Threat Hunt Feed (2026-09-16)
Hacker News: Best
- Show HN: Capsule – Single-file web apps that save their data into SQLite — Tue, 15 Sep 2026 13:31:40 +0000
- Matched TTPs: Databases (T1213.006), Cloud Accounts (T1078.004), Server (T1584.004), At (T1053.002)
BleepingComputer
- BambooToken malware controls Windows and Linux systems via MQTT — Tue, 15 Sep 2026 11:00:00 -0400
- Matched TTPs: Keylogging (T1056.001), Rootkit (T1014), Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), Tool (T1588.002), Software (T1592.002), At (T1053.002)
- What Zero-Day Response Should Be in the Post-Mythos Era — Tue, 15 Sep 2026 09:45:54 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), At (T1053.002)
Darkreading
[Black Hat USA 2026 The ‘Breaking’ News: The OpenAI–Hugging Face Incident](https://www.darkreading.com/vulnerabilities-threats/bhusa26huggingfacetalk) — Tue, 15 Sep 2026 19:27:19 GMT - Matched TTPs: Vulnerabilities (T1588.006), At (T1053.002)
- VectraRAT Can Hack Windows Enterprises for $250 per Month — Tue, 15 Sep 2026 16:45:37 GMT
- Matched TTPs: Keylogging (T1056.001), Malware (T1588.001), Vulnerabilities (T1588.006), Remote Access Tools (T1219), Server (T1584.004), Proxy (T1090), Process Discovery (T1057), PowerShell (T1059.001), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
The Hacker News
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens — Wed, 16 Sep 2026 00:24:14 +0530
- Matched TTPs: Scheduled Task (T1053.005), JavaScript (T1059.007), Malware (T1588.001), Hardware (T1592.001), Browser Extensions (T1176.001), Vulnerabilities (T1588.006), DLL (T1574.001), Domains (T1584.001), Web Shell (T1505.003), Server (T1584.004), Phishing (T1566), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists — Tue, 15 Sep 2026 21:59:51 +0530
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Web Shell (T1505.003), Email Addresses (T1589.002), Proxy (T1090), Chat Messages (T1552.008), Phishing (T1566), Multi-Factor Authentication (T1556.006), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- BambooToken Malware Uses MQTT to Control Windows and Linux Systems — Tue, 15 Sep 2026 20:53:19 +0530
- Matched TTPs: Windows Management Instrumentation (T1047), IP Addresses (T1590.005), Malware (T1588.001), Malicious File (T1204.002), Hardware (T1592.001), Vulnerabilities (T1588.006), DLL (T1574.001), Virtual Private Server (T1583.003), Domains (T1584.001), Web Shell (T1505.003), Server (T1584.004), Proxy (T1090), PowerShell (T1059.001), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds — Tue, 15 Sep 2026 17:22:28 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Web Shell (T1505.003), Server (T1584.004), Trap (T1546.005), Web Services (T1584.006), Phishing (T1566), Lua (T1059.011), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)
- Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point — Tue, 15 Sep 2026 16:56:36 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), Web Shell (T1505.003), Phishing (T1566), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers — Tue, 15 Sep 2026 16:42:32 +0530
- Matched TTPs: Serverless (T1584.007), Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), Web Shell (T1505.003), Server (T1584.004), Web Services (T1584.006), Phishing (T1566), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server — Tue, 15 Sep 2026 12:22:16 +0530
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Web Shell (T1505.003), Server (T1584.004), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution — Tue, 15 Sep 2026 11:41:11 +0530
- Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Vulnerabilities (T1588.006), Web Shell (T1505.003), Email Addresses (T1589.002), Employee Names (T1589.003), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE — Tue, 15 Sep 2026 11:01:05 +0530
- Matched TTPs: Keylogging (T1056.001), JavaScript (T1059.007), Malware (T1588.001), Vulnerabilities (T1588.006), DLL (T1574.001), Process Injection (T1055), Web Shell (T1505.003), Server (T1584.004), Phishing (T1566), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Hidden Window (T1564.003), At (T1053.002)