Threat Hunting: A Guide | Recorded Future

The article argues that modern enterprises must assume they are already breached and use proactive, intelligence-led threat hunting to find attackers hiding in normal business activity. It explains the core methods, required telemetry, and lifecycle of threat hunting while highlighting how Recorded Future’s Intelligence Graph, Insikt Group, Cyber Operations, and Autonomous Threat Operations help reduce manual triage and speed detection. #RecordedFuture #IntelligenceGraph #InsiktGroup #CyberOperations #AutonomousThreatOperations #MITREATTACK

Read More
Targeted Attack on Government Entities in the Middle East | Part 1

Zscaler ThreatLabz observed a multi-stage campaign in July 2026 in which a threat actor linked to East Asia targeted government entities in the Middle East using previously undocumented tooling including TELESHIM, MIXEDKEY, and BINDCLOAK. The malware abused Telegram API traffic for command-and-control, relied on heavy obfuscation and environmental keying, and deployed post-compromise reconnaissance and staged payloads to maintain access. #TELESHIM #MIXEDKEY #BINDCLOAK #TelegramAPI #ThreatLabz

Read More
A Look Inside the HuggingFace Breach

HuggingFace disclosed that an autonomous AI attacker chained two RCE vulnerabilities in its dataset processing pipeline, leaked cloud and cluster credentials, moved laterally, and used decoy activity to slow investigation. HuggingFace contained the incident with AI-driven detection and defensive analysis, then recommended rotating API tokens, tightening least privilege, and treating downloaded…

Read More
Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service

Proofpoint analyzed Cruciferra, a crypter service sold on Exploit.in and used by multiple unrelated threat actors to deliver payloads such as AsyncRAT, XWorm, zgRAT, and other stealers and RATs. The service relies on heavy defense evasion, including DLL side-loading, BYOVD tampering, indirect syscalls, IAT unhooking, and a customized Process Ghosting variant,…

Read More
Detecting common Linux privilege escalation techniques with Wazuh

The article demonstrates how Wazuh detects multiple Linux privilege escalation techniques, including sudo abuse, SUID/SGID misuse, group membership changes, ptrace injection, dynamic linker hijacking, and cron abuse. It also shows the auditd, File Integrity Monitoring, and custom rule configurations used to generate alerts for these attacks on Ubuntu endpoints. #Wazuh #auditd…

Read More

MalwareHunterTeam analyzed a low-detection Linux ELF backdoor named gregbfdah.png that was delivered from an AWS S3 URL and uploaded to VirusTotal in June 2026. The implant uses AES-128-GCM and MessagePack for configuration and C2 communication, and it supports registration, command execution, file operations, and reverse pivot tunneling. #MalwareHunterTeam #gregbfdah.png #VirusTotal #iot.981666.xyz

Read More
Wp2shell: Critical Vulnerabilities in the Core of WordPress. Systems Must Be Updated

Two WordPress core vulnerabilities, CVE-2026-60137 and CVE-2026-63030, can be chained into wp2shell to enable unauthenticated access, SQL injection, and potentially remote code execution on affected sites. CERT-AGID urges administrators, especially public-sector operators, to update to the fixed versions and inspect systems for signs of compromise such as suspicious batch API requests, new admin accounts, web shells, or unexpected database activity. #WordPress #CERT-AGID #CVE-2026-60137 #CVE-2026-63030 #wp2shell

Read More
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

Volexity investigated the compromise of SonicWall Secure Mobile Access (SMA) VPN appliances by UTA0533, which chained multiple zero-day exploits to gain root access, deploy KNUCKLEBALL, ROOTRUN, Suo5, and ORANGETAIL, and pivot inside victim networks. The intrusion leveraged CVE-2026-15409 and CVE-2026-15410, exposed localhost-only services through /wsproxy, and used captured LDAP traffic and modified nginx routes to support post-exploitation activity. #SonicWall #SMA #UTA0533 #KNUCKLEBALL #ORANGETAIL #Suo5 #ROOTRUN #CVE-2026-15409 #CVE-2026-15410

Read More
Session recording adoption takes off

Acronis RMM’s selective session recording became generally available on April 22, 2026, and adoption rose quickly across thousands of tenants over the next two months. The feature is being used broadly and substantively for privileged remote-access audit evidence, with especially strong uptake in Canada, Switzerland, Japan, South Africa, and Brazil. #AcronisRMM #AU14 #NISTSP80053 #GDPR #ISOIEC270012022

Read More
New North Korean campaign uses fake coding interviews to steal developer credentials

Elastic Security Labs uncovered REF9403, a new Contagious Interview campaign that hides malware in SVG files via steganography and uses fake job offers to target developers. The payloads align with OTTERCOOKIE and include browser and wallet theft, file theft, a Socket.IO-based RAT, and clipboard stealing, with infrastructure on rightwidth[.]dev and related subdomains. #REF9403 #ContagiousInterview #OTTERCOOKIE #rightwidthdev

Read More
Case Study: Packetwatch product and research integration with Validin

PacketWatch uses Validin threat intelligence inside WireSight to identify malicious traffic, pivot into related infrastructure, and uncover additional indicators of compromise tied to the LandUpdate808 and SmartApeSG campaigns. The investigation traces a malicious visit to cpajoliette[.]com, a ClickFix-delivered JavaScript chain, and a wider cluster of newly discovered .top domains and IP addresses used for SEO abuse and threat actor infrastructure. #Validin #PacketWatch #WireSight #LandUpdate808 #SmartApeSG #cpajoliettecom #bronzewhispertop

Read More
DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150’s Evolving Tradecraft

eSentire TRU disrupted a ClickFix-style infection chain in a finance customer environment that used an MSI installer and AI-generated PowerShell to deploy DinDoor, DenoRAT, and NightshadeC2. The campaign is attributed to TAG-150 and used Deno-based tooling, hard-coded JWTs, and in-memory loading to establish persistence, steal data, and execute NightshadeC2. #TAG150 #DinDoor #DenoRAT #NightshadeC2 #ClickFix

Read More
Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain

Seqrite Labs identified a GST-themed phishing campaign that impersonated the Government of India to deliver a multi-stage .NET malware chain ending in Remcos RAT. The operation used malicious archives, bitmap-based payload concealment, fileless execution, and dynamic DNS infrastructure to target Indian businesses and taxpayers. #RemcosRAT #GST #GovernmentofIndia #hathnetwork #synologyme

Read More
DNS Investigation: Threat Actor TA4922 Goes Global

TA4922 is a highly sophisticated cybercriminal group that rapidly shifted between Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT (Winos4.0) while expanding campaigns from nearby regions into parts of Europe and Africa. Proofpoint and subsequent investigation uncovered multiple related network indicators, victim communications, and infrastructure artifacts tied to malicious domains, subdomains, and IP addresses. #TA4922 #AtlasRAT #RomulusLoader #SilentRunLoader #ValleyRAT #Winos4.0 #Proofpoint #nwphotoblogcom #wsztts88cyou

Read More
Still Circling: Blind Eagle’s Toolkit Keeps Evolving

LevelBlue SpiderLabs reports that Blind Eagle has continued evolving its delivery chains in 2026, including new obfuscation schemes, a GitHub-staged AutoIt loader, and a heavily upgraded AsyncRAT build. The cluster still relies on recurring “Photo Studio” persistence artifacts and shared infrastructure patterns while adding WNF injection, HVNC banking fraud, browser profile cloning, and a Chrome App-Bound Encryption bypass. #BlindEagle #Proton66 #AsyncRAT #PhotoStudioVBS #JC-46

Read More