#http — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #http, aggregated by home.social.
-
Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations
Indicators extracted from public reporting. Source: https://www.fortra.com/blog/exfilsquad-data-extortion-group-ransoming-microsoft-d365-data
Pulse ID: 6a7f2d7cd148c2db4f9bb65b
Pulse Link: https://otx.alienvault.com/pulse/6a7f2d7cd148c2db4f9bb65b
Pulse Author: CyberHunter_NL
Created: 2026-08-14 15:00:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations
Indicators extracted from public reporting. Source: https://www.fortra.com/blog/exfilsquad-data-extortion-group-ransoming-microsoft-d365-data
Pulse ID: 6a7f2d7cd148c2db4f9bb65b
Pulse Link: https://otx.alienvault.com/pulse/6a7f2d7cd148c2db4f9bb65b
Pulse Author: CyberHunter_NL
Created: 2026-08-14 15:00:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #Microsoft #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/
Pulse ID: 6a7f105c416203282deae39f
Pulse Link: https://otx.alienvault.com/pulse/6a7f105c416203282deae39f
Pulse Author: CyberHunter_NL
Created: 2026-08-14 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL
-
DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/signed-sealed-injected-dcrat-mechanics-2026/
Pulse ID: 6a7f105c416203282deae39f
Pulse Link: https://otx.alienvault.com/pulse/6a7f105c416203282deae39f
Pulse Author: CyberHunter_NL
Created: 2026-08-14 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DCRat #HTML #HTTP #HTTPS #ICS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SVG #Trellix #bot #CyberHunter_NL
-
Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses to Cybercriminals
Indicators extracted from public reporting. Source: https://www.recordedfuture.com/research/malware-crypting-services-threat-actors
Pulse ID: 6a7f024a33246de9a1d05cad
Pulse Link: https://otx.alienvault.com/pulse/6a7f024a33246de9a1d05cad
Pulse Author: CyberHunter_NL
Created: 2026-08-14 11:55:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #EDR #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Windows #bot #CyberHunter_NL
-
Malware Crypter Services Sell Windows Defender, EDR and SmartScreen Bypasses to Cybercriminals
Indicators extracted from public reporting. Source: https://www.recordedfuture.com/research/malware-crypting-services-threat-actors
Pulse ID: 6a7f024a33246de9a1d05cad
Pulse Link: https://otx.alienvault.com/pulse/6a7f024a33246de9a1d05cad
Pulse Author: CyberHunter_NL
Created: 2026-08-14 11:55:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #EDR #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Windows #bot #CyberHunter_NL
-
Who’s Tracking You? Use This New Service to Find Out
Indicators extracted from public reporting. Source: https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/
Pulse ID: 6a7f024f93999a00dd2b1dff
Pulse Link: https://otx.alienvault.com/pulse/6a7f024f93999a00dd2b1dff
Pulse Author: CyberHunter_NL
Created: 2026-08-14 11:55:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Who’s Tracking You? Use This New Service to Find Out
Indicators extracted from public reporting. Source: https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/
Pulse ID: 6a7f024f93999a00dd2b1dff
Pulse Link: https://otx.alienvault.com/pulse/6a7f024f93999a00dd2b1dff
Pulse Author: CyberHunter_NL
Created: 2026-08-14 11:55:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel
Indicators extracted from public reporting. Source: https://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/
Pulse ID: 6a7ef483bde8f195b14ed712
Pulse Link: https://otx.alienvault.com/pulse/6a7ef483bde8f195b14ed712
Pulse Author: CyberHunter_NL
Created: 2026-08-14 10:57:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Telecom #bot #CyberHunter_NL
-
HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel
Indicators extracted from public reporting. Source: https://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/
Pulse ID: 6a7ef483bde8f195b14ed712
Pulse Link: https://otx.alienvault.com/pulse/6a7ef483bde8f195b14ed712
Pulse Author: CyberHunter_NL
Created: 2026-08-14 10:57:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #Telecom #bot #CyberHunter_NL
-
AI Token Jacking Lets Hackers Steal API Keys and Rack Up Nearly $1 Million in Charges
