#cyberhunter_nl — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cyberhunter_nl, aggregated by home.social.
-
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report
Pulse ID: 6ac3ac6e93930b4d37dbe1fa
Pulse Link: https://otx.alienvault.com/pulse/6ac3ac6e93930b4d37dbe1fa
Pulse Author: CyberHunter_NL
Created: 2026-10-05 13:55:58Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report
Pulse ID: 6ac3ac6e93930b4d37dbe1fa
Pulse Link: https://otx.alienvault.com/pulse/6ac3ac6e93930b4d37dbe1fa
Pulse Author: CyberHunter_NL
Created: 2026-10-05 13:55:58Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report
Pulse ID: 6ac3ac6e93930b4d37dbe1fa
Pulse Link: https://otx.alienvault.com/pulse/6ac3ac6e93930b4d37dbe1fa
Pulse Author: CyberHunter_NL
Created: 2026-10-05 13:55:58Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report
Pulse ID: 6ac3ac6e93930b4d37dbe1fa
Pulse Link: https://otx.alienvault.com/pulse/6ac3ac6e93930b4d37dbe1fa
Pulse Author: CyberHunter_NL
Created: 2026-10-05 13:55:58Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices
Cling malware is turning compromised internet-connected devices into a botnet while disguising its control traffic as replies from Google’s public STUN service. The technique makes attacker instructions look like routine communications used by applications to connect across network boundaries. The infection begins with attacks against exposed devices running vulnerable Realtek software. Earlier reporting on Realtek […] The post Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices appeared first on Cyber Security News .
Pulse ID: 6ac35805e1df7ad5ed81fdf1
Pulse Link: https://otx.alienvault.com/pulse/6ac35805e1df7ad5ed81fdf1
Pulse Author: CyberHunter_NL
Created: 2026-10-05 07:55:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices
Cling malware is turning compromised internet-connected devices into a botnet while disguising its control traffic as replies from Google’s public STUN service. The technique makes attacker instructions look like routine communications used by applications to connect across network boundaries. The infection begins with attacks against exposed devices running vulnerable Realtek software. Earlier reporting on Realtek […] The post Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices appeared first on Cyber Security News .
Pulse ID: 6ac35805e1df7ad5ed81fdf1
Pulse Link: https://otx.alienvault.com/pulse/6ac35805e1df7ad5ed81fdf1
Pulse Author: CyberHunter_NL
Created: 2026-10-05 07:55:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices
Cling malware is turning compromised internet-connected devices into a botnet while disguising its control traffic as replies from Google’s public STUN service. The technique makes attacker instructions look like routine communications used by applications to connect across network boundaries. The infection begins with attacks against exposed devices running vulnerable Realtek software. Earlier reporting on Realtek […] The post Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices appeared first on Cyber Security News .
Pulse ID: 6ac35805e1df7ad5ed81fdf1
Pulse Link: https://otx.alienvault.com/pulse/6ac35805e1df7ad5ed81fdf1
Pulse Author: CyberHunter_NL
Created: 2026-10-05 07:55:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices
Cling malware is turning compromised internet-connected devices into a botnet while disguising its control traffic as replies from Google’s public STUN service. The technique makes attacker instructions look like routine communications used by applications to connect across network boundaries. The infection begins with attacks against exposed devices running vulnerable Realtek software. Earlier reporting on Realtek […] The post Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices appeared first on Cyber Security News .
Pulse ID: 6ac35805e1df7ad5ed81fdf1
Pulse Link: https://otx.alienvault.com/pulse/6ac35805e1df7ad5ed81fdf1
Pulse Author: CyberHunter_NL
Created: 2026-10-05 07:55:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories
This week’s security newsletter was dominated by a Pentagon personnel data breach affecting more than three million people, actively exploited zero-days in Apple CoreGraphics and Fortinet FortiMail, and reports of two still-unpatched Citrix NetScaler RCE flaws. The broader bulletin covers 26 developments spanning cloud identity, malware, AI-agent governance, remote access, browser security, vulnerable infrastructure, and […] The post Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories appeared first on Cyber Security News .
Pulse ID: 6ac303aa1b172c6bf2176dfb
Pulse Link: https://otx.alienvault.com/pulse/6ac303aa1b172c6bf2176dfb
Pulse Author: CyberHunter_NL
Created: 2026-10-05 01:55:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories
This week’s security newsletter was dominated by a Pentagon personnel data breach affecting more than three million people, actively exploited zero-days in Apple CoreGraphics and Fortinet FortiMail, and reports of two still-unpatched Citrix NetScaler RCE flaws. The broader bulletin covers 26 developments spanning cloud identity, malware, AI-agent governance, remote access, browser security, vulnerable infrastructure, and […] The post Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories appeared first on Cyber Security News .
