#cyberhunter_nl — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cyberhunter_nl, aggregated by home.social.
-
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
Pulse ID: 6abff04d054297919c0ddc67
Pulse Link: https://otx.alienvault.com/pulse/6abff04d054297919c0ddc67
Pulse Author: CyberHunter_NL
Created: 2026-10-02 17:56:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
Pulse ID: 6abff04d054297919c0ddc67
Pulse Link: https://otx.alienvault.com/pulse/6abff04d054297919c0ddc67
Pulse Author: CyberHunter_NL
Created: 2026-10-02 17:56:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
Pulse ID: 6abff04d054297919c0ddc67
Pulse Link: https://otx.alienvault.com/pulse/6abff04d054297919c0ddc67
Pulse Author: CyberHunter_NL
Created: 2026-10-02 17:56:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
Pulse ID: 6abff04d054297919c0ddc67
Pulse Link: https://otx.alienvault.com/pulse/6abff04d054297919c0ddc67
Pulse Author: CyberHunter_NL
Created: 2026-10-02 17:56:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Protected Quick Tunnels: simple accountless authentication for your next dev project
Quick Tunnels now support email authentication. Add --allowed-mail to one cloudflared command, and only the addresses or domains you list can reach your local app. No Cloudflare account required on either side.
Pulse ID: 6abfb81e5ed3ed2a9976a5da
Pulse Link: https://otx.alienvault.com/pulse/6abfb81e5ed3ed2a9976a5da
Pulse Author: CyberHunter_NL
Created: 2026-10-02 13:56:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Protected Quick Tunnels: simple accountless authentication for your next dev project
Quick Tunnels now support email authentication. Add --allowed-mail to one cloudflared command, and only the addresses or domains you list can reach your local app. No Cloudflare account required on either side.
Pulse ID: 6abfb81e5ed3ed2a9976a5da
Pulse Link: https://otx.alienvault.com/pulse/6abfb81e5ed3ed2a9976a5da
Pulse Author: CyberHunter_NL
Created: 2026-10-02 13:56:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Protected Quick Tunnels: simple accountless authentication for your next dev project
Quick Tunnels now support email authentication. Add --allowed-mail to one cloudflared command, and only the addresses or domains you list can reach your local app. No Cloudflare account required on either side.
Pulse ID: 6abfb81e5ed3ed2a9976a5da
Pulse Link: https://otx.alienvault.com/pulse/6abfb81e5ed3ed2a9976a5da
Pulse Author: CyberHunter_NL
Created: 2026-10-02 13:56:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Protected Quick Tunnels: simple accountless authentication for your next dev project
Quick Tunnels now support email authentication. Add --allowed-mail to one cloudflared command, and only the addresses or domains you list can reach your local app. No Cloudflare account required on either side.
Pulse ID: 6abfb81e5ed3ed2a9976a5da
Pulse Link: https://otx.alienvault.com/pulse/6abfb81e5ed3ed2a9976a5da
Pulse Author: CyberHunter_NL
Created: 2026-10-02 13:56:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials
Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK. Rather than relying on one technique, its components search websites for sensitive files, recover stored passwords, and collect secrets from JavaScript delivered to visitors. The operation was already active at scale when researchers first observed […] The post Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials appeared first on Cyber Security News .
Pulse ID: 6abfa9e7b400add5633256b5
Pulse Link: https://otx.alienvault.com/pulse/6abfa9e7b400add5633256b5
Pulse Author: CyberHunter_NL
Created: 2026-10-02 12:56:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials
Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK. Rather than relying on one technique, its components search websites for sensitive files, recover stored passwords, and collect secrets from JavaScript delivered to visitors. The operation was already active at scale when researchers first observed […] The post Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials appeared first on Cyber Security News .
