:24 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), Rootkit (T1014), JavaScript (T1059.007), Malware (T1588.001), Browser Extensions (T1176.001), Vulnerabilities (T1588.006), Server (T1584.004), Multi-Factor Authentication (T1556.006), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
보안뉴스 > SECURITY
- 백업 안 하는 Z세대 vs 종이 믿는 장년층… 카스퍼스키 정보 저장 리포트 — Fri, 19 Jun 2026 10:56:00 +0900
- Matched TTPs: Credential Stuffing (T1110.004)