home.social

#http — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #http, aggregated by home.social.

fetched live
  1. Curiouser and Curiouser

    Indicators extracted from public reporting. Source: talosintelligence.com

    Pulse ID: 6a7e2fb107f9a7cc1cd4e95b
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 20:57:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL

  2. Curiouser and Curiouser

    Indicators extracted from public reporting. Source: talosintelligence.com

    Pulse ID: 6a7e2fb107f9a7cc1cd4e95b
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 20:57:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL

  3. У nginx сжатие заголовков одностороннее

    Стенд: один nginx, одно HTTP/3-соединение, четыре одинаковых запроса подряд. Меряем размер сжатого блока заголовков в обе стороны. Ответ (nginx → клиент): 131, 131, 131, 131 байт. Запрос (клиент → nginx): 246, 8, 8, 8. Ответ — константа: сколько запросов ни повтори, столько же байт. Запрос со второго раза схлопывается в тридцать раз. В HTTP/2 к тому же серверу — та же константа. Между тем динамическая таблица HPACK и QPACK и есть половина смысла обоих протоколов: повторяющийся заголовок отправляется один раз, дальше идут ссылки на номер. Клиент ей пользуется. Сервер не пользуется ни в одном из двух — в HTTP/2 выставляет её размер в ноль, в HTTP/3 не открывает encoder-поток вовсе. Разбор по фиксированным тегам: nginx 1.31.3, quic-go, Cloudflare quiche, ls-qpack, Google QUICHE. Две реализации из пяти таблицу всё-таки ведут. И приёмная половина — та, которой сервер сам не пользуется, но обязан обслуживать, — в мае принесла nginx use-after-free с оценкой 9.2.

    habr.com/ru/articles/1070310/

    #nginx #quic #qpack #hpack #сжатие_заголовков #динамическая_таблица #cve202642530 #useafterfree #исходный_код #http

  4. AI 'watermark removers' flood the web. Almost none can prove they work.

    Indicators extracted from public reporting. Source: pasqualepillitteri.it/en/news/

    Pulse ID: 6a7e052794ae78dc7d5d109a
    Pulse Link: otx.alienvault.com/pulse/6a7e0
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 17:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  5. AI 'watermark removers' flood the web. Almost none can prove they work.

    Indicators extracted from public reporting. Source: pasqualepillitteri.it/en/news/

    Pulse ID: 6a7e052794ae78dc7d5d109a
    Pulse Link: otx.alienvault.com/pulse/6a7e0
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 17:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  6. AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure

    Indicators extracted from public reporting. Source: jamf.com/blog/amnesia-stealer-

    Pulse ID: 6a7df72c743c82d5d51acf07
    Pulse Link: otx.alienvault.com/pulse/6a7df
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 16:56:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  7. AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure

    Indicators extracted from public reporting. Source: jamf.com/blog/amnesia-stealer-

    Pulse ID: 6a7df72c743c82d5d51acf07
    Pulse Link: otx.alienvault.com/pulse/6a7df
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 16:56:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  8. HTTP/1 vs HTTP/2 vs HTTP/3 This article provides a detailed, clear-cut analysis of HTTP/1 vs HTTP/2 vs HTTP/3, focusing on how each version improves (or fails to improve) web performance, efficiency, and modern use cases.
    What is HTTP?
    HTTP stands for Hypertext Transfer Protocol. It’s the foundation of data communication on the World Wide Web. When you visit a website, your browser uses #HTTP to request content (like text, images, videos) from a ...
    Continued 👉 blog.radwebhosting.com/http-1- #quiccloud

  9. Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations

    Indicators extracted from public reporting. Source: securelist.com/armored-likho-s

    Pulse ID: 6a7dbee44352b7893591e9d3
    Pulse Link: otx.alienvault.com/pulse/6a7db
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 12:56:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #Telegram #bot #CyberHunter_NL

  10. Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations

    Indicators extracted from public reporting. Source: securelist.com/armored-likho-s

