home.social

#https — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #https, aggregated by home.social.

fetched live
  1. Aeternum Botnet Uses Polygon Smart Contracts for Takedown-Resistant Malware C2

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ae

    Pulse ID: 6a7eca0c254771760ee44515
    Pulse Link: otx.alienvault.com/pulse/6a7ec
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 07:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  2. Aeternum Botnet Uses Polygon Smart Contracts for Takedown-Resistant Malware C2

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ae

    Pulse ID: 6a7eca0c254771760ee44515
    Pulse Link: otx.alienvault.com/pulse/6a7ec
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 07:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  3. Curiouser and Curiouser

    Indicators extracted from public reporting. Source: talosintelligence.com

    Pulse ID: 6a7e2fb107f9a7cc1cd4e95b
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 20:57:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL

  4. Curiouser and Curiouser

    Indicators extracted from public reporting. Source: talosintelligence.com

    Pulse ID: 6a7e2fb107f9a7cc1cd4e95b
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 20:57:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Talos #bot #CyberHunter_NL

  5. AI 'watermark removers' flood the web. Almost none can prove they work.

    Indicators extracted from public reporting. Source: pasqualepillitteri.it/en/news/

    Pulse ID: 6a7e052794ae78dc7d5d109a
    Pulse Link: otx.alienvault.com/pulse/6a7e0
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 17:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  6. AI 'watermark removers' flood the web. Almost none can prove they work.

    Indicators extracted from public reporting. Source: pasqualepillitteri.it/en/news/

    Pulse ID: 6a7e052794ae78dc7d5d109a
    Pulse Link: otx.alienvault.com/pulse/6a7e0
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 17:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  7. @b0rk

    yeah me ISP in here in #Iran during the protests was seemingly trying to do #MITM on both #SSH and #HTTPS. Or perhaps it was the network admin as we were in a government building?

    Also please use hashtags!

  8. @b0rk

    yeah me ISP in here in #Iran during the protests was seemingly trying to do #MITM on both #SSH and #HTTPS. Or perhaps it was the network admin as we were in a government building?

    Also please use hashtags!

  9. AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure

    Indicators extracted from public reporting. Source: jamf.com/blog/amnesia-stealer-

    Pulse ID: 6a7df72c743c82d5d51acf07
    Pulse Link: otx.alienvault.com/pulse/6a7df
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 16:56:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  10. AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure

    Indicators extracted from public reporting. Source: jamf.com/blog/amnesia-stealer-

    Pulse ID: 6a7df72c743c82d5d51acf07
    Pulse Link: otx.alienvault.com/pulse/6a7df
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 16:56:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  11. Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations

    Indicators extracted from public reporting. Source: securelist.com/armored-likho-s

    Pulse ID: 6a7dbee44352b7893591e9d3
    Pulse Link: otx.alienvault.com/pulse/6a7db
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 12:56:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #Telegram #bot #CyberHunter_NL

  12. Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations

    Indicators extracted from public reporting. Source: securelist.com/armored-likho-s

    Pulse ID: 6a7dbee44352b7893591e9d3
    Pulse Link: otx.alienvault.com/pulse/6a7db
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 12:56:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #Telegram #bot #CyberHunter_NL

  13. Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ki

    Pulse ID: 6a7da2b72179e3a4cb0c1d31
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 10:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  14. Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ki

    Pulse ID: 6a7da2b72179e3a4cb0c1d31
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 10:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  15. Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Indicators extracted from public reporting. Source: sed-cms.broadcom.com/sites/def

    Pulse ID: 6a7da2dc1ab7ab31faf83152
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 10:56:27

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DoS #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #RAT #RCE #bot #CyberHunter_NL

  16. Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side

    Indicators extracted from public reporting. Source: sed-cms.broadcom.com/sites/def

    Pulse ID: 6a7da2dc1ab7ab31faf83152
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 10:56:27

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DoS #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #RAT #RCE #bot #CyberHunter_NL

  17. Project CAV3RN uses Google Apps Script for stealthy C2 in Israel

    A modular espionage framework targeting entities in Israel has evolved to incorporate sophisticated command-and-control capabilities. The framework employs DNS A-record responses to dynamically select between direct HTTPS connections and a Google Apps Script relay for each transaction, enabling operators to rotate communication channels and deployment identifiers. The communication module uses DNS infrastructure to validate and update Google Apps Script deployment IDs, while XOR encoding obfuscates command-and-control traffic. An inter-component broker coordinates framework DLL components, enabling runtime upgrades without system restarts. The infrastructure leveraged a previously expired Israeli domain, now repurposed with custom authoritative DNS servers, alongside legitimate Google services to blend malicious traffic with normal network activity.

