#cyberhunter_nl — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cyberhunter_nl, aggregated by home.social.
-
Data Broker Radaris Loses Domains in Privacy Fight
Indicators extracted from public reporting. Source: https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/
Pulse ID: 6aaae64e6d6f30daf109048b
Pulse Link: https://otx.alienvault.com/pulse/6aaae64e6d6f30daf109048b
Pulse Author: CyberHunter_NL
Created: 2026-09-16 18:56:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Indicators extracted from public reporting. Source: https://securelist.com/tr/nighteagle-apt-ghostcontainer-and-tunneling/121323/
Pulse ID: 6aaaca196483f96e20acbb97
Pulse Link: https://otx.alienvault.com/pulse/6aaaca196483f96e20acbb97
Pulse Author: CyberHunter_NL
Created: 2026-09-16 16:55:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware
Indicators extracted from public reporting. Source: https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists
Pulse ID: 6aaa59a26ba2b28d330ac303
Pulse Link: https://otx.alienvault.com/pulse/6aaa59a26ba2b28d330ac303
Pulse Author: CyberHunter_NL
Created: 2026-09-16 08:56:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign
Indicators extracted from public reporting. Source: https://research.jfrog.com/post/gemstuffer-openai-rubygems/
Pulse ID: 6aaa4b8c65d157b30c294f2d
Pulse Link: https://otx.alienvault.com/pulse/6aaa4b8c65d157b30c294f2d
Pulse Author: CyberHunter_NL
Created: 2026-09-16 07:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Indicators extracted from public reporting. Source: https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-woocommerce-wholesale-lead-capture-plugin/
Pulse ID: 6aaa3d77f8079160d3d2ce7a
Pulse Link: https://otx.alienvault.com/pulse/6aaa3d77f8079160d3d2ce7a
Pulse Author: CyberHunter_NL
Created: 2026-09-16 06:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Indicators extracted from public reporting. Source: https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware
Pulse ID: 6aa9a2c21e2c7eb1f6725f29
Pulse Link: https://otx.alienvault.com/pulse/6aa9a2c21e2c7eb1f6725f29
Pulse Author: CyberHunter_NL
Created: 2026-09-15 19:55:46Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Indicators extracted from public reporting. Source: https://www.fbi.gov/investigate/cyber/alerts/2026/government-of-iran-cyber-actors-deploy-telegram-c2-to-push-malware-to-identified-targets
Pulse ID: 6aa986b9407ba33f3d75cb86
Pulse Link: https://otx.alienvault.com/pulse/6aa986b9407ba33f3d75cb86
Pulse Author: CyberHunter_NL
Created: 2026-09-15 17:56:09Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
Indicators extracted from public reporting. Source: https://www.lumen.com/blog/en-us/the-banana-stand-brokering-and-managing-infections-across-asia-using-mqtt
Pulse ID: 6aa96a97f5049ec6f3649a6f
Pulse Link: https://otx.alienvault.com/pulse/6aa96a97f5049ec6f3649a6f
Pulse Author: CyberHunter_NL
Created: 2026-09-15 15:56:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
Indicators extracted from public reporting. Source: https://hunt.io/blog/redis-cryptomining-botnet-3562-servers
Pulse ID: 6aa94063cede304a0c4f78d5
Pulse Link: https://otx.alienvault.com/pulse/6aa94063cede304a0c4f78d5
Pulse Author: CyberHunter_NL
Created: 2026-09-15 12:56:03Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Indicators extracted from public reporting. Source: https://www.f5.com/labs/articles/cloud-takeover-mass-scanning-for-exposed-vite-endpoints-cve-2026-39364
Pulse ID: 6aa9406e744080ca6dddb815
Pulse Link: https://otx.alienvault.com/pulse/6aa9406e744080ca6dddb815
Pulse Author: CyberHunter_NL
Created: 2026-09-15 12:56:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
HBO Max’s verified Reddit account hijacked to spread malware
Indicators extracted from public reporting. Source: https://www.hudsonrock.com/blog/hbo-max-ads-on-a-compromised-reddit-account-exposed-a-massive-pasteswitch-clickfix-operation
Pulse ID: 6aa94072d05585b5b12c7a73
Pulse Link: https://otx.alienvault.com/pulse/6aa94072d05585b5b12c7a73
Pulse Author: CyberHunter_NL
Created: 2026-09-15 12:56:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Indicators extracted from public reporting. Source: https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-woocommerce-wholesale-lead-capture-plugin/
Pulse ID: 6aa93268344088e074561b84
Pulse Link: https://otx.alienvault.com/pulse/6aa93268344088e074561b84
Pulse Author: CyberHunter_NL