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/ai-token-jacking/
Pulse ID: 6a7ef488514604ef607054a1
Pulse Link: https://otx.alienvault.com/pulse/6a7ef488514604ef607054a1
Pulse Author: CyberHunter_NL
Created: 2026-08-14 10:57:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
AI Token Jacking Lets Hackers Steal API Keys and Rack Up Nearly $1 Million in Charges
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/ai-token-jacking/
Pulse ID: 6a7ef488514604ef607054a1
Pulse Link: https://otx.alienvault.com/pulse/6a7ef488514604ef607054a1
Pulse Author: CyberHunter_NL
Created: 2026-08-14 10:57:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Indicators extracted from public reporting. Source: https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
Pulse ID: 6a7ee620d0cfd8859d00dfd9
Pulse Link: https://otx.alienvault.com/pulse/6a7ee620d0cfd8859d00dfd9
Pulse Author: CyberHunter_NL
Created: 2026-08-14 09:55:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Rootkit #SecureList #Windows #bot #CyberHunter_NL
-
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Indicators extracted from public reporting. Source: https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
Pulse ID: 6a7ee620d0cfd8859d00dfd9
Pulse Link: https://otx.alienvault.com/pulse/6a7ee620d0cfd8859d00dfd9
Pulse Author: CyberHunter_NL
Created: 2026-08-14 09:55:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Rootkit #SecureList #Windows #bot #CyberHunter_NL
-
Hackers Using New BlackHat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/weaponized-ai-commoditization-of-cybercrime/
Pulse ID: 6a7ed8859b17643b3a21e6e1
Pulse Link: https://otx.alienvault.com/pulse/6a7ed8859b17643b3a21e6e1
Pulse Author: CyberHunter_NL
Created: 2026-08-14 08:57:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #RansomWare #Trellix #bot #CyberHunter_NL
-
Hackers Using New BlackHat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits
Indicators extracted from public reporting. Source: https://www.trellix.com/blogs/research/weaponized-ai-commoditization-of-cybercrime/
Pulse ID: 6a7ed8859b17643b3a21e6e1
Pulse Link: https://otx.alienvault.com/pulse/6a7ed8859b17643b3a21e6e1
Pulse Author: CyberHunter_NL
Created: 2026-08-14 08:57:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberCrime #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #RansomWare #Trellix #bot #CyberHunter_NL
-
Aeternum Botnet Uses Polygon Smart Contracts for Takedown-Resistant Malware C2
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/
Pulse ID: 6a7eca0c254771760ee44515
Pulse Link: https://otx.alienvault.com/pulse/6a7eca0c254771760ee44515
Pulse Author: CyberHunter_NL
Created: 2026-08-14 07:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Aeternum Botnet Uses Polygon Smart Contracts for Takedown-Resistant Malware C2
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/
Pulse ID: 6a7eca0c254771760ee44515
Pulse Link: https://otx.alienvault.com/pulse/6a7eca0c254771760ee44515
Pulse Author: CyberHunter_NL
Created: 2026-08-14 07:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Ever shipped a /search endpoint that's technically a POST but really just runs a SELECT? I've seen it in dozens of production APIs. GET can't carry a body, so the filter gets crammed into the URL or shoved into a POST that lies about what the request does.
RFC 10008 fixes it. QUERY carries a body like POST, but it's safe and idempotent like GET, so gateways can retry it and caches can store the response.
Full writeup with a Go server example:
-
To explain the obscurity, the song is Kernkraft 400 by the band Zombie Nation. It’s often sampled/played at #football matches, but most don’t recall the name of the work https://youtu.be/gbcG2TI4GBk
And, 4xx client errors refer to a series of standardized #http status codes for client-caused errors; typically applicable to any request method.
-
To explain the obscurity, the song is Kernkraft 400 by the band Zombie Nation. It’s often sampled/played at #football matches, but most don’t recall the name of the work https://youtu.be/gbcG2TI4GBk
And, 4xx client errors refer to a series of standardized #http status codes for client-caused errors; typically applicable to any request method.