    Pulse ID: 6a7dbee44352b7893591e9d3
    Pulse Link: otx.alienvault.com/pulse/6a7db
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 12:56:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #Telegram #bot #CyberHunter_NL

  11. Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ki

    Pulse ID: 6a7da2b72179e3a4cb0c1d31
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 10:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  12. Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ki

    Pulse ID: 6a7da2b72179e3a4cb0c1d31
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 10:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  13. Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Indicators extracted from public reporting. Source: sed-cms.broadcom.com/sites/def

    Pulse ID: 6a7da2dc1ab7ab31faf83152
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 10:56:27

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DoS #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #RAT #RCE #bot #CyberHunter_NL

  14. Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Indicators extracted from public reporting. Source: sed-cms.broadcom.com/sites/def

    Pulse ID: 6a7da2dc1ab7ab31faf83152
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 10:56:27

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DoS #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #RAT #RCE #bot #CyberHunter_NL

  15. 🦖 Content Security Policy errors and warnings 🦖

    developer.mozilla.org/en-US/do

    When you see any of the following messages logged in the browser devtools console, it indicates that a problem related to CSP has occurred.

    #webdev #HTTP

  16. 🦖 Content Security Policy errors and warnings 🦖

    developer.mozilla.org/en-US/do

    When you see any of the following messages logged in the browser devtools console, it indicates that a problem related to CSP has occurred.

    #webdev #HTTP

  17. Project CAV3RN uses Google Apps Script for stealthy C2 in Israel

    A modular espionage framework targeting entities in Israel has evolved to incorporate sophisticated command-and-control capabilities. The framework employs DNS A-record responses to dynamically select between direct HTTPS connections and a Google Apps Script relay for each transaction, enabling operators to rotate communication channels and deployment identifiers. The communication module uses DNS infrastructure to validate and update Google Apps Script deployment IDs, while XOR encoding obfuscates command-and-control traffic. An inter-component broker coordinates framework DLL components, enabling runtime upgrades without system restarts. The infrastructure leveraged a previously expired Israeli domain, now repurposed with custom authoritative DNS servers, alongside legitimate Google services to blend malicious traffic with normal network activity.

    Pulse ID: 6a7d8cc2109e73821519b31d
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:22:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #Israel #OTX #OpenThreatExchange #RAT #bot #AlienVault

  18. Project CAV3RN uses Google Apps Script for stealthy C2 in Israel

    A modular espionage framework targeting entities in Israel has evolved to incorporate sophisticated command-and-control capabilities. The framework employs DNS A-record responses to dynamically select between direct HTTPS connections and a Google Apps Script relay for each transaction, enabling operators to rotate communication channels and deployment identifiers. The communication module uses DNS infrastructure to validate and update Google Apps Script deployment IDs, while XOR encoding obfuscates command-and-control traffic. An inter-component broker coordinates framework DLL components, enabling runtime upgrades without system restarts. The infrastructure leveraged a previously expired Israeli domain, now repurposed with custom authoritative DNS servers, alongside legitimate Google services to blend malicious traffic with normal network activity.

    Pulse ID: 6a7d8cc2109e73821519b31d
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:22:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #Israel #OTX #OpenThreatExchange #RAT #bot #AlienVault

  19. Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto

    Indicators extracted from public reporting. Source: splunk.com/en_us/blog/security

    Pulse ID: 6a7d94b079c2c1e42df7974b
    Pulse Link: otx.alienvault.com/pulse/6a7d9
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 09:56:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cookies #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #ShellCode #Steganography #Word #bot #CyberHunter_NL

  20. Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto

    Indicators extracted from public reporting. Source: splunk.com/en_us/blog/security

    Pulse ID: 6a7d94b079c2c1e42df7974b
    Pulse Link: otx.alienvault.com/pulse/6a7d9
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 09:56:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cookies #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #ShellCode #Steganography #Word #bot #CyberHunter_NL

