#http — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #http, aggregated by home.social.
-
Curiouser and Curiouser
Indicators extracted from public reporting. Source: https://talosintelligence.com
Pulse ID: 6a7e2fb107f9a7cc1cd4e95b
Pulse Link: https://otx.alienvault.com/pulse/6a7e2fb107f9a7cc1cd4e95b
Pulse Author: CyberHunter_NL
Created: 2026-08-13 20:57:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL
-
Curiouser and Curiouser
Indicators extracted from public reporting. Source: https://talosintelligence.com
Pulse ID: 6a7e2fb107f9a7cc1cd4e95b
Pulse Link: https://otx.alienvault.com/pulse/6a7e2fb107f9a7cc1cd4e95b
Pulse Author: CyberHunter_NL
Created: 2026-08-13 20:57:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL
-
У nginx сжатие заголовков одностороннее
Стенд: один nginx, одно HTTP/3-соединение, четыре одинаковых запроса подряд. Меряем размер сжатого блока заголовков в обе стороны. Ответ (nginx → клиент): 131, 131, 131, 131 байт. Запрос (клиент → nginx): 246, 8, 8, 8. Ответ — константа: сколько запросов ни повтори, столько же байт. Запрос со второго раза схлопывается в тридцать раз. В HTTP/2 к тому же серверу — та же константа. Между тем динамическая таблица HPACK и QPACK и есть половина смысла обоих протоколов: повторяющийся заголовок отправляется один раз, дальше идут ссылки на номер. Клиент ей пользуется. Сервер не пользуется ни в одном из двух — в HTTP/2 выставляет её размер в ноль, в HTTP/3 не открывает encoder-поток вовсе. Разбор по фиксированным тегам: nginx 1.31.3, quic-go, Cloudflare quiche, ls-qpack, Google QUICHE. Две реализации из пяти таблицу всё-таки ведут. И приёмная половина — та, которой сервер сам не пользуется, но обязан обслуживать, — в мае принесла nginx use-after-free с оценкой 9.2.
https://habr.com/ru/articles/1070310/
#nginx #quic #qpack #hpack #сжатие_заголовков #динамическая_таблица #cve202642530 #useafterfree #исходный_код #http
-
AI 'watermark removers' flood the web. Almost none can prove they work.
Indicators extracted from public reporting. Source: https://pasqualepillitteri.it/en/news/10649/claude-watermark-remover-github-tested
Pulse ID: 6a7e052794ae78dc7d5d109a
Pulse Link: https://otx.alienvault.com/pulse/6a7e052794ae78dc7d5d109a
Pulse Author: CyberHunter_NL
Created: 2026-08-13 17:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
AI 'watermark removers' flood the web. Almost none can prove they work.
Indicators extracted from public reporting. Source: https://pasqualepillitteri.it/en/news/10649/claude-watermark-remover-github-tested
Pulse ID: 6a7e052794ae78dc7d5d109a
Pulse Link: https://otx.alienvault.com/pulse/6a7e052794ae78dc7d5d109a
Pulse Author: CyberHunter_NL
Created: 2026-08-13 17:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
Indicators extracted from public reporting. Source: https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/
Pulse ID: 6a7df72c743c82d5d51acf07
Pulse Link: https://otx.alienvault.com/pulse/6a7df72c743c82d5d51acf07
Pulse Author: CyberHunter_NL
Created: 2026-08-13 16:56:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
Indicators extracted from public reporting. Source: https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/
Pulse ID: 6a7df72c743c82d5d51acf07
Pulse Link: https://otx.alienvault.com/pulse/6a7df72c743c82d5d51acf07
Pulse Author: CyberHunter_NL
Created: 2026-08-13 16:56:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
HTTP/1 vs HTTP/2 vs HTTP/3 This article provides a detailed, clear-cut analysis of HTTP/1 vs HTTP/2 vs HTTP/3, focusing on how each version improves (or fails to improve) web performance, efficiency, and modern use cases.
What is HTTP?
HTTP stands for Hypertext Transfer Protocol. It’s the foundation of data communication on the World Wide Web. When you visit a website, your browser uses #HTTP to request content (like text, images, videos) from a ...
