Threat Hunt Feed (2026-08-13)
Hacker News: Best
- AI is removing the middle class of software engineering? — Wed, 12 Aug 2026 13:20:05 +0000
- Matched TTPs: Serverless (T1584.007), Software (T1592.002), At (T1053.002)
- WorldClaw Agentic 3D open-world generation at scale — Tue, 11 Aug 2026 21:56:18 +0000
- Matched TTPs: At (T1053.002)
- Compression is prediction — Tue, 11 Aug 2026 19:49:44 +0000
- Matched TTPs: JavaScript (T1059.007), SSH (T1021.004), Server (T1584.004), Tool (T1588.002), At (T1053.002), Compression (T1027.015)
- Go is an ideal language for AI-assisted software engineering — Tue, 11 Aug 2026 16:57:09 +0000
- Matched TTPs: Vulnerabilities (T1588.006), Vulnerability Scanning (T1595.002), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Python (T1059.006), At (T1053.002)
BleepingComputer
- Android malware combo takes out loans and relays victims’ credit cards — Wed, 12 Aug 2026 18:22:57 -0400
- Matched TTPs: VNC (T1021.005), IP Addresses (T1590.005), Malware (T1588.001), Hardware (T1592.001), Proxy (T1090), Financial Theft (T1657), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- Hundreds of fake Chrome VPN extensions route traffic through a proxy — Wed, 12 Aug 2026 14:54:57 -0400
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Hardware (T1592.001), Browser Extensions (T1176.001), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- Plug and Pwn attack uses fake USB devices for Windows SYSTEM access — Wed, 12 Aug 2026 12:05:12 -0400
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Malicious File (T1204.002), Hardware (T1592.001), Vulnerabilities (T1588.006), DLL (T1574.001), Server (T1584.004), Proxy (T1090), PowerShell (T1059.001), Tool (T1588.002), Firmware (T1592.003), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
- FBI: Hackers target online accounts to steal nude photos — Wed, 12 Aug 2026 10:15:09 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Social Media Accounts (T1585.001), Proxy (T1090), Tool (T1588.002), Multi-Factor Authentication (T1556.006), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001)
- The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In — Wed, 12 Aug 2026 10:01:11 -0400
- Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Hardware (T1592.001), Social Media Accounts (T1585.001), Code Repositories (T1213.003), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Remote Desktop Software (T1219.002), At (T1053.002)
- Hackers leverage new Microsoft SharePoint exploit in attacks — Wed, 12 Aug 2026 08:25:37 -0400
- Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), Impersonation (T1656)
Darkreading
- Long-running Data Theft Campaign Targeting Salesforce, ServiceNow — Wed, 12 Aug 2026 21:08:54 GMT
- Matched TTPs: Vulnerabilities (T1588.006), Software (T1592.002), Exploits (T1588.005), At (T1053.002)
The Hacker News
- Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor — Wed, 12 Aug 2026 23:09:27 +0530
- Matched TTPs: Sharepoint (T1213.002), Rootkit (T1014), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Msiexec (T1218.007), Domains (T1584.001), Web Shell (T1505.003), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), At (T1053.002)
- 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One — Wed, 12 Aug 2026 19:39:50 +0530
- Matched TTPs: Adversary-in-the-Middle (T1557), IP Addresses (T1590.005), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Social Media (T1593.001), Impersonation (T1656), At (T1053.002)
- Enterprise Defenses Recovered at the Edge and Collapsed Inside — Wed, 12 Aug 2026 17:11:34 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Tool (T1588.002), Social Media (T1593.001), Credentials (T1589.001), Service Execution (T1569.002), At (T1053.002)
- Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws — Wed, 12 Aug 2026 16:43:03 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Social Media (T1593.001), At (T1053.002)
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access — Wed, 12 Aug 2026 14:31:54 +0530
- Matched TTPs: IP Addresses (T1590.005), DNS (T1071.004), Malware (T1588.001), Cron (T1053.003), Vulnerabilities (T1588.006), SSH (T1021.004), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Tool (T1588.002), Social Media (T1593.001), At (T1053.002)
- Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations — Wed, 12 Aug 2026 13:34:52 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
- Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS — Wed, 12 Aug 2026 11:45:58 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
- Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks — Tue, 11 Aug 2026 14:46:24 +0530
- Matched TTPs: Sharepoint (T1213.002), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Clear Command History (T1070.003), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Phishing (T1566), Multi-Factor Authentication (T1556.006), Firmware (T1592.003), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), NTDS (T1003.003), At (T1053.002)