  21. Armored Likho expands its cyber-espionage toolkit

    Indicators extracted from public reporting. Source: securelist.com/armored-likho-s

    Pulse ID: 6a7d8697e0bd510e87086185
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 08:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL

  22. Armored Likho expands its cyber-espionage toolkit

    Indicators extracted from public reporting. Source: securelist.com/armored-likho-s

    Pulse ID: 6a7d8697e0bd510e87086185
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 08:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL

  23. "City-Forum" data-theft attacks target Salesforce, ServiceNow portals

    Indicators extracted from public reporting. Source: reco.ai/blog/city-forum-campai

    Pulse ID: 6a7d084bd3aa421c0a525be6
    Pulse Link: otx.alienvault.com/pulse/6a7d0
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 23:56:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  24. "City-Forum" data-theft attacks target Salesforce, ServiceNow portals

    Indicators extracted from public reporting. Source: reco.ai/blog/city-forum-campai

    Pulse ID: 6a7d084bd3aa421c0a525be6
    Pulse Link: otx.alienvault.com/pulse/6a7d0
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 23:56:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  25. Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7cc1f91810a474e1284a56
    Pulse Link: otx.alienvault.com/pulse/6a7cc
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 18:56:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL

  26. Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7cc1f91810a474e1284a56
    Pulse Link: otx.alienvault.com/pulse/6a7cc
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 18:56:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL

  27. New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide

    Indicators extracted from public reporting. Source: reco.ai/blog/city-forum-campai

    Pulse ID: 6a7cb3a3d02c4e72307b552e
    Pulse Link: otx.alienvault.com/pulse/6a7cb
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 17:55:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  28. New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide

    Indicators extracted from public reporting. Source: reco.ai/blog/city-forum-campai

    Pulse ID: 6a7cb3a3d02c4e72307b552e
    Pulse Link: otx.alienvault.com/pulse/6a7cb
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 17:55:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  29. deno-case-studies

    Indicators extracted from public reporting. Source: sophos.com/en-us/blog/deno-cas

    Pulse ID: 6a7c7b59412e34c4ea97e1b9
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 13:55:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL

  30. deno-case-studies

    Indicators extracted from public reporting. Source: sophos.com/en-us/blog/deno-cas

    Pulse ID: 6a7c7b59412e34c4ea97e1b9
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 13:55:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL

  31. ClickFix campaign abuses Deno runtime for infostealer delivery

    Indicators extracted from public reporting. Source: sophos.com/en-us/blog/clickfix

    Pulse ID: 6a7c7b5dcc776888b41f6fab
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 13:55:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #InfoStealer #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL

  32. ClickFix campaign abuses Deno runtime for infostealer delivery

    Indicators extracted from public reporting. Source: sophos.com/en-us/blog/clickfix

    Pulse ID: 6a7c7b5dcc776888b41f6fab
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 13:55:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #InfoStealer #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL

  33. 737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies

    Indicators extracted from public reporting. Source: socket.dev/blog/chrome-vpn-ext

    Pulse ID: 6a7c7b770ce5c908efa958f2
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 13:56:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Troll #VPN #bot #socks5 #CyberHunter_NL

  34. 737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies

    Indicators extracted from public reporting. Source: socket.dev/blog/chrome-vpn-ext

    Pulse ID: 6a7c7b770ce5c908efa958f2
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 13:56:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Troll #VPN #bot #socks5 #CyberHunter_NL

  35. Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7c6d5cf70eca6997f0ff3b
    Pulse Link: otx.alienvault.com/pulse/6a7c6
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL

  36. Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7c6d5cf70eca6997f0ff3b
    Pulse Link: otx.alienvault.com/pulse/6a7c6
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL

  37. 13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts

    Indicators extracted from public reporting. Source: group-ib.com/blog/windrelay-nf

    Pulse ID: 6a7c6d65bad96416b5bbfbd3
    Pulse Link: otx.alienvault.com/pulse/6a7c6
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 12:56:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GroupIB #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SpyNote #bot #CyberHunter_NL

