home.social

#cyberhunter_nl — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cyberhunter_nl, aggregated by home.social.

  1. Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

    Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

    Pulse ID: 6abff04d054297919c0ddc67
    Pulse Link: otx.alienvault.com/pulse/6abff
    Pulse Author: CyberHunter_NL
    Created: 2026-10-02 17:56:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Antino #BackDoor #China #Espionage #OTX #CyberHunter_NL

  2. Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

    Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

    Pulse ID: 6abff04d054297919c0ddc67
    Pulse Link: otx.alienvault.com/pulse/6abff
    Pulse Author: CyberHunter_NL
    Created: 2026-10-02 17:56:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Antino #BackDoor #China #Espionage #OTX #CyberHunter_NL

  3. Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

    Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

    Pulse ID: 6abff04d054297919c0ddc67
    Pulse Link: otx.alienvault.com/pulse/6abff
    Pulse Author: CyberHunter_NL
    Created: 2026-10-02 17:56:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Antino #BackDoor #China #Espionage #OTX #CyberHunter_NL

  4. Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

    Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster

    Pulse ID: 6abff04d054297919c0ddc67
    Pulse Link: otx.alienvault.com/pulse/6abff
    Pulse Author: CyberHunter_NL
    Created: 2026-10-02 17:56:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Antino #BackDoor #China #Espionage #OTX #CyberHunter_NL

  5. Protected Quick Tunnels: simple accountless authentication for your next dev project

    Quick Tunnels now support email authentication. Add --allowed-mail to one cloudflared command, and only the addresses or domains you list can reach your local app. No Cloudflare account required on either side.

    Pulse ID: 6abfb81e5ed3ed2a9976a5da
    Pulse Link: otx.alienvault.com/pulse/6abfb
    Pulse Author: CyberHunter_NL
    Created: 2026-10-02 13:56:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Email #OTX #CyberHunter_NL

  6. Protected Quick Tunnels: simple accountless authentication for your next dev project

    Quick Tunnels now support email authentication. Add --allowed-mail to one cloudflared command, and only the addresses or domains you list can reach your local app. No Cloudflare account required on either side.

    Pulse ID: 6abfb81e5ed3ed2a9976a5da
    Pulse Link: otx.alienvault.com/pulse/6abfb
    Pulse Author: CyberHunter_NL
    Created: 2026-10-02 13:56:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Email #OTX #CyberHunter_NL

  7. Protected Quick Tunnels: simple accountless authentication for your next dev project

    Quick Tunnels now support email authentication. Add --allowed-mail to one cloudflared command, and only the addresses or domains you list can reach your local app. No Cloudflare account required on either side.

    Pulse ID: 6abfb81e5ed3ed2a9976a5da
    Pulse Link: otx.alienvault.com/pulse/6abfb
    Pulse Author: CyberHunter_NL
    Created: 2026-10-02 13:56:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Email #OTX #CyberHunter_NL

  8. Protected Quick Tunnels: simple accountless authentication for your next dev project

    Quick Tunnels now support email authentication. Add --allowed-mail to one cloudflared command, and only the addresses or domains you list can reach your local app. No Cloudflare account required on either side.

    Pulse ID: 6abfb81e5ed3ed2a9976a5da
    Pulse Link: otx.alienvault.com/pulse/6abfb
    Pulse Author: CyberHunter_NL
    Created: 2026-10-02 13:56:46

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Email #OTX #CyberHunter_NL

  9. Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials

    Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK. Rather than relying on one technique, its components search websites for sensitive files, recover stored passwords, and collect secrets from JavaScript delivered to visitors. The operation was already active at scale when researchers first observed […] The post Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials appeared first on Cyber Security News .

    Pulse ID: 6abfa9e7b400add5633256b5
    Pulse Link: otx.alienvault.com/pulse/6abfa
    Pulse Author: CyberHunter_NL
    Created: 2026-10-02 12:56:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Email #Wordpress #Cloud #OTX #CyberHunter_NL

  10. Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials

    Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK. Rather than relying on one technique, its components search websites for sensitive files, recover stored passwords, and collect secrets from JavaScript delivered to visitors. The operation was already active at scale when researchers first observed […] The post Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials appeared first on Cyber Security News .

