#securelist — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #securelist, aggregated by home.social.
-
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Indicators extracted from public reporting. Source: https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
Pulse ID: 6a7ee620d0cfd8859d00dfd9
Pulse Link: https://otx.alienvault.com/pulse/6a7ee620d0cfd8859d00dfd9
Pulse Author: CyberHunter_NL
Created: 2026-08-14 09:55:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Rootkit #SecureList #Windows #bot #CyberHunter_NL
-
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Indicators extracted from public reporting. Source: https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
Pulse ID: 6a7ee620d0cfd8859d00dfd9
Pulse Link: https://otx.alienvault.com/pulse/6a7ee620d0cfd8859d00dfd9
Pulse Author: CyberHunter_NL
Created: 2026-08-14 09:55:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Rootkit #SecureList #Windows #bot #CyberHunter_NL
-
Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7dbee44352b7893591e9d3
Pulse Link: https://otx.alienvault.com/pulse/6a7dbee44352b7893591e9d3
Pulse Author: CyberHunter_NL
Created: 2026-08-13 12:56:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #Telegram #bot #CyberHunter_NL
-
Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7dbee44352b7893591e9d3
Pulse Link: https://otx.alienvault.com/pulse/6a7dbee44352b7893591e9d3
Pulse Author: CyberHunter_NL
Created: 2026-08-13 12:56:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #Telegram #bot #CyberHunter_NL
-
Armored Likho expands its cyber-espionage toolkit
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7d8697e0bd510e87086185
Pulse Link: https://otx.alienvault.com/pulse/6a7d8697e0bd510e87086185
Pulse Author: CyberHunter_NL
Created: 2026-08-13 08:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL
-
Armored Likho expands its cyber-espionage toolkit
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7d8697e0bd510e87086185
Pulse Link: https://otx.alienvault.com/pulse/6a7d8697e0bd510e87086185
Pulse Author: CyberHunter_NL
Created: 2026-08-13 08:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL
-
CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure
Indicators extracted from public reporting. Source: https://securelist.com/project-cav3rn-continues/120991/
Pulse ID: 6a7c513bd3c90ca3ddb62baf
Pulse Link: https://otx.alienvault.com/pulse/6a7c513bd3c90ca3ddb62baf
Pulse Author: CyberHunter_NL
Created: 2026-08-12 10:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL
-
CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure
Indicators extracted from public reporting. Source: https://securelist.com/project-cav3rn-continues/120991/
Pulse ID: 6a7c513bd3c90ca3ddb62baf
Pulse Link: https://otx.alienvault.com/pulse/6a7c513bd3c90ca3ddb62baf
Pulse Author: CyberHunter_NL
Created: 2026-08-12 10:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL
-
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference p...
Indicators extracted from public reporting. Source: https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/
Pulse ID: 6a7b1bd795d85f7389c29800
Pulse Link: https://otx.alienvault.com/pulse/6a7b1bd795d85f7389c29800
Pulse Author: CyberHunter_NL
Created: 2026-08-11 12:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL
-
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference p...
Indicators extracted from public reporting. Source: https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/
Pulse ID: 6a7b1bd795d85f7389c29800
Pulse Link: https://otx.alienvault.com/pulse/6a7b1bd795d85f7389c29800
Pulse Author: CyberHunter_NL
Created: 2026-08-11 12:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL
-
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Indicators extracted from public reporting. Source: https://securelist.com/project-cav3rn-continues/120991/
Pulse ID: 6a7affafccc18af7b7b09e80
Pulse Link: https://otx.alienvault.com/pulse/6a7affafccc18af7b7b09e80
Pulse Author: CyberHunter_NL
Created: 2026-08-11 10:55:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL
-
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Indicators extracted from public reporting. Source: https://securelist.com/project-cav3rn-continues/120991/