Pulse ID: 6ac303aa1b172c6bf2176dfb
Pulse Link: https://otx.alienvault.com/pulse/6ac303aa1b172c6bf2176dfb
Pulse Author: CyberHunter_NL
Created: 2026-10-05 01:55:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories
This week’s security newsletter was dominated by a Pentagon personnel data breach affecting more than three million people, actively exploited zero-days in Apple CoreGraphics and Fortinet FortiMail, and reports of two still-unpatched Citrix NetScaler RCE flaws. The broader bulletin covers 26 developments spanning cloud identity, malware, AI-agent governance, remote access, browser security, vulnerable infrastructure, and […] The post Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories appeared first on Cyber Security News .
Pulse ID: 6ac303aa1b172c6bf2176dfb
Pulse Link: https://otx.alienvault.com/pulse/6ac303aa1b172c6bf2176dfb
Pulse Author: CyberHunter_NL
Created: 2026-10-05 01:55:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories
This week’s security newsletter was dominated by a Pentagon personnel data breach affecting more than three million people, actively exploited zero-days in Apple CoreGraphics and Fortinet FortiMail, and reports of two still-unpatched Citrix NetScaler RCE flaws. The broader bulletin covers 26 developments spanning cloud identity, malware, AI-agent governance, remote access, browser security, vulnerable infrastructure, and […] The post Cybersecurity Newsletter Bulletin – Pentagon Data Breach, Citrix, Fortimail and Apple 0-days and 20+ stories appeared first on Cyber Security News .
Pulse ID: 6ac303aa1b172c6bf2176dfb
Pulse Link: https://otx.alienvault.com/pulse/6ac303aa1b172c6bf2176dfb
Pulse Author: CyberHunter_NL
Created: 2026-10-05 01:55:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Citrix patches NetScaler SAML zero-day exploited in attacks
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]
Pulse ID: 6ac2d9685c5b9ac47954ce12
Pulse Link: https://otx.alienvault.com/pulse/6ac2d9685c5b9ac47954ce12
Pulse Author: CyberHunter_NL
Created: 2026-10-04 22:55:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Citrix #NetScaler #ZeroDay #CVE202688779 #OTX #CyberHunter_NL
-
Citrix patches NetScaler SAML zero-day exploited in attacks
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]
Pulse ID: 6ac2d9685c5b9ac47954ce12
Pulse Link: https://otx.alienvault.com/pulse/6ac2d9685c5b9ac47954ce12
Pulse Author: CyberHunter_NL
Created: 2026-10-04 22:55:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Citrix #NetScaler #ZeroDay #CVE202688779 #OTX #CyberHunter_NL
-
Citrix patches NetScaler SAML zero-day exploited in attacks
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]
Pulse ID: 6ac2d9685c5b9ac47954ce12
Pulse Link: https://otx.alienvault.com/pulse/6ac2d9685c5b9ac47954ce12
Pulse Author: CyberHunter_NL
Created: 2026-10-04 22:55:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Citrix #NetScaler #ZeroDay #CVE202688779 #OTX #CyberHunter_NL
-
Citrix patches NetScaler SAML zero-day exploited in attacks
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]
Pulse ID: 6ac2d9685c5b9ac47954ce12
Pulse Link: https://otx.alienvault.com/pulse/6ac2d9685c5b9ac47954ce12
Pulse Author: CyberHunter_NL
Created: 2026-10-04 22:55:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Citrix #NetScaler #ZeroDay #CVE202688779 #OTX #CyberHunter_NL
-
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) and
Pulse ID: 6ac20681a17325948569f86c
Pulse Link: https://otx.alienvault.com/pulse/6ac20681a17325948569f86c
Pulse Author: CyberHunter_NL
Created: 2026-10-04 07:55:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) and
Pulse ID: 6ac20681a17325948569f86c
Pulse Link: https://otx.alienvault.com/pulse/6ac20681a17325948569f86c
Pulse Author: CyberHunter_NL
Created: 2026-10-04 07:55:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) and
Pulse ID: 6ac20681a17325948569f86c
Pulse Link: https://otx.alienvault.com/pulse/6ac20681a17325948569f86c
Pulse Author: CyberHunter_NL
Created: 2026-10-04 07:55:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name is Saif al-Din Khader, is said to have been brought into custody on September 29, 2026, cooperating with the U.S. Federal Bureau of Investigation (FBI) and
Pulse ID: 6ac20681a17325948569f86c
Pulse Link: https://otx.alienvault.com/pulse/6ac20681a17325948569f86c
