Threat Hunt Feed (2026-09-22)
Hacker News: Best
- Show HN: Mini-AGI – Dynamic continual learning model trained on 8GB VRAM — Mon, 21 Sep 2026 04:42:37 +0000
- Matched TTPs: Hardware (T1592.001), Vulnerabilities (T1588.006), Domains (T1584.001), Tool (T1588.002), Software (T1592.002), Python (T1059.006), At (T1053.002)
BleepingComputer
- BigCommerce alerts merchants of data breach linked to Ribon apps — Mon, 21 Sep 2026 17:18:49 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), Email Addresses (T1589.002), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- CISA alerts of active exploitation of three Linux kernel flaws — Mon, 21 Sep 2026 16:12:17 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), At (T1053.002)
- WordPress Click2Shell flaw lets hackers execute PHP on the server — Mon, 21 Sep 2026 14:23:11 -0400
- Matched TTPs: JavaScript (T1059.007), Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- FBI’s CJIS v6.1: What Security Teams Need to Know. — Mon, 21 Sep 2026 10:02:12 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Vulnerability Scanning (T1595.002), Server (T1584.004), Tool (T1588.002), Multi-Factor Authentication (T1556.006), Firmware (T1592.003), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- Microsoft reminds admins to migrate Entra ID users to passkeys — Mon, 21 Sep 2026 09:16:20 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), At (T1053.002)
Darkreading
- Cybercriminals Are Hiding New Malware in Torrents for Popular Films — Mon, 21 Sep 2026 19:11:26 GMT
- Matched TTPs: Bypass User Account Control (T1548.002), Malware (T1588.001), Vulnerabilities (T1588.006), Server (T1584.004), Software (T1592.002), At (T1053.002)
The Hacker News
- Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR — Mon, 21 Sep 2026 23:01:01 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Malicious File (T1204.002), Hardware (T1592.001), Vulnerabilities (T1588.006), DLL (T1574.001), Cloud Accounts (T1078.004), Server (T1584.004), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Impersonation (T1656), Windows Credential Manager (T1555.004), At (T1053.002)
- Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto — Mon, 21 Sep 2026 22:49:00 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), IP Addresses (T1590.005), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Cloud Accounts (T1078.004), Server (T1584.004), Proxy (T1090), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data — Mon, 21 Sep 2026 19:45:40 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Clipboard Data (T1115), Cloud Accounts (T1078.004), Server (T1584.004), PowerShell (T1059.001), Phishing (T1566), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Visual Basic (T1059.005), At (T1053.002)
- ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure — Mon, 21 Sep 2026 14:09:38 +0530
- Matched TTPs: Scheduled Task (T1053.005), JavaScript (T1059.007), DNS (T1071.004), Malware (T1588.001), Browser Extensions (T1176.001), Vulnerabilities (T1588.006), Msiexec (T1218.007), Cloud Accounts (T1078.004), Domains (T1584.001), Server (T1584.004), PowerShell (T1059.001), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)