Pulse ID: 6a7affafccc18af7b7b09e80
Pulse Link: https://otx.alienvault.com/pulse/6a7affafccc18af7b7b09e80
Pulse Author: CyberHunter_NL
Created: 2026-08-11 10:55:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL
-
How legitimate cloud platforms enable phishers to bypass MFA
Indicators extracted from public reporting. Source: https://securelist.com/cloud-platforms-in-phishing/120832/
Pulse ID: 6a71e195cc4d01c3cb1caa89
Pulse Link: https://otx.alienvault.com/pulse/6a71e195cc4d01c3cb1caa89
Pulse Author: CyberHunter_NL
Created: 2026-08-04 12:56:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #RCE #SecureList #bot #CyberHunter_NL
-
How legitimate cloud platforms enable phishers to bypass MFA
Indicators extracted from public reporting. Source: https://securelist.com/cloud-platforms-in-phishing/120832/
Pulse ID: 6a71e195cc4d01c3cb1caa89
Pulse Link: https://otx.alienvault.com/pulse/6a71e195cc4d01c3cb1caa89
Pulse Author: CyberHunter_NL
Created: 2026-08-04 12:56:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #RCE #SecureList #bot #CyberHunter_NL
-
New GenieLocker ransomware for Windows, ESXi, and Linux | Securelist
Pulse ID: 6a6b1a04de20fcbbf1047084
Pulse Link: https://otx.alienvault.com/pulse/6a6b1a04de20fcbbf1047084
Pulse Author: CyberHunter_NL
Created: 2026-07-30 09:31:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Linux #OTX #OpenThreatExchange #RansomWare #SecureList #Windows #bot #CyberHunter_NL
-
New GenieLocker ransomware for Windows, ESXi, and Linux | Securelist
Pulse ID: 6a6b1a04de20fcbbf1047084
Pulse Link: https://otx.alienvault.com/pulse/6a6b1a04de20fcbbf1047084
Pulse Author: CyberHunter_NL
Created: 2026-07-30 09:31:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Linux #OTX #OpenThreatExchange #RansomWare #SecureList #Windows #bot #CyberHunter_NL
-
Malicious AI Gateway Exposes Data Through Supply Chain Breach
A recent analysis of LiteLLM, a popular AI gateway, revealed a supply chain breach that embedded malicious code designed to steal sensitive data, highlighting the vulnerability of even the most trusted components. This breach turned a multifunctional gateway meant to enhance AI agents into a vector for data theft, putting countless users…
https://osintsights.com/malicious-ai-gateway-exposes-data-through-supply-chain-breach
#Litellm #SupplyChainBreach #AiAgents #DataExfiltration #Securelist
-
How attackers adapt to built-in macOS protection – Source: securelist.com https://ciso2ciso.com/how-attackers-adapt-to-built-in-macos-protection-source-securelist-com/ #securelist.com #0CISO2CISO
-
How attackers adapt to built-in macOS protection – Source: securelist.com https://ciso2ciso.com/how-attackers-adapt-to-built-in-macos-protection-source-securelist-com/ #securelist.com #0CISO2CISO
-
Exploits and vulnerabilities in Q2 2025 – Source: securelist.com https://ciso2ciso.com/exploits-and-vulnerabilities-in-q2-2025-source-securelist-com/ #securelist.com #0CISO2CISO
-
Exploits and vulnerabilities in Q2 2025 – Source: securelist.com https://ciso2ciso.com/exploits-and-vulnerabilities-in-q2-2025-source-securelist-com/ #securelist.com #0CISO2CISO
-
GodRAT – New RAT targeting financial institutions – Source: securelist.com https://ciso2ciso.com/godrat-new-rat-targeting-financial-institutions-source-securelist-com/ #securelist.com #0CISO2CISO
-
GodRAT – New RAT targeting financial institutions – Source: securelist.com https://ciso2ciso.com/godrat-new-rat-targeting-financial-institutions-source-securelist-com/ #securelist.com #0CISO2CISO
-
Efimer Trojan Steals Crypto, Hacks WordPress Sites via Torrents and Phishing – Source:hackread.com https://ciso2ciso.com/efimer-trojan-steals-crypto-hacks-wordpress-sites-via-torrents-and-phishing-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #Securelist #Kaspersky #Hackread #Phishing #security #malware #Crypto #Efimer #trojan #Fraud
-
Efimer Trojan Steals Crypto, Hacks WordPress Sites via Torrents and Phishing – Source:hackread.com https://ciso2ciso.com/efimer-trojan-steals-crypto-hacks-wordpress-sites-via-torrents-and-phishing-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #Securelist #Kaspersky #Hackread #Phishing #security #malware #Crypto #Efimer #trojan #Fraud
-