Pulse ID: 6abfa9e7b400add5633256b5
Pulse Link: https://otx.alienvault.com/pulse/6abfa9e7b400add5633256b5
Pulse Author: CyberHunter_NL
Created: 2026-10-02 12:56:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials
Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK. Rather than relying on one technique, its components search websites for sensitive files, recover stored passwords, and collect secrets from JavaScript delivered to visitors. The operation was already active at scale when researchers first observed […] The post Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials appeared first on Cyber Security News .
Pulse ID: 6abfa9e7b400add5633256b5
Pulse Link: https://otx.alienvault.com/pulse/6abfa9e7b400add5633256b5
Pulse Author: CyberHunter_NL
Created: 2026-10-02 12:56:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials
Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK. Rather than relying on one technique, its components search websites for sensitive files, recover stored passwords, and collect secrets from JavaScript delivered to visitors. The operation was already active at scale when researchers first observed […] The post Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials appeared first on Cyber Security News .
Pulse ID: 6abfa9e7b400add5633256b5
Pulse Link: https://otx.alienvault.com/pulse/6abfa9e7b400add5633256b5
Pulse Author: CyberHunter_NL
Created: 2026-10-02 12:56:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Autonomous AI agents tried to hack US, Canadian government websites
Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]
Pulse ID: 6abec8cad6344592e61e9855
Pulse Link: https://otx.alienvault.com/pulse/6abec8cad6344592e61e9855
Pulse Author: CyberHunter_NL
Created: 2026-10-01 20:55:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Autonomous AI agents tried to hack US, Canadian government websites
Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]
Pulse ID: 6abec8cad6344592e61e9855
Pulse Link: https://otx.alienvault.com/pulse/6abec8cad6344592e61e9855
Pulse Author: CyberHunter_NL
Created: 2026-10-01 20:55:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Autonomous AI agents tried to hack US, Canadian government websites
Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]
Pulse ID: 6abec8cad6344592e61e9855
Pulse Link: https://otx.alienvault.com/pulse/6abec8cad6344592e61e9855
Pulse Author: CyberHunter_NL
Created: 2026-10-01 20:55:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]
Pulse ID: 6abe746e3b37a624f1ed67cc
Pulse Link: https://otx.alienvault.com/pulse/6abe746e3b37a624f1ed67cc
Pulse Author: CyberHunter_NL
Created: 2026-10-01 14:55:42Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]
Pulse ID: 6abe746e3b37a624f1ed67cc
Pulse Link: https://otx.alienvault.com/pulse/6abe746e3b37a624f1ed67cc
Pulse Author: CyberHunter_NL
Created: 2026-10-01 14:55:42Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]
Pulse ID: 6abe746e3b37a624f1ed67cc
Pulse Link: https://otx.alienvault.com/pulse/6abe746e3b37a624f1ed67cc
Pulse Author: CyberHunter_NL
Created: 2026-10-01 14:55:42Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts
A China-aligned hacking group tracked as TA419 has impersonated a senior Anthropic employee and well-known policy figures to target US artificial intelligence experts. Proofpoint linked the activity to credential-phishing campaigns aimed at researchers at think tanks, universities, and law firms, with lures designed to steal access to their cloud accounts. The targeting likely supports Chinese […] The post Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts appeared first on Cyber Security News .
Pulse ID: 6abe74904426ab4ef87aef5c
Pulse Link: https://otx.alienvault.com/pulse/6abe74904426ab4ef87aef5c
Pulse Author: CyberHunter_NL
Created: 2026-10-01 14:56:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts
A China-aligned hacking group tracked as TA419 has impersonated a senior Anthropic employee and well-known policy figures to target US artificial intelligence experts. Proofpoint linked the activity to credential-phishing campaigns aimed at researchers at think tanks, universities, and law firms, with lures designed to steal access to their cloud accounts. The targeting likely supports Chinese […] The post Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts appeared first on Cyber Security News .