Pulse Author: CyberHunter_NL
Created: 2026-10-04 07:55:45Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
2026-09-30: SmartApeSG ClickFix pushes CNCmachineRMS RAT
2026-09-30 (WEDNESDAY): SMARTAPESG CLICKFIX PUSHES CNCMACHINERMS RAT
Pulse ID: 6ac1b22d5c09d0c722b681ad
Pulse Link: https://otx.alienvault.com/pulse/6ac1b22d5c09d0c722b681ad
Pulse Author: CyberHunter_NL
Created: 2026-10-04 01:55:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
2026-09-30: SmartApeSG ClickFix pushes CNCmachineRMS RAT
2026-09-30 (WEDNESDAY): SMARTAPESG CLICKFIX PUSHES CNCMACHINERMS RAT
Pulse ID: 6ac1b22d5c09d0c722b681ad
Pulse Link: https://otx.alienvault.com/pulse/6ac1b22d5c09d0c722b681ad
Pulse Author: CyberHunter_NL
Created: 2026-10-04 01:55:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
2026-09-30: SmartApeSG ClickFix pushes CNCmachineRMS RAT
2026-09-30 (WEDNESDAY): SMARTAPESG CLICKFIX PUSHES CNCMACHINERMS RAT
Pulse ID: 6ac1b22d5c09d0c722b681ad
Pulse Link: https://otx.alienvault.com/pulse/6ac1b22d5c09d0c722b681ad
Pulse Author: CyberHunter_NL
Created: 2026-10-04 01:55:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
2026-09-30: SmartApeSG ClickFix pushes CNCmachineRMS RAT
2026-09-30 (WEDNESDAY): SMARTAPESG CLICKFIX PUSHES CNCMACHINERMS RAT
Pulse ID: 6ac1b22d5c09d0c722b681ad
Pulse Link: https://otx.alienvault.com/pulse/6ac1b22d5c09d0c722b681ad
Pulse Author: CyberHunter_NL
Created: 2026-10-04 01:55:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Suspect “Rey” Detained in Jordan, Reportedly Helping FBI
ShinyHunters hacker “Rey” was detained in Jordan and is reportedly cooperating with the FBI after the group claimed major FBI and corporate data breaches.
Pulse ID: 6ac16be8eb6ce85849fcb753
Pulse Link: https://otx.alienvault.com/pulse/6ac16be8eb6ce85849fcb753
Pulse Author: CyberHunter_NL
Created: 2026-10-03 20:56:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Suspect “Rey” Detained in Jordan, Reportedly Helping FBI
ShinyHunters hacker “Rey” was detained in Jordan and is reportedly cooperating with the FBI after the group claimed major FBI and corporate data breaches.
Pulse ID: 6ac16be8eb6ce85849fcb753
Pulse Link: https://otx.alienvault.com/pulse/6ac16be8eb6ce85849fcb753
Pulse Author: CyberHunter_NL
Created: 2026-10-03 20:56:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Suspect “Rey” Detained in Jordan, Reportedly Helping FBI
ShinyHunters hacker “Rey” was detained in Jordan and is reportedly cooperating with the FBI after the group claimed major FBI and corporate data breaches.
Pulse ID: 6ac16be8eb6ce85849fcb753
Pulse Link: https://otx.alienvault.com/pulse/6ac16be8eb6ce85849fcb753
Pulse Author: CyberHunter_NL
Created: 2026-10-03 20:56:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Suspect “Rey” Detained in Jordan, Reportedly Helping FBI
ShinyHunters hacker “Rey” was detained in Jordan and is reportedly cooperating with the FBI after the group claimed major FBI and corporate data breaches.
Pulse ID: 6ac16be8eb6ce85849fcb753
Pulse Link: https://otx.alienvault.com/pulse/6ac16be8eb6ce85849fcb753
Pulse Author: CyberHunter_NL
Created: 2026-10-03 20:56:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers
A suspected ShinyHunters member has been detained in Jordan and is reportedly helping the FBI identify other hackers linked to the group. Reuters reported on October 3 that three people familiar with the matter confirmed the detention of Saif al-Din Khader, whose alleged online nickname is Rey. Two sources said Jordanian authorities took Khader into […] The post ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers appeared first on Cyber Security News .
Pulse ID: 6ac141ad28d9b6245bff4348
Pulse Link: https://otx.alienvault.com/pulse/6ac141ad28d9b6245bff4348
Pulse Author: CyberHunter_NL
Created: 2026-10-03 17:55:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers
A suspected ShinyHunters member has been detained in Jordan and is reportedly helping the FBI identify other hackers linked to the group. Reuters reported on October 3 that three people familiar with the matter confirmed the detention of Saif al-Din Khader, whose alleged online nickname is Rey. Two sources said Jordanian authorities took Khader into […] The post ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers appeared first on Cyber Security News .