-
Curiouser and Curiouser
Indicators extracted from public reporting. Source: https://talosintelligence.com
Pulse ID: 6a7e2fb107f9a7cc1cd4e95b
Pulse Link: https://otx.alienvault.com/pulse/6a7e2fb107f9a7cc1cd4e95b
Pulse Author: CyberHunter_NL
Created: 2026-08-13 20:57:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL
-
Curiouser and Curiouser
Indicators extracted from public reporting. Source: https://talosintelligence.com
Pulse ID: 6a7e2fb107f9a7cc1cd4e95b
Pulse Link: https://otx.alienvault.com/pulse/6a7e2fb107f9a7cc1cd4e95b
Pulse Author: CyberHunter_NL
Created: 2026-08-13 20:57:21Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL
-
У nginx сжатие заголовков одностороннее
Стенд: один nginx, одно HTTP/3-соединение, четыре одинаковых запроса подряд. Меряем размер сжатого блока заголовков в обе стороны. Ответ (nginx → клиент): 131, 131, 131, 131 байт. Запрос (клиент → nginx): 246, 8, 8, 8. Ответ — константа: сколько запросов ни повтори, столько же байт. Запрос со второго раза схлопывается в тридцать раз. В HTTP/2 к тому же серверу — та же константа. Между тем динамическая таблица HPACK и QPACK и есть половина смысла обоих протоколов: повторяющийся заголовок отправляется один раз, дальше идут ссылки на номер. Клиент ей пользуется. Сервер не пользуется ни в одном из двух — в HTTP/2 выставляет её размер в ноль, в HTTP/3 не открывает encoder-поток вовсе. Разбор по фиксированным тегам: nginx 1.31.3, quic-go, Cloudflare quiche, ls-qpack, Google QUICHE. Две реализации из пяти таблицу всё-таки ведут. И приёмная половина — та, которой сервер сам не пользуется, но обязан обслуживать, — в мае принесла nginx use-after-free с оценкой 9.2.
https://habr.com/ru/articles/1070310/
#nginx #quic #qpack #hpack #сжатие_заголовков #динамическая_таблица #cve202642530 #useafterfree #исходный_код #http
-
AI 'watermark removers' flood the web. Almost none can prove they work.
Indicators extracted from public reporting. Source: https://pasqualepillitteri.it/en/news/10649/claude-watermark-remover-github-tested
Pulse ID: 6a7e052794ae78dc7d5d109a
Pulse Link: https://otx.alienvault.com/pulse/6a7e052794ae78dc7d5d109a
Pulse Author: CyberHunter_NL
Created: 2026-08-13 17:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
AI 'watermark removers' flood the web. Almost none can prove they work.
Indicators extracted from public reporting. Source: https://pasqualepillitteri.it/en/news/10649/claude-watermark-remover-github-tested
Pulse ID: 6a7e052794ae78dc7d5d109a
Pulse Link: https://otx.alienvault.com/pulse/6a7e052794ae78dc7d5d109a
Pulse Author: CyberHunter_NL
Created: 2026-08-13 17:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
Indicators extracted from public reporting. Source: https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/
Pulse ID: 6a7df72c743c82d5d51acf07
Pulse Link: https://otx.alienvault.com/pulse/6a7df72c743c82d5d51acf07
Pulse Author: CyberHunter_NL
Created: 2026-08-13 16:56:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure
Indicators extracted from public reporting. Source: https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/
Pulse ID: 6a7df72c743c82d5d51acf07
Pulse Link: https://otx.alienvault.com/pulse/6a7df72c743c82d5d51acf07
Pulse Author: CyberHunter_NL
Created: 2026-08-13 16:56:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
HTTP/1 vs HTTP/2 vs HTTP/3 This article provides a detailed, clear-cut analysis of HTTP/1 vs HTTP/2 vs HTTP/3, focusing on how each version improves (or fails to improve) web performance, efficiency, and modern use cases.
What is HTTP?
HTTP stands for Hypertext Transfer Protocol. It’s the foundation of data communication on the World Wide Web. When you visit a website, your browser uses #HTTP to request content (like text, images, videos) from a ...