    Pulse ID: 6abfa9e7b400add5633256b5
    Pulse Link: otx.alienvault.com/pulse/6abfa
    Pulse Author: CyberHunter_NL
    Created: 2026-10-02 12:56:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Email #Wordpress #Cloud #OTX #CyberHunter_NL

  11. Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials

    Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK. Rather than relying on one technique, its components search websites for sensitive files, recover stored passwords, and collect secrets from JavaScript delivered to visitors. The operation was already active at scale when researchers first observed […] The post Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials appeared first on Cyber Security News .

    Pulse ID: 6abfa9e7b400add5633256b5
    Pulse Link: otx.alienvault.com/pulse/6abfa
    Pulse Author: CyberHunter_NL
    Created: 2026-10-02 12:56:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Email #Wordpress #Cloud #OTX #CyberHunter_NL

  12. Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials

    Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK. Rather than relying on one technique, its components search websites for sensitive files, recover stored passwords, and collect secrets from JavaScript delivered to visitors. The operation was already active at scale when researchers first observed […] The post Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials appeared first on Cyber Security News .

    Pulse ID: 6abfa9e7b400add5633256b5
    Pulse Link: otx.alienvault.com/pulse/6abfa
    Pulse Author: CyberHunter_NL
    Created: 2026-10-02 12:56:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Email #Wordpress #Cloud #OTX #CyberHunter_NL

  13. Autonomous AI agents tried to hack US, Canadian government websites

    Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]

    Pulse ID: 6abec8cad6344592e61e9855
    Pulse Link: otx.alienvault.com/pulse/6abec
    Pulse Author: CyberHunter_NL
    Created: 2026-10-01 20:55:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Canadian #Government #OTX #CyberHunter_NL

  14. Autonomous AI agents tried to hack US, Canadian government websites

    Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]

    Pulse ID: 6abec8cad6344592e61e9855
    Pulse Link: otx.alienvault.com/pulse/6abec
    Pulse Author: CyberHunter_NL
    Created: 2026-10-01 20:55:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Canadian #Government #OTX #CyberHunter_NL

  15. Autonomous AI agents tried to hack US, Canadian government websites

    Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]

    Pulse ID: 6abec8cad6344592e61e9855
    Pulse Link: otx.alienvault.com/pulse/6abec
    Pulse Author: CyberHunter_NL
    Created: 2026-10-01 20:55:38

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Canadian #Government #OTX #CyberHunter_NL

  16. Police dismantle KillSec ransomware gang allegedly led by 16-year-old

    An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]

    Pulse ID: 6abe746e3b37a624f1ed67cc
    Pulse Link: otx.alienvault.com/pulse/6abe7
    Pulse Author: CyberHunter_NL
    Created: 2026-10-01 14:55:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #RansomWare #LawEnforcement #OTX #CyberHunter_NL

  17. Police dismantle KillSec ransomware gang allegedly led by 16-year-old

    An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]

    Pulse ID: 6abe746e3b37a624f1ed67cc
    Pulse Link: otx.alienvault.com/pulse/6abe7
    Pulse Author: CyberHunter_NL
    Created: 2026-10-01 14:55:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #RansomWare #LawEnforcement #OTX #CyberHunter_NL

  18. Police dismantle KillSec ransomware gang allegedly led by 16-year-old

    An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]

    Pulse ID: 6abe746e3b37a624f1ed67cc
    Pulse Link: otx.alienvault.com/pulse/6abe7
    Pulse Author: CyberHunter_NL
    Created: 2026-10-01 14:55:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #RansomWare #LawEnforcement #OTX #CyberHunter_NL

  19. Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts

    A China-aligned hacking group tracked as TA419 has impersonated a senior Anthropic employee and well-known policy figures to target US artificial intelligence experts. Proofpoint linked the activity to credential-phishing campaigns aimed at researchers at think tanks, universities, and law firms, with lures designed to steal access to their cloud accounts. The targeting likely supports Chinese […] The post Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts appeared first on Cyber Security News .

