Posts 2026 08 13 Daily Hunt Feed - 2026-08-13
Post
Cancel

Daily Hunt Feed - 2026-08-13

Threat Hunt Feed (2026-08-13)

Hacker News: Best

BleepingComputer

  • Android malware combo takes out loans and relays victims’ credit cards — Wed, 12 Aug 2026 18:22:57 -0400
    • Matched TTPs: VNC (T1021.005), IP Addresses (T1590.005), Malware (T1588.001), Hardware (T1592.001), Proxy (T1090), Financial Theft (T1657), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
  • Hundreds of fake Chrome VPN extensions route traffic through a proxy — Wed, 12 Aug 2026 14:54:57 -0400
    • Matched TTPs: DNS (T1071.004), Malware (T1588.001), Hardware (T1592.001), Browser Extensions (T1176.001), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
  • Plug and Pwn attack uses fake USB devices for Windows SYSTEM access — Wed, 12 Aug 2026 12:05:12 -0400
    • Matched TTPs: DNS (T1071.004), Malware (T1588.001), Malicious File (T1204.002), Hardware (T1592.001), Vulnerabilities (T1588.006), DLL (T1574.001), Server (T1584.004), Proxy (T1090), PowerShell (T1059.001), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
  • FBI: Hackers target online accounts to steal nude photos — Wed, 12 Aug 2026 10:15:09 -0400
    • Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Social Media Accounts (T1585.001), Proxy (T1090), Tool (T1588.002), Multi-Factor Authentication (T1556.006), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001)
  • The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In — Wed, 12 Aug 2026 10:01:11 -0400
    • Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Hardware (T1592.001), Social Media Accounts (T1585.001), Code Repositories (T1213.003), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Remote Desktop Software (T1219.002), At (T1053.002)
  • Hackers leverage new Microsoft SharePoint exploit in attacks — Wed, 12 Aug 2026 08:25:37 -0400
    • Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), Impersonation (T1656)

Darkreading

The Hacker News

  • Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor — Wed, 12 Aug 2026 23:09:27 +0530
    • Matched TTPs: Sharepoint (T1213.002), Rootkit (T1014), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Msiexec (T1218.007), Domains (T1584.001), Web Shell (T1505.003), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), At (T1053.002)
  • 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One — Wed, 12 Aug 2026 19:39:50 +0530
    • Matched TTPs: Adversary-in-the-Middle (T1557), IP Addresses (T1590.005), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Social Media (T1593.001), Impersonation (T1656), At (T1053.002)
  • Enterprise Defenses Recovered at the Edge and Collapsed Inside — Wed, 12 Aug 2026 17:11:34 +0530
    • Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Tool (T1588.002), Social Media (T1593.001), Credentials (T1589.001), Service Execution (T1569.002), At (T1053.002)
  • Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws — Wed, 12 Aug 2026 16:43:03 +0530
    • Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Social Media (T1593.001), At (T1053.002)
  • Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access — Wed, 12 Aug 2026 14:31:54 +0530
    • Matched TTPs: IP Addresses (T1590.005), DNS (T1071.004), Malware (T1588.001), Cron (T1053.003), Vulnerabilities (T1588.006), SSH (T1021.004), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Tool (T1588.002), Social Media (T1593.001), At (T1053.002)
  • Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations — Wed, 12 Aug 2026 13:34:52 +0530
    • Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
  • Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS — Wed, 12 Aug 2026 11:45:58 +0530
    • Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
  • Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks — Tue, 11 Aug 2026 14:46:24 +0530
    • Matched TTPs: Sharepoint (T1213.002), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Clear Command History (T1070.003), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Phishing (T1566), Multi-Factor Authentication (T1556.006), Firmware (T1592.003), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), NTDS (T1003.003), At (T1053.002)
This post is licensed under CC BY 4.0 by the author.