Posts 2026 07 02 Daily Hunt Feed - 2026-07-02
Post
Cancel

Daily Hunt Feed - 2026-07-02

Threat Hunt Feed (2026-07-02)

BleepingComputer

  • FortiBleed credential-theft campaign linked to Lynx ransomware — Wed, 01 Jul 2026 17:37:24 -0400
    • Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), At (T1053.002)
  • New ChocoPoC malware targets researchers via trojanized PoC exploits — Wed, 01 Jul 2026 16:08:13 -0400
    • Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Databases (T1213.006), Vulnerabilities (T1588.006), Server (T1584.004), Email Addresses (T1589.002), Shell History (T1552.003), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
  • Webinar: Why traditional email security is no longer enough — Wed, 01 Jul 2026 12:54:22 -0400
    • Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Domains (T1584.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), At (T1053.002)
  • Turning Indicators into Intelligence in OpenCTI with Criminal IP — Wed, 01 Jul 2026 10:01:11 -0400
    • Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Domains (T1584.001), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Impersonation (T1656), At (T1053.002)
  • Adobe patches seven max severity ColdFusion, Campaign flaws — Wed, 01 Jul 2026 03:34:52 -0400
    • Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), At (T1053.002)

Darkreading

  • Crafty Phishing Campaigns Auto-Adapt to Victim’s Device, OS — Wed, 01 Jul 2026 20:31:21 GMT
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Remote Access Tools (T1219), Email Addresses (T1589.002), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Malicious Link (T1204.001), At (T1053.002)
  • And the Winner in Dominant Malware Delivery? ClickFix — Wed, 01 Jul 2026 19:46:34 GMT
    • Matched TTPs: Malvertising (T1583.008), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), AppleScript (T1059.002), PowerShell (T1059.001), Phishing (T1566), Software (T1592.002), At (T1053.002)
  • ‘Phantom Squatting’: An Emerging AI-Driven Supply Chain Threat — Wed, 01 Jul 2026 15:17:14 GMT
    • Matched TTPs: Vulnerabilities (T1588.006), Supply Chain Compromise (T1195), Domains (T1584.001), Server (T1584.004), Phishing (T1566), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
  • China-Linked Group Targets Southeast Asia Critical Systems — Wed, 01 Jul 2026 01:00:01 GMT
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Vulnerability Scanning (T1595.002), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Python (T1059.006), At (T1053.002)
  • Fake Bug Report Hijacks AI Coding Agents at Scale — Tue, 30 Jun 2026 21:37:50 GMT
    • Matched TTPs: Vulnerabilities (T1588.006), SSH (T1021.004), Code Repositories (T1213.003), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
  • Why Identity Security Is Your Cyber Career Entry Point — Tue, 30 Jun 2026 19:11:40 GMT
    • Matched TTPs: Artificial Intelligence (T1588.007), Browser Extensions (T1176.001), Vulnerabilities (T1588.006), Server (T1584.004), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
  • Phishers Gain Persistence at EU, Asia Hospitality Orgs — Tue, 30 Jun 2026 18:59:46 GMT
    • Matched TTPs: JavaScript (T1059.007), Malware (T1588.001), Vulnerabilities (T1588.006), Masquerading (T1036), Server (T1584.004), Proxy (T1090), Web Services (T1584.006), PowerShell (T1059.001), Phishing (T1566), Credentials (T1589.001), At (T1053.002), Dead Drop Resolver (T1102.001)

The Hacker News

  • Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters — Thu, 02 Jul 2026 01:10:06 +0530
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT — Wed, 01 Jul 2026 23:23:06 +0530
    • Matched TTPs: Scheduled Task (T1053.005), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Proxy (T1090), PowerShell (T1059.001), Tool (T1588.002), Process Hollowing (T1055.012), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Hidden Window (T1564.003), Visual Basic (T1059.005), SEO Poisoning (T1608.006), At (T1053.002)
  • VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer — Wed, 01 Jul 2026 22:48:50 +0530
    • Matched TTPs: JavaScript (T1059.007), Malware (T1588.001), Vulnerabilities (T1588.006), InstallUtil (T1218.004), Botnet (T1584.005), Masquerading (T1036), Reflective Code Loading (T1620), Proxy (T1090), Cloud Services (T1021.007), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), MSBuild (T1127.001), Drive-by Compromise (T1189), At (T1053.002)
  • Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures — Wed, 01 Jul 2026 20:56:55 +0530
    • Matched TTPs: IP Addresses (T1590.005), JavaScript (T1059.007), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Web Services (T1584.006), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Steganography (T1001.002), At (T1053.002)
  • Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic — Wed, 01 Jul 2026 20:55:46 +0530
    • Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android — Wed, 01 Jul 2026 18:29:19 +0530
    • Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
  • Phantom Squatting Uses AI-Hallucinated Domains for Phishing and Malware — Wed, 01 Jul 2026 12:50:51 +0530
    • Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Impersonation (T1656), At (T1053.002)
  • Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts — Wed, 01 Jul 2026 11:16:03 +0530
    • Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Server (T1584.004), Password Spraying (T1110.003), Proxy (T1090), Tool (T1588.002), Multi-Factor Authentication (T1556.006), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Conditional Access Policies (T1556.009), At (T1053.002)
  • Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery — Wed, 01 Jul 2026 11:02:12 +0530
    • Matched TTPs: JavaScript (T1059.007), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Msiexec (T1218.007), Server (T1584.004), Proxy (T1090), User Execution (T1204), PowerShell (T1059.001), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Malicious Copy and Paste (T1204.004), At (T1053.002)
  • Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service — Wed, 01 Jul 2026 09:24:22 +0530
    • Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
This post is licensed under CC BY 4.0 by the author.