Continued 👉 https://blog.radwebhosting.com/http-1-vs-http-2-vs-http-3/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.social #quiccloud -
Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7dbee44352b7893591e9d3
Pulse Link: https://otx.alienvault.com/pulse/6a7dbee44352b7893591e9d3
Pulse Author: CyberHunter_NL
Created: 2026-08-13 12:56:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #Telegram #bot #CyberHunter_NL
-
Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7dbee44352b7893591e9d3
Pulse Link: https://otx.alienvault.com/pulse/6a7dbee44352b7893591e9d3
Pulse Author: CyberHunter_NL
Created: 2026-08-13 12:56:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #Telegram #bot #CyberHunter_NL
-
Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
Pulse ID: 6a7da2b72179e3a4cb0c1d31
Pulse Link: https://otx.alienvault.com/pulse/6a7da2b72179e3a4cb0c1d31
Pulse Author: CyberHunter_NL
Created: 2026-08-13 10:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
Pulse ID: 6a7da2b72179e3a4cb0c1d31
Pulse Link: https://otx.alienvault.com/pulse/6a7da2b72179e3a4cb0c1d31
Pulse Author: CyberHunter_NL
Created: 2026-08-13 10:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Indicators extracted from public reporting. Source: https://sed-cms.broadcom.com/sites/default/files/2026-08/Jewelbug%20Dossier.pdf
Pulse ID: 6a7da2dc1ab7ab31faf83152
Pulse Link: https://otx.alienvault.com/pulse/6a7da2dc1ab7ab31faf83152
Pulse Author: CyberHunter_NL
Created: 2026-08-13 10:56:27Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DoS #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #RAT #RCE #bot #CyberHunter_NL
-
Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Indicators extracted from public reporting. Source: https://sed-cms.broadcom.com/sites/default/files/2026-08/Jewelbug%20Dossier.pdf
Pulse ID: 6a7da2dc1ab7ab31faf83152
Pulse Link: https://otx.alienvault.com/pulse/6a7da2dc1ab7ab31faf83152
Pulse Author: CyberHunter_NL
Created: 2026-08-13 10:56:27Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DoS #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #RAT #RCE #bot #CyberHunter_NL
-
🦖 Content Security Policy errors and warnings 🦖
https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CSP/Errors
When you see any of the following messages logged in the browser devtools console, it indicates that a problem related to CSP has occurred.
-
🦖 Content Security Policy errors and warnings 🦖
https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CSP/Errors
When you see any of the following messages logged in the browser devtools console, it indicates that a problem related to CSP has occurred.
-
Project CAV3RN uses Google Apps Script for stealthy C2 in Israel
A modular espionage framework targeting entities in Israel has evolved to incorporate sophisticated command-and-control capabilities. The framework employs DNS A-record responses to dynamically select between direct HTTPS connections and a Google Apps Script relay for each transaction, enabling operators to rotate communication channels and deployment identifiers. The communication module uses DNS infrastructure to validate and update Google Apps Script deployment IDs, while XOR encoding obfuscates command-and-control traffic. An inter-component broker coordinates framework DLL components, enabling runtime upgrades without system restarts. The infrastructure leveraged a previously expired Israeli domain, now repurposed with custom authoritative DNS servers, alongside legitimate Google services to blend malicious traffic with normal network activity.
Pulse ID: 6a7d8cc2109e73821519b31d
Pulse Link: https://otx.alienvault.com/pulse/6a7d8cc2109e73821519b31d
Pulse Author: AlienVault
Created: 2026-08-13 09:22:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #Israel #OTX #OpenThreatExchange #RAT #bot #AlienVault
-
Project CAV3RN uses Google Apps Script for stealthy C2 in Israel
A modular espionage framework targeting entities in Israel has evolved to incorporate sophisticated command-and-control capabilities. The framework employs DNS A-record responses to dynamically select between direct HTTPS connections and a Google Apps Script relay for each transaction, enabling operators to rotate communication channels and deployment identifiers. The communication module uses DNS infrastructure to validate and update Google Apps Script deployment IDs, while XOR encoding obfuscates command-and-control traffic. An inter-component broker coordinates framework DLL components, enabling runtime upgrades without system restarts. The infrastructure leveraged a previously expired Israeli domain, now repurposed with custom authoritative DNS servers, alongside legitimate Google services to blend malicious traffic with normal network activity.
