Threat Hunt Feed (2026-08-17)
Hacker News: Best
- Incident with Github.com — Mon, 17 Aug 2026 13:35:06 +0000
- Matched TTPs: Server (T1584.004), At (T1053.002)
BleepingComputer
- Hacker claims 3.6 million Azure account records stolen from major companies — Mon, 17 Aug 2026 15:35:01 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Databases (T1213.006), Vulnerabilities (T1588.006), Domains (T1584.001), Email Addresses (T1589.002), Tool (T1588.002), Multi-Factor Authentication (T1556.006), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), At (T1053.002)
- Windows Server 2022 reaches end of mainstream support in 60 days — Mon, 17 Aug 2026 08:33:11 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- SafePal data breach impacts 39,798 customers, stolen info for sale — Sun, 16 Aug 2026 19:47:06 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Private Keys (T1552.004), Email Addresses (T1589.002), Tool (T1588.002), Phishing (T1566), Firmware (T1592.003), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
Darkreading
- Video Call Exploit Chains Two Flaws in Unisoc Modems — Mon, 17 Aug 2026 21:37:23 GMT
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Phishing (T1566), Firmware (T1592.003), Software (T1592.002), At (T1053.002)
- ‘Turf War’ Between Claude Agents Leads to Self-Replicating Malware — Mon, 17 Aug 2026 20:26:34 GMT
- Matched TTPs: Malvertising (T1583.008), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Python (T1059.006), At (T1053.002)
- Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS — Mon, 17 Aug 2026 15:44:34 GMT
- Matched TTPs: Malware (T1588.001), Cron (T1053.003), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Proxy (T1090), Exploits (T1588.005), Systemd Service (T1543.002), At (T1053.002)
The Hacker News
- Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects — Tue, 18 Aug 2026 02:33:04 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection — Tue, 18 Aug 2026 00:14:17 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic — Mon, 17 Aug 2026 23:11:06 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Domains (T1584.001), Masquerading (T1036), Server (T1584.004), Email Addresses (T1589.002), Proxy (T1090), Confluence (T1213.001), Phishing (T1566), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More — Mon, 17 Aug 2026 18:53:51 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), IP Addresses (T1590.005), JavaScript (T1059.007), DNS (T1071.004), Keychain (T1555.001), Malware (T1588.001), Databases (T1213.006), Vulnerabilities (T1588.006), SSH (T1021.004), DLL (T1574.001), Domains (T1584.001), Web Shell (T1505.003), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Mshta (T1218.005), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
- How MCP Servers Can Expose Enterprise Secrets — Mon, 17 Aug 2026 17:28:00 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access — Mon, 17 Aug 2026 16:22:34 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Firmware (T1592.003), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
- Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies — Mon, 17 Aug 2026 14:59:55 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Exploits (T1588.005), Social Media (T1593.001), At (T1053.002)
- Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware — Mon, 17 Aug 2026 13:06:19 +0530
- Matched TTPs: IP Addresses (T1590.005), DNS (T1071.004), Malware (T1588.001), Local Account (T1136.001), Cron (T1053.003), Vulnerabilities (T1588.006), SSH (T1021.004), Domains (T1584.001), Web Shell (T1505.003), Server (T1584.004), Active Scanning (T1595), Proxy (T1090), Confluence (T1213.001), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), Systemd Service (T1543.002), At (T1053.002), Local Accounts (T1078.003)
- Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware — Sat, 15 Aug 2026 00:18:46 +0530
- Matched TTPs: JavaScript (T1059.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Social Media (T1593.001), At (T1053.002)
- Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth — Fri, 14 Aug 2026 18:38:56 +0530
- Matched TTPs: Scheduled Task (T1053.005), Keylogging (T1056.001), Rootkit (T1014), DNS (T1071.004), Malware (T1588.001), Windows Service (T1543.003), Vulnerabilities (T1588.006), DLL (T1574.001), Domains (T1584.001), Process Injection (T1055), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Social Media (T1593.001), At (T1053.002)
- CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps — Fri, 14 Aug 2026 16:27:00 +0530
- Matched TTPs: IP Addresses (T1590.005), DNS (T1071.004), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Trap (T1546.005), Proxy (T1090), Confluence (T1213.001), Phishing (T1566), Multi-Factor Authentication (T1556.006), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud — Fri, 14 Aug 2026 13:24:18 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), IP Addresses (T1590.005), Rootkit (T1014), JavaScript (T1059.007), DNS (T1071.004), Network Devices (T1584.008), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Control Panel (T1218.002), Server (T1584.004), Email Addresses (T1589.002), Search Engines (T1593.002), Proxy (T1090), Confluence (T1213.001), Tool (T1588.002), Social Media (T1593.001), Credentials (T1589.001), SEO Poisoning (T1608.006), At (T1053.002)
- GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE — Fri, 14 Aug 2026 00:15:12 +0530
- Matched TTPs: IP Addresses (T1590.005), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Social Media (T1593.001), At (T1053.002)
- ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories — Thu, 13 Aug 2026 23:47:10 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), JavaScript (T1059.007), DNS (T1071.004), Malware (T1588.001), Social Media Accounts (T1585.001), Vulnerabilities (T1588.006), SSH (T1021.004), Domains (T1584.001), Process Injection (T1055), Server (T1584.004), Trap (T1546.005), Email Addresses (T1589.002), Proxy (T1090), Confluence (T1213.001), Cloud Services (T1021.007), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Impersonation (T1656), At (T1053.002)
- WindRelay Android Malware Turns Victims’ Phones Into NFC Relays for Payment Fraud — Thu, 13 Aug 2026 17:23:14 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Phishing (T1566), Social Media (T1593.001), At (T1053.002)
- North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring — Thu, 13 Aug 2026 17:15:00 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), IP Addresses (T1590.005), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
데일리시큐 - 최근인기기사
- 해커들, 만료된 도메인 사들여 악성코드 유포…하루 6만5천개 재등록 — 2026-08-17 16:25:27
- Matched TTPs: DNS (T1071.004)