  38. 13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts

    Indicators extracted from public reporting. Source: group-ib.com/blog/windrelay-nf

    Pulse ID: 6a7c6d65bad96416b5bbfbd3
    Pulse Link: otx.alienvault.com/pulse/6a7c6
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 12:56:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GroupIB #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SpyNote #bot #CyberHunter_NL

  39. CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure

    Indicators extracted from public reporting. Source: securelist.com/project-cav3rn-

    Pulse ID: 6a7c513bd3c90ca3ddb62baf
    Pulse Link: otx.alienvault.com/pulse/6a7c5
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 10:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Google #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL

  40. CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure

    Indicators extracted from public reporting. Source: securelist.com/project-cav3rn-

    Pulse ID: 6a7c513bd3c90ca3ddb62baf
    Pulse Link: otx.alienvault.com/pulse/6a7c5
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 10:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Google #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL

  41. Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals

    Indicators extracted from public reporting. Source: cert.gov.ua/article/6318863

    Pulse ID: 6a7c433680aefab88821c968
    Pulse Link: otx.alienvault.com/pulse/6a7c4
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 09:56:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL

  42. Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals

    Indicators extracted from public reporting. Source: cert.gov.ua/article/6318863

    Pulse ID: 6a7c433680aefab88821c968
    Pulse Link: otx.alienvault.com/pulse/6a7c4
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 09:56:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL

  43. Google-themed Credential Phishing Attempt Delivered Through a Fake ‘New Audio MSG’ Email

    Indicators extracted from public reporting. Source: cybersecuritynews.com/google-t

    Pulse ID: 6a7c351ee2a19c50e9902e3c
    Pulse Link: otx.alienvault.com/pulse/6a7c3
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 08:55:58

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL

  44. Google-themed Credential Phishing Attempt Delivered Through a Fake ‘New Audio MSG’ Email

    Indicators extracted from public reporting. Source: cybersecuritynews.com/google-t

    Pulse ID: 6a7c351ee2a19c50e9902e3c
    Pulse Link: otx.alienvault.com/pulse/6a7c3
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 08:55:58

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL

  45. ClickFix Attack Abuses Signed IBM SPSS IDE to Deploy New CNCMachineRMS RAT

    Indicators extracted from public reporting. Source: levelblue.com/blogs/spiderlabs

    Pulse ID: 6a7c352538d09ace0dfaf9ce
    Pulse Link: otx.alienvault.com/pulse/6a7c3
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 08:56:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Mac #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL

  46. ClickFix Attack Abuses Signed IBM SPSS IDE to Deploy New CNCMachineRMS RAT

    Indicators extracted from public reporting. Source: levelblue.com/blogs/spiderlabs

    Pulse ID: 6a7c352538d09ace0dfaf9ce
    Pulse Link: otx.alienvault.com/pulse/6a7c3
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 08:56:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Mac #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL

  47. Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

    Indicators extracted from public reporting. Source: exposure.cloudsek.com/ai-suppl

    Pulse ID: 6a7c3531982e86f5db5a1906
    Pulse Link: otx.alienvault.com/pulse/6a7c3
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 08:56:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  48. Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

    Indicators extracted from public reporting. Source: exposure.cloudsek.com/ai-suppl

    Pulse ID: 6a7c3531982e86f5db5a1906
    Pulse Link: otx.alienvault.com/pulse/6a7c3
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 08:56:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  49. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  50. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  51. CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials

    A sophisticated credential theft campaign manipulates DNS and HTTP traffic on captive portal networks at hotels, conference centers, and hospitality venues to redirect victims to attacker-controlled infrastructure. The operation harvests Microsoft 365 credentials through phishing pages, device code phishing abusing Microsoft Entra ID authentication flow, and malware delivery via ClickFix social engineering techniques. Evidence indicates compromised shared captive portal services rather than individual venue breaches, with affected gateways identified in several U.S. cities, India, and Saudi Arabia. The campaign deploys two primary malware tools: CornFlake, a Go-based RAT providing persistent access and extensive surveillance capabilities, and ChocoShell, an in-memory PowerShell stealer that harvests browser credentials, Microsoft 365 tokens, and Azure AD tokens. The operation targets travelers across multiple sectors and has expanded to include Android devices through malicious APK files.

