Threat Hunt Feed (2026-08-20)
Hacker News: Best
- Air Theremin – A browser theremin you play by waving at your webcam — Wed, 19 Aug 2026 10:15:00 +0000
- Matched TTPs: At (T1053.002)
BleepingComputer
- Hackers poison arrayref Rust crate to push infostealer malware — Thu, 20 Aug 2026 13:53:52 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Databases (T1213.006), Stage Capabilities (T1608), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- Critical Elementor Pro bug exposes WordPress sites to RCE attacks — Thu, 20 Aug 2026 10:39:48 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), SSH (T1021.004), Server (T1584.004), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- How MSPs can catch phishing attacks email filters miss — Thu, 20 Aug 2026 10:01:11 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Cloud Services (T1021.007), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Credentials (T1589.001), Malicious Link (T1204.001), At (T1053.002)
- Citrix urges admins to patch new NetScaler flaws as soon as possible — Thu, 20 Aug 2026 08:14:38 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Firmware (T1592.003), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), At (T1053.002)
- New Manic Android malware can exfiltrate data through nearby devices — Thu, 20 Aug 2026 06:02:02 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
Darkreading
- ‘Grandoreiro’ Malware Resurfaces With Mexico Campaign — Thu, 20 Aug 2026 13:30:00 GMT
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Server (T1584.004), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
The Hacker News
- Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads — Fri, 21 Aug 2026 01:52:35 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Databases (T1213.006), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), PowerShell (T1059.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More — Thu, 20 Aug 2026 22:53:48 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), JavaScript (T1059.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Email Accounts (T1585.002), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Tool (T1588.002), Phishing (T1566), Process Hollowing (T1055.012), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure — Thu, 20 Aug 2026 22:29:44 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), DNS (T1071.004), Malware (T1588.001), Databases (T1213.006), Vulnerabilities (T1588.006), DLL (T1574.001), Domains (T1584.001), Server (T1584.004), Password Spraying (T1110.003), Proxy (T1090), Confluence (T1213.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
- New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data — Thu, 20 Aug 2026 20:06:27 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Chat Messages (T1552.008), Tool (T1588.002), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
- Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE — Thu, 20 Aug 2026 19:18:24 +0530
- Matched TTPs: JavaScript (T1059.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Escape to Host (T1611), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Social Media (T1593.001), At (T1053.002)
- Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments — Thu, 20 Aug 2026 17:31:24 +0530
- Matched TTPs: IP Addresses (T1590.005), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Software (T1592.002), Social Media (T1593.001), At (T1053.002)
- Why “Shady AI” is Security’s Next Big Governance Problem — Thu, 20 Aug 2026 17:15:00 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Tool (T1588.002), Social Media (T1593.001), At (T1053.002)
- CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification — Thu, 20 Aug 2026 17:09:35 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), CDNs (T1596.004), Social Media (T1593.001), At (T1053.002), Compression (T1027.015)
- Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices — Thu, 20 Aug 2026 16:56:08 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Phishing (T1566), Social Media (T1593.001), At (T1053.002), Messaging Applications (T1213.005)
- NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands — Thu, 20 Aug 2026 16:35:11 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud — Thu, 20 Aug 2026 16:08:28 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets — Thu, 20 Aug 2026 14:12:03 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Clipboard Data (T1115), Domains (T1584.001), Masquerading (T1036), Private Keys (T1552.004), Server (T1584.004), Proxy (T1090), Confluence (T1213.001), Phishing (T1566), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)