Pulse ID: 6abe74904426ab4ef87aef5c
Pulse Link: https://otx.alienvault.com/pulse/6abe74904426ab4ef87aef5c
Pulse Author: CyberHunter_NL
Created: 2026-10-01 14:56:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts
A China-aligned hacking group tracked as TA419 has impersonated a senior Anthropic employee and well-known policy figures to target US artificial intelligence experts. Proofpoint linked the activity to credential-phishing campaigns aimed at researchers at think tanks, universities, and law firms, with lures designed to steal access to their cloud accounts. The targeting likely supports Chinese […] The post Chinese Hackers Posing as Senior Anthropic Employee Targeting US AI Policy Experts appeared first on Cyber Security News .
Pulse ID: 6abe74904426ab4ef87aef5c
Pulse Link: https://otx.alienvault.com/pulse/6abe74904426ab4ef87aef5c
Pulse Author: CyberHunter_NL
Created: 2026-10-01 14:56:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles
Key Findings In July 2026, a China-aligned threat actor Proofpoint tracks as TA419 conducted multiple credential phishing campaigns impersonating prominent economists and artificial intelligence (AI) policymakers to target AI experts working for US think tanks, universities, and legal sector organizations. TA419 also previously impersonated a prominent Anthropic employee to target an AI policy expert at a US think tank in February 2026. This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the US AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation, and export controls involving the US and China. Overview In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US. The group first sent benign...
Pulse ID: 6abe2e2c3c77a1c9276b0827
Pulse Link: https://otx.alienvault.com/pulse/6abe2e2c3c77a1c9276b0827
Pulse Author: CyberHunter_NL
Created: 2026-10-01 09:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles
Key Findings In July 2026, a China-aligned threat actor Proofpoint tracks as TA419 conducted multiple credential phishing campaigns impersonating prominent economists and artificial intelligence (AI) policymakers to target AI experts working for US think tanks, universities, and legal sector organizations. TA419 also previously impersonated a prominent Anthropic employee to target an AI policy expert at a US think tank in February 2026. This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the US AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation, and export controls involving the US and China. Overview In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US. The group first sent benign...
Pulse ID: 6abe2e2c3c77a1c9276b0827
Pulse Link: https://otx.alienvault.com/pulse/6abe2e2c3c77a1c9276b0827
Pulse Author: CyberHunter_NL
Created: 2026-10-01 09:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles
Key Findings In July 2026, a China-aligned threat actor Proofpoint tracks as TA419 conducted multiple credential phishing campaigns impersonating prominent economists and artificial intelligence (AI) policymakers to target AI experts working for US think tanks, universities, and legal sector organizations. TA419 also previously impersonated a prominent Anthropic employee to target an AI policy expert at a US think tank in February 2026. This activity likely supports wider Chinese intelligence objectives to better understand ongoing developments within the US AI policy and regulatory landscape and occurs amid intense strategic competition, accusations of model distillation, and export controls involving the US and China. Overview In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing campaigns targeting AI policy experts in the US. The group first sent benign...
Pulse ID: 6abe2e2c3c77a1c9276b0827
Pulse Link: https://otx.alienvault.com/pulse/6abe2e2c3c77a1c9276b0827
Pulse Author: CyberHunter_NL
Created: 2026-10-01 09:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster
Investigating a phishing alert often means working through several layers of activity before an analyst can confidently close or escalate the case. Modern campaigns can hide malicious activity behind encrypted traffic, CAPTCHA challenges, redirects, browser scripts, and token-based authentication, leaving analysts to reconstruct the attack before they can determine what happened. The investigation does not […] The post Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster appeared first on Cyber Security News .
Pulse ID: 6abd3f487bd0ca4bcb80df4b
Pulse Link: https://otx.alienvault.com/pulse/6abd3f487bd0ca4bcb80df4b
Pulse Author: CyberHunter_NL
Created: 2026-09-30 16:56:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster
Investigating a phishing alert often means working through several layers of activity before an analyst can confidently close or escalate the case. Modern campaigns can hide malicious activity behind encrypted traffic, CAPTCHA challenges, redirects, browser scripts, and token-based authentication, leaving analysts to reconstruct the attack before they can determine what happened. The investigation does not […] The post Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster appeared first on Cyber Security News .
