Posts 2026 08 19 Daily Hunt Feed - 2026-08-18
Post
Cancel

Daily Hunt Feed - 2026-08-18

Threat Hunt Feed (2026-08-18)

Hacker News: Best

BleepingComputer

  • Clop created custom web shell for Windchill data theft attacks — Tue, 18 Aug 2026 13:29:51 -0400
    • Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Domains (T1584.001), Web Shell (T1505.003), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
  • Microsoft confirms outage affecting search in Microsoft 365 apps — Tue, 18 Aug 2026 05:24:49 -0400
    • Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Hardware (T1592.001), Domains (T1584.001), Web Shell (T1505.003), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001)
  • Microsoft starts removing WMIC tool used by cybercriminals — Tue, 18 Aug 2026 04:12:08 -0400
    • Matched TTPs: Windows Management Instrumentation (T1047), Malware (T1588.001), Hardware (T1592.001), Domains (T1584.001), Web Shell (T1505.003), Server (T1584.004), PowerShell (T1059.001), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001)

Darkreading

The Hacker News

  • Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps — Tue, 18 Aug 2026 23:17:22 +0530
    • Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets — Tue, 18 Aug 2026 23:14:05 +0530
    • Matched TTPs: Artificial Intelligence (T1588.007), IP Addresses (T1590.005), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002), Junk Data (T1001.001)
  • AI “Mind Viruses” Can Spread Between Agents Through Persistent Prompt Files — Tue, 18 Aug 2026 18:08:36 +0530
    • Matched TTPs: Artificial Intelligence (T1588.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
  • TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks — Tue, 18 Aug 2026 18:08:20 +0530
    • Matched TTPs: Sharepoint (T1213.002), JavaScript (T1059.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Domains (T1584.001), Masquerading (T1036), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), Remote Desktop Protocol (T1021.001), At (T1053.002)
  • One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025 — Tue, 18 Aug 2026 17:00:00 +0530
    • Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
  • 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets — Tue, 18 Aug 2026 16:50:00 +0530
    • Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers — Tue, 18 Aug 2026 14:40:45 +0530
    • Matched TTPs: DNS (T1071.004), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Domains (T1584.001), Private Keys (T1552.004), Server (T1584.004), Email Addresses (T1589.002), Proxy (T1090), Confluence (T1213.001), Tool (T1588.002), Phishing (T1566), Firmware (T1592.003), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE — Tue, 18 Aug 2026 12:04:20 +0530
    • Matched TTPs: Artificial Intelligence (T1588.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Phishing (T1566), Social Media (T1593.001), Python (T1059.006), At (T1053.002)

데일리시큐 - 최근인기기사

This post is licensed under CC BY 4.0 by the author.