Posts 2026 10 01 Daily Hunt Feed - 2026-10-01
Post
Cancel

Daily Hunt Feed - 2026-10-01

Threat Hunt Feed (2026-10-01)

Hacker News: Best

  • Tcl/Tk 9.1 — Tue, 29 Sep 2026 17:13:38 +0000
    • Matched TTPs: Software (T1592.002)

BleepingComputer

Darkreading

The Hacker News

  • Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets — Wed, 30 Sep 2026 22:16:29 +0530
    • Matched TTPs: Sharepoint (T1213.002), Malware (T1588.001), Local Account (T1136.001), Cron (T1053.003), Vulnerabilities (T1588.006), SSH (T1021.004), Web Shell (T1505.003), Server (T1584.004), SSH Authorized Keys (T1098.004), Tool (T1588.002), Exploits (T1588.005), Social Media (T1593.001), Credentials (T1589.001), Systemd Service (T1543.002), At (T1053.002)
  • Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks — Wed, 30 Sep 2026 22:02:59 +0530
    • Matched TTPs: Sharepoint (T1213.002), Vulnerabilities (T1588.006), SSH (T1021.004), Server (T1584.004), Cloud Services (T1021.007), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Social Media (T1593.001), Installer Packages (T1546.016), At (T1053.002)
  • Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures — Wed, 30 Sep 2026 20:30:15 +0530
    • Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), JavaScript (T1059.007), DNS (T1071.004), Malvertising (T1583.008), Malware (T1588.001), Active Setup (T1547.014), Vulnerabilities (T1588.006), SSH (T1021.004), DLL (T1574.001), Server (T1584.004), Proxy (T1090), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub — Wed, 30 Sep 2026 17:00:00 +0530
    • Matched TTPs: Sharepoint (T1213.002), Artificial Intelligence (T1588.007), Vulnerabilities (T1588.006), SSH (T1021.004), Server (T1584.004), Tool (T1588.002), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
  • US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access — Wed, 30 Sep 2026 16:15:00 +0530
    • Matched TTPs: Sharepoint (T1213.002), JavaScript (T1059.007), Vulnerabilities (T1588.006), SSH (T1021.004), Domains (T1584.001), Server (T1584.004), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Social Media (T1593.001), At (T1053.002)
This post is licensed under CC BY 4.0 by the author.