Continued 👉 https://blog.radwebhosting.com/http-1-vs-http-2-vs-http-3/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.social #quiccloud -
Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7dbee44352b7893591e9d3
Pulse Link: https://otx.alienvault.com/pulse/6a7dbee44352b7893591e9d3
Pulse Author: CyberHunter_NL
Created: 2026-08-13 12:56:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #Telegram #bot #CyberHunter_NL
-
Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7dbee44352b7893591e9d3
Pulse Link: https://otx.alienvault.com/pulse/6a7dbee44352b7893591e9d3
Pulse Author: CyberHunter_NL
Created: 2026-08-13 12:56:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #Telegram #bot #CyberHunter_NL
-
Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
Pulse ID: 6a7da2b72179e3a4cb0c1d31
Pulse Link: https://otx.alienvault.com/pulse/6a7da2b72179e3a4cb0c1d31
Pulse Author: CyberHunter_NL
Created: 2026-08-13 10:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
Pulse ID: 6a7da2b72179e3a4cb0c1d31
Pulse Link: https://otx.alienvault.com/pulse/6a7da2b72179e3a4cb0c1d31
Pulse Author: CyberHunter_NL
Created: 2026-08-13 10:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Indicators extracted from public reporting. Source: https://sed-cms.broadcom.com/sites/default/files/2026-08/Jewelbug%20Dossier.pdf
Pulse ID: 6a7da2dc1ab7ab31faf83152
Pulse Link: https://otx.alienvault.com/pulse/6a7da2dc1ab7ab31faf83152
Pulse Author: CyberHunter_NL
Created: 2026-08-13 10:56:27Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DoS #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #RAT #RCE #bot #CyberHunter_NL
-
Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Indicators extracted from public reporting. Source: https://sed-cms.broadcom.com/sites/default/files/2026-08/Jewelbug%20Dossier.pdf
Pulse ID: 6a7da2dc1ab7ab31faf83152
Pulse Link: https://otx.alienvault.com/pulse/6a7da2dc1ab7ab31faf83152
Pulse Author: CyberHunter_NL
Created: 2026-08-13 10:56:27Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DoS #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #RAT #RCE #bot #CyberHunter_NL
-
🦖 Content Security Policy errors and warnings 🦖
https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CSP/Errors
When you see any of the following messages logged in the browser devtools console, it indicates that a problem related to CSP has occurred.
-
🦖 Content Security Policy errors and warnings 🦖
https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CSP/Errors
When you see any of the following messages logged in the browser devtools console, it indicates that a problem related to CSP has occurred.
-
Project CAV3RN uses Google Apps Script for stealthy C2 in Israel
A modular espionage framework targeting entities in Israel has evolved to incorporate sophisticated command-and-control capabilities. The framework employs DNS A-record responses to dynamically select between direct HTTPS connections and a Google Apps Script relay for each transaction, enabling operators to rotate communication channels and deployment identifiers. The communication module uses DNS infrastructure to validate and update Google Apps Script deployment IDs, while XOR encoding obfuscates command-and-control traffic. An inter-component broker coordinates framework DLL components, enabling runtime upgrades without system restarts. The infrastructure leveraged a previously expired Israeli domain, now repurposed with custom authoritative DNS servers, alongside legitimate Google services to blend malicious traffic with normal network activity.
Pulse ID: 6a7d8cc2109e73821519b31d
Pulse Link: https://otx.alienvault.com/pulse/6a7d8cc2109e73821519b31d
Pulse Author: AlienVault
Created: 2026-08-13 09:22:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #Israel #OTX #OpenThreatExchange #RAT #bot #AlienVault
-
Project CAV3RN uses Google Apps Script for stealthy C2 in Israel
A modular espionage framework targeting entities in Israel has evolved to incorporate sophisticated command-and-control capabilities. The framework employs DNS A-record responses to dynamically select between direct HTTPS connections and a Google Apps Script relay for each transaction, enabling operators to rotate communication channels and deployment identifiers. The communication module uses DNS infrastructure to validate and update Google Apps Script deployment IDs, while XOR encoding obfuscates command-and-control traffic. An inter-component broker coordinates framework DLL components, enabling runtime upgrades without system restarts. The infrastructure leveraged a previously expired Israeli domain, now repurposed with custom authoritative DNS servers, alongside legitimate Google services to blend malicious traffic with normal network activity.