Pulse ID: 6a7d8cc2109e73821519b31d
Pulse Link: https://otx.alienvault.com/pulse/6a7d8cc2109e73821519b31d
Pulse Author: AlienVault
Created: 2026-08-13 09:22:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #Israel #OTX #OpenThreatExchange #RAT #bot #AlienVault
-
Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto
Indicators extracted from public reporting. Source: https://www.splunk.com/en_us/blog/security/phantom-stealer-shellcode-steganography-credential-theft.html
Pulse ID: 6a7d94b079c2c1e42df7974b
Pulse Link: https://otx.alienvault.com/pulse/6a7d94b079c2c1e42df7974b
Pulse Author: CyberHunter_NL
Created: 2026-08-13 09:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cookies #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #ShellCode #Steganography #Word #bot #CyberHunter_NL
-
Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto
Indicators extracted from public reporting. Source: https://www.splunk.com/en_us/blog/security/phantom-stealer-shellcode-steganography-credential-theft.html
Pulse ID: 6a7d94b079c2c1e42df7974b
Pulse Link: https://otx.alienvault.com/pulse/6a7d94b079c2c1e42df7974b
Pulse Author: CyberHunter_NL
Created: 2026-08-13 09:56:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cookies #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #ShellCode #Steganography #Word #bot #CyberHunter_NL
-
Armored Likho expands its cyber-espionage toolkit
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7d8697e0bd510e87086185
Pulse Link: https://otx.alienvault.com/pulse/6a7d8697e0bd510e87086185
Pulse Author: CyberHunter_NL
Created: 2026-08-13 08:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL
-
Armored Likho expands its cyber-espionage toolkit
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7d8697e0bd510e87086185
Pulse Link: https://otx.alienvault.com/pulse/6a7d8697e0bd510e87086185
Pulse Author: CyberHunter_NL
Created: 2026-08-13 08:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL
-
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
Indicators extracted from public reporting. Source: https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow
Pulse ID: 6a7d084bd3aa421c0a525be6
Pulse Link: https://otx.alienvault.com/pulse/6a7d084bd3aa421c0a525be6
Pulse Author: CyberHunter_NL
Created: 2026-08-12 23:56:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
Indicators extracted from public reporting. Source: https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow
Pulse ID: 6a7d084bd3aa421c0a525be6
Pulse Link: https://otx.alienvault.com/pulse/6a7d084bd3aa421c0a525be6
Pulse Author: CyberHunter_NL
Created: 2026-08-12 23:56:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7cc1f91810a474e1284a56
Pulse Link: https://otx.alienvault.com/pulse/6a7cc1f91810a474e1284a56
Pulse Author: CyberHunter_NL
Created: 2026-08-12 18:56:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL
-
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7cc1f91810a474e1284a56
Pulse Link: https://otx.alienvault.com/pulse/6a7cc1f91810a474e1284a56
Pulse Author: CyberHunter_NL
Created: 2026-08-12 18:56:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL
-
New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide
Indicators extracted from public reporting. Source: https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow
Pulse ID: 6a7cb3a3d02c4e72307b552e
Pulse Link: https://otx.alienvault.com/pulse/6a7cb3a3d02c4e72307b552e
Pulse Author: CyberHunter_NL
Created: 2026-08-12 17:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide
Indicators extracted from public reporting. Source: https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow
Pulse ID: 6a7cb3a3d02c4e72307b552e
Pulse Link: https://otx.alienvault.com/pulse/6a7cb3a3d02c4e72307b552e
Pulse Author: CyberHunter_NL
Created: 2026-08-12 17:55:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
deno-case-studies
Indicators extracted from public reporting. Source: https://www.sophos.com/en-us/blog/deno-case-studies
Pulse ID: 6a7c7b59412e34c4ea97e1b9
