Threat Hunt Feed (2026-07-03)
Hacker News: Best
- Android Developer Verification: Threat masquerading as protection — Thu, 02 Jul 2026 03:00:15 +0000
- Matched TTPs: Malware (T1588.001), Masquerading (T1036), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
Krebs on Security
- FBI Seizes NetNut Proxy Platform, Popa Botnet — Thu, 02 Jul 2026 19:27:33 +0000
- Matched TTPs: Malware (T1588.001), Botnet (T1584.005), Domains (T1584.001), Proxy (T1090), Software (T1592.002), At (T1053.002)
BleepingComputer
- CISA: Microsoft SharePoint RCE flaw now actively exploited — Thu, 02 Jul 2026 06:52:43 -0400
- Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Server (T1584.004), Cloud Services (T1021.007), Tool (T1588.002), Software (T1592.002)
Darkreading
- Apple Reverses Age-Old Patch Policy to Keep Up With AI — Thu, 02 Jul 2026 19:31:58 GMT
- Matched TTPs: Artificial Intelligence (T1588.007), Vulnerabilities (T1588.006), Phishing (T1566), At (T1053.002)
- Anthropic’s AI Finds Bugs. IBM Bets $5B It Can Fix Them. — Thu, 02 Jul 2026 12:33:57 GMT
- Matched TTPs: JavaScript (T1059.007), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), At (T1053.002)
- When Too Much Security Data Became the Risk — Wed, 01 Jul 2026 15:44:41 GMT
- Matched TTPs: Artificial Intelligence (T1588.007), DNS (T1071.004), Vulnerabilities (T1588.006), Tool (T1588.002), Phishing (T1566), At (T1053.002)
The Hacker News
- Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices — Fri, 03 Jul 2026 00:24:06 +0530
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials — Fri, 03 Jul 2026 00:00:33 +0530
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Credential Stuffing (T1110.004), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories — Thu, 02 Jul 2026 20:54:18 +0530
- Matched TTPs: Keylogging (T1056.001), Artificial Intelligence (T1588.007), DNS (T1071.004), Malware (T1588.001), Malicious File (T1204.002), Vulnerabilities (T1588.006), Botnet (T1584.005), Remote Access Tools (T1219), Domains (T1584.001), Masquerading (T1036), Server (T1584.004), Email Addresses (T1589.002), Proxy (T1090), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Compute Hijacking (T1496.001), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Resource Hijacking (T1496), At (T1053.002)
- ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API — Thu, 02 Jul 2026 18:34:13 +0530
- Matched TTPs: Scheduled Task (T1053.005), JavaScript (T1059.007), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Botnet (T1584.005), Email Accounts (T1585.002), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack — Thu, 02 Jul 2026 14:43:13 +0530
- Matched TTPs: Scheduled Task (T1053.005), Artificial Intelligence (T1588.007), Malware (T1588.001), Databases (T1213.006), Vulnerabilities (T1588.006), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
- FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations — Thu, 02 Jul 2026 13:30:49 +0530
- Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Proxy (T1090), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos — Thu, 02 Jul 2026 12:54:23 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Databases (T1213.006), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Server (T1584.004), Trap (T1546.005), Proxy (T1090), Shell History (T1552.003), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
- SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation — Thu, 02 Jul 2026 11:16:45 +0530
- Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), DLL (T1574.001), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- AI-Generated Browser Ransomware Abuses Chromium API on Windows, Linux, macOS, Android — Wed, 01 Jul 2026 18:29:19 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)