Posts 2026 06 23 Daily Hunt Feed - 2026-06-23
Post
Cancel

Daily Hunt Feed - 2026-06-23

Threat Hunt Feed (2026-06-23)

Hacker News: Best

BleepingComputer

  • WhatsApp phishing attack uses fake business docs to hack PCs — Mon, 22 Jun 2026 18:42:21 -0400
    • Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Botnet (T1584.005), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • FortiBleed campaign used custom FortiGate sniffer to steal credentials — Mon, 22 Jun 2026 16:01:02 -0400
    • Matched TTPs: IP Addresses (T1590.005), Password Cracking (T1110.002), Malware (T1588.001), Hardware (T1592.001), SSH (T1021.004), Server (T1584.004), Tool (T1588.002), Phishing (T1566), Credential Stuffing (T1110.004), Software (T1592.002), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
  • A Glimpse into the “Search Your Target” Market for Stolen Credentials — Mon, 22 Jun 2026 10:05:15 -0400
    • Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Databases (T1213.006), Email Accounts (T1585.002), Domains (T1584.001), Gather Victim Identity Information (T1589), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Credentials (T1589.001), Acquire Access (T1650), At (T1053.002)

Darkreading

The Hacker News

  • Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants — Mon, 22 Jun 2026 21:43:28 +0530
    • Matched TTPs: Artificial Intelligence (T1588.007), Rootkit (T1014), Vulnerabilities (T1588.006), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), At (T1053.002)
  • 29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests — Mon, 22 Jun 2026 19:59:46 +0530
    • Matched TTPs: Rootkit (T1014), Vulnerabilities (T1588.006), Server (T1584.004), Proxy (T1090), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer — Mon, 22 Jun 2026 18:50:12 +0530
    • Matched TTPs: Rootkit (T1014), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Masquerading (T1036), Search Engines (T1593.002), PowerShell (T1059.001), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), At (T1053.002)
  • Stop Your Legacy Infrastructure from Hijacking Your AI Agents — Mon, 22 Jun 2026 17:28:00 +0530
    • Matched TTPs: Rootkit (T1014), Vulnerabilities (T1588.006), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More — Mon, 22 Jun 2026 16:25:10 +0530
    • Matched TTPs: Adversary-in-the-Middle (T1557), Serverless (T1584.007), Keylogging (T1056.001), Artificial Intelligence (T1588.007), Rootkit (T1014), JavaScript (T1059.007), Malvertising (T1583.008), Malware (T1588.001), Hardware (T1592.001), Browser Extensions (T1176.001), Windows Service (T1543.003), Vulnerabilities (T1588.006), DLL (T1574.001), Botnet (T1584.005), Domains (T1584.001), Masquerading (T1036), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Credential Stuffing (T1110.004), Multi-Factor Authentication (T1556.006), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Email Bombing (T1667), Conditional Access Policies (T1556.009), At (T1053.002), Dead Drop Resolver (T1102.001)
  • Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices — Mon, 22 Jun 2026 14:41:37 +0530
    • Matched TTPs: IP Addresses (T1590.005), Rootkit (T1014), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Firmware (T1592.003), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network — Mon, 22 Jun 2026 12:27:44 +0530
    • Matched TTPs: Rootkit (T1014), DNS (T1071.004), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Python (T1059.006), At (T1053.002)
  • INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific — Mon, 22 Jun 2026 11:36:53 +0530
    • Matched TTPs: Artificial Intelligence (T1588.007), Rootkit (T1014), Malware (T1588.001), Vulnerabilities (T1588.006), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), At (T1053.002)
This post is licensed under CC BY 4.0 by the author.