Efimer Trojan Steals Crypto, Hacks WordPress Sites via Torrents and Phishing https://hackread.com/efimer-trojan-crypto-hacks-wordpress-torrents-phishing/ #Cybersecurity #Securelist #Kaspersky #Security #Phishing #Malware #Crypto #Efimer #TROJAN #Fraud
-
Efimer Trojan Steals Crypto, Hacks WordPress Sites via Torrents and Phishing https://hackread.com/efimer-trojan-crypto-hacks-wordpress-torrents-phishing/ #Cybersecurity #Securelist #Kaspersky #Security #Phishing #Malware #Crypto #Efimer #TROJAN #Fraud
-
New trends in phishing and scams: how AI and social media are changing the game – Source: securelist.com https://ciso2ciso.com/new-trends-in-phishing-and-scams-how-ai-and-social-media-are-changing-the-game-source-securelist-com/ #securelist.com #0CISO2CISO
-
New trends in phishing and scams: how AI and social media are changing the game – Source: securelist.com https://ciso2ciso.com/new-trends-in-phishing-and-scams-how-ai-and-social-media-are-changing-the-game-source-securelist-com/ #securelist.com #0CISO2CISO
-
Scammers mass-mailing the Efimer Trojan to steal crypto – Source: securelist.com https://ciso2ciso.com/scammers-mass-mailing-the-efimer-trojan-to-steal-crypto-source-securelist-com/ #securelist.com #0CISO2CISO
-
Scammers mass-mailing the Efimer Trojan to steal crypto – Source: securelist.com https://ciso2ciso.com/scammers-mass-mailing-the-efimer-trojan-to-steal-crypto-source-securelist-com/ #securelist.com #0CISO2CISO
-
Driver of destruction: How a legitimate driver is being used to take down AV processes – Source: securelist.com https://ciso2ciso.com/driver-of-destruction-how-a-legitimate-driver-is-being-used-to-take-down-av-processes-source-securelist-com/ #securelist.com #0CISO2CISO
-
Driver of destruction: How a legitimate driver is being used to take down AV processes – Source: securelist.com https://ciso2ciso.com/driver-of-destruction-how-a-legitimate-driver-is-being-used-to-take-down-av-processes-source-securelist-com/ #securelist.com #0CISO2CISO
-
Kaspersky hat die durch ToolShell ausgenutzten Schwachstellen in Microsofts on-premise SharePont-Server intensiver aufgearbeitet.
Da bleibst staunend zurück.
https://securelist.com/toolshell-explained/117045/
#infosec #microsoft #toolshell #sharepoint #BeDiS #kaspersky #securelist -
Approach to mainframe penetration testing on z/OS. Deep dive into RACF – Source: securelist.com https://ciso2ciso.com/approach-to-mainframe-penetration-testing-on-z-os-deep-dive-into-racf-source-securelist-com/ #securelist.com #0CISO2CISO
-
Approach to mainframe penetration testing on z/OS. Deep dive into RACF – Source: securelist.com https://ciso2ciso.com/approach-to-mainframe-penetration-testing-on-z-os-deep-dive-into-racf-source-securelist-com/ #securelist.com #0CISO2CISO
-
SparkKitty, SparkCat’s little brother: A new Trojan spy found in the App Store and Google Play – Source: securelist.com https://ciso2ciso.com/sparkkitty-sparkcats-little-brother-a-new-trojan-spy-found-in-the-app-store-and-google-play-source-securelist-com/ #securelist.com #0CISO2CISO
-
SparkKitty, SparkCat’s little brother: A new Trojan spy found in the App Store and Google Play – Source: securelist.com https://ciso2ciso.com/sparkkitty-sparkcats-little-brother-a-new-trojan-spy-found-in-the-app-store-and-google-play-source-securelist-com/ #securelist.com #0CISO2CISO
-
Zanubis in motion: Tracing the active evolution of the Android banking malware – Source: securelist.com https://ciso2ciso.com/zanubis-in-motion-tracing-the-active-evolution-of-the-android-banking-malware-source-securelist-com/ #securelist.com #0CISO2CISO
-
Zanubis in motion: Tracing the active evolution of the Android banking malware – Source: securelist.com https://ciso2ciso.com/zanubis-in-motion-tracing-the-active-evolution-of-the-android-banking-malware-source-securelist-com/ #securelist.com #0CISO2CISO
-
GOFFEE continues to attack organizations in Russia – Source: securelist.com https://ciso2ciso.com/goffee-continues-to-attack-organizations-in-russia-source-securelist-com/ #securelist.com #0CISO2CISO
-
GOFFEE continues to attack organizations in Russia – Source: securelist.com https://ciso2ciso.com/goffee-continues-to-attack-organizations-in-russia-source-securelist-com/ #securelist.com #0CISO2CISO