Created: 2026-09-15 11:56:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Search results are sending people to fake Bitrefill checkouts
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts
Pulse ID: 6aa9163460570086788a836c
Pulse Link: https://otx.alienvault.com/pulse/6aa9163460570086788a836c
Pulse Author: CyberHunter_NL
Created: 2026-09-15 09:56:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Indicators extracted from public reporting. Source: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Pulse ID: 6aa8ebf73ff0d28609555e64
Pulse Link: https://otx.alienvault.com/pulse/6aa8ebf73ff0d28609555e64
Pulse Author: CyberHunter_NL
Created: 2026-09-15 06:55:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Indicators extracted from public reporting. Source: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Pulse ID: 6aa8ebf73ff0d28609555e64
Pulse Link: https://otx.alienvault.com/pulse/6aa8ebf73ff0d28609555e64
Pulse Author: CyberHunter_NL
Created: 2026-09-15 06:55:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Indicators extracted from public reporting. Source: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Pulse ID: 6aa8ebf73ff0d28609555e64
Pulse Link: https://otx.alienvault.com/pulse/6aa8ebf73ff0d28609555e64
Pulse Author: CyberHunter_NL
Created: 2026-09-15 06:55:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Indicators extracted from public reporting. Source: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Pulse ID: 6aa8ebf73ff0d28609555e64
Pulse Link: https://otx.alienvault.com/pulse/6aa8ebf73ff0d28609555e64
Pulse Author: CyberHunter_NL
Created: 2026-09-15 06:55:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Indicators extracted from public reporting. Source: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
Pulse ID: 6aa8ebf73ff0d28609555e64
Pulse Link: https://otx.alienvault.com/pulse/6aa8ebf73ff0d28609555e64
Pulse Author: CyberHunter_NL
Created: 2026-09-15 06:55:50Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
Indicators extracted from public reporting. Source: https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/
Pulse ID: 6aa8ebfa8d18e6075284f70e
Pulse Link: https://otx.alienvault.com/pulse/6aa8ebfa8d18e6075284f70e
Pulse Author: CyberHunter_NL
Created: 2026-09-15 06:55:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Twitch extension with 30K installs exposes users’ OAuth tokens
Indicators extracted from public reporting. Source: https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/
Pulse ID: 6aa8513a4081c7d15a5a0a40
Pulse Link: https://otx.alienvault.com/pulse/6aa8513a4081c7d15a5a0a40
Pulse Author: CyberHunter_NL
Created: 2026-09-14 19:55:38Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
Indicators extracted from public reporting. Source: https://hunt.io/blog/thai-broadband-fortigate-sslvpn-meshcentral-intrusion
Pulse ID: 6aa851575cff24d10924ffc1
Pulse Link: https://otx.alienvault.com/pulse/6aa851575cff24d10924ffc1
Pulse Author: CyberHunter_NL
Created: 2026-09-14 19:56:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Indicators extracted from public reporting. Source: https://www.hudsonrock.com/blog/hbo-max-ads-on-a-compromised-reddit-account-exposed-a-massive-pasteswitch-clickfix-operation
Pulse ID: 6aa843278361920eaabc970a
Pulse Link: https://otx.alienvault.com/pulse/6aa843278361920eaabc970a
Pulse Author: CyberHunter_NL
Created: 2026-09-14 18:55:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Exploit FortiGate SSL-VPN Vulnerability to Attack Broadband Provider
Indicators extracted from public reporting. Source: https://cybersecuritynews.com/fortigate-ssl-vpn-vulnerability/
Pulse ID: 6aa835ee9dc88a53daa3efde
Pulse Link: https://otx.alienvault.com/pulse/6aa835ee9dc88a53daa3efde
Pulse Author: CyberHunter_NL
Created: 2026-09-14 17:59:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers target exposed Vite dev servers to steal AWS, Azure secrets
Indicators extracted from public reporting. Source: https://www.f5.com/labs/articles/cloud-takeover-mass-scanning-for-exposed-vite-endpoints-cve-2026-39364
Pulse ID: 6aa827098a5afc79562c13c8
Pulse Link: https://otx.alienvault.com/pulse/6aa827098a5afc79562c13c8
Pulse Author: CyberHunter_NL
Created: 2026-09-14 16:55:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers target exposed Vite dev servers to steal AWS, Azure secrets
Indicators extracted from public reporting. Source: https://www.f5.com/labs/articles/cloud-takeover-mass-scanning-for-exposed-vite-endpoints-cve-2026-39364
Pulse ID: 6aa827098a5afc79562c13c8