    Pulse ID: 6abe74904426ab4ef87aef5c
    Pulse Link: otx.alienvault.com/pulse/6abe7
    Pulse Author: CyberHunter_NL
    Created: 2026-10-01 14:56:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #China #Cloud #Proofpoint #OTX #CyberHunter_NL

  20. Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts

    A China-aligned hacking group tracked as TA419 has impersonated a senior Anthropic employee and well-known policy figures to target US artificial intelligence experts. Proofpoint linked the activity to credential-phishing campaigns aimed at researchers at think tanks, universities, and law firms, with lures designed to steal access to their cloud accounts. The targeting likely supports Chinese […] The post Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts appeared first on Cyber Security News .

    Pulse ID: 6abe74904426ab4ef87aef5c
    Pulse Link: otx.alienvault.com/pulse/6abe7
    Pulse Author: CyberHunter_NL
    Created: 2026-10-01 14:56:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #China #Cloud #Proofpoint #OTX #CyberHunter_NL

  21. Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts

    A China-aligned hacking group tracked as TA419 has impersonated a senior Anthropic employee and well-known policy figures to target US artificial intelligence experts. Proofpoint linked the activity to credential-phishing campaigns aimed at researchers at think tanks, universities, and law firms, with lures designed to steal access to their cloud accounts. The targeting likely supports Chinese […] The post Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts appeared first on Cyber Security News .

    Pulse ID: 6abe74904426ab4ef87aef5c
    Pulse Link: otx.alienvault.com/pulse/6abe7
    Pulse Author: CyberHunter_NL
    Created: 2026-10-01 14:56:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #China #Cloud #Proofpoint #OTX #CyberHunter_NL

  22. Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles

    Key Findings In July 2026, a China-aligned threat actor Proofpoint tracks as TA419 conducted multiple credential phishing campaigns impersonating prominent economists and artificial intelligence (AI) policymakers to target AI experts working for US think tanks, universities, and legal sector organizations. TA419 also previously impersonated a prominent Anthropic employee to target an AI policy expert at a US think tank in February 2026. This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the US AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation, and export controls involving the US and China. Overview In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US. The group first sent benign...

    Pulse ID: 6abe2e2c3c77a1c9276b0827
    Pulse Link: otx.alienvault.com/pulse/6abe2
    Pulse Author: CyberHunter_NL
    Created: 2026-10-01 09:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #Chinese #Office #Proofpoint #OTX #CyberHunter_NL

  23. Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles

    Key Findings In July 2026, a China-aligned threat actor Proofpoint tracks as TA419 conducted multiple credential phishing campaigns impersonating prominent economists and artificial intelligence (AI) policymakers to target AI experts working for US think tanks, universities, and legal sector organizations. TA419 also previously impersonated a prominent Anthropic employee to target an AI policy expert at a US think tank in February 2026. This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the US AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation, and export controls involving the US and China. Overview In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US. The group first sent benign...

    Pulse ID: 6abe2e2c3c77a1c9276b0827
    Pulse Link: otx.alienvault.com/pulse/6abe2
    Pulse Author: CyberHunter_NL
    Created: 2026-10-01 09:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #Chinese #Office #Proofpoint #OTX #CyberHunter_NL

  24. Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles

    Key Findings In July 2026, a China-aligned threat actor Proofpoint tracks as TA419 conducted multiple credential phishing campaigns impersonating prominent economists and artificial intelligence (AI) policymakers to target AI experts working for US think tanks, universities, and legal sector organizations. TA419 also previously impersonated a prominent Anthropic employee to target an AI policy expert at a US think tank in February 2026. This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the US AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation, and export controls involving the US and China. Overview In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US. The group first sent benign...

    Pulse ID: 6abe2e2c3c77a1c9276b0827
    Pulse Link: otx.alienvault.com/pulse/6abe2
    Pulse Author: CyberHunter_NL
    Created: 2026-10-01 09:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #Chinese #Office #Proofpoint #OTX #CyberHunter_NL

  25. Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster

    Investigating a phishing alert often means working through several layers of activity before an analyst can confidently close or escalate the case. Modern campaigns can hide malicious activity behind encrypted traffic, CAPTCHA challenges, redirects, browser scripts, and token-based authentication, leaving analysts to reconstruct the attack before they can determine what happened. The investigation does not […] The post Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster appeared first on Cyber Security News .

