Threat Hunt Feed (2026-09-23)
Hacker News: Best
- Python Workers are now generally available — Mon, 21 Sep 2026 13:38:19 +0000
- Matched TTPs: Serverless (T1584.007), Artificial Intelligence (T1588.007), JavaScript (T1059.007), DNS (T1071.004), Malware (T1588.001), Hardware (T1592.001), Databases (T1213.006), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Phishing (T1566), Lua (T1059.011), Firmware (T1592.003), Social Media (T1593.001), Python (T1059.006), Remote Desktop Protocol (T1021.001), At (T1053.002), Compression (T1027.015)
BleepingComputer
- Chinese hackers exploit WordPress, Zyxel flaws to steal govt data — Tue, 22 Sep 2026 16:35:24 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Databases (T1213.006), Vulnerabilities (T1588.006), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), Credentials (T1589.001), Impersonation (T1656), At (T1053.002), Local Accounts (T1078.003)
- New ClosedQuorum Windows malware uses AI for attack decisions — Tue, 22 Sep 2026 14:04:39 -0400
- Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), Tool (T1588.002), Process Hollowing (T1055.012), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- Reducing shadow IT visibility gaps with Wazuh — Tue, 22 Sep 2026 13:17:41 -0400
- Matched TTPs: Network Devices (T1584.008), Malware (T1588.001), Hardware (T1592.001), Browser Extensions (T1176.001), Vulnerabilities (T1588.006), SSH (T1021.004), Remote Access Tools (T1219), Server (T1584.004), Tool (T1588.002), Software (T1592.002)
- Check Point warns of Management Server zero-day exploited in attacks — Tue, 22 Sep 2026 12:32:47 -0400
- Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Hardware (T1592.001), Server (T1584.004), Tool (T1588.002), Software (T1592.002), At (T1053.002)
- EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts — Tue, 22 Sep 2026 11:00:00 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Domains (T1584.001), Server (T1584.004), Compromise Accounts (T1586), Tool (T1588.002), Phishing (T1566), Software (T1592.002), At (T1053.002)
Darkreading
- Microsoft Disrupts EvilTokens Device Code Phishing Service — Tue, 22 Sep 2026 20:02:02 GMT
- Matched TTPs: Adversary-in-the-Middle (T1557), Vulnerabilities (T1588.006), Domains (T1584.001), Phishing (T1566), At (T1053.002)
The Hacker News
- Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks — Tue, 22 Sep 2026 23:59:39 +0530
- Matched TTPs: IP Addresses (T1590.005), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Cloud Accounts (T1078.004), Server (T1584.004), Web Service (T1102), Phishing (T1566), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers — Tue, 22 Sep 2026 23:33:10 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Cloud Accounts (T1078.004), Server (T1584.004), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials — Tue, 22 Sep 2026 23:28:15 +0530
- Matched TTPs: Serverless (T1584.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Cloud Accounts (T1078.004), Server (T1584.004), Tool (T1588.002), Phishing (T1566), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises — Tue, 22 Sep 2026 22:33:31 +0530
- Matched TTPs: Serverless (T1584.007), Artificial Intelligence (T1588.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Cloud Accounts (T1078.004), Email Accounts (T1585.002), Domains (T1584.001), Control Panel (T1218.002), Server (T1584.004), Phishing (T1566), Multi-Factor Authentication (T1556.006), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Impersonation (T1656), Malicious Link (T1204.001), At (T1053.002)
- Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials — Tue, 22 Sep 2026 22:11:12 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Cloud Accounts (T1078.004), Server (T1584.004), Phishing (T1566), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates — Tue, 22 Sep 2026 21:44:04 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Cloud Accounts (T1078.004), Server (T1584.004), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups — Tue, 22 Sep 2026 17:59:00 +0530
- Matched TTPs: IP Addresses (T1590.005), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Cloud Accounts (T1078.004), Server (T1584.004), Phishing (T1566), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE — Tue, 22 Sep 2026 16:47:41 +0530
- Matched TTPs: Sharepoint (T1213.002), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Cloud Accounts (T1078.004), Server (T1584.004), Phishing (T1566), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing — Tue, 22 Sep 2026 13:22:03 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Malicious File (T1204.002), Vulnerabilities (T1588.006), DLL (T1574.001), Cloud Accounts (T1078.004), Server (T1584.004), Mshta (T1218.005), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor — Tue, 22 Sep 2026 12:03:57 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Cloud Accounts (T1078.004), Server (T1584.004), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session — Tue, 22 Sep 2026 11:33:14 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Cloud Accounts (T1078.004), Web Shell (T1505.003), Server (T1584.004), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access — Tue, 22 Sep 2026 11:01:59 +0530
- Matched TTPs: DNS (T1071.004), Malware (T1588.001), Vulnerabilities (T1588.006), Cloud Accounts (T1078.004), Server (T1584.004), Tool (T1588.002), Phishing (T1566), Firmware (T1592.003), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), At (T1053.002)