home.social

#cyberhunter_nl — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cyberhunter_nl, aggregated by home.social.

  1. Iranian Hackers Use Fake Dubai Airports Coding Test to Target Iraqi Critical Infrastructure

    Iranian state-aligned hackers have used a fake Dubai Airports recruitment process to target Iraqi critical infrastructure with a booby-trapped coding test. The campaign, called Blinder Tunnel, turned a routine developer task into a quiet, potentially long-term route for remote access, persistence and network tunneling across a victim environment. The operation was prepared as early as […] The post Iranian Hackers Use Fake Dubai Airports Coding Test to Target Iraqi Critical Infrastructure appeared first on Cyber Security News .

    Pulse ID: 6ac50c1b5db79ae0d9b3b778
    Pulse Link: otx.alienvault.com/pulse/6ac50
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 14:56:27

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #TASK #OTX #CyberHunter_NL

  2. Ransomware Hacker Uses AI Coding Assistant as Attack Channel Against Enterprise Networks

    A ransomware affiliate has turned an AI coding assistant into a channel for running attacks inside enterprise networks. The operator, known as Azazel, combined stolen development credentials, remote command execution and data theft while working with the Gentlemen ransomware group. The campaign affected more than two dozen organisations across six countries, including logistics, insurance, pharmaceuticals, […] The post Ransomware Hacker Uses AI Coding Assistant as Attack Channel Against Enterprise Networks appeared first on Cyber Security News .

    Pulse ID: 6ac50c22da460370716e4978
    Pulse Link: otx.alienvault.com/pulse/6ac50
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 14:56:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #RansomWare #DataTheft #Gentlemen #RemoteCommandExecution #OTX #CyberHunter_NL

  3. Hackers Exploit Exposed Industrial Controllers to Disrupt US Water and Critical Infrastructure

    Hackers are exploiting internet-connected industrial controllers to disrupt US water utilities and other essential services. Recent incidents show that poorly protected equipment can give attackers direct access to physical operations, with consequences ranging from lost monitoring to flooding and reduced water pressure. The threat involves several campaigns rather than one newly discovered malware family. Attackers […] The post Hackers Exploit Exposed Industrial Controllers to Disrupt US Water and Critical Infrastructure appeared first on Cyber Security News .

    Pulse ID: 6ac4fdfad2141ccf0ebf1cc8
    Pulse Link: otx.alienvault.com/pulse/6ac4f
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 13:56:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #CyberHunter_NL

  4. Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials

    Travelers connecting to hotel Wi-Fi may now face more than an unreliable internet signal. A campaign linked to Midnight Blizzard has turned captive portals, the sign-in pages shown before online access, into a route for malware, credential theft, and possible access to corporate accounts. The operation, known as CaptiveCrunch, has affected hospitality-related networks and other […] The post Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials appeared first on Cyber Security News .

    Pulse ID: 6ac4d3b9884839b3b6b8fcbf
    Pulse Link: otx.alienvault.com/pulse/6ac4d
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 10:55:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Deliver #Malware #Credential #OTX #CyberHunter_NL

  5. Blinder Tunnel Campaign Targets Iraqi Infrastructure

    Analysis of Blinder Tunnel, an Iran-nexus campaign using fake Dubai Airports recruitment lures and GitHub C2 malware to target critical infrastructure. The post Blinder Tunnel Campaign Targets Iraqi Infrastructure appeared first on Unit 42 .

    Pulse ID: 6ac4d3cb21c3c2f7a2c1d865
    Pulse Link: otx.alienvault.com/pulse/6ac4d
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 10:56:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #GitHub #Iran #Unit42 #OTX #CyberHunter_NL

  6. ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

    ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote access. Rather than simply infecting routers and cameras, it turns compromised equipment into remotely controlled proxy nodes that can relay traffic and run commands. The campaign targets known security flaws across multiple vendors, expanding its attack methods as it evolves. […] The post ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access appeared first on Cyber Security News .

    Pulse ID: 6ac4c5b172d0180a9464f655
    Pulse Link: otx.alienvault.com/pulse/6ac4c
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 09:56:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #IoT #Linux #Proxy #OTX #CyberHunter_NL

  7. ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

    A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.

    Pulse ID: 6ac49b893a8000cf4c9c1735
    Pulse Link: otx.alienvault.com/pulse/6ac49
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 06:56:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Clickfix #Windows #Browser #Microsoft #OTX #CyberHunter_NL

  8. CVE-2026-104286: Critical FortiMail Zero-Day Exploited for Unauthenticated File Writes

    Fortinet has disclosed a critical FortiMail zero-day vulnerability that attackers are already exploiting in the wild. Tracked as CVE-2026-104286 and rated 9.8 on the CVSS scale, the flaw enables an unauthenticated remote attacker to write arbitrary files to the underlying system by sending specially crafted HTTP or HTTPS requests. The vulnerability poses a significant risk […] The post CVE-2026-104286: Critical FortiMail Zero-Day Exploited for Unauthenticated File Writes appeared first on SOC Prime .

    Pulse ID: 6ac3e4c60b5f3d6ef7c5140a
    Pulse Link: otx.alienvault.com/pulse/6ac3e
    Pulse Author: CyberHunter_NL
    Created: 2026-10-05 17:56:22

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CVE2026104286 #ZeroDay #HTTP #HTTPS #OTX #CyberHunter_NL

  9. ClickFix Fake CAPTCHA Attack Executes Malware Hidden Inside Browser Cache

    A new ClickFix campaign is turning a web safety check into a route for malware. Visitors to compromised websites see a fake CAPTCHA or repair message and are told to open the Windows Run dialog, paste copied text, and press Enter. The instruction looks simple, but it makes the victim run the attacker’s command. The […] The post ClickFix Fake CAPTCHA Attack Executes Malware Hidden Inside Browser Cache appeared first on Cyber Security News .

