Posts 2026 07 30 Daily Hunt Feed - 2026-07-30
Post
Cancel

Daily Hunt Feed - 2026-07-30

Threat Hunt Feed (2026-07-30)

Hacker News: Best

BleepingComputer

  • OpenAI agent used exposed credentials at 4 services in Hugging Face breach — Wed, 29 Jul 2026 12:04:59 -0400
    • Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Compromise Accounts (T1586), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
  • Your AI Agents Are Guessing at Scale: Permissions Decide the Damage — Wed, 29 Jul 2026 10:02:12 -0400
    • Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Botnet (T1584.005), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)

Darkreading

The Hacker News

  • Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads — Wed, 29 Jul 2026 23:40:00 +0530
    • Matched TTPs: Sharepoint (T1213.002), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), Server (T1584.004), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline — Wed, 29 Jul 2026 19:18:36 +0530
    • Matched TTPs: Sharepoint (T1213.002), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), At (T1053.002)
  • Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass — Wed, 29 Jul 2026 14:28:27 +0530
    • Matched TTPs: Sharepoint (T1213.002), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), Server (T1584.004), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Python (T1059.006), At (T1053.002)
  • OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach — Wed, 29 Jul 2026 13:21:00 +0530
    • Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), Server (T1584.004), Code Repositories (T1213.003), Proxy (T1090), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Impersonation (T1656), At (T1053.002)
  • Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js — Wed, 29 Jul 2026 09:50:57 +0530
    • Matched TTPs: Sharepoint (T1213.002), JavaScript (T1059.007), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), Clipboard Data (T1115), Password Managers (T1555.005), Server (T1584.004), PowerShell (T1059.001), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), Windows Credential Manager (T1555.004), At (T1053.002)
This post is licensed under CC BY 4.0 by the author.