Posts 2026 07 09 Daily Hunt Feed - 2026-07-09
Post
Cancel

Daily Hunt Feed - 2026-07-09

Threat Hunt Feed (2026-07-09)

Krebs on Security

BleepingComputer

  • Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials — Wed, 08 Jul 2026 15:54:59 -0400
    • Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), Proxy (T1090), Web Services (T1584.006), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
  • Hackers exploit Roundcube flaw to spy on academic researchers — Wed, 08 Jul 2026 14:56:02 -0400
    • Matched TTPs: JavaScript (T1059.007), Malware (T1588.001), Hardware (T1592.001), Domains (T1584.001), Server (T1584.004), Tool (T1588.002), Phishing (T1566), Firmware (T1592.003), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
  • 3 Ways AI Powers Service Desk Attacks and How to Prevent Them — Wed, 08 Jul 2026 10:01:11 -0400
    • Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Chat Messages (T1552.008), Tool (T1588.002), Phishing (T1566), Firmware (T1592.003), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Impersonation (T1656), At (T1053.002)
  • Telco giant KDDI says data breach affects over 12 million people — Wed, 08 Jul 2026 07:24:16 -0400
    • Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Email Accounts (T1585.002), Email Addresses (T1589.002), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
  • Ubiquiti warns of new max severity UniFi OS vulnerability — Wed, 08 Jul 2026 04:15:20 -0400
    • Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002), Credentials (T1589.001), At (T1053.002)

Darkreading

  • Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours — Wed, 08 Jul 2026 20:32:22 GMT
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Code Repositories (T1213.003), Cloud Services (T1021.007), Web Services (T1584.006), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
  • Vidar Infostealer Hammers SMBs via Malvertising Campaign — Wed, 08 Jul 2026 16:45:54 GMT
    • Matched TTPs: Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Server (T1584.004), Software (T1592.002), Credentials (T1589.001), At (T1053.002)

The Hacker News

  • AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers — Wed, 08 Jul 2026 22:32:12 +0530
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Proxy (T1090), PowerShell (T1059.001), Tool (T1588.002), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), Windows Credential Manager (T1555.004), At (T1053.002)
  • New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware — Wed, 08 Jul 2026 20:37:24 +0530
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Domains (T1584.001), Trap (T1546.005), Proxy (T1090), Tool (T1588.002), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS — Wed, 08 Jul 2026 20:08:05 +0530
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • New Ghost Phishing Wave Is Breaking Traditional Email Security — Wed, 08 Jul 2026 18:30:00 +0530
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Domains (T1584.001), Proxy (T1090), Cloud Services (T1021.007), Tool (T1588.002), Phishing (T1566), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users — Wed, 08 Jul 2026 18:22:15 +0530
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Proxy (T1090), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Visual Basic (T1059.005), At (T1053.002)
  • GitHub ‘Verified’ Commits Can Be Rewritten Into New Hashes Without Breaking Signatures — Wed, 08 Jul 2026 17:21:24 +0530
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Code Signing (T1553.002), Proxy (T1090), Tool (T1588.002), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • The Verification Step Is the New ATO Battleground in 2026 — Wed, 08 Jul 2026 17:00:00 +0530
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Compute Hijacking (T1496.001), Credential Stuffing (T1110.004), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Impersonation (T1656), At (T1053.002)
  • China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware — Wed, 08 Jul 2026 14:34:33 +0530
    • Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros — Wed, 08 Jul 2026 11:46:44 +0530
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Proxy (T1090), Tool (T1588.002), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Malicious Link (T1204.001), At (T1053.002)
  • CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV — Wed, 08 Jul 2026 11:03:12 +0530
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Web Shell (T1505.003), Proxy (T1090), Tool (T1588.002), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
This post is licensed under CC BY 4.0 by the author.