Pulse ID: 6a7d8cc2109e73821519b31d
Pulse Link: https://otx.alienvault.com/pulse/6a7d8cc2109e73821519b31d
Pulse Author: AlienVault
Created: 2026-08-13 09:22:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #Israel #OTX #OpenThreatExchange #RAT #bot #AlienVault
-
Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto
Indicators extracted from public reporting. Source: https://www.splunk.com/en_us/blog/security/phantom-stealer-shellcode-steganography-credential-theft.html
Pulse ID: 6a7d94b079c2c1e42df7974b
Pulse Link: https://otx.alienvault.com/pulse/6a7d94b079c2c1e42df7974b
Pulse Author: CyberHunter_NL
Created: 2026-08-13 09:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cookies #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #ShellCode #Steganography #Word #bot #CyberHunter_NL
-
Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto
Indicators extracted from public reporting. Source: https://www.splunk.com/en_us/blog/security/phantom-stealer-shellcode-steganography-credential-theft.html
Pulse ID: 6a7d94b079c2c1e42df7974b
Pulse Link: https://otx.alienvault.com/pulse/6a7d94b079c2c1e42df7974b
Pulse Author: CyberHunter_NL
Created: 2026-08-13 09:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cookies #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #ShellCode #Steganography #Word #bot #CyberHunter_NL
-
Armored Likho expands its cyber-espionage toolkit
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7d8697e0bd510e87086185
Pulse Link: https://otx.alienvault.com/pulse/6a7d8697e0bd510e87086185
Pulse Author: CyberHunter_NL
Created: 2026-08-13 08:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL
-
Armored Likho expands its cyber-espionage toolkit
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7d8697e0bd510e87086185
Pulse Link: https://otx.alienvault.com/pulse/6a7d8697e0bd510e87086185
Pulse Author: CyberHunter_NL
Created: 2026-08-13 08:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL
-
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
Indicators extracted from public reporting. Source: https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow
Pulse ID: 6a7d084bd3aa421c0a525be6
Pulse Link: https://otx.alienvault.com/pulse/6a7d084bd3aa421c0a525be6
Pulse Author: CyberHunter_NL
Created: 2026-08-12 23:56:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
Indicators extracted from public reporting. Source: https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow
Pulse ID: 6a7d084bd3aa421c0a525be6
Pulse Link: https://otx.alienvault.com/pulse/6a7d084bd3aa421c0a525be6
Pulse Author: CyberHunter_NL
Created: 2026-08-12 23:56:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7cc1f91810a474e1284a56
Pulse Link: https://otx.alienvault.com/pulse/6a7cc1f91810a474e1284a56
Pulse Author: CyberHunter_NL
Created: 2026-08-12 18:56:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL
-
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7cc1f91810a474e1284a56
Pulse Link: https://otx.alienvault.com/pulse/6a7cc1f91810a474e1284a56
Pulse Author: CyberHunter_NL
Created: 2026-08-12 18:56:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL
-
New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide
Indicators extracted from public reporting. Source: https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow
Pulse ID: 6a7cb3a3d02c4e72307b552e
Pulse Link: https://otx.alienvault.com/pulse/6a7cb3a3d02c4e72307b552e
Pulse Author: CyberHunter_NL
Created: 2026-08-12 17:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide
Indicators extracted from public reporting. Source: https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow
Pulse ID: 6a7cb3a3d02c4e72307b552e
Pulse Link: https://otx.alienvault.com/pulse/6a7cb3a3d02c4e72307b552e
Pulse Author: CyberHunter_NL
Created: 2026-08-12 17:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
deno-case-studies
Indicators extracted from public reporting. Source: https://www.sophos.com/en-us/blog/deno-case-studies
Pulse ID: 6a7c7b59412e34c4ea97e1b9
Pulse Link: https://otx.alienvault.com/pulse/6a7c7b59412e34c4ea97e1b9
Pulse Author: CyberHunter_NL
Created: 2026-08-12 13:55:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL
-
deno-case-studies
Indicators extracted from public reporting. Source: https://www.sophos.com/en-us/blog/deno-case-studies
Pulse ID: 6a7c7b59412e34c4ea97e1b9
Pulse Link: https://otx.alienvault.com/pulse/6a7c7b59412e34c4ea97e1b9
Pulse Author: CyberHunter_NL
Created: 2026-08-12 13:55:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL
-
ClickFix campaign abuses Deno runtime for infostealer delivery
Indicators extracted from public reporting. Source: https://www.sophos.com/en-us/blog/clickfix-campaign-abuses-deno-runtime-for-infostealer-delivery
Pulse ID: 6a7c7b5dcc776888b41f6fab
Pulse Link: https://otx.alienvault.com/pulse/6a7c7b5dcc776888b41f6fab
Pulse Author: CyberHunter_NL
Created: 2026-08-12 13:55:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #InfoStealer #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL
-
ClickFix campaign abuses Deno runtime for infostealer delivery
Indicators extracted from public reporting. Source: https://www.sophos.com/en-us/blog/clickfix-campaign-abuses-deno-runtime-for-infostealer-delivery
Pulse ID: 6a7c7b5dcc776888b41f6fab
Pulse Link: https://otx.alienvault.com/pulse/6a7c7b5dcc776888b41f6fab
Pulse Author: CyberHunter_NL
Created: 2026-08-12 13:55:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #InfoStealer #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL
-
737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies
Indicators extracted from public reporting. Source: https://socket.dev/blog/chrome-vpn-extension-impersonation
Pulse ID: 6a7c7b770ce5c908efa958f2
Pulse Link: https://otx.alienvault.com/pulse/6a7c7b770ce5c908efa958f2
Pulse Author: CyberHunter_NL
Created: 2026-08-12 13:56:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Troll #VPN #bot #socks5 #CyberHunter_NL
-
737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies
Indicators extracted from public reporting. Source: https://socket.dev/blog/chrome-vpn-extension-impersonation
Pulse ID: 6a7c7b770ce5c908efa958f2
Pulse Link: https://otx.alienvault.com/pulse/6a7c7b770ce5c908efa958f2
Pulse Author: CyberHunter_NL
Created: 2026-08-12 13:56:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Troll #VPN #bot #socks5 #CyberHunter_NL
-
Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
Pulse ID: 6a7c6d5cf70eca6997f0ff3b
Pulse Link: https://otx.alienvault.com/pulse/6a7c6d5cf70eca6997f0ff3b
Pulse Author: CyberHunter_NL
Created: 2026-08-12 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL
-
Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
Pulse ID: 6a7c6d5cf70eca6997f0ff3b
Pulse Link: https://otx.alienvault.com/pulse/6a7c6d5cf70eca6997f0ff3b
Pulse Author: CyberHunter_NL
Created: 2026-08-12 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL
-
13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts
Indicators extracted from public reporting. Source: https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/
Pulse ID: 6a7c6d65bad96416b5bbfbd3
Pulse Link: https://otx.alienvault.com/pulse/6a7c6d65bad96416b5bbfbd3
Pulse Author: CyberHunter_NL
Created: 2026-08-12 12:56:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GroupIB #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SpyNote #bot #CyberHunter_NL
-
13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts
Indicators extracted from public reporting. Source: https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/
Pulse ID: 6a7c6d65bad96416b5bbfbd3
Pulse Link: https://otx.alienvault.com/pulse/6a7c6d65bad96416b5bbfbd3
Pulse Author: CyberHunter_NL
Created: 2026-08-12 12:56:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GroupIB #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SpyNote #bot #CyberHunter_NL
-
CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure
Indicators extracted from public reporting. Source: https://securelist.com/project-cav3rn-continues/120991/
Pulse ID: 6a7c513bd3c90ca3ddb62baf
Pulse Link: https://otx.alienvault.com/pulse/6a7c513bd3c90ca3ddb62baf
Pulse Author: CyberHunter_NL
Created: 2026-08-12 10:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL
-
CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure
Indicators extracted from public reporting. Source: https://securelist.com/project-cav3rn-continues/120991/
Pulse ID: 6a7c513bd3c90ca3ddb62baf
Pulse Link: https://otx.alienvault.com/pulse/6a7c513bd3c90ca3ddb62baf
Pulse Author: CyberHunter_NL
Created: 2026-08-12 10:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL
-
Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals
Indicators extracted from public reporting. Source: https://cert.gov.ua/article/6318863
Pulse ID: 6a7c433680aefab88821c968
Pulse Link: https://otx.alienvault.com/pulse/6a7c433680aefab88821c968
Pulse Author: CyberHunter_NL
Created: 2026-08-12 09:56:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL
-
Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals
Indicators extracted from public reporting. Source: https://cert.gov.ua/article/6318863
Pulse ID: 6a7c433680aefab88821c968
Pulse Link: https://otx.alienvault.com/pulse/6a7c433680aefab88821c968
Pulse Author: CyberHunter_NL
Created: 2026-08-12 09:56:06Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL
-
Google-themed Credential Phishing Attempt Delivered Through a Fake ‘New Audio MSG’ Email
Indicators extracted from public reporting. Source: https://cybersecuritynews.com/google-themed-credential-phishing/
Pulse ID: 6a7c351ee2a19c50e9902e3c
Pulse Link: https://otx.alienvault.com/pulse/6a7c351ee2a19c50e9902e3c
Pulse Author: CyberHunter_NL
Created: 2026-08-12 08:55:58Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL
-
Google-themed Credential Phishing Attempt Delivered Through a Fake ‘New Audio MSG’ Email
Indicators extracted from public reporting. Source: https://cybersecuritynews.com/google-themed-credential-phishing/
Pulse ID: 6a7c351ee2a19c50e9902e3c
Pulse Link: https://otx.alienvault.com/pulse/6a7c351ee2a19c50e9902e3c
Pulse Author: CyberHunter_NL
Created: 2026-08-12 08:55:58Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL
-
ClickFix Attack Abuses Signed IBM SPSS IDE to Deploy New CNCMachineRMS RAT
Indicators extracted from public reporting. Source: https://www.levelblue.com/blogs/spiderlabs-blog/cncmachinerms-the-undocumented-rat-at-the-end-of-a-babadeda-chain
Pulse ID: 6a7c352538d09ace0dfaf9ce
Pulse Link: https://otx.alienvault.com/pulse/6a7c352538d09ace0dfaf9ce
Pulse Author: CyberHunter_NL
Created: 2026-08-12 08:56:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Mac #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL
-
ClickFix Attack Abuses Signed IBM SPSS IDE to Deploy New CNCMachineRMS RAT
Indicators extracted from public reporting. Source: https://www.levelblue.com/blogs/spiderlabs-blog/cncmachinerms-the-undocumented-rat-at-the-end-of-a-babadeda-chain
Pulse ID: 6a7c352538d09ace0dfaf9ce
Pulse Link: https://otx.alienvault.com/pulse/6a7c352538d09ace0dfaf9ce
Pulse Author: CyberHunter_NL
Created: 2026-08-12 08:56:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Mac #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL
-
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Indicators extracted from public reporting. Source: https://exposure.cloudsek.com/ai-supply-chain-incident
Pulse ID: 6a7c3531982e86f5db5a1906
Pulse Link: https://otx.alienvault.com/pulse/6a7c3531982e86f5db5a1906
Pulse Author: CyberHunter_NL
Created: 2026-08-12 08:56:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Indicators extracted from public reporting. Source: https://exposure.cloudsek.com/ai-supply-chain-incident
Pulse ID: 6a7c3531982e86f5db5a1906
Pulse Link: https://otx.alienvault.com/pulse/6a7c3531982e86f5db5a1906
Pulse Author: CyberHunter_NL
Created: 2026-08-12 08:56:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.
Pulse ID: 6a7c183cfe509b035144c5a6
Pulse Link: https://otx.alienvault.com/pulse/6a7c183cfe509b035144c5a6
Pulse Author: AlienVault
Created: 2026-08-12 06:52:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault
-
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.
Pulse ID: 6a7c183cfe509b035144c5a6
Pulse Link: https://otx.alienvault.com/pulse/6a7c183cfe509b035144c5a6
Pulse Author: AlienVault
Created: 2026-08-12 06:52:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault
-
CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials
A sophisticated credential theft campaign manipulates DNS and HTTP traffic on captive portal networks at hotels, conference centers, and hospitality venues to redirect victims to attacker-controlled infrastructure. The operation harvests Microsoft 365 credentials through phishing pages, device code phishing abusing Microsoft Entra ID authentication flow, and malware delivery via ClickFix social engineering techniques. Evidence indicates compromised shared captive portal services rather than individual venue breaches, with affected gateways identified in several U.S. cities, India, and Saudi Arabia. The campaign deploys two primary malware tools: CornFlake, a Go-based RAT providing persistent access and extensive surveillance capabilities, and ChocoShell, an in-memory PowerShell stealer that harvests browser credentials, Microsoft 365 tokens, and Azure AD tokens. The operation targets travelers across multiple sectors and has expanded to include Android devices through malicious APK files.