Pulse ID: 6abd3f487bd0ca4bcb80df4b
Pulse Link: https://otx.alienvault.com/pulse/6abd3f487bd0ca4bcb80df4b
Pulse Author: CyberHunter_NL
Created: 2026-09-30 16:56:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster
Investigating a phishing alert often means working through several layers of activity before an analyst can confidently close or escalate the case. Modern campaigns can hide malicious activity behind encrypted traffic, CAPTCHA challenges, redirects, browser scripts, and token-based authentication, leaving analysts to reconstruct the attack before they can determine what happened. The investigation does not […] The post Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster appeared first on Cyber Security News .
Pulse ID: 6abd3f487bd0ca4bcb80df4b
Pulse Link: https://otx.alienvault.com/pulse/6abd3f487bd0ca4bcb80df4b
Pulse Author: CyberHunter_NL
Created: 2026-09-30 16:56:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster
Investigating a phishing alert often means working through several layers of activity before an analyst can confidently close or escalate the case. Modern campaigns can hide malicious activity behind encrypted traffic, CAPTCHA challenges, redirects, browser scripts, and token-based authentication, leaving analysts to reconstruct the attack before they can determine what happened. The investigation does not […] The post Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster appeared first on Cyber Security News .
Pulse ID: 6abd3f487bd0ca4bcb80df4b
Pulse Link: https://otx.alienvault.com/pulse/6abd3f487bd0ca4bcb80df4b
Pulse Author: CyberHunter_NL
Created: 2026-09-30 16:56:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches
A routine software update can now open the door to a cloud breach. Attackers are hiding credential stealing malware inside trusted packages and development tools, allowing malicious code to run on developer computers and automated build systems before an application even starts. The threat spans several campaigns rather than one malware family. Shai-Hulud emerged in […] The post Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches appeared first on Cyber Security News .
Pulse ID: 6abd310b4d273aad58b696ff
Pulse Link: https://otx.alienvault.com/pulse/6abd310b4d273aad58b696ff
Pulse Author: CyberHunter_NL
Created: 2026-09-30 15:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches
A routine software update can now open the door to a cloud breach. Attackers are hiding credential stealing malware inside trusted packages and development tools, allowing malicious code to run on developer computers and automated build systems before an application even starts. The threat spans several campaigns rather than one malware family. Shai-Hulud emerged in […] The post Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches appeared first on Cyber Security News .
Pulse ID: 6abd310b4d273aad58b696ff
Pulse Link: https://otx.alienvault.com/pulse/6abd310b4d273aad58b696ff
Pulse Author: CyberHunter_NL
Created: 2026-09-30 15:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches
A routine software update can now open the door to a cloud breach. Attackers are hiding credential stealing malware inside trusted packages and development tools, allowing malicious code to run on developer computers and automated build systems before an application even starts. The threat spans several campaigns rather than one malware family. Shai-Hulud emerged in […] The post Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches appeared first on Cyber Security News .
Pulse ID: 6abd310b4d273aad58b696ff
Pulse Link: https://otx.alienvault.com/pulse/6abd310b4d273aad58b696ff
Pulse Author: CyberHunter_NL
Created: 2026-09-30 15:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches
A routine software update can now open the door to a cloud breach. Attackers are hiding credential stealing malware inside trusted packages and development tools, allowing malicious code to run on developer computers and automated build systems before an application even starts. The threat spans several campaigns rather than one malware family. Shai-Hulud emerged in […] The post Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches appeared first on Cyber Security News .
Pulse ID: 6abd310b4d273aad58b696ff
Pulse Link: https://otx.alienvault.com/pulse/6abd310b4d273aad58b696ff
Pulse Author: CyberHunter_NL
Created: 2026-09-30 15:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches
A routine software update can now open the door to a cloud breach. Attackers are hiding credential stealing malware inside trusted packages and development tools, allowing malicious code to run on developer computers and automated build systems before an application even starts. The threat spans several campaigns rather than one malware family. Shai-Hulud emerged in […] The post Supply Chain Attacks Turn Developer Machines Into Gateways for Cloud Breaches appeared first on Cyber Security News .
