Posts 2026 07 14 Daily Hunt Feed - 2026-07-14
Post
Cancel

Daily Hunt Feed - 2026-07-14

Threat Hunt Feed (2026-07-14)

Krebs on Security

  • Lessons Learned from CISA’s Recent GitHub Leak — Mon, 13 Jul 2026 15:03:28 +0000
    • Matched TTPs: Vulnerabilities (T1588.006), Botnet (T1584.005), Code Repositories (T1213.003), Proxy (T1090), Cloud Services (T1021.007), Credentials (T1589.001), At (T1053.002)

BleepingComputer

  • Hackers backdoor Jscrambler npm package with infostealer malware — Mon, 13 Jul 2026 15:44:19 -0400
    • Matched TTPs: Artificial Intelligence (T1588.007), JavaScript (T1059.007), Malware (T1588.001), Hardware (T1592.001), SSH (T1021.004), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002), Credentials (T1589.001)
  • New CrashStealer malware poses as Apple crash reporting tool — Mon, 13 Jul 2026 15:04:02 -0400
    • Matched TTPs: Artificial Intelligence (T1588.007), Keychain (T1555.001), Malware (T1588.001), Hardware (T1592.001), Password Managers (T1555.005), Server (T1584.004), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
  • CISA warns of actively exploited RCE flaws in Joomla extensions — Mon, 13 Jul 2026 11:20:16 -0400
    • Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Web Shell (T1505.003), Server (T1584.004), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002)
  • Lidl discloses online shop breach after service provider hack — Mon, 13 Jul 2026 10:19:43 -0400
    • Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Tool (T1588.002), Phishing (T1566), Firmware (T1592.003), Software (T1592.002), At (T1053.002)
  • Breach at the Beach: Play the Ultimate Entra ID CTF — Mon, 13 Jul 2026 10:01:11 -0400
    • Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002), At (T1053.002)

Darkreading

The Hacker News

  • CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks — Mon, 13 Jul 2026 23:06:12 +0530
    • Matched TTPs: Keychain (T1555.001), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Password Managers (T1555.005), AppleScript (T1059.002), Domains (T1584.001), Escape to Host (T1611), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More — Mon, 13 Jul 2026 20:35:57 +0530
    • Matched TTPs: VNC (T1021.005), Keylogging (T1056.001), Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Remote Access Tools (T1219), Domains (T1584.001), Masquerading (T1036), Escape to Host (T1611), Email Account (T1087.003), Web Shell (T1505.003), Server (T1584.004), Proxy (T1090), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Multi-Factor Authentication (T1556.006), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft — Mon, 13 Jul 2026 18:33:33 +0530
    • Matched TTPs: Adversary-in-the-Middle (T1557), Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Email Accounts (T1585.002), Domains (T1584.001), Escape to Host (T1611), Server (T1584.004), Email Addresses (T1589.002), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots — Mon, 13 Jul 2026 17:07:05 +0530
    • Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Escape to Host (T1611), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
  • Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory — Mon, 13 Jul 2026 16:32:33 +0530
    • Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Escape to Host (T1611), Server (T1584.004), Proxy (T1090), Web Services (T1584.006), PowerShell (T1059.001), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Remote Desktop Protocol (T1021.001), At (T1053.002)
  • Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 — Mon, 13 Jul 2026 13:00:00 +0530
    • Matched TTPs: Adversary-in-the-Middle (T1557), Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Escape to Host (T1611), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Multi-Factor Authentication (T1556.006), Software (T1592.002), Social Media (T1593.001), Python (T1059.006), At (T1053.002)
  • iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days — Mon, 13 Jul 2026 11:06:02 +0530
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Escape to Host (T1611), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
This post is licensed under CC BY 4.0 by the author.