Pulse Link: https://otx.alienvault.com/pulse/6aa827098a5afc79562c13c8
Pulse Author: CyberHunter_NL
Created: 2026-09-14 16:55:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
Indicators extracted from public reporting. Source: https://socket.dev/blog/malicious-twitch-browser-extension
Pulse ID: 6aa7fd0924a922abb5fe4702
Pulse Link: https://otx.alienvault.com/pulse/6aa7fd0924a922abb5fe4702
Pulse Author: CyberHunter_NL
Created: 2026-09-14 13:56:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning
Indicators extracted from public reporting. Source: https://www.sophos.com/en-gb/blog/eye-spy-cyclops-blink-returns-with-extended-capabilities/
Pulse ID: 6aa7fd0f75016a3168fa100c
Pulse Link: https://otx.alienvault.com/pulse/6aa7fd0f75016a3168fa100c
Pulse Author: CyberHunter_NL
Created: 2026-09-14 13:56:31Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users
Indicators extracted from public reporting. Source: https://www.gendigital.com/blog/insights/research/one-click-backdoor-sogou
Pulse ID: 6aa7fd15b23e2bb5be55eed8
Pulse Link: https://otx.alienvault.com/pulse/6aa7fd15b23e2bb5be55eed8
Pulse Author: CyberHunter_NL
Created: 2026-09-14 13:56:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Indicators extracted from public reporting. Source: https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers
Pulse ID: 6aa7b6a228f095cb8744d1ee
Pulse Link: https://otx.alienvault.com/pulse/6aa7b6a228f095cb8744d1ee
Pulse Author: CyberHunter_NL
Created: 2026-09-14 08:56:02Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
Pulse ID: 6aa7b6b92f301028ac1edc54
Pulse Link: https://otx.alienvault.com/pulse/6aa7b6b92f301028ac1edc54
Pulse Author: CyberHunter_NL
Created: 2026-09-14 08:56:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
Pulse ID: 6aa7b6b92f301028ac1edc54
Pulse Link: https://otx.alienvault.com/pulse/6aa7b6b92f301028ac1edc54
Pulse Author: CyberHunter_NL
Created: 2026-09-14 08:56:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
Pulse ID: 6aa7b6b92f301028ac1edc54
Pulse Link: https://otx.alienvault.com/pulse/6aa7b6b92f301028ac1edc54
Pulse Author: CyberHunter_NL
Created: 2026-09-14 08:56:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
Pulse ID: 6aa7b6b92f301028ac1edc54
Pulse Link: https://otx.alienvault.com/pulse/6aa7b6b92f301028ac1edc54
Pulse Author: CyberHunter_NL
Created: 2026-09-14 08:56:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/
Pulse ID: 6aa7b6b92f301028ac1edc54
Pulse Link: https://otx.alienvault.com/pulse/6aa7b6b92f301028ac1edc54
Pulse Author: CyberHunter_NL
Created: 2026-09-14 08:56:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
Indicators extracted from public reporting. Source: https://socket.dev/blog/malicious-twitch-browser-extension
Pulse ID: 6aa7b6c46c7b4754ba91e496
Pulse Link: https://otx.alienvault.com/pulse/6aa7b6c46c7b4754ba91e496
Pulse Author: CyberHunter_NL
Created: 2026-09-14 08:56:36Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
OpenAI Agent Swarm Hacks RubyGems Package Manager
Indicators extracted from public reporting. Source: https://www.rubyhack.ai/
Pulse ID: 6aa7b6e08bbe641908be34b5
Pulse Link: https://otx.alienvault.com/pulse/6aa7b6e08bbe641908be34b5
Pulse Author: CyberHunter_NL
Created: 2026-09-14 08:57:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process
Indicators extracted from public reporting. Source: https://www.pointwild.com/threat-intelligence/asyncrat-delivered-via-autoit-full-chain-analysis/
Pulse ID: 6aa7a88342ad718ae208e629
Pulse Link: https://otx.alienvault.com/pulse/6aa7a88342ad718ae208e629
Pulse Author: CyberHunter_NL
Created: 2026-09-14 07:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process
Indicators extracted from public reporting. Source: https://www.pointwild.com/threat-intelligence/asyncrat-delivered-via-autoit-full-chain-analysis/
Pulse ID: 6aa7a88342ad718ae208e629
Pulse Link: https://otx.alienvault.com/pulse/6aa7a88342ad718ae208e629
Pulse Author: CyberHunter_NL
Created: 2026-09-14 07:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process
Indicators extracted from public reporting. Source: https://www.pointwild.com/threat-intelligence/asyncrat-delivered-via-autoit-full-chain-analysis/
Pulse ID: 6aa7a88342ad718ae208e629
Pulse Link: https://otx.alienvault.com/pulse/6aa7a88342ad718ae208e629
Pulse Author: CyberHunter_NL
Created: 2026-09-14 07:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process
