Posts 2026 07 18 Daily Hunt Feed - 2026-07-18
Post
Cancel

Daily Hunt Feed - 2026-07-18

Threat Hunt Feed (2026-07-18)

Hacker News: Best

BleepingComputer

Darkreading

  • Inc Ransomware Exploits SonicWall SMA Zero-Days — Fri, 17 Jul 2026 20:01:13 GMT
    • Matched TTPs: Databases (T1213.006), Vulnerabilities (T1588.006), Server (T1584.004), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), At (T1053.002)
  • Agentic AI: Taming the Unpredictable — Thu, 16 Jul 2026 20:57:47 GMT
    • Matched TTPs: Artificial Intelligence (T1588.007), Browser Extensions (T1176.001), Vulnerabilities (T1588.006), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), At (T1053.002)

The Hacker News

  • New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code — Sat, 18 Jul 2026 02:50:10 +0530
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Escape to Host (T1611), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
  • OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests — Sat, 18 Jul 2026 01:50:53 +0530
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Escape to Host (T1611), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), At (T1053.002), Compression (T1027.015)
  • Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT — Sat, 18 Jul 2026 00:24:51 +0530
    • Matched TTPs: JavaScript (T1059.007), Malware (T1588.001), Malicious File (T1204.002), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Escape to Host (T1611), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens — Fri, 17 Jul 2026 22:42:23 +0530
    • Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Cron (T1053.003), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Domains (T1584.001), Escape to Host (T1611), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images — Fri, 17 Jul 2026 19:18:56 +0530
    • Matched TTPs: Artificial Intelligence (T1588.007), JavaScript (T1059.007), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Masquerading (T1036), Escape to Host (T1611), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Steganography (T1001.002), At (T1053.002)
  • E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants — Fri, 17 Jul 2026 17:14:41 +0530
    • Matched TTPs: Artificial Intelligence (T1588.007), IP Addresses (T1590.005), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Escape to Host (T1611), Server (T1584.004), Search Engines (T1593.002), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
  • The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace? — Fri, 17 Jul 2026 17:00:00 +0530
    • Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Escape to Host (T1611), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
  • Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man — Fri, 17 Jul 2026 16:23:31 +0530
    • Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Escape to Host (T1611), Control Panel (T1218.002), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
  • ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files — Fri, 17 Jul 2026 14:26:39 +0530
    • Matched TTPs: Scheduled Task (T1053.005), Rundll32 (T1218.011), Sharepoint (T1213.002), JavaScript (T1059.007), Malvertising (T1583.008), Malware (T1588.001), Databases (T1213.006), Vulnerabilities (T1588.006), DLL (T1574.001), Botnet (T1584.005), Domains (T1584.001), Masquerading (T1036), Escape to Host (T1611), Proxy (T1090), Mshta (T1218.005), PowerShell (T1059.001), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
  • New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage — Fri, 17 Jul 2026 14:16:45 +0530
    • Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Hardware (T1592.001), Local Account (T1136.001), Vulnerabilities (T1588.006), SSH (T1021.004), DLL (T1574.001), Botnet (T1584.005), Domains (T1584.001), Escape to Host (T1611), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Template Injection (T1221), At (T1053.002)
  • CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV — Fri, 17 Jul 2026 12:12:23 +0530
    • Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Escape to Host (T1611), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
This post is licensed under CC BY 4.0 by the author.