Threat Hunt Feed (2026-08-12)
Hacker News: Best
- Woman pulled over twice after Flock-linked software connected her to homicide — Tue, 11 Aug 2026 17:02:59 +0000
- Matched TTPs: Tool (T1588.002), Software (T1592.002), At (T1053.002)
- Show HN: Needle2: 14MB agentic LLM for phones, wearables, smart home and robots — Mon, 10 Aug 2026 17:22:07 +0000
- Matched TTPs: JavaScript (T1059.007), Hardware (T1592.001), Domains (T1584.001), Tool (T1588.002), Python (T1059.006), At (T1053.002), Compression (T1027.015)
Krebs on Security
- Microsoft Plugs Nearly 400 Security Holes — Tue, 11 Aug 2026 21:28:35 +0000
- Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), Software (T1592.002), At (T1053.002)
BleepingComputer
- Sandworm hackers target IT pros with trojanized WireGuard VPN client — Tue, 11 Aug 2026 17:07:24 -0400
- Matched TTPs: Scheduled Task (T1053.005), Sharepoint (T1213.002), Malware (T1588.001), Hardware (T1592.001), Email Addresses (T1589.002), PowerShell (T1059.001), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), At (T1053.002)
- Cisco warns of ASA and FTD VPN flaw exploited to crash devices — Tue, 11 Aug 2026 15:45:31 -0400
- Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001)
- Microsoft releases Windows 10 KB5120249 extended security update — Tue, 11 Aug 2026 14:26:03 -0400
- Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), At (T1053.002)
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days — Tue, 11 Aug 2026 14:08:50 -0400
- Matched TTPs: Windows Management Instrumentation (T1047), Sharepoint (T1213.002), Rootkit (T1014), DNS (T1071.004), Network Devices (T1584.008), DNS Server (T1584.002), Malware (T1588.001), Hardware (T1592.001), Local Account (T1136.001), Vulnerabilities (T1588.006), Server (T1584.004), PowerShell (T1059.001), Tool (T1588.002), Lua (T1059.011), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
- Windows 11 KB5121003 & KB5120240 cumulative updates released — Tue, 11 Aug 2026 13:38:42 -0400
- Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), Power Settings (T1653), At (T1053.002)
- CISA: Microsoft SharePoint flaw now exploited in ransomware attacks — Tue, 11 Aug 2026 08:12:16 -0400
- Matched TTPs: Sharepoint (T1213.002), Security Account Manager (T1003.002), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), At (T1053.002), Local Accounts (T1078.003)
- Cisco warns of high-severity ClamAV flaws with public exploits — Tue, 11 Aug 2026 07:03:01 -0400
- Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001)
Darkreading
- Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA — Tue, 11 Aug 2026 21:16:25 GMT
- Matched TTPs: OS Credential Dumping (T1003), Malvertising (T1583.008), Hardware (T1592.001), Vulnerabilities (T1588.006), Server (T1584.004), Multi-Factor Authentication (T1556.006), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), At (T1053.002)
The Hacker News
- Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing — Wed, 12 Aug 2026 01:06:37 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client — Wed, 12 Aug 2026 00:38:47 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
- Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands — Wed, 12 Aug 2026 00:06:47 +0530
- Matched TTPs: Scheduled Task (T1053.005), Artificial Intelligence (T1588.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Masquerading (T1036), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), PowerShell (T1059.001), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
- Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE — Tue, 11 Aug 2026 22:17:44 +0530
- Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), DNS (T1071.004), Malware (T1588.001), Windows Service (T1543.003), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development — Tue, 11 Aug 2026 18:41:23 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), JavaScript (T1059.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), At (T1053.002)
- A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices — Tue, 11 Aug 2026 17:35:03 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Firmware (T1592.003), Software (T1592.002), Social Media (T1593.001), Malicious Link (T1204.001), At (T1053.002)
- Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo — Tue, 11 Aug 2026 17:34:51 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Code Repositories (T1213.003), Proxy (T1090), Confluence (T1213.001), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
- Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 — Tue, 11 Aug 2026 16:18:26 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), DLL (T1574.001), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Software (T1592.002), Social Media (T1593.001), Python (T1059.006), At (T1053.002)
- Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets — Tue, 11 Aug 2026 15:54:00 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks — Tue, 11 Aug 2026 14:46:24 +0530
- Matched TTPs: Sharepoint (T1213.002), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Clear Command History (T1070.003), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Phishing (T1566), Multi-Factor Authentication (T1556.006), Firmware (T1592.003), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), NTDS (T1003.003), At (T1053.002)
- Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine — Tue, 11 Aug 2026 12:25:45 +0530
- Matched TTPs: IP Addresses (T1590.005), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Multi-Factor Authentication (T1556.006), Firmware (T1592.003), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins — Tue, 11 Aug 2026 11:18:44 +0530
- Matched TTPs: JavaScript (T1059.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Supply Chain Compromise (T1195), Domains (T1584.001), Web Shell (T1505.003), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
데일리시큐 - 최근인기기사
- 악성 SIM 하나로 스마트폰·전기차 충전기 해킹 가능…IoT 통신모듈 새 공격면 드러나 — 2026-08-12 00:04:46
- Matched TTPs: At (T1053.002)