Pulse ID: 6a7bdb051d6a41c7ea440061
Pulse Link: https://otx.alienvault.com/pulse/6a7bdb051d6a41c7ea440061
Pulse Author: AlienVault
Created: 2026-08-12 02:31:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APK #Android #Azure #Browser #CyberSecurity #DNS #HTTP #Hospital #India #InfoSec #Malware #Microsoft #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SaudiArabia #SocialEngineering #Troll #bot #AlienVault
-
CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials
A sophisticated credential theft campaign manipulates DNS and HTTP traffic on captive portal networks at hotels, conference centers, and hospitality venues to redirect victims to attacker-controlled infrastructure. The operation harvests Microsoft 365 credentials through phishing pages, device code phishing abusing Microsoft Entra ID authentication flow, and malware delivery via ClickFix social engineering techniques. Evidence indicates compromised shared captive portal services rather than individual venue breaches, with affected gateways identified in several U.S. cities, India, and Saudi Arabia. The campaign deploys two primary malware tools: CornFlake, a Go-based RAT providing persistent access and extensive surveillance capabilities, and ChocoShell, an in-memory PowerShell stealer that harvests browser credentials, Microsoft 365 tokens, and Azure AD tokens. The operation targets travelers across multiple sectors and has expanded to include Android devices through malicious APK files.
Pulse ID: 6a7bdb051d6a41c7ea440061
Pulse Link: https://otx.alienvault.com/pulse/6a7bdb051d6a41c7ea440061
Pulse Author: AlienVault
Created: 2026-08-12 02:31:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APK #Android #Azure #Browser #CyberSecurity #DNS #HTTP #Hospital #India #InfoSec #Malware #Microsoft #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SaudiArabia #SocialEngineering #Troll #bot #AlienVault
-
Почему HTTPS-прокси не видит трафик приложения
Если вы когда-нибудь пытались просмотреть сетевые запросы десктопного или мобильного приложения через HTTPS-прокси, то наверняка сталкивались со странной ситуацией: прокси настроен, корневой сертификат установлен и доверен, системный прокси прописан, а в списке запросов пусто. Или приложение начинает выдавать ошибку сразу после включения перехвата. Ниже будет описан набор реальных сценариев, со схемами работы на сетевом уровне и примерами того, как это выглядит в прокси-приложении. Для этого я использую Сольпугу и несколько демо-приложений с разными условиями.
https://habr.com/ru/articles/1067638/
#прокси #приложения #тестирование #трафик #проблема #http #запрос
-
Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7beecb020ccbfd7b706fad
Pulse Link: https://otx.alienvault.com/pulse/6a7beecb020ccbfd7b706fad
Pulse Author: CyberHunter_NL
Created: 2026-08-12 03:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL
-
Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7beecb020ccbfd7b706fad
Pulse Link: https://otx.alienvault.com/pulse/6a7beecb020ccbfd7b706fad
Pulse Author: CyberHunter_NL
Created: 2026-08-12 03:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL
-
Sandworm hackers target IT pros with trojanized WireGuard VPN client
Indicators extracted from public reporting. Source: https://cert.gov.ua/article/6318863
Pulse ID: 6a7b9a56ed0787edeab00dfb
Pulse Link: https://otx.alienvault.com/pulse/6a7b9a56ed0787edeab00dfb
Pulse Author: CyberHunter_NL
Created: 2026-08-11 21:55:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL
-
Sandworm hackers target IT pros with trojanized WireGuard VPN client
Indicators extracted from public reporting. Source: https://cert.gov.ua/article/6318863
Pulse ID: 6a7b9a56ed0787edeab00dfb
Pulse Link: https://otx.alienvault.com/pulse/6a7b9a56ed0787edeab00dfb
Pulse Author: CyberHunter_NL
Created: 2026-08-11 21:55:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL
-
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
Pulse ID: 6a7b8c7ac9f862e53382eab9
Pulse Link: https://otx.alienvault.com/pulse/6a7b8c7ac9f862e53382eab9
Pulse Author: CyberHunter_NL
Created: 2026-08-11 20:56:26Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
Pulse ID: 6a7b8c7ac9f862e53382eab9
Pulse Link: https://otx.alienvault.com/pulse/6a7b8c7ac9f862e53382eab9
Pulse Author: CyberHunter_NL
Created: 2026-08-11 20:56:26Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Fake CCleaner installs GhostDesk Chrome spyware
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
Pulse ID: 6a7b8c83bf51f40e5a39c8e5
Pulse Link: https://otx.alienvault.com/pulse/6a7b8c83bf51f40e5a39c8e5
Pulse Author: CyberHunter_NL
Created: 2026-08-11 20:56:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #bot #CyberHunter_NL