Pulse ID: 6abd310b4d273aad58b696ff
Pulse Link: https://otx.alienvault.com/pulse/6abd310b4d273aad58b696ff
Pulse Author: CyberHunter_NL
Created: 2026-09-30 15:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.
Pulse ID: 6abd313ccae1bd87dd51d611
Pulse Link: https://otx.alienvault.com/pulse/6abd313ccae1bd87dd51d611
Pulse Author: CyberHunter_NL
Created: 2026-09-30 15:56:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.
Pulse ID: 6abd313ccae1bd87dd51d611
Pulse Link: https://otx.alienvault.com/pulse/6abd313ccae1bd87dd51d611
Pulse Author: CyberHunter_NL
Created: 2026-09-30 15:56:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.
Pulse ID: 6abd313ccae1bd87dd51d611
Pulse Link: https://otx.alienvault.com/pulse/6abd313ccae1bd87dd51d611
Pulse Author: CyberHunter_NL
Created: 2026-09-30 15:56:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.
Pulse ID: 6abd313ccae1bd87dd51d611
Pulse Link: https://otx.alienvault.com/pulse/6abd313ccae1bd87dd51d611
Pulse Author: CyberHunter_NL
Created: 2026-09-30 15:56:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.
Pulse ID: 6abd313ccae1bd87dd51d611
Pulse Link: https://otx.alienvault.com/pulse/6abd313ccae1bd87dd51d611
Pulse Author: CyberHunter_NL
Created: 2026-09-30 15:56:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs
Hackers are using familiar Zoom setup files and PDF reader downloads to place remote-control software on business computers. The campaign turns ordinary workplace prompts into a path for outsiders to take over a device. The phishing emails use meeting invitations, document requests, software updates, RSVP cards, job offers and delivery notices. Victims who follow the […] The post Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs appeared first on Cyber Security News .
Pulse ID: 6abd230a2a81c3eaefad30d0
Pulse Link: https://otx.alienvault.com/pulse/6abd230a2a81c3eaefad30d0
Pulse Author: CyberHunter_NL
Created: 2026-09-30 14:56:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs
Hackers are using familiar Zoom setup files and PDF reader downloads to place remote-control software on business computers. The campaign turns ordinary workplace prompts into a path for outsiders to take over a device. The phishing emails use meeting invitations, document requests, software updates, RSVP cards, job offers and delivery notices. Victims who follow the […] The post Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs appeared first on Cyber Security News .
Pulse ID: 6abd230a2a81c3eaefad30d0
Pulse Link: https://otx.alienvault.com/pulse/6abd230a2a81c3eaefad30d0
Pulse Author: CyberHunter_NL
Created: 2026-09-30 14:56:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs
Hackers are using familiar Zoom setup files and PDF reader downloads to place remote-control software on business computers. The campaign turns ordinary workplace prompts into a path for outsiders to take over a device. The phishing emails use meeting invitations, document requests, software updates, RSVP cards, job offers and delivery notices. Victims who follow the […] The post Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs appeared first on Cyber Security News .
Pulse ID: 6abd230a2a81c3eaefad30d0
Pulse Link: https://otx.alienvault.com/pulse/6abd230a2a81c3eaefad30d0
Pulse Author: CyberHunter_NL
Created: 2026-09-30 14:56:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs
Hackers are using familiar Zoom setup files and PDF reader downloads to place remote-control software on business computers. The campaign turns ordinary workplace prompts into a path for outsiders to take over a device. The phishing emails use meeting invitations, document requests, software updates, RSVP cards, job offers and delivery notices. Victims who follow the […] The post Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs appeared first on Cyber Security News .