    Pulse ID: 6a7bdb051d6a41c7ea440061
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:31:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APK #Android #Azure #Browser #CyberSecurity #DNS #HTTP #Hospital #India #InfoSec #Malware #Microsoft #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SaudiArabia #SocialEngineering #Troll #bot #AlienVault

  52. CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials

    A sophisticated credential theft campaign manipulates DNS and HTTP traffic on captive portal networks at hotels, conference centers, and hospitality venues to redirect victims to attacker-controlled infrastructure. The operation harvests Microsoft 365 credentials through phishing pages, device code phishing abusing Microsoft Entra ID authentication flow, and malware delivery via ClickFix social engineering techniques. Evidence indicates compromised shared captive portal services rather than individual venue breaches, with affected gateways identified in several U.S. cities, India, and Saudi Arabia. The campaign deploys two primary malware tools: CornFlake, a Go-based RAT providing persistent access and extensive surveillance capabilities, and ChocoShell, an in-memory PowerShell stealer that harvests browser credentials, Microsoft 365 tokens, and Azure AD tokens. The operation targets travelers across multiple sectors and has expanded to include Android devices through malicious APK files.

    Pulse ID: 6a7bdb051d6a41c7ea440061
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:31:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APK #Android #Azure #Browser #CyberSecurity #DNS #HTTP #Hospital #India #InfoSec #Malware #Microsoft #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SaudiArabia #SocialEngineering #Troll #bot #AlienVault

  53. Почему HTTPS-прокси не видит трафик приложения

    Если вы когда-нибудь пытались просмотреть сетевые запросы десктопного или мобильного приложения через HTTPS-прокси, то наверняка сталкивались со странной ситуацией: прокси настроен, корневой сертификат установлен и доверен, системный прокси прописан, а в списке запросов пусто. Или приложение начинает выдавать ошибку сразу после включения перехвата. Ниже будет описан набор реальных сценариев, со схемами работы на сетевом уровне и примерами того, как это выглядит в прокси-приложении. Для этого я использую Сольпугу и несколько демо-приложений с разными условиями.

    habr.com/ru/articles/1067638/

    #прокси #приложения #тестирование #трафик #проблема #http #запрос

  54. Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7beecb020ccbfd7b706fad
    Pulse Link: otx.alienvault.com/pulse/6a7be
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 03:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL

  55. Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7beecb020ccbfd7b706fad
    Pulse Link: otx.alienvault.com/pulse/6a7be
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 03:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL

  56. Sandworm hackers target IT pros with trojanized WireGuard VPN client

    Indicators extracted from public reporting. Source: cert.gov.ua/article/6318863

    Pulse ID: 6a7b9a56ed0787edeab00dfb
    Pulse Link: otx.alienvault.com/pulse/6a7b9
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 21:55:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL

  57. Sandworm hackers target IT pros with trojanized WireGuard VPN client

    Indicators extracted from public reporting. Source: cert.gov.ua/article/6318863

    Pulse ID: 6a7b9a56ed0787edeab00dfb
    Pulse Link: otx.alienvault.com/pulse/6a7b9
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 21:55:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL

  58. Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ki

    Pulse ID: 6a7b8c7ac9f862e53382eab9
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 20:56:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  59. Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ki

    Pulse ID: 6a7b8c7ac9f862e53382eab9
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 20:56:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  60. Fake CCleaner installs GhostDesk Chrome spyware

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7b8c83bf51f40e5a39c8e5
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 20:56:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #bot #CyberHunter_NL