Threat Hunt Feed (2026-07-10)
Hacker News: Best
- Show HN: Getting GLM 5.2 running on my slow computer — Thu, 09 Jul 2026 08:05:04 +0000
- Matched TTPs: Hardware (T1592.001), Vulnerabilities (T1588.006), Software (T1592.002), Python (T1059.006), At (T1053.002)
- Show HN: Microsoft releases Flint, a visualization language for AI agents — Wed, 08 Jul 2026 17:46:12 +0000
- Matched TTPs: Server (T1584.004)
- Tenda firmware (multiple versions) contains hidden authentication backdoor — Wed, 08 Jul 2026 00:08:51 +0000
- Matched TTPs: Network Devices (T1584.008), Server (T1584.004), Firmware (T1592.003), Software (T1592.002), Credentials (T1589.001)
BleepingComputer
- Injective SDK on npm infected with cryptocurrency wallet stealer — Thu, 09 Jul 2026 16:10:00 -0400
- Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), JavaScript (T1059.007), Malware (T1588.001), Hardware (T1592.001), Private Keys (T1552.004), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002), At (T1053.002)
- New Helix vishing group emerges in SharePoint data theft attacks — Thu, 09 Jul 2026 13:08:29 -0400
- Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Domains (T1584.001), Tool (T1588.002), Phishing (T1566), Multi-Factor Authentication (T1556.006), Firmware (T1592.003), Software (T1592.002), Impersonation (T1656), Python (T1059.006), At (T1053.002)
- Microsoft expects more Windows security updates from AI-discovered flaws — Thu, 09 Jul 2026 13:00:00 -0400
- Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002), At (T1053.002)
- New Forg365 phishing platform uses AI to target Microsoft 365 accounts — Thu, 09 Jul 2026 10:39:51 -0400
- Matched TTPs: Adversary-in-the-Middle (T1557), Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Polymorphic Code (T1027.014), Firmware (T1592.003), Software (T1592.002), At (T1053.002)
- Microsoft to retire the OWA Light client in Exchange Server — Thu, 09 Jul 2026 07:00:35 -0400
- Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002), At (T1053.002)
Darkreading
- Iran’s Cyber Crosshairs Focus Beyond Critical Infrastructure — Thu, 09 Jul 2026 20:32:00 GMT
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), At (T1053.002)
- As Global Conflicts Go Digital, Businesses Need Wartime Gameplans — Thu, 09 Jul 2026 14:31:20 GMT
- Matched TTPs: Browser Extensions (T1176.001), Vulnerabilities (T1588.006), Software (T1592.002), At (T1053.002)
- ‘GodDamn’ Ransomware Uses BYOVD to Smite US Companies — Thu, 09 Jul 2026 10:00:00 GMT
- Matched TTPs: Malvertising (T1583.008), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Tool (T1588.002), Software (T1592.002), At (T1053.002)
The Hacker News
- New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware — Thu, 09 Jul 2026 23:38:07 +0530
- Matched TTPs: Scheduled Task (T1053.005), VNC (T1021.005), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), File Deletion (T1070.004), At (T1053.002)
- ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories — Thu, 09 Jul 2026 20:39:28 +0530
- Matched TTPs: Scheduled Task (T1053.005), Artificial Intelligence (T1588.007), DNS (T1071.004), SAML Tokens (T1606.002), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), DLL (T1574.001), Botnet (T1584.005), System Information Discovery (T1082), Remote Access Tools (T1219), Process Injection (T1055), Server (T1584.004), Email Addresses (T1589.002), Proxy (T1090), Web Services (T1584.006), Tool (T1588.002), Phishing (T1566), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Steganography (T1001.002), Impersonation (T1656), SEO Poisoning (T1608.006), At (T1053.002)
- AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up — Thu, 09 Jul 2026 17:56:58 +0530
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Proxy (T1090), Tool (T1588.002), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses — Thu, 09 Jul 2026 16:13:09 +0530
- Matched TTPs: VNC (T1021.005), Malware (T1588.001), Windows Service (T1543.003), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Cached Domain Credentials (T1003.005), Proxy (T1090), PowerShell (T1059.001), Tool (T1588.002), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Windows Credential Manager (T1555.004), At (T1053.002)
- Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges — Thu, 09 Jul 2026 14:18:48 +0530
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), DLL (T1574.001), Botnet (T1584.005), Proxy (T1090), Tool (T1588.002), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Meta’s New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images — Thu, 09 Jul 2026 12:51:06 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Proxy (T1090), Tool (T1588.002), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents — Thu, 09 Jul 2026 09:57:18 +0530
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes — Thu, 09 Jul 2026 09:31:49 +0530
- Matched TTPs: IP Addresses (T1590.005), DNS (T1071.004), Malvertising (T1583.008), WHOIS (T1596.002), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Domains (T1584.001), Proxy (T1090), Tool (T1588.002), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)