Pulse ID: 6abd230a2a81c3eaefad30d0
Pulse Link: https://otx.alienvault.com/pulse/6abd230a2a81c3eaefad30d0
Pulse Author: CyberHunter_NL
Created: 2026-09-30 14:56:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller
A vulnerable print server became the entry point for an Active Directory compromise after attackers exploited two PaperCut MF zero-day flaws. The intrusion shows how an overlooked business system can give criminals access to sensitive identity infrastructure. The attackers targeted an internet-facing PaperCut MF server running version 24.0.2, build 69746. They delivered Java code through […] The post Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller appeared first on Cyber Security News .
Pulse ID: 6abd15130ba474e11c706382
Pulse Link: https://otx.alienvault.com/pulse/6abd15130ba474e11c706382
Pulse Author: CyberHunter_NL
Created: 2026-09-30 13:56:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller
A vulnerable print server became the entry point for an Active Directory compromise after attackers exploited two PaperCut MF zero-day flaws. The intrusion shows how an overlooked business system can give criminals access to sensitive identity infrastructure. The attackers targeted an internet-facing PaperCut MF server running version 24.0.2, build 69746. They delivered Java code through […] The post Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller appeared first on Cyber Security News .
Pulse ID: 6abd15130ba474e11c706382
Pulse Link: https://otx.alienvault.com/pulse/6abd15130ba474e11c706382
Pulse Author: CyberHunter_NL
Created: 2026-09-30 13:56:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller
A vulnerable print server became the entry point for an Active Directory compromise after attackers exploited two PaperCut MF zero-day flaws. The intrusion shows how an overlooked business system can give criminals access to sensitive identity infrastructure. The attackers targeted an internet-facing PaperCut MF server running version 24.0.2, build 69746. They delivered Java code through […] The post Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller appeared first on Cyber Security News .
Pulse ID: 6abd15130ba474e11c706382
Pulse Link: https://otx.alienvault.com/pulse/6abd15130ba474e11c706382
Pulse Author: CyberHunter_NL
Created: 2026-09-30 13:56:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller
A vulnerable print server became the entry point for an Active Directory compromise after attackers exploited two PaperCut MF zero-day flaws. The intrusion shows how an overlooked business system can give criminals access to sensitive identity infrastructure. The attackers targeted an internet-facing PaperCut MF server running version 24.0.2, build 69746. They delivered Java code through […] The post Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller appeared first on Cyber Security News .
Pulse ID: 6abd15130ba474e11c706382
Pulse Link: https://otx.alienvault.com/pulse/6abd15130ba474e11c706382
Pulse Author: CyberHunter_NL
Created: 2026-09-30 13:56:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller
A vulnerable print server became the entry point for an Active Directory compromise after attackers exploited two PaperCut MF zero-day flaws. The intrusion shows how an overlooked business system can give criminals access to sensitive identity infrastructure. The attackers targeted an internet-facing PaperCut MF server running version 24.0.2, build 69746. They delivered Java code through […] The post Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller appeared first on Cyber Security News .
Pulse ID: 6abd15130ba474e11c706382
Pulse Link: https://otx.alienvault.com/pulse/6abd15130ba474e11c706382
Pulse Author: CyberHunter_NL
Created: 2026-09-30 13:56:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.
Pulse ID: 6abcf9150143ec9b24b9ccef
Pulse Link: https://otx.alienvault.com/pulse/6abcf9150143ec9b24b9ccef
Pulse Author: CyberHunter_NL
Created: 2026-09-30 11:57:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.
Pulse ID: 6abcf9150143ec9b24b9ccef
Pulse Link: https://otx.alienvault.com/pulse/6abcf9150143ec9b24b9ccef
Pulse Author: CyberHunter_NL
Created: 2026-09-30 11:57:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor
Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.
Pulse ID: 6abcf9150143ec9b24b9ccef
Pulse Link: https://otx.alienvault.com/pulse/6abcf9150143ec9b24b9ccef
Pulse Author: CyberHunter_NL
Created: 2026-09-30 11:57:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.