home.social

#cyberhunter_nl — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cyberhunter_nl, aggregated by home.social.

  1. RMM tools currently being distributed through phishing attacks (ScreenConnect, FleetDeck, Datto, SimpleHelp, JumpCloud, N-able)

    In January 2026, the AhnLab SEcurity intelligence Center (ASEC) reported on attack cases that distributed RMM (Remote Monitoring and Management) tools through video files or attachments in phishing emails. [1] [2] In these attack cases, tools such as Syncro, ConnectWise ScreenConnect, NinjaOne, and SuperOps were exploited. RMM (Remote Monitoring and Management) tools are not malware […]

    Pulse ID: 6ac7225a628b753a1391a580
    Pulse Link: otx.alienvault.com/pulse/6ac72
    Pulse Author: CyberHunter_NL
    Created: 2026-10-08 04:55:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Phishing #ScreenConnect #AhnLab #ASEC #OTX #CyberHunter_NL

  2. CyberXero Combines Claude Code, PentAGI and Cobalt Strike in AI-Augmented Cyberattacks

    CyberXero has emerged as an initial access broker that combines familiar hacking tools with artificial intelligence to run large-scale intrusions. The Russian-speaking operator targeted WordPress and e-commerce sites worldwide while separately probing Ukrainian energy and utility organizations. The campaign came to light after an open directory exposed more than 90,000 files, including scripts, AI session […] The post CyberXero Combines Claude Code, PentAGI and Cobalt Strike in AI-Augmented Cyberattacks appeared first on Cyber Security News .

    Pulse ID: 6ac65da1a40ac76d535034d2
    Pulse Link: otx.alienvault.com/pulse/6ac65
    Pulse Author: CyberHunter_NL
    Created: 2026-10-07 14:56:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CobaltStrike #CyberAttacks #Ukrainian #Wordpress #OTX #CyberHunter_NL

  3. Hackers Use Fake ChatGPT, Claude and Gemini Ads to Steal Passwords and MFA Codes

    Hackers are impersonating ChatGPT, Claude and Gemini with fake advertising products that steal passwords and multifactor authentication codes. Instead of delivering a conventional malware download, the campaign uses convincing websites and live human operators to guide victims through fraudulent sign-in screens. Invitation emails lead advertisers to pages promising campaign planning, spending audits and account connections. […] The post Hackers Use Fake ChatGPT, Claude and Gemini Ads to Steal Passwords and MFA Codes appeared first on Cyber Security News .

    Pulse ID: 6ac61730efce31f3ad21748e
    Pulse Link: otx.alienvault.com/pulse/6ac61
    Pulse Author: CyberHunter_NL
    Created: 2026-10-07 09:56:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChatGPT #MFA #Passwords #MultiFactorAuthentication #OTX #CyberHunter_NL

  4. Hackers Hide Vasilek Backdoor Inside VMware Tools to Target Medical Organizations

    Hackers concealed the Vasilek backdoor inside an existing VMware Tools installation during a prolonged intrusion at a medical organization. The attackers maintained access for approximately two years, exposing sensitive medical information while leaving systems operational rather than launching a destructive attack. The earliest evidence dates to early 2024. Investigators found signs of remote command execution, […] The post Hackers Hide Vasilek Backdoor Inside VMware Tools to Target Medical Organizations appeared first on Cyber Security News .

    Pulse ID: 6ac5fb12f7445f5f8dff5067
    Pulse Link: otx.alienvault.com/pulse/6ac5f
    Pulse Author: CyberHunter_NL
    Created: 2026-10-07 07:56:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #VMware #RemoteCommandExecution #OTX #CyberHunter_NL

  5. Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

    Cybersecurity researchers have disclosed details of a "human-operated phishing platform" that impersonates advertising products for artificial intelligence (AI) chatbots like Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The products, which claim to offer campaign optimization, spend audits, and business-account connections, are designed with one goal in

    Pulse ID: 6ac560546397ed54df439a99
    Pulse Link: otx.alienvault.com/pulse/6ac56
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 20:55:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChatGPT #MFA #Google #Phishing #OTX #CyberHunter_NL

  6. Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

    Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may

    Pulse ID: 6ac56057918347181355728d
    Pulse Link: otx.alienvault.com/pulse/6ac56
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 20:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Email #Linux #SouthKorea #Telecom #OTX #CyberHunter_NL

  7. Iranian Hackers Use Fake Dubai Airports Coding Test to Target Iraqi Critical Infrastructure

    Iranian state-aligned hackers have used a fake Dubai Airports recruitment process to target Iraqi critical infrastructure with a booby-trapped coding test. The campaign, called Blinder Tunnel, turned a routine developer task into a quiet, potentially long-term route for remote access, persistence and network tunneling across a victim environment. The operation was prepared as early as […] The post Iranian Hackers Use Fake Dubai Airports Coding Test to Target Iraqi Critical Infrastructure appeared first on Cyber Security News .