Indicators extracted from public reporting. Source: https://www.pointwild.com/threat-intelligence/asyncrat-delivered-via-autoit-full-chain-analysis/
Pulse ID: 6aa7a88342ad718ae208e629
Pulse Link: https://otx.alienvault.com/pulse/6aa7a88342ad718ae208e629
Pulse Author: CyberHunter_NL
Created: 2026-09-14 07:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process
Indicators extracted from public reporting. Source: https://www.pointwild.com/threat-intelligence/asyncrat-delivered-via-autoit-full-chain-analysis/
Pulse ID: 6aa7a88342ad718ae208e629
Pulse Link: https://otx.alienvault.com/pulse/6aa7a88342ad718ae208e629
Pulse Author: CyberHunter_NL
Created: 2026-09-14 07:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Indicators extracted from public reporting. Source: https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks
Pulse ID: 6aa3d0350084bab84979a84d
Pulse Link: https://otx.alienvault.com/pulse/6aa3d0350084bab84979a84d
Pulse Author: CyberHunter_NL
Created: 2026-09-11 09:56:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Zscaler #bot #CyberHunter_NL
-
Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Indicators extracted from public reporting. Source: https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks
Pulse ID: 6aa3d0350084bab84979a84d
Pulse Link: https://otx.alienvault.com/pulse/6aa3d0350084bab84979a84d
Pulse Author: CyberHunter_NL
Created: 2026-09-11 09:56:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Zscaler #bot #CyberHunter_NL
-
Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Indicators extracted from public reporting. Source: https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks
Pulse ID: 6aa3d0350084bab84979a84d
Pulse Link: https://otx.alienvault.com/pulse/6aa3d0350084bab84979a84d
Pulse Author: CyberHunter_NL
Created: 2026-09-11 09:56:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Zscaler #bot #CyberHunter_NL
-
Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Indicators extracted from public reporting. Source: https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks
Pulse ID: 6aa3d0350084bab84979a84d
Pulse Link: https://otx.alienvault.com/pulse/6aa3d0350084bab84979a84d
Pulse Author: CyberHunter_NL
Created: 2026-09-11 09:56:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Zscaler #bot #CyberHunter_NL
-
Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
Indicators extracted from public reporting. Source: https://www.zscaler.com/blogs/security-research/sloppyrat-new-tool-ransomware-attacks
Pulse ID: 6aa3d0350084bab84979a84d
Pulse Link: https://otx.alienvault.com/pulse/6aa3d0350084bab84979a84d
Pulse Author: CyberHunter_NL
Created: 2026-09-11 09:56:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RansomWare #Zscaler #bot #CyberHunter_NL
-
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Indicators extracted from public reporting. Source: https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit
Pulse ID: 6aa12d2fef480cc7edfcd3c7
Pulse Link: https://otx.alienvault.com/pulse/6aa12d2fef480cc7edfcd3c7
Pulse Author: CyberHunter_NL
Created: 2026-09-09 09:55:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #PHP #RCE #Rootkit #Sophos #bot #CyberHunter_NL
-
Linux Rootkit Injects Fileless PHP Web Shells Into Compromised F5 BIG-IP Servers
Indicators extracted from public reporting. Source: https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit
Pulse ID: 6a9ede94dbcc391c11b9dde8
Pulse Link: https://otx.alienvault.com/pulse/6a9ede94dbcc391c11b9dde8
Pulse Author: CyberHunter_NL
Created: 2026-09-07 15:56:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Linux #OTX #OpenThreatExchange #PHP #RCE #Rootkit #Sophos #bot #CyberHunter_NL
-
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Indicators extracted from public reporting. Source: https://www.huntress.com/blog/rogue-screenconnect-installations
Pulse ID: 6a9eb45f42544c9e25b28e1e
Pulse Link: https://otx.alienvault.com/pulse/6a9eb45f42544c9e25b28e1e
Pulse Author: CyberHunter_NL
Created: 2026-09-07 12:55:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #ScreenConnect #VBS #bot #CyberHunter_NL
-
Dissecting a PHP web server rootkit
Indicators extracted from public reporting. Source: https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit
Pulse ID: 6a9e98258feba9bd6af09e8c
Pulse Link: https://otx.alienvault.com/pulse/6a9e98258feba9bd6af09e8c
Pulse Author: CyberHunter_NL
Created: 2026-09-07 10:55:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PHP #RCE #Rootkit #Sophos #bot #CyberHunter_NL