    Pulse ID: 6a7d8cc2109e73821519b31d
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:22:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #Israel #OTX #OpenThreatExchange #RAT #bot #AlienVault

  18. Project CAV3RN uses Google Apps Script for stealthy C2 in Israel

    A modular espionage framework targeting entities in Israel has evolved to incorporate sophisticated command-and-control capabilities. The framework employs DNS A-record responses to dynamically select between direct HTTPS connections and a Google Apps Script relay for each transaction, enabling operators to rotate communication channels and deployment identifiers. The communication module uses DNS infrastructure to validate and update Google Apps Script deployment IDs, while XOR encoding obfuscates command-and-control traffic. An inter-component broker coordinates framework DLL components, enabling runtime upgrades without system restarts. The infrastructure leveraged a previously expired Israeli domain, now repurposed with custom authoritative DNS servers, alongside legitimate Google services to blend malicious traffic with normal network activity.

    Pulse ID: 6a7d8cc2109e73821519b31d
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:22:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DNS #Espionage #Google #HTTP #HTTPS #InfoSec #Israel #OTX #OpenThreatExchange #RAT #bot #AlienVault

  19. Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto

    Indicators extracted from public reporting. Source: splunk.com/en_us/blog/security

    Pulse ID: 6a7d94b079c2c1e42df7974b
    Pulse Link: otx.alienvault.com/pulse/6a7d9
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 09:56:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cookies #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #ShellCode #Steganography #Word #bot #CyberHunter_NL

  20. Phantom Stealer Hides Inside PNG Files, Then Steals Your Passwords, Cookies and Crypto

    Indicators extracted from public reporting. Source: splunk.com/en_us/blog/security

    Pulse ID: 6a7d94b079c2c1e42df7974b
    Pulse Link: otx.alienvault.com/pulse/6a7d9
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 09:56:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cookies #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #ShellCode #Steganography #Word #bot #CyberHunter_NL

  21. Armored Likho expands its cyber-espionage toolkit

    Indicators extracted from public reporting. Source: securelist.com/armored-likho-s

    Pulse ID: 6a7d8697e0bd510e87086185
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 08:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL

  22. Armored Likho expands its cyber-espionage toolkit

    Indicators extracted from public reporting. Source: securelist.com/armored-likho-s

    Pulse ID: 6a7d8697e0bd510e87086185
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 08:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL

  23. "City-Forum" data-theft attacks target Salesforce, ServiceNow portals

    Indicators extracted from public reporting. Source: reco.ai/blog/city-forum-campai

    Pulse ID: 6a7d084bd3aa421c0a525be6
    Pulse Link: otx.alienvault.com/pulse/6a7d0
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 23:56:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  24. "City-Forum" data-theft attacks target Salesforce, ServiceNow portals

    Indicators extracted from public reporting. Source: reco.ai/blog/city-forum-campai

    Pulse ID: 6a7d084bd3aa421c0a525be6
    Pulse Link: otx.alienvault.com/pulse/6a7d0
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 23:56:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  25. Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7cc1f91810a474e1284a56
    Pulse Link: otx.alienvault.com/pulse/6a7cc
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 18:56:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL

  26. Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7cc1f91810a474e1284a56
    Pulse Link: otx.alienvault.com/pulse/6a7cc
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 18:56:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL

  27. New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide

    Indicators extracted from public reporting. Source: reco.ai/blog/city-forum-campai

    Pulse ID: 6a7cb3a3d02c4e72307b552e
    Pulse Link: otx.alienvault.com/pulse/6a7cb
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 17:55:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  28. New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide

    Indicators extracted from public reporting. Source: reco.ai/blog/city-forum-campai

    Pulse ID: 6a7cb3a3d02c4e72307b552e
    Pulse Link: otx.alienvault.com/pulse/6a7cb
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 17:55:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  29. deno-case-studies

    Indicators extracted from public reporting. Source: sophos.com/en-us/blog/deno-cas

    Pulse ID: 6a7c7b59412e34c4ea97e1b9
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 13:55:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL

  30. deno-case-studies

    Indicators extracted from public reporting. Source: sophos.com/en-us/blog/deno-cas

    Pulse ID: 6a7c7b59412e34c4ea97e1b9
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 13:55:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL

  31. ClickFix campaign abuses Deno runtime for infostealer delivery

    Indicators extracted from public reporting. Source: sophos.com/en-us/blog/clickfix