    Pulse ID: 6ac50c1b5db79ae0d9b3b778
    Pulse Link: otx.alienvault.com/pulse/6ac50
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 14:56:27

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #TASK #OTX #CyberHunter_NL

  8. Ransomware Hacker Uses AI Coding Assistant as Attack Channel Against Enterprise Networks

    A ransomware affiliate has turned an AI coding assistant into a channel for running attacks inside enterprise networks. The operator, known as Azazel, combined stolen development credentials, remote command execution and data theft while working with the Gentlemen ransomware group. The campaign affected more than two dozen organisations across six countries, including logistics, insurance, pharmaceuticals, […] The post Ransomware Hacker Uses AI Coding Assistant as Attack Channel Against Enterprise Networks appeared first on Cyber Security News .

    Pulse ID: 6ac50c22da460370716e4978
    Pulse Link: otx.alienvault.com/pulse/6ac50
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 14:56:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #RansomWare #DataTheft #Gentlemen #RemoteCommandExecution #OTX #CyberHunter_NL

  9. Hackers Exploit Exposed Industrial Controllers to Disrupt US Water and Critical Infrastructure

    Hackers are exploiting internet-connected industrial controllers to disrupt US water utilities and other essential services. Recent incidents show that poorly protected equipment can give attackers direct access to physical operations, with consequences ranging from lost monitoring to flooding and reduced water pressure. The threat involves several campaigns rather than one newly discovered malware family. Attackers […] The post Hackers Exploit Exposed Industrial Controllers to Disrupt US Water and Critical Infrastructure appeared first on Cyber Security News .

    Pulse ID: 6ac4fdfad2141ccf0ebf1cc8
    Pulse Link: otx.alienvault.com/pulse/6ac4f
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 13:56:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #CyberHunter_NL

  10. Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials

    Travelers connecting to hotel Wi-Fi may now face more than an unreliable internet signal. A campaign linked to Midnight Blizzard has turned captive portals, the sign-in pages shown before online access, into a route for malware, credential theft, and possible access to corporate accounts. The operation, known as CaptiveCrunch, has affected hospitality-related networks and other […] The post Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials appeared first on Cyber Security News .

    Pulse ID: 6ac4d3b9884839b3b6b8fcbf
    Pulse Link: otx.alienvault.com/pulse/6ac4d
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 10:55:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Deliver #Malware #Credential #OTX #CyberHunter_NL

  11. Blinder Tunnel Campaign Targets Iraqi Infrastructure

    Analysis of Blinder Tunnel, an Iran-nexus campaign using fake Dubai Airports recruitment lures and GitHub C2 malware to target critical infrastructure. The post Blinder Tunnel Campaign Targets Iraqi Infrastructure appeared first on Unit 42 .

    Pulse ID: 6ac4d3cb21c3c2f7a2c1d865
    Pulse Link: otx.alienvault.com/pulse/6ac4d
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 10:56:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #GitHub #Iran #Unit42 #OTX #CyberHunter_NL

  12. ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

    ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote access. Rather than simply infecting routers and cameras, it turns compromised equipment into remotely controlled proxy nodes that can relay traffic and run commands. The campaign targets known security flaws across multiple vendors, expanding its attack methods as it evolves. […] The post ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access appeared first on Cyber Security News .

    Pulse ID: 6ac4c5b172d0180a9464f655
    Pulse Link: otx.alienvault.com/pulse/6ac4c
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 09:56:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #IoT #Linux #Proxy #OTX #CyberHunter_NL

  13. ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

    A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.

    Pulse ID: 6ac49b893a8000cf4c9c1735
    Pulse Link: otx.alienvault.com/pulse/6ac49
    Pulse Author: CyberHunter_NL
    Created: 2026-10-06 06:56:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Clickfix #Windows #Browser #Microsoft #OTX #CyberHunter_NL

  14. CVE-2026-104286: Critical FortiMail Zero-Day Exploited for Unauthenticated File Writes

    Fortinet has disclosed a critical FortiMail zero-day vulnerability that attackers are already exploiting in the wild. Tracked as CVE-2026-104286 and rated 9.8 on the CVSS scale, the flaw enables an unauthenticated remote attacker to write arbitrary files to the underlying system by sending specially crafted HTTP or HTTPS requests. The vulnerability poses a significant risk […] The post CVE-2026-104286: Critical FortiMail Zero-Day Exploited for Unauthenticated File Writes appeared first on SOC Prime .

    Pulse ID: 6ac3e4c60b5f3d6ef7c5140a
    Pulse Link: otx.alienvault.com/pulse/6ac3e
    Pulse Author: CyberHunter_NL
    Created: 2026-10-05 17:56:22

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CVE2026104286 #ZeroDay #HTTP #HTTPS #OTX #CyberHunter_NL

Share on Mastodon

Enter the server where you have an account.