Threat Hunt Feed (2026-09-01)
Hacker News: Best
- ChatGPT Work Tool and Skill Reference — Mon, 31 Aug 2026 14:07:15 +0000
- Matched TTPs: JavaScript (T1059.007), Databases (T1213.006), Domains (T1584.001), Server (T1584.004), Email Addresses (T1589.002), Accessibility Features (T1546.008), Proxy (T1090), Extended Attributes (T1564.014), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), Python (T1059.006), File Deletion (T1070.004), At (T1053.002)
BleepingComputer
- Microsoft warns of TerminalFix attacks deploying reverse tunnels — Mon, 31 Aug 2026 14:51:04 -0400
- Matched TTPs: Scheduled Task (T1053.005), Embedded Payloads (T1027.009), Malware (T1588.001), Hardware (T1592.001), Databases (T1213.006), DLL (T1574.001), Server (T1584.004), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Credentials (T1589.001), Steganography (T1001.002), Python (T1059.006)
- File servers are here to stay. Here’s how to manage them securely — Mon, 31 Aug 2026 10:00:10 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), Cloud Services (T1021.007), Local Groups (T1069.001), Tool (T1588.002), Software (T1592.002)
Darkreading
- ‘TerminalFix’ Campaign Weaponizes PowerShell for Enterprise Attacks — Mon, 31 Aug 2026 20:25:36 GMT
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Server (T1584.004), PowerShell (T1059.001), Software (T1592.002), Steganography (T1001.002), Python (T1059.006), At (T1053.002)
The Hacker News
- ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More — Mon, 31 Aug 2026 19:20:00 +0530
- Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Rootkit (T1014), External Remote Services (T1133), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), DLL (T1574.001), Botnet (T1584.005), Masquerading (T1036), Remote Services (T1021), Server (T1584.004), Email Addresses (T1589.002), Proxy (T1090), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Firmware (T1592.003), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Email Bombing (T1667), At (T1053.002)
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions — Mon, 31 Aug 2026 17:44:00 +0530
- Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets — Mon, 31 Aug 2026 17:17:24 +0530
- Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Credentials from Web Browsers (T1555.003), Server (T1584.004), Shell History (T1552.003), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Email Bombing (T1667), Python (T1059.006), At (T1053.002), Inhibit System Recovery (T1490)
- Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance — Mon, 31 Aug 2026 17:01:47 +0530
- Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Vulnerabilities (T1588.006), Botnet (T1584.005), Server (T1584.004), Cloud Services (T1021.007), Tool (T1588.002), Phishing (T1566), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs — Mon, 31 Aug 2026 14:34:55 +0530
- Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Server (T1584.004), Malicious Library (T1204.005), Tool (T1588.002), Phishing (T1566), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)