Pulse ID: 6ac141ad28d9b6245bff4348
Pulse Link: https://otx.alienvault.com/pulse/6ac141ad28d9b6245bff4348
Pulse Author: CyberHunter_NL
Created: 2026-10-03 17:55:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers
A suspected ShinyHunters member has been detained in Jordan and is reportedly helping the FBI identify other hackers linked to the group. Reuters reported on October 3 that three people familiar with the matter confirmed the detention of Saif al-Din Khader, whose alleged online nickname is Rey. Two sources said Jordanian authorities took Khader into […] The post ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers appeared first on Cyber Security News .
Pulse ID: 6ac141ad28d9b6245bff4348
Pulse Link: https://otx.alienvault.com/pulse/6ac141ad28d9b6245bff4348
Pulse Author: CyberHunter_NL
Created: 2026-10-03 17:55:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers
A suspected ShinyHunters member has been detained in Jordan and is reportedly helping the FBI identify other hackers linked to the group. Reuters reported on October 3 that three people familiar with the matter confirmed the detention of Saif al-Din Khader, whose alleged online nickname is Rey. Two sources said Jordanian authorities took Khader into […] The post ShinyHunters Member Detained in Jordan, Reportedly Helping FBI Identify Fellow Hackers appeared first on Cyber Security News .
Pulse ID: 6ac141ad28d9b6245bff4348
Pulse Link: https://otx.alienvault.com/pulse/6ac141ad28d9b6245bff4348
Pulse Author: CyberHunter_NL
Created: 2026-10-03 17:55:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
Pulse ID: 6ac125c07a29860f0d145a82
Pulse Link: https://otx.alienvault.com/pulse/6ac125c07a29860f0d145a82
Pulse Author: CyberHunter_NL
Created: 2026-10-03 15:56:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Warlock #Deploy #RansomWare #CarbonBlack #OTX #CyberHunter_NL
-
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
Pulse ID: 6ac125c07a29860f0d145a82
Pulse Link: https://otx.alienvault.com/pulse/6ac125c07a29860f0d145a82
Pulse Author: CyberHunter_NL
Created: 2026-10-03 15:56:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Warlock #Deploy #RansomWare #CarbonBlack #OTX #CyberHunter_NL
-
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
Pulse ID: 6ac125c07a29860f0d145a82
Pulse Link: https://otx.alienvault.com/pulse/6ac125c07a29860f0d145a82
Pulse Author: CyberHunter_NL
Created: 2026-10-03 15:56:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Warlock #Deploy #RansomWare #CarbonBlack #OTX #CyberHunter_NL
-
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
Pulse ID: 6ac125c07a29860f0d145a82
Pulse Link: https://otx.alienvault.com/pulse/6ac125c07a29860f0d145a82
Pulse Author: CyberHunter_NL
Created: 2026-10-03 15:56:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Warlock #Deploy #RansomWare #CarbonBlack #OTX #CyberHunter_NL
-
Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]
Pulse ID: 6ac00c3752b6f7395ae134f7
Pulse Link: https://otx.alienvault.com/pulse/6ac00c3752b6f7395ae134f7
Pulse Author: CyberHunter_NL
Created: 2026-10-02 19:55:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]
Pulse ID: 6ac00c3752b6f7395ae134f7
Pulse Link: https://otx.alienvault.com/pulse/6ac00c3752b6f7395ae134f7
Pulse Author: CyberHunter_NL
Created: 2026-10-02 19:55:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]
Pulse ID: 6ac00c3752b6f7395ae134f7
Pulse Link: https://otx.alienvault.com/pulse/6ac00c3752b6f7395ae134f7
Pulse Author: CyberHunter_NL
Created: 2026-10-02 19:55:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]
Pulse ID: 6ac00c3752b6f7395ae134f7
Pulse Link: https://otx.alienvault.com/pulse/6ac00c3752b6f7395ae134f7
Pulse Author: CyberHunter_NL
Created: 2026-10-02 19:55:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
Pulse ID: 6abff04d054297919c0ddc67
Pulse Link: https://otx.alienvault.com/pulse/6abff04d054297919c0ddc67
Pulse Author: CyberHunter_NL
Created: 2026-10-02 17:56:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
Pulse ID: 6abff04d054297919c0ddc67
Pulse Link: https://otx.alienvault.com/pulse/6abff04d054297919c0ddc67
Pulse Author: CyberHunter_NL
Created: 2026-10-02 17:56:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
Pulse ID: 6abff04d054297919c0ddc67
Pulse Link: https://otx.alienvault.com/pulse/6abff04d054297919c0ddc67
Pulse Author: CyberHunter_NL
Created: 2026-10-02 17:56:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
Pulse ID: 6abff04d054297919c0ddc67
Pulse Link: https://otx.alienvault.com/pulse/6abff04d054297919c0ddc67
Pulse Author: CyberHunter_NL
Created: 2026-10-02 17:56:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.