-
Attackers distributing a miner and the ClipBanker Trojan via SourceForge – Source: securelist.com https://ciso2ciso.com/attackers-distributing-a-miner-and-the-clipbanker-trojan-via-sourceforge-source-securelist-com/ #securelist.com #0CISO2CISO
-
Attackers distributing a miner and the ClipBanker Trojan via SourceForge – Source: securelist.com https://ciso2ciso.com/attackers-distributing-a-miner-and-the-clipbanker-trojan-via-sourceforge-source-securelist-com/ #securelist.com #0CISO2CISO
-
A journey into forgotten Null Session and MS-RPC interfaces, part 2 – Source: securelist.com https://ciso2ciso.com/a-journey-into-forgotten-null-session-and-ms-rpc-interfaces-part-2-source-securelist-com/ #securelist.com #0CISO2CISO
-
A journey into forgotten Null Session and MS-RPC interfaces, part 2 – Source: securelist.com https://ciso2ciso.com/a-journey-into-forgotten-null-session-and-ms-rpc-interfaces-part-2-source-securelist-com/ #securelist.com #0CISO2CISO
-
TookPS: DeepSeek isn’t the only game in town – Source: securelist.com https://ciso2ciso.com/tookps-deepseek-isnt-the-only-game-in-town-source-securelist-com/ #securelist.com #0CISO2CISO
-
TookPS: DeepSeek isn’t the only game in town – Source: securelist.com https://ciso2ciso.com/tookps-deepseek-isnt-the-only-game-in-town-source-securelist-com/ #securelist.com #0CISO2CISO
-
Operation ForumTroll: APT attack with Google Chrome zero-day exploit chain – Source: securelist.com https://ciso2ciso.com/operation-forumtroll-apt-attack-with-google-chrome-zero-day-exploit-chain-source-securelist-com/ #securelist.com #0CISO2CISO
-
Operation ForumTroll: APT attack with Google Chrome zero-day exploit chain – Source: securelist.com https://ciso2ciso.com/operation-forumtroll-apt-attack-with-google-chrome-zero-day-exploit-chain-source-securelist-com/ #securelist.com #0CISO2CISO
-
DCRat backdoor returns – Source: securelist.com https://ciso2ciso.com/dcrat-backdoor-returns-source-securelist-com/ #securelist.com #0CISO2CISO
-
DCRat backdoor returns – Source: securelist.com https://ciso2ciso.com/dcrat-backdoor-returns-source-securelist-com/ #securelist.com #0CISO2CISO
-
Angry Likho APT Resurfaces with Lumma Stealer Attacks Against Russia – Source:hackread.com https://ciso2ciso.com/angry-likho-apt-resurfaces-with-lumma-stealer-attacks-against-russia-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #StickyWerewolf #cybersecurity #CyberAttacks #LummaStealer #Securelist #Kaspersky #Hackread #security #Belarus #malware #Russia #APT
-
Angry Likho APT Resurfaces with Lumma Stealer Attacks Against Russia – Source:hackread.com https://ciso2ciso.com/angry-likho-apt-resurfaces-with-lumma-stealer-attacks-against-russia-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #StickyWerewolf #cybersecurity #CyberAttacks #LummaStealer #Securelist #Kaspersky #Hackread #security #Belarus #malware #Russia #APT
-
Angry Likho APT Resurfaces with Lumma Stealer Attacks Against Russia https://hackread.com/angry-likho-apt-lumma-stealer-attacks-on-russia/ #StickyWerewolf #Cybersecurity #CyberAttacks #LummaStealer #Securelist #Kaspersky #Security #security #Malware #Belarus #Russia #APT
-
Angry Likho APT Resurfaces with Lumma Stealer Attacks Against Russia https://hackread.com/angry-likho-apt-lumma-stealer-attacks-on-russia/ #StickyWerewolf #Cybersecurity #CyberAttacks #LummaStealer #Securelist #Kaspersky #Security #security #Malware #Belarus #Russia #APT
-
Exploits and vulnerabilities in Q4 2024 – Source: securelist.com https://ciso2ciso.com/exploits-and-vulnerabilities-in-q4-2024-source-securelist-com/ #securelist.com #0CISO2CISO
-
Exploits and vulnerabilities in Q4 2024 – Source: securelist.com https://ciso2ciso.com/exploits-and-vulnerabilities-in-q4-2024-source-securelist-com/ #securelist.com #0CISO2CISO
-
The GitVenom campaign: cryptocurrency theft using GitHub – Source: securelist.com https://ciso2ciso.com/the-gitvenom-campaign-cryptocurrency-theft-using-github-source-securelist-com/ #securelist.com #0CISO2CISO
-
The GitVenom campaign: cryptocurrency theft using GitHub – Source: securelist.com https://ciso2ciso.com/the-gitvenom-campaign-cryptocurrency-theft-using-github-source-securelist-com/ #securelist.com #0CISO2CISO