Posts 2026 07 28 Daily Hunt Feed - 2026-07-28
Post
Cancel

Daily Hunt Feed - 2026-07-28

Threat Hunt Feed (2026-07-28)

Hacker News: Best

BleepingComputer

  • New Dysphoria DDoS botnet spreads to 200k devices worldwide — Mon, 27 Jul 2026 17:08:15 -0400
    • Matched TTPs: DNS (T1071.004), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Domains (T1584.001), Proxy (T1090), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
  • New Certighost PoC exploit lets attackers hijack Windows domains — Mon, 27 Jul 2026 17:00:25 -0400
    • Matched TTPs: Sharepoint (T1213.002), DNS (T1071.004), Malware (T1588.001), Hardware (T1592.001), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), DCSync (T1003.006)
  • Ernst & Young data breach claimed by ShinyHunters extortion gang — Mon, 27 Jul 2026 11:12:27 -0400
    • Matched TTPs: DNS (T1071.004), Malware (T1588.001), Hardware (T1592.001), Botnet (T1584.005), Domains (T1584.001), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)

Darkreading

The Hacker News

  • NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework — Mon, 27 Jul 2026 23:40:05 +0530
    • Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Malvertising (T1583.008), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), Template Injection (T1221), At (T1053.002)
  • Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption — Mon, 27 Jul 2026 22:46:28 +0530
    • Matched TTPs: Password Guessing (T1110.001), Sharepoint (T1213.002), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Server (T1584.004), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw — Mon, 27 Jul 2026 20:10:00 +0530
    • Matched TTPs: Sharepoint (T1213.002), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), Server (T1584.004), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), At (T1053.002)
  • ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More — Mon, 27 Jul 2026 19:40:54 +0530
    • Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), JavaScript (T1059.007), Malvertising (T1583.008), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), DLL (T1574.001), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Golden Ticket (T1558.001), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), DCSync (T1003.006), At (T1053.002)
  • n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process — Mon, 27 Jul 2026 18:35:15 +0530
    • Matched TTPs: Sharepoint (T1213.002), JavaScript (T1059.007), Malvertising (T1583.008), Malware (T1588.001), Databases (T1213.006), Vulnerabilities (T1588.006), Server (T1584.004), PowerShell (T1059.001), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update — Mon, 27 Jul 2026 18:07:49 +0530
    • Matched TTPs: Sharepoint (T1213.002), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), PowerShell (T1059.001), Phishing (T1566), Multi-Factor Authentication (T1556.006), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Hidden Window (T1564.003), At (T1053.002)
  • Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware — Mon, 27 Jul 2026 16:21:45 +0530
    • Matched TTPs: Sharepoint (T1213.002), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Server (T1584.004), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), At (T1053.002)
  • TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments — Mon, 27 Jul 2026 14:18:47 +0530
    • Matched TTPs: Windows Management Instrumentation (T1047), Sharepoint (T1213.002), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Server (T1584.004), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Environmental Keying (T1480.001), At (T1053.002)
  • GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption — Mon, 27 Jul 2026 13:31:23 +0530
    • Matched TTPs: Sharepoint (T1213.002), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Python (T1059.006), At (T1053.002)

데일리시큐 - 최근인기기사

보안뉴스 > SECURITY

This post is licensed under CC BY 4.0 by the author.