    Pulse ID: 6abd3f487bd0ca4bcb80df4b
    Pulse Link: otx.alienvault.com/pulse/6abd3
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 16:56:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Phishing #CAPTCHA #OTX #CyberHunter_NL

  26. Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster

    Investigating a phishing alert often means working through several layers of activity before an analyst can confidently close or escalate the case. Modern campaigns can hide malicious activity behind encrypted traffic, CAPTCHA challenges, redirects, browser scripts, and token-based authentication, leaving analysts to reconstruct the attack before they can determine what happened. The investigation does not […] The post Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster appeared first on Cyber Security News .

    Pulse ID: 6abd3f487bd0ca4bcb80df4b
    Pulse Link: otx.alienvault.com/pulse/6abd3
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 16:56:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Phishing #CAPTCHA #OTX #CyberHunter_NL

  27. Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster

    Investigating a phishing alert often means working through several layers of activity before an analyst can confidently close or escalate the case. Modern campaigns can hide malicious activity behind encrypted traffic, CAPTCHA challenges, redirects, browser scripts, and token-based authentication, leaving analysts to reconstruct the attack before they can determine what happened. The investigation does not […] The post Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster appeared first on Cyber Security News .

    Pulse ID: 6abd3f487bd0ca4bcb80df4b
    Pulse Link: otx.alienvault.com/pulse/6abd3
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 16:56:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Phishing #CAPTCHA #OTX #CyberHunter_NL

  28. Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster

    Investigating a phishing alert often means working through several layers of activity before an analyst can confidently close or escalate the case. Modern campaigns can hide malicious activity behind encrypted traffic, CAPTCHA challenges, redirects, browser scripts, and token-based authentication, leaving analysts to reconstruct the attack before they can determine what happened. The investigation does not […] The post Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster appeared first on Cyber Security News .

    Pulse ID: 6abd3f487bd0ca4bcb80df4b
    Pulse Link: otx.alienvault.com/pulse/6abd3
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 16:56:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Phishing #CAPTCHA #OTX #CyberHunter_NL

  29. Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches

    A routine software update can now open the door to a cloud breach. Attackers are hiding credential stealing malware inside trusted packages and development tools, allowing malicious code to run on developer computers and automated build systems before an application even starts. The threat spans several campaigns rather than one malware family. Shai-Hulud emerged in […] The post Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches appeared first on Cyber Security News .

    Pulse ID: 6abd310b4d273aad58b696ff
    Pulse Link: otx.alienvault.com/pulse/6abd3
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 15:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #SupplyChain #OTX #CyberHunter_NL

  30. Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches

    A routine software update can now open the door to a cloud breach. Attackers are hiding credential stealing malware inside trusted packages and development tools, allowing malicious code to run on developer computers and automated build systems before an application even starts. The threat spans several campaigns rather than one malware family. Shai-Hulud emerged in […] The post Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches appeared first on Cyber Security News .

    Pulse ID: 6abd310b4d273aad58b696ff
    Pulse Link: otx.alienvault.com/pulse/6abd3
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 15:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #SupplyChain #OTX #CyberHunter_NL

  31. Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches

    A routine software update can now open the door to a cloud breach. Attackers are hiding credential stealing malware inside trusted packages and development tools, allowing malicious code to run on developer computers and automated build systems before an application even starts. The threat spans several campaigns rather than one malware family. Shai-Hulud emerged in […] The post Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches appeared first on Cyber Security News .

    Pulse ID: 6abd310b4d273aad58b696ff
    Pulse Link: otx.alienvault.com/pulse/6abd3
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 15:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #SupplyChain #OTX #CyberHunter_NL

  32. Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches

    A routine software update can now open the door to a cloud breach. Attackers are hiding credential stealing malware inside trusted packages and development tools, allowing malicious code to run on developer computers and automated build systems before an application even starts. The threat spans several campaigns rather than one malware family. Shai-Hulud emerged in […] The post Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches appeared first on Cyber Security News .

