Threat Hunt Feed (2026-10-01)
Hacker News: Best
- Tcl/Tk 9.1 — Tue, 29 Sep 2026 17:13:38 +0000
- Matched TTPs: Software (T1592.002)
BleepingComputer
- Russian state hackers use new RedFlick technique to push malware — Wed, 30 Sep 2026 16:34:01 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), DLL (T1574.001), Domains (T1584.001), Control Panel (T1218.002), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Credentials (T1589.001), Hidden Window (T1564.003), Python (T1059.006), Conditional Access Policies (T1556.009), At (T1053.002)
- DIVD says Zammad zero-days enabled AI-driven network breach — Wed, 30 Sep 2026 15:49:15 -0400
- Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Domains (T1584.001), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- Over 543,000 valid credentials exposed in public GitHub repositories — Wed, 30 Sep 2026 14:08:34 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Databases (T1213.006), Domains (T1584.001), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
- TeamViewer urges users to patch severe flaws “as soon as possible” — Wed, 30 Sep 2026 08:25:10 -0400
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Domains (T1584.001), Tool (T1588.002), Software (T1592.002), Credentials (T1589.001), At (T1053.002)
Darkreading
- Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure — Wed, 30 Sep 2026 21:25:47 GMT
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), PowerShell (T1059.001), Tool (T1588.002), Software (T1592.002), Exploits (T1588.005), At (T1053.002)
- Russia’s Star Blizzard Ditches ClickFix to Widen Phishing Net — Wed, 30 Sep 2026 15:02:25 GMT
- Matched TTPs: Malware (T1588.001), Vulnerabilities (T1588.006), Domains (T1584.001), PowerShell (T1059.001), Phishing (T1566), Credentials (T1589.001), Steganography (T1001.002), Python (T1059.006), Conditional Access Policies (T1556.009), At (T1053.002)
- South Africa Seeks Help After Cyberattack Targets Air Traffic Control — Wed, 30 Sep 2026 07:00:00 GMT
- Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Vulnerabilities (T1588.006), Software (T1592.002), Python (T1059.006), At (T1053.002)
The Hacker News
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets — Wed, 30 Sep 2026 22:16:29 +0530
- Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Local Account (T1136.001), Cron (T1053.003), Vulnerabilities (T1588.006), SSH (T1021.004), Web Shell (T1505.003), Server (T1584.004), SSH Authorized Keys (T1098.004), Tool (T1588.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Systemd Service (T1543.002), At (T1053.002)
- Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks — Wed, 30 Sep 2026 22:02:59 +0530
- Matched TTPs: Sharepoint (T1213.002), Vulnerabilities (T1588.006), SSH (T1021.004), Server (T1584.004), Cloud Services (T1021.007), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Installer Packages (T1546.016), At (T1053.002)
- Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures — Wed, 30 Sep 2026 20:30:15 +0530
- Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), JavaScript (T1059.007), DNS (T1071.004), Malvertising (T1583.008), Malware (T1588.001), Active Setup (T1547.014), Vulnerabilities (T1588.006), SSH (T1021.004), DLL (T1574.001), Server (T1584.004), Proxy (T1090), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub — Wed, 30 Sep 2026 17:00:00 +0530
- Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Vulnerabilities (T1588.006), SSH (T1021.004), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access — Wed, 30 Sep 2026 16:15:00 +0530
- Matched TTPs: Sharepoint (T1213.002), JavaScript (T1059.007), Vulnerabilities (T1588.006), SSH (T1021.004), Domains (T1584.001), Server (T1584.004), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Social Media (T1593.001), At (T1053.002)