Pulse Link: https://otx.alienvault.com/pulse/6a7c7b59412e34c4ea97e1b9
Pulse Author: CyberHunter_NL
Created: 2026-08-12 13:55:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL
-
deno-case-studies
Indicators extracted from public reporting. Source: https://www.sophos.com/en-us/blog/deno-case-studies
Pulse ID: 6a7c7b59412e34c4ea97e1b9
Pulse Link: https://otx.alienvault.com/pulse/6a7c7b59412e34c4ea97e1b9
Pulse Author: CyberHunter_NL
Created: 2026-08-12 13:55:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL
-
ClickFix campaign abuses Deno runtime for infostealer delivery
Indicators extracted from public reporting. Source: https://www.sophos.com/en-us/blog/clickfix-campaign-abuses-deno-runtime-for-infostealer-delivery
Pulse ID: 6a7c7b5dcc776888b41f6fab
Pulse Link: https://otx.alienvault.com/pulse/6a7c7b5dcc776888b41f6fab
Pulse Author: CyberHunter_NL
Created: 2026-08-12 13:55:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #InfoStealer #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL
-
ClickFix campaign abuses Deno runtime for infostealer delivery
Indicators extracted from public reporting. Source: https://www.sophos.com/en-us/blog/clickfix-campaign-abuses-deno-runtime-for-infostealer-delivery
Pulse ID: 6a7c7b5dcc776888b41f6fab
Pulse Link: https://otx.alienvault.com/pulse/6a7c7b5dcc776888b41f6fab
Pulse Author: CyberHunter_NL
Created: 2026-08-12 13:55:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #InfoStealer #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL
-
737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies
Indicators extracted from public reporting. Source: https://socket.dev/blog/chrome-vpn-extension-impersonation
Pulse ID: 6a7c7b770ce5c908efa958f2
Pulse Link: https://otx.alienvault.com/pulse/6a7c7b770ce5c908efa958f2
Pulse Author: CyberHunter_NL
Created: 2026-08-12 13:56:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Troll #VPN #bot #socks5 #CyberHunter_NL
-
737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies
Indicators extracted from public reporting. Source: https://socket.dev/blog/chrome-vpn-extension-impersonation
Pulse ID: 6a7c7b770ce5c908efa958f2
Pulse Link: https://otx.alienvault.com/pulse/6a7c7b770ce5c908efa958f2
Pulse Author: CyberHunter_NL
Created: 2026-08-12 13:56:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Troll #VPN #bot #socks5 #CyberHunter_NL
-
Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
Pulse ID: 6a7c6d5cf70eca6997f0ff3b
Pulse Link: https://otx.alienvault.com/pulse/6a7c6d5cf70eca6997f0ff3b
Pulse Author: CyberHunter_NL
Created: 2026-08-12 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL
-
Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs
Indicators extracted from public reporting. Source: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-ccleaner-installs-ghostdesk-chrome-spyware
Pulse ID: 6a7c6d5cf70eca6997f0ff3b
Pulse Link: https://otx.alienvault.com/pulse/6a7c6d5cf70eca6997f0ff3b
Pulse Author: CyberHunter_NL
Created: 2026-08-12 12:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL
-
13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts
Indicators extracted from public reporting. Source: https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/
Pulse ID: 6a7c6d65bad96416b5bbfbd3
Pulse Link: https://otx.alienvault.com/pulse/6a7c6d65bad96416b5bbfbd3
Pulse Author: CyberHunter_NL
Created: 2026-08-12 12:56:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GroupIB #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SpyNote #bot #CyberHunter_NL
-
13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts
Indicators extracted from public reporting. Source: https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/
Pulse ID: 6a7c6d65bad96416b5bbfbd3
Pulse Link: https://otx.alienvault.com/pulse/6a7c6d65bad96416b5bbfbd3
Pulse Author: CyberHunter_NL
Created: 2026-08-12 12:56:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GroupIB #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SpyNote #bot #CyberHunter_NL