    Pulse ID: 6abd310b4d273aad58b696ff
    Pulse Link: otx.alienvault.com/pulse/6abd3
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 15:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #SupplyChain #OTX #CyberHunter_NL

  33. Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches

    A routine software update can now open the door to a cloud breach. Attackers are hiding credential stealing malware inside trusted packages and development tools, allowing malicious code to run on developer computers and automated build systems before an application even starts. The threat spans several campaigns rather than one malware family. Shai-Hulud emerged in […] The post Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches appeared first on Cyber Security News .

    Pulse ID: 6abd310b4d273aad58b696ff
    Pulse Link: otx.alienvault.com/pulse/6abd3
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 15:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #SupplyChain #OTX #CyberHunter_NL

  34. Global Group Ransomware Abuses WinMerge to Deploy Encryptor

    Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.

    Pulse ID: 6abd313ccae1bd87dd51d611
    Pulse Link: otx.alienvault.com/pulse/6abd3
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 15:56:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Deploy #RansomWare #Phishing #OTX #CyberHunter_NL

  35. Global Group Ransomware Abuses WinMerge to Deploy Encryptor

    Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.

    Pulse ID: 6abd313ccae1bd87dd51d611
    Pulse Link: otx.alienvault.com/pulse/6abd3
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 15:56:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Deploy #RansomWare #Phishing #OTX #CyberHunter_NL

  36. Global Group Ransomware Abuses WinMerge to Deploy Encryptor

    Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.

    Pulse ID: 6abd313ccae1bd87dd51d611
    Pulse Link: otx.alienvault.com/pulse/6abd3
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 15:56:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Deploy #RansomWare #Phishing #OTX #CyberHunter_NL

  37. Global Group Ransomware Abuses WinMerge to Deploy Encryptor

    Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.

    Pulse ID: 6abd313ccae1bd87dd51d611
    Pulse Link: otx.alienvault.com/pulse/6abd3
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 15:56:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Deploy #RansomWare #Phishing #OTX #CyberHunter_NL

  38. Global Group Ransomware Abuses WinMerge to Deploy Encryptor

    Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.

    Pulse ID: 6abd313ccae1bd87dd51d611
    Pulse Link: otx.alienvault.com/pulse/6abd3
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 15:56:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Deploy #RansomWare #Phishing #OTX #CyberHunter_NL

  39. Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs

    Hackers are using familiar Zoom setup files and PDF reader downloads to place remote-control software on business computers. The campaign turns ordinary workplace prompts into a path for outsiders to take over a device. The phishing emails use meeting invitations, document requests, software updates, RSVP cards, job offers and delivery notices. Victims who follow the […] The post Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs appeared first on Cyber Security News .

    Pulse ID: 6abd230a2a81c3eaefad30d0
    Pulse Link: otx.alienvault.com/pulse/6abd2
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 14:56:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #PDF #Zoom #Phishing #OTX #CyberHunter_NL

  40. Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs

    Hackers are using familiar Zoom setup files and PDF reader downloads to place remote-control software on business computers. The campaign turns ordinary workplace prompts into a path for outsiders to take over a device. The phishing emails use meeting invitations, document requests, software updates, RSVP cards, job offers and delivery notices. Victims who follow the […] The post Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs appeared first on Cyber Security News .

    Pulse ID: 6abd230a2a81c3eaefad30d0
    Pulse Link: otx.alienvault.com/pulse/6abd2
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 14:56:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #PDF #Zoom #Phishing #OTX #CyberHunter_NL

  41. Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs

    Hackers are using familiar Zoom setup files and PDF reader downloads to place remote-control software on business computers. The campaign turns ordinary workplace prompts into a path for outsiders to take over a device. The phishing emails use meeting invitations, document requests, software updates, RSVP cards, job offers and delivery notices. Victims who follow the […] The post Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs appeared first on Cyber Security News .

    Pulse ID: 6abd230a2a81c3eaefad30d0
    Pulse Link: otx.alienvault.com/pulse/6abd2
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 14:56:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #PDF #Zoom #Phishing #OTX #CyberHunter_NL

  42. Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs

    Hackers are using familiar Zoom setup files and PDF reader downloads to place remote-control software on business computers. The campaign turns ordinary workplace prompts into a path for outsiders to take over a device. The phishing emails use meeting invitations, document requests, software updates, RSVP cards, job offers and delivery notices. Victims who follow the […] The post Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs appeared first on Cyber Security News .

