Threat Hunt Feed (2026-07-30)
Hacker News: Best
- Keychron announces first open-source firmware for gaming mice — Wed, 29 Jul 2026 16:36:59 +0000
- Matched TTPs: Hardware (T1592.001), Firmware (T1592.003), Software (T1592.002), At (T1053.002)
- Show HN: Open-source engine running Gemma 4 26B in 2 GB RAM on any M-series Mac — Wed, 29 Jul 2026 15:05:43 +0000
- Matched TTPs: Hardware (T1592.001), Vulnerabilities (T1588.006), Server (T1584.004), Chat Messages (T1552.008), Tool (T1588.002), Software (T1592.002), Python (T1059.006), At (T1053.002)
- French musician Kavinsky found dead — Wed, 29 Jul 2026 11:54:37 +0000
- Matched TTPs: Artificial Intelligence (T1588.007), Social Media (T1593.001), At (T1053.002)
- More Tailscale tricks for your jailbroken Kindle — Wed, 29 Jul 2026 04:58:46 +0000
- Matched TTPs: IP Addresses (T1590.005), SSH (T1021.004), Server (T1584.004), Proxy (T1090), At (T1053.002)
- Show HN: I was tired of opening 2 tabs for every HN link, so I made a userscript — Tue, 28 Jul 2026 22:09:06 +0000
- Matched TTPs: Vulnerabilities (T1588.006), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
BleepingComputer
- OpenAI agent used exposed credentials at 4 services in Hugging Face breach — Wed, 29 Jul 2026 12:04:59 -0400
- Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Compromise Accounts (T1586), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- Your AI Agents Are Guessing at Scale: Permissions Decide the Damage — Wed, 29 Jul 2026 10:02:12 -0400
- Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Botnet (T1584.005), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
Darkreading
- ‘Flying Eagle’ Full-Service Mobile RAT Builder Wings Across China — Thu, 30 Jul 2026 00:30:00 GMT
- Matched TTPs: Keylogging (T1056.001), IP Addresses (T1590.005), Malware (T1588.001), Vulnerabilities (T1588.006), Masquerading (T1036), Server (T1584.004), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- Red Agents vs. Blue Agents: How to Make AI Better At Defense — Wed, 29 Jul 2026 19:46:20 GMT
- Matched TTPs: Malvertising (T1583.008), Hardware (T1592.001), Vulnerabilities (T1588.006), Tool (T1588.002), Software (T1592.002), At (T1053.002)
- When AppSec Scanners Become a Supply Chain Attack Vector — Wed, 29 Jul 2026 17:06:52 GMT
- Matched TTPs: Vulnerabilities (T1588.006), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
The Hacker News
- Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads — Wed, 29 Jul 2026 23:40:00 +0530
- Matched TTPs: Sharepoint (T1213.002), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), Server (T1584.004), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline — Wed, 29 Jul 2026 19:18:36 +0530
- Matched TTPs: Sharepoint (T1213.002), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), At (T1053.002)
- Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass — Wed, 29 Jul 2026 14:28:27 +0530
- Matched TTPs: Sharepoint (T1213.002), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), Server (T1584.004), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Python (T1059.006), At (T1053.002)
- OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach — Wed, 29 Jul 2026 13:21:00 +0530
- Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), Server (T1584.004), Code Repositories (T1213.003), Proxy (T1090), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Impersonation (T1656), At (T1053.002)
- Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js — Wed, 29 Jul 2026 09:50:57 +0530
- Matched TTPs: Sharepoint (T1213.002), JavaScript (T1059.007), Malvertising (T1583.008), Malware (T1588.001), Vulnerabilities (T1588.006), Clipboard Data (T1115), Password Managers (T1555.005), Server (T1584.004), PowerShell (T1059.001), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), Windows Credential Manager (T1555.004), At (T1053.002)