    Pulse ID: 6a7c7b5dcc776888b41f6fab
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 13:55:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #InfoStealer #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL

  32. ClickFix campaign abuses Deno runtime for infostealer delivery

    Indicators extracted from public reporting. Source: sophos.com/en-us/blog/clickfix

    Pulse ID: 6a7c7b5dcc776888b41f6fab
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 13:55:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #InfoStealer #OTX #OpenThreatExchange #RCE #Sophos #bot #CyberHunter_NL

  33. 737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies

    Indicators extracted from public reporting. Source: socket.dev/blog/chrome-vpn-ext

    Pulse ID: 6a7c7b770ce5c908efa958f2
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 13:56:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Troll #VPN #bot #socks5 #CyberHunter_NL

  34. 737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies

    Indicators extracted from public reporting. Source: socket.dev/blog/chrome-vpn-ext

    Pulse ID: 6a7c7b770ce5c908efa958f2
    Pulse Link: otx.alienvault.com/pulse/6a7c7
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 13:56:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Troll #VPN #bot #socks5 #CyberHunter_NL

  35. Сертификат TLS для IP-адреса

    Let’s Encrypt всегда проверял только доменные имена. Однако с развитием микросервисных архитектур, API-взаимодействий и IoT-устройств возникла необходимость защищать трафик серверов, у которых нет домена. 15 января 2026 года стал общедоступным профиль shortlived с 6-дневными сертификатами для «чистых» IP-адресов. Теперь не нужно тратить деньги и время на покупку и регистрацию бесполезных доменных имен. На Хабре уже есть подробные статьи и руководства на тему настройки HTTPS, выпуска сертификатов и конфигурации веб-серверов, но в большинстве случаев они объясняют, как защитить сайт с доменом. Мы же разберём, как обойтись без него и выпустить официальный доверенный TLS-сертификат прямо на «голый» IPv4-адрес.

    habr.com/ru/companies/ruvds/ar

    #ruvds_статьи #vds #vps #https #lets_encrypt #tlsсертификат

  36. Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7c6d5cf70eca6997f0ff3b
    Pulse Link: otx.alienvault.com/pulse/6a7c6
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL

  37. Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7c6d5cf70eca6997f0ff3b
    Pulse Link: otx.alienvault.com/pulse/6a7c6
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 12:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #Windows #bot #CyberHunter_NL

  38. 13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts

    Indicators extracted from public reporting. Source: group-ib.com/blog/windrelay-nf

    Pulse ID: 6a7c6d65bad96416b5bbfbd3
    Pulse Link: otx.alienvault.com/pulse/6a7c6
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 12:56:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GroupIB #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SpyNote #bot #CyberHunter_NL

  39. 13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts

    Indicators extracted from public reporting. Source: group-ib.com/blog/windrelay-nf

    Pulse ID: 6a7c6d65bad96416b5bbfbd3
    Pulse Link: otx.alienvault.com/pulse/6a7c6
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 12:56:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GroupIB #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SpyNote #bot #CyberHunter_NL

  40. CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure

    Indicators extracted from public reporting. Source: securelist.com/project-cav3rn-

    Pulse ID: 6a7c513bd3c90ca3ddb62baf
    Pulse Link: otx.alienvault.com/pulse/6a7c5
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 10:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Google #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL

  41. CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure

    Indicators extracted from public reporting. Source: securelist.com/project-cav3rn-

    Pulse ID: 6a7c513bd3c90ca3ddb62baf
    Pulse Link: otx.alienvault.com/pulse/6a7c5
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 10:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Google #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL

  42. Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals

    Indicators extracted from public reporting. Source: cert.gov.ua/article/6318863

    Pulse ID: 6a7c433680aefab88821c968
    Pulse Link: otx.alienvault.com/pulse/6a7c4
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 09:56:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL

  43. Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals

    Indicators extracted from public reporting. Source: cert.gov.ua/article/6318863

    Pulse ID: 6a7c433680aefab88821c968
    Pulse Link: otx.alienvault.com/pulse/6a7c4
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 09:56:06

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL

  44. Google-themed Credential Phishing Attempt Delivered Through a Fake ‘New Audio MSG’ Email

    Indicators extracted from public reporting. Source: cybersecuritynews.com/google-t

    Pulse ID: 6a7c351ee2a19c50e9902e3c
    Pulse Link: otx.alienvault.com/pulse/6a7c3
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 08:55:58