    Pulse ID: 6abd230a2a81c3eaefad30d0
    Pulse Link: otx.alienvault.com/pulse/6abd2
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 14:56:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #PDF #Zoom #Phishing #OTX #CyberHunter_NL

  43. Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller

    A vulnerable print server became the entry point for an Active Directory compromise after attackers exploited two PaperCut MF zero-day flaws. The intrusion shows how an overlooked business system can give criminals access to sensitive identity infrastructure. The attackers targeted an internet-facing PaperCut MF server running version 24.0.2, build 69746. They delivered Java code through […] The post Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller appeared first on Cyber Security News .

    Pulse ID: 6abd15130ba474e11c706382
    Pulse Link: otx.alienvault.com/pulse/6abd1
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 13:56:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #DomainController #Java #ZeroDay #OTX #CyberHunter_NL

  44. Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller

    A vulnerable print server became the entry point for an Active Directory compromise after attackers exploited two PaperCut MF zero-day flaws. The intrusion shows how an overlooked business system can give criminals access to sensitive identity infrastructure. The attackers targeted an internet-facing PaperCut MF server running version 24.0.2, build 69746. They delivered Java code through […] The post Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller appeared first on Cyber Security News .

    Pulse ID: 6abd15130ba474e11c706382
    Pulse Link: otx.alienvault.com/pulse/6abd1
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 13:56:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #DomainController #Java #ZeroDay #OTX #CyberHunter_NL

  45. Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller

    A vulnerable print server became the entry point for an Active Directory compromise after attackers exploited two PaperCut MF zero-day flaws. The intrusion shows how an overlooked business system can give criminals access to sensitive identity infrastructure. The attackers targeted an internet-facing PaperCut MF server running version 24.0.2, build 69746. They delivered Java code through […] The post Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller appeared first on Cyber Security News .

    Pulse ID: 6abd15130ba474e11c706382
    Pulse Link: otx.alienvault.com/pulse/6abd1
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 13:56:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #DomainController #Java #ZeroDay #OTX #CyberHunter_NL

  46. Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller

    A vulnerable print server became the entry point for an Active Directory compromise after attackers exploited two PaperCut MF zero-day flaws. The intrusion shows how an overlooked business system can give criminals access to sensitive identity infrastructure. The attackers targeted an internet-facing PaperCut MF server running version 24.0.2, build 69746. They delivered Java code through […] The post Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller appeared first on Cyber Security News .

    Pulse ID: 6abd15130ba474e11c706382
    Pulse Link: otx.alienvault.com/pulse/6abd1
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 13:56:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #DomainController #Java #ZeroDay #OTX #CyberHunter_NL

  47. Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller

    A vulnerable print server became the entry point for an Active Directory compromise after attackers exploited two PaperCut MF zero-day flaws. The intrusion shows how an overlooked business system can give criminals access to sensitive identity infrastructure. The attackers targeted an internet-facing PaperCut MF server running version 24.0.2, build 69746. They delivered Java code through […] The post Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller appeared first on Cyber Security News .

    Pulse ID: 6abd15130ba474e11c706382
    Pulse Link: otx.alienvault.com/pulse/6abd1
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 13:56:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #DomainController #Java #ZeroDay #OTX #CyberHunter_NL

  48. China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

    Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.

    Pulse ID: 6abcf9150143ec9b24b9ccef
    Pulse Link: otx.alienvault.com/pulse/6abcf
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 11:57:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #China #Government #OTX #CyberHunter_NL

  49. China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

    Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.

    Pulse ID: 6abcf9150143ec9b24b9ccef
    Pulse Link: otx.alienvault.com/pulse/6abcf
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 11:57:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #China #Government #OTX #CyberHunter_NL

  50. China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

    Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.

    Pulse ID: 6abcf9150143ec9b24b9ccef
    Pulse Link: otx.alienvault.com/pulse/6abcf
    Pulse Author: CyberHunter_NL
    Created: 2026-09-30 11:57:09

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #China #Government #OTX #CyberHunter_NL