Posts 2026 07 22 Daily Hunt Feed - 2026-07-22
Post
Cancel

Daily Hunt Feed - 2026-07-22

Threat Hunt Feed (2026-07-22)

BleepingComputer

  • Police dismantle Kratos phishing platform, arrest developer — Tue, 21 Jul 2026 19:07:33 -0400
    • Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Hardware (T1592.001), Email Addresses (T1589.002), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), At (T1053.002)
  • FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware — Tue, 21 Jul 2026 18:34:17 -0400
    • Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Hardware (T1592.001), Tool (T1588.002), Phishing (T1566), Lua (T1059.011), Software (T1592.002), Exploits (T1588.005), At (T1053.002)
  • Critical SharePoint RCE flaw exploited to steal machine keys — Tue, 21 Jul 2026 16:06:55 -0400
    • Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), At (T1053.002)
  • Closing the Identity Gaps in Critical Infrastructure Security — Tue, 21 Jul 2026 10:00:10 -0400
    • Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Hardware (T1592.001), Remote Access Tools (T1219), Tool (T1588.002), Phishing (T1566), Multi-Factor Authentication (T1556.006), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), At (T1053.002)
  • US seizes over 1,000 websites in FIFA World Cup piracy crackdown — Tue, 21 Jul 2026 07:07:07 -0400
    • Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Hardware (T1592.001), Domains (T1584.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), At (T1053.002)
  • Microsoft shares manual fix for WSUS sync delays and timeouts — Tue, 21 Jul 2026 05:05:50 -0400
    • Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Hardware (T1592.001), Databases (T1213.006), Server (T1584.004), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005)

Darkreading

The Hacker News

  • Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs — Wed, 22 Jul 2026 00:16:32 +0530
    • Matched TTPs: Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Email Addresses (T1589.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities — Tue, 21 Jul 2026 20:39:28 +0530
    • Matched TTPs: Artificial Intelligence (T1588.007), JavaScript (T1059.007), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC — Tue, 21 Jul 2026 20:27:51 +0530
    • Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities — Tue, 21 Jul 2026 18:48:31 +0530
    • Matched TTPs: Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit — Tue, 21 Jul 2026 16:54:50 +0530
    • Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning — Tue, 21 Jul 2026 14:29:30 +0530
    • Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Web Shell (T1505.003), Server (T1584.004), Email Addresses (T1589.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack — Tue, 21 Jul 2026 13:04:32 +0530
    • Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Databases (T1213.006), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Bind Mounts (T1564.013), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
This post is licensed under CC BY 4.0 by the author.