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL

  45. Google-themed Credential Phishing Attempt Delivered Through a Fake ‘New Audio MSG’ Email

    Indicators extracted from public reporting. Source: cybersecuritynews.com/google-t

    Pulse ID: 6a7c351ee2a19c50e9902e3c
    Pulse Link: otx.alienvault.com/pulse/6a7c3
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 08:55:58

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Phishing #RCE #bot #CyberHunter_NL

  46. ClickFix Attack Abuses Signed IBM SPSS IDE to Deploy New CNCMachineRMS RAT

    Indicators extracted from public reporting. Source: levelblue.com/blogs/spiderlabs

    Pulse ID: 6a7c352538d09ace0dfaf9ce
    Pulse Link: otx.alienvault.com/pulse/6a7c3
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 08:56:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Mac #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL

  47. ClickFix Attack Abuses Signed IBM SPSS IDE to Deploy New CNCMachineRMS RAT

    Indicators extracted from public reporting. Source: levelblue.com/blogs/spiderlabs

    Pulse ID: 6a7c352538d09ace0dfaf9ce
    Pulse Link: otx.alienvault.com/pulse/6a7c3
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 08:56:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Mac #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL

  48. Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

    Indicators extracted from public reporting. Source: exposure.cloudsek.com/ai-suppl

    Pulse ID: 6a7c3531982e86f5db5a1906
    Pulse Link: otx.alienvault.com/pulse/6a7c3
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 08:56:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  49. Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

    Indicators extracted from public reporting. Source: exposure.cloudsek.com/ai-suppl

    Pulse ID: 6a7c3531982e86f5db5a1906
    Pulse Link: otx.alienvault.com/pulse/6a7c3
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 08:56:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  50. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  51. 737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection

    Socket's Threat Research Team identified a campaign of 737 malicious VPN and proxy extensions in the Chrome Web Store, accumulating over 75,000 installs. The extensions, published across 40 developer accounts, target Russian-speaking users seeking access to blocked services. 274 extensions impersonate 66 established VPN brands including Proton VPN, NordVPN, and AmneziaVPN. The extensions route all browser traffic through SOCKS5 proxies controlled by a single operator on port 1082, placing the threat actor in an adversary-in-the-middle position. Premium subscription tiers advertise servers in five countries that do not resolve. The campaign employs DNS-over-HTTPS for evasion, post-approval code substitution, and coordinated review gaming. The operation is linked to a Russian subscription VPN business that names a tax-registered self-employed individual as the contracting party.

    Pulse ID: 6a7c183cfe509b035144c5a6
    Pulse Link: otx.alienvault.com/pulse/6a7c1
    Pulse Author: AlienVault
    Created: 2026-08-12 06:52:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #Browser #Chrome #CyberSecurity #DNS #ELF #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RAT #Russia #Troll #VPN #bot #socks5 #AlienVault

  52. Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7beecb020ccbfd7b706fad
    Pulse Link: otx.alienvault.com/pulse/6a7be
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 03:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL

  53. Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7beecb020ccbfd7b706fad
    Pulse Link: otx.alienvault.com/pulse/6a7be
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 03:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL

  54. Sandworm hackers target IT pros with trojanized WireGuard VPN client

    Indicators extracted from public reporting. Source: cert.gov.ua/article/6318863

    Pulse ID: 6a7b9a56ed0787edeab00dfb
    Pulse Link: otx.alienvault.com/pulse/6a7b9
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 21:55:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL

  55. Sandworm hackers target IT pros with trojanized WireGuard VPN client

    Indicators extracted from public reporting. Source: cert.gov.ua/article/6318863

    Pulse ID: 6a7b9a56ed0787edeab00dfb
    Pulse Link: otx.alienvault.com/pulse/6a7b9
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 21:55:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Sandworm #Trojan #VPN #Worm #bot #CyberHunter_NL

  56. Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ki

    Pulse ID: 6a7b8c7ac9f862e53382eab9
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 20:56:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  57. Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ki

    Pulse ID: 6a7b8c7ac9f862e53382eab9
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 20:56:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  58. Fake CCleaner installs GhostDesk Chrome spyware

    Indicators extracted from public reporting. Source: malwarebytes.com/blog/threat-i

    Pulse ID: 6a7b8c83bf51f40e5a39c8e5
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 20:56:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CCleaner #Chrome #CyberSecurity #HTTP #HTTPS #InfoSec #MalWareBytes #Malware #OTX #OpenThreatExchange #RCE #SpyWare #bot #CyberHunter_NL