    Pulse ID: 6ac3ac68f9c76cd14a4824e4
    Pulse Link: otx.alienvault.com/pulse/6ac3a
    Pulse Author: CyberHunter_NL
    Created: 2026-10-05 13:55:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #Clickfix #Browser #Malware #OTX #CyberHunter_NL

  10. Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

    Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report

    Pulse ID: 6ac3ac6e93930b4d37dbe1fa
    Pulse Link: otx.alienvault.com/pulse/6ac3a
    Pulse Author: CyberHunter_NL
    Created: 2026-10-05 13:55:58

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #botnet #Deploy #OTX #CyberHunter_NL

  11. GlassWorm Supply Chain Attack Uses Fake VS Code Themes to Deliver Hidden Malware

    GlassWorm is turning developer tools into malware delivery channels, this time through extensions advertised as attractive VS Code themes. The investigated cluster spans Visual Studio Marketplace and Open VSX, showing how appearance changes can provide cover for code that runs on developer machines. The campaign first surfaced in October 2025 and has since expanded across […] The post GlassWorm Supply Chain Attack Uses Fake VS Code Themes to Deliver Hidden Malware appeared first on Cyber Security News .

    Pulse ID: 6ac39e5ee608657a5f263a97
    Pulse Link: otx.alienvault.com/pulse/6ac39
    Pulse Author: CyberHunter_NL
    Created: 2026-10-05 12:55:58

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #SupplyChain #Malware #OTX #CyberHunter_NL

  12. Response Overview and Colonel Clustered – Grouping Burp Responses by Content

    Two Burp Suite extensions that group responses by content: Response Overview, a BApp with a threshold you set, and Colonel Clustered, which picks its own.

    Pulse ID: 6ac39e746ceb2124f3eb1e3d
    Pulse Link: otx.alienvault.com/pulse/6ac39
    Pulse Author: CyberHunter_NL
    Created: 2026-10-05 12:56:20

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #CyberHunter_NL

  13. Hackers Abuse Legitimate ScreenConnect Tool to Gain Remote Access Through Phishing

    Hackers are using a legitimate ScreenConnect client to turn a payment notification into a route for remote access. Instead of delivering custom malware, the phishing attempt directs recipients to software already designed to let someone else connect to their computer. The email claims that a payment of $5745.65 has been received and invites the recipient […] The post Hackers Abuse Legitimate ScreenConnect Tool to Gain Remote Access Through Phishing appeared first on Cyber Security News .

    Pulse ID: 6ac39071863fe3f8d9c2d228
    Pulse Link: otx.alienvault.com/pulse/6ac39
    Pulse Author: CyberHunter_NL
    Created: 2026-10-05 11:56:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ScreenConnect #Phishing #Email #OTX #CyberHunter_NL

  14. Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices

    Cling malware is turning compromised internet-connected devices into a botnet while disguising its control traffic as replies from Google’s public STUN service. The technique makes attacker instructions look like routine communications used by applications to connect across network boundaries. The infection begins with attacks against exposed devices running vulnerable Realtek software. Earlier reporting on Realtek […] The post Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices appeared first on Cyber Security News .

    Pulse ID: 6ac35805e1df7ad5ed81fdf1
    Pulse Link: otx.alienvault.com/pulse/6ac35
    Pulse Author: CyberHunter_NL
    Created: 2026-10-05 07:55:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Google #IoT #botnet #Malware #OTX #CyberHunter_NL

  15. Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories

    This week’s security newsletter was dominated by a Pentagon personnel data breach affecting more than three million people, actively exploited zero-days in Apple CoreGraphics and Fortinet FortiMail, and reports of two still-unpatched Citrix NetScaler RCE flaws. The broader bulletin covers 26 developments spanning cloud identity, malware, AI-agent governance, remote access, browser security, vulnerable infrastructure, and […] The post Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories appeared first on Cyber Security News .

    Pulse ID: 6ac303aa1b172c6bf2176dfb
    Pulse Link: otx.alienvault.com/pulse/6ac30
    Pulse Author: CyberHunter_NL
    Created: 2026-10-05 01:55:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Citrix #DataBreach #Cloud #NetScaler #OTX #CyberHunter_NL

  16. Citrix patches NetScaler SAML zero-day exploited in attacks

    Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]

    Pulse ID: 6ac2d9685c5b9ac47954ce12
    Pulse Link: otx.alienvault.com/pulse/6ac2d
    Pulse Author: CyberHunter_NL
    Created: 2026-10-04 22:55:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Citrix #NetScaler #ZeroDay #CVE202688779 #OTX #CyberHunter_NL

  17. ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

    A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif ‌al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) and

    Pulse ID: 6ac20681a17325948569f86c
    Pulse Link: otx.alienvault.com/pulse/6ac20
    Pulse Author: CyberHunter_NL
    Created: 2026-10-04 07:55:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #FBI #ShinyHunters #Reuters #OTX #CyberHunter_NL

  18. 2026-09-30: SmartApeSG ClickFix pushes CNCmachineRMS RAT

    2026-09-30 (WEDNESDAY): SMARTAPESG CLICKFIX PUSHES CNCMACHINERMS RAT

    Pulse ID: 6ac1b22d5c09d0c722b681ad
    Pulse Link: otx.alienvault.com/pulse/6ac1b
    Pulse Author: CyberHunter_NL
    Created: 2026-10-04 01:55:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Clickfix #RAT #SmartApeSg #OTX #CyberHunter_NL

Share on Mastodon

Enter the server where you have an account.