Threat Hunt Feed (2026-09-02)
Hacker News: Best
- Run macOS Software on Linux — Mon, 31 Aug 2026 22:53:45 +0000
- Matched TTPs: Hardware (T1592.001), Software (T1592.002)
BleepingComputer
- Hackers abuse Faronics Deploy admin tool to install ScreenConnect — Tue, 01 Sep 2026 16:53:23 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Msiexec (T1218.007), Mshta (T1218.005), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- Critical Langflow flaw exploited to steal OpenAI and AWS keys — Tue, 01 Sep 2026 13:54:22 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Databases (T1213.006), SSH (T1021.004), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
- Hackers push malicious Virtualizor update in BGP hijacking attack — Tue, 01 Sep 2026 10:45:06 -0400
- Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Hardware (T1592.001), SSH (T1021.004), Control Panel (T1218.002), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001)
- Five Venezuelans plead guilty to ATM jackpotting attacks in US — Tue, 01 Sep 2026 05:15:07 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- Recently patched PaperCut zero-days used in data theft attacks — Tue, 01 Sep 2026 03:48:24 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
Darkreading
- Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency — Wed, 02 Sep 2026 01:00:00 GMT
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Databases (T1213.006), Vulnerabilities (T1588.006), Server (T1584.004), Software (T1592.002), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
- ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain — Tue, 01 Sep 2026 13:56:42 GMT
- Matched TTPs: JavaScript (T1059.007), Malware (T1588.001), Vulnerabilities (T1588.006), Server (T1584.004), PowerShell (T1059.001), Phishing (T1566), At (T1053.002)
The Hacker News
- Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems — Tue, 01 Sep 2026 22:49:24 +0530
- Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), DNS (T1071.004), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Server (T1584.004), Password Spraying (T1110.003), Proxy (T1090), PowerShell (T1059.001), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Remote Desktop Protocol (T1021.001), At (T1053.002)
- 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds — Tue, 01 Sep 2026 19:37:20 +0530
- Matched TTPs: Sharepoint (T1213.002), JavaScript (T1059.007), Keychain (T1555.001), Malware (T1588.001), Databases (T1213.006), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Financial Theft (T1657), Phishing (T1566), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests — Tue, 01 Sep 2026 18:38:58 +0530
- Matched TTPs: Scheduled Task (T1053.005), Sharepoint (T1213.002), Artificial Intelligence (T1588.007), IP Addresses (T1590.005), JavaScript (T1059.007), DNS (T1071.004), Malware (T1588.001), Cron (T1053.003), Vulnerabilities (T1588.006), SSH (T1021.004), DLL (T1574.001), Botnet (T1584.005), Domains (T1584.001), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Launch Agent (T1543.001), Visual Basic (T1059.005), At (T1053.002)
- Attackers Steal METR API Key and Consume AI Credits Worth About $600,000 — Tue, 01 Sep 2026 14:35:30 +0530
- Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Server (T1584.004), Phishing (T1566), Credential Stuffing (T1110.004), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis — Tue, 01 Sep 2026 13:56:24 +0530
- Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), JavaScript (T1059.007), Malware (T1588.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Server (T1584.004), Phishing (T1566), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity — Tue, 01 Sep 2026 12:52:30 +0530
- Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Phishing (T1566), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)