home.social

#rce — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #rce, aggregated by home.social.

fetched live
  1. Fake CAPTCHA Tricks Mac Users Into Installing a Backdoor That Steals Passwords and Mines Crypto

    Indicators extracted from public reporting. Source: notes.netbytesec.com/2026/08/a

    Pulse ID: 6a8c154672cfbab8119b15ad
    Pulse Link: otx.alienvault.com/pulse/6a8c1
    Pulse Author: CyberHunter_NL
    Created: 2026-08-24 09:56:22

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CAPTCHA #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #Mac #MacOS #NATO #NET #OTX #OpenThreatExchange #Password #Passwords #RCE #Word #bot #CyberHunter_NL

  2. UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

    Indicators extracted from public reporting. Source: blog.talosintelligence.com/uat

    Pulse ID: 6a8c073a62ba2c96744372ac
    Pulse Link: otx.alienvault.com/pulse/6a8c0
    Pulse Author: CyberHunter_NL
    Created: 2026-08-24 08:56:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #EDR #HTTP #HTTPS #InfoSec #Linux #OTX #OpenThreatExchange #RCE #Rootkit #Talos #bot #CyberHunter_NL

  3. Hackers Infect Android Car Screens Through Their Built-In Software Update System

    Indicators extracted from public reporting. Source: securelist.com/android-head-un

    Pulse ID: 6a8bf904b1da950db7f4adaf
    Pulse Link: otx.alienvault.com/pulse/6a8bf
    Pulse Author: CyberHunter_NL
    Created: 2026-08-24 07:55:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL

  4. Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, Azure Credential Theft +20 Stories

    Indicators extracted from public reporting. Source: cybersecuritynews.com/cyber-se

    Pulse ID: 6a8b260da48fae71c37000fb
    Pulse Link: otx.alienvault.com/pulse/6a8b2
    Pulse Author: CyberHunter_NL
    Created: 2026-08-23 16:55:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Azure #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RansomWare #bot #CyberHunter_NL

  5. Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter

    Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...

    #WBiegu #Apt #Chiny #Cve #DirectoryTraversal #Rce #Vmware

    sekurak.pl/chinskie-grupy-apt-

  6. Hackers infect Android car head units with proxy botnet malware

    Indicators extracted from public reporting. Source: securelist.com/android-head-un

    Pulse ID: 6a89b871c96a8775a97fd5cd
    Pulse Link: otx.alienvault.com/pulse/6a89b
    Pulse Author: CyberHunter_NL
    Created: 2026-08-22 14:55:45

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RCE #SecureList #bot #botnet #CyberHunter_NL

  7. Grok Zero-Click Attack Steals Chat Data Using Encrypted Prompt Injection

    Indicators extracted from public reporting. Source: adversa.ai/blog/cryptographic-

    Pulse ID: 6a8901bb9c1388a4bafaf914
    Pulse Link: otx.alienvault.com/pulse/6a890
    Pulse Author: CyberHunter_NL
    Created: 2026-08-22 01:56:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  8. 2026-08-21: SmartApeSG ClickFix campaign leads to two RATs

    Indicators extracted from public reporting. Source: malware-traffic-analysis.net/2

    Pulse ID: 6a889165b097c9fea9c95d72
    Pulse Link: otx.alienvault.com/pulse/6a889
    Pulse Author: CyberHunter_NL
    Created: 2026-08-21 17:56:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTML #HTTP #HTTPS #InfoSec #Malware #NET #OTX #OpenThreatExchange #RAT #RCE #SmartApeSg #bot #CyberHunter_NL

  9. Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

    Indicators extracted from public reporting. Source: securelist.com/android-head-un

    Pulse ID: 6a888313c9f88c699eae9eb1
    Pulse Link: otx.alienvault.com/pulse/6a888
    Pulse Author: CyberHunter_NL
    Created: 2026-08-21 16:55:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RCE #SecureList #bot #botnet #CyberHunter_NL

  10. Chinese Hackers Use AI Agents to Exploit Web Servers and Automate Attacks

    Indicators extracted from public reporting. Source: blog.talosintelligence.com/uat

    Pulse ID: 6a8867325d4b7e6ebca35a51
    Pulse Link: otx.alienvault.com/pulse/6a886
    Pulse Author: CyberHunter_NL
    Created: 2026-08-21 14:56:50

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #Talos #bot #CyberHunter_NL

  11. Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials

    Indicators extracted from public reporting. Source: telegram.me/share/url?url=http

    Pulse ID: 6a883cd3267d21c3675a3a86
    Pulse Link: otx.alienvault.com/pulse/6a883
    Pulse Author: CyberHunter_NL
    Created: 2026-08-21 11:56:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Telegram #Vidar #bot #CyberHunter_NL

  12. Bandwidth-Sharing App Can Turn Employee Devices Into Gateways to Internal Networks

    Indicators extracted from public reporting. Source: silentpush.com/blog/peer2profi

    Pulse ID: 6a8820a72c12cdd1a022136b
    Pulse Link: otx.alienvault.com/pulse/6a882
    Pulse Author: CyberHunter_NL
    Created: 2026-08-21 09:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Proxy #RCE #bot #CyberHunter_NL

  13. The invisible passenger in your car

    Indicators extracted from public reporting. Source: securelist.com/android-head-un

    Pulse ID: 6a88129425e8190825aa2854
    Pulse Link: otx.alienvault.com/pulse/6a881
    Pulse Author: CyberHunter_NL
    Created: 2026-08-21 08:55:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL

  14. DOJ Charges 17 Iranian Hackers in IRGC-Linked Campaign That Stole 31.5TB of Research Data

    Indicators extracted from public reporting. Source: justice.gov/opa/pr/17-iranians

    Pulse ID: 6a880480823c6a8bf25fa3c0
    Pulse Link: otx.alienvault.com/pulse/6a880
    Pulse Author: CyberHunter_NL
    Created: 2026-08-21 07:55:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #IRGC #InfoSec #Iran #Islam #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  15. Hackers Exploit TrueConf Servers to Push Malware Through Legitimate Video Conference Downloads

    Indicators extracted from public reporting. Source: ics-cert.kaspersky.com/publica

    Pulse ID: 6a87f6783ab4c393dd31b010
    Pulse Link: otx.alienvault.com/pulse/6a87f
    Pulse Author: CyberHunter_NL
    Created: 2026-08-21 06:55:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #ICS #InfoSec #Kaspersky #Malware #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  16. China-Linked Spy Campaign Uses Five New Malware Families Against Central Asian Governments

    Indicators extracted from public reporting. Source: bitdefender.com/en-us/blog/bus

    Pulse ID: 6a87f67e4a85b9b9ccc19842
    Pulse Link: otx.alienvault.com/pulse/6a87f
    Pulse Author: CyberHunter_NL
    Created: 2026-08-21 06:55:58

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BitDefender #CentralAsia #China #CyberSecurity #Government #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  17. July 2026 Infostealer Trend Report

    Indicators extracted from public reporting. Source: feedly.com/i/subscription/feed

    Pulse ID: 6a87f692d0ad3593335ce61d
    Pulse Link: otx.alienvault.com/pulse/6a87f
    Pulse Author: CyberHunter_NL
    Created: 2026-08-21 06:56:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #ASEC #AhnLab #CyberSecurity #HTTP #HTTPS #InfoSec #InfoStealer #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  18. How Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else's Product

    Investigation into residential proxy networks reveals that bandwidth-sharing applications like PEER2PROFIT recruit users to share internet connections for payment, then monetize this bandwidth through commercial proxy service ASTROPROXY at up to 27 times the original cost. Over 72 hours, researchers identified 117,224 unique IPs across residential, mobile, and datacenter pools, with residential pools adding over 1,000 new IPs hourly. These applications install through official channels with user consent, making them invisible to traditional security tools. Reverse engineering of the Windows SDK revealed the communications protocol and backconnect infrastructure coordinating proxy sessions. Testing demonstrated that proxy networks could access internal network resources through simple DNS entries resolving to internal IPs, potentially exposing corporate assets. The scale, legitimacy, and internal network access capabilities present significant risks to organizations where employees may unknowingly expose co...

    Pulse ID: 6a8734bb1e57bed1c101e5e9
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:09:15

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DNS #InfoSec #Mac #OTX #OpenThreatExchange #Proxy #RAT #RCE #Windows #bot #AlienVault

  19. Chinese-speaking adversary integrates agentic AI into post-compromise operations

    A Chinese-speaking cybercrime group designated UAT-10147 has been identified targeting Windows and Linux web servers worldwide, affecting organizations across government, education, media, technology, and gaming sectors. The adversary exploits publicly disclosed vulnerabilities to achieve initial access at scale, then deploys AI-driven tooling throughout exploitation, reconnaissance, payload generation, validation, and persistence workflows. The operation leverages open-source offensive frameworks including Metasploit, ysoserial, PentestGPT, and DeepAudit to automate intrusion operations. UAT-10147 demonstrates an emerging capability of integrating semi-autonomous AI systems for iterative exploit refinement, adaptive troubleshooting, and operational documentation generation. Targeting includes approximately 170,000 URLs across multiple countries, with post-compromise activities involving deployment of various implants, BadIIS installations, and SEO fraud operations.

    Pulse ID: 6a86e8edcfc7cbd751fb1b3d
    Pulse Link: otx.alienvault.com/pulse/6a86e
    Pulse Author: AlienVault
    Created: 2026-08-20 11:45:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberCrime #CyberSecurity #Education #Government #InfoSec #Linux #OTX #OpenThreatExchange #RAT #RCE #Windows #bot #AlienVault

  20. Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign

    Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.

    Pulse ID: 6a86146ca27454b03a4cbe2d
    Pulse Link: otx.alienvault.com/pulse/6a861
    Pulse Author: AlienVault
    Created: 2026-08-19 20:39:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault

  21. Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware

    Following Black Hat and DEF CON conferences, a threat actor targeted attendees through X direct messages, posing as CoinDesk's VP and Head of Marketing to establish trust under the pretext of conference planning. The campaign employed a malicious Google Apps Script embedded in a Google Doc that presented ClickFix-style instructions and manual download options. The attack delivered different payloads based on the victim's operating system: macOS users received AMOS infostealer, while Windows users were infected with NetSupport RAT, a Ledger wallet implant, and a TLS-intercepting proxy. A secondary lure masqueraded as a DocSend installer to deliver additional payloads. The operation demonstrated sophisticated social engineering by leveraging trusted platforms and post-conference networking expectations.

    Pulse ID: 6a85d24a1bf7db5b97a4e9f8
    Pulse Link: otx.alienvault.com/pulse/6a85d
    Pulse Author: AlienVault
    Created: 2026-08-19 15:56:58

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AMOS #CyberSecurity #Edge #Google #InfoSec #InfoStealer #Mac #MacOS #Malware #NetSupport #NetSupportRAT #OTX #OpenThreatExchange #Phishing #Proxy #RAT #RCE #Rust #SocialEngineering #TLS #Windows #bot #AlienVault