#securelist — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #securelist, aggregated by home.social.
-
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Indicators extracted from public reporting. Source: https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
Pulse ID: 6a7ee620d0cfd8859d00dfd9
Pulse Link: https://otx.alienvault.com/pulse/6a7ee620d0cfd8859d00dfd9
Pulse Author: CyberHunter_NL
Created: 2026-08-14 09:55:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Rootkit #SecureList #Windows #bot #CyberHunter_NL
-
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Indicators extracted from public reporting. Source: https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
Pulse ID: 6a7ee620d0cfd8859d00dfd9
Pulse Link: https://otx.alienvault.com/pulse/6a7ee620d0cfd8859d00dfd9
Pulse Author: CyberHunter_NL
Created: 2026-08-14 09:55:44Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #Rootkit #SecureList #Windows #bot #CyberHunter_NL
-
Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7dbee44352b7893591e9d3
Pulse Link: https://otx.alienvault.com/pulse/6a7dbee44352b7893591e9d3
Pulse Author: CyberHunter_NL
Created: 2026-08-13 12:56:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #Telegram #bot #CyberHunter_NL
-
Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7dbee44352b7893591e9d3
Pulse Link: https://otx.alienvault.com/pulse/6a7dbee44352b7893591e9d3
Pulse Author: CyberHunter_NL
Created: 2026-08-13 12:56:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #Telegram #bot #CyberHunter_NL
-
Armored Likho expands its cyber-espionage toolkit
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7d8697e0bd510e87086185
Pulse Link: https://otx.alienvault.com/pulse/6a7d8697e0bd510e87086185
Pulse Author: CyberHunter_NL
Created: 2026-08-13 08:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL
-
Armored Likho expands its cyber-espionage toolkit
Indicators extracted from public reporting. Source: https://securelist.com/armored-likho-still-toolkit/121033/
Pulse ID: 6a7d8697e0bd510e87086185
Pulse Link: https://otx.alienvault.com/pulse/6a7d8697e0bd510e87086185
Pulse Author: CyberHunter_NL
Created: 2026-08-13 08:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #cyberespionage #CyberHunter_NL
-
CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure
Indicators extracted from public reporting. Source: https://securelist.com/project-cav3rn-continues/120991/
Pulse ID: 6a7c513bd3c90ca3ddb62baf
Pulse Link: https://otx.alienvault.com/pulse/6a7c513bd3c90ca3ddb62baf
Pulse Author: CyberHunter_NL
Created: 2026-08-12 10:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL
-
CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure
Indicators extracted from public reporting. Source: https://securelist.com/project-cav3rn-continues/120991/
Pulse ID: 6a7c513bd3c90ca3ddb62baf
Pulse Link: https://otx.alienvault.com/pulse/6a7c513bd3c90ca3ddb62baf
Pulse Author: CyberHunter_NL
Created: 2026-08-12 10:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL
-
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference p...
Indicators extracted from public reporting. Source: https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/
Pulse ID: 6a7b1bd795d85f7389c29800
Pulse Link: https://otx.alienvault.com/pulse/6a7b1bd795d85f7389c29800
Pulse Author: CyberHunter_NL
Created: 2026-08-11 12:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL
-
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference p...
Indicators extracted from public reporting. Source: https://securelist.ru/tr/head-mare-targets-trueconf-server-with-phantomcore/116557/
Pulse ID: 6a7b1bd795d85f7389c29800
Pulse Link: https://otx.alienvault.com/pulse/6a7b1bd795d85f7389c29800
Pulse Author: CyberHunter_NL
Created: 2026-08-11 12:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL
-
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Indicators extracted from public reporting. Source: https://securelist.com/project-cav3rn-continues/120991/
Pulse ID: 6a7affafccc18af7b7b09e80
Pulse Link: https://otx.alienvault.com/pulse/6a7affafccc18af7b7b09e80
Pulse Author: CyberHunter_NL
Created: 2026-08-11 10:55:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL
-
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Indicators extracted from public reporting. Source: https://securelist.com/project-cav3rn-continues/120991/
Pulse ID: 6a7affafccc18af7b7b09e80
Pulse Link: https://otx.alienvault.com/pulse/6a7affafccc18af7b7b09e80
Pulse Author: CyberHunter_NL
Created: 2026-08-11 10:55:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Google #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #SecureList #bot #CyberHunter_NL
-
How legitimate cloud platforms enable phishers to bypass MFA
Indicators extracted from public reporting. Source: https://securelist.com/cloud-platforms-in-phishing/120832/
Pulse ID: 6a71e195cc4d01c3cb1caa89
Pulse Link: https://otx.alienvault.com/pulse/6a71e195cc4d01c3cb1caa89
Pulse Author: CyberHunter_NL
Created: 2026-08-04 12:56:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #RCE #SecureList #bot #CyberHunter_NL
-
How legitimate cloud platforms enable phishers to bypass MFA
Indicators extracted from public reporting. Source: https://securelist.com/cloud-platforms-in-phishing/120832/
Pulse ID: 6a71e195cc4d01c3cb1caa89
Pulse Link: https://otx.alienvault.com/pulse/6a71e195cc4d01c3cb1caa89
Pulse Author: CyberHunter_NL
Created: 2026-08-04 12:56:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #HTTP #HTTPS #InfoSec #MFA #OTX #OpenThreatExchange #Phishing #RCE #SecureList #bot #CyberHunter_NL
-
New GenieLocker ransomware for Windows, ESXi, and Linux | Securelist
Pulse ID: 6a6b1a04de20fcbbf1047084
Pulse Link: https://otx.alienvault.com/pulse/6a6b1a04de20fcbbf1047084
Pulse Author: CyberHunter_NL
Created: 2026-07-30 09:31:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Linux #OTX #OpenThreatExchange #RansomWare #SecureList #Windows #bot #CyberHunter_NL
-
New GenieLocker ransomware for Windows, ESXi, and Linux | Securelist
Pulse ID: 6a6b1a04de20fcbbf1047084
Pulse Link: https://otx.alienvault.com/pulse/6a6b1a04de20fcbbf1047084
Pulse Author: CyberHunter_NL
Created: 2026-07-30 09:31:48Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Linux #OTX #OpenThreatExchange #RansomWare #SecureList #Windows #bot #CyberHunter_NL
-
OkoBot framework infection chain | Securelist
Kaspersky has identified a new sophisticated malware framework and orchestrate an attack via an SSH tunnel, which it believes is being used to capture the contents of cryptocurrency users' wallets and steal their money.
Pulse ID: 6a58a078dd8cb6b5d6a74978
Pulse Link: https://otx.alienvault.com/pulse/6a58a078dd8cb6b5d6a74978
Pulse Author: CyberHunter_NL
Created: 2026-07-16 09:12:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Kaspersky #Malware #OTX #OpenThreatExchange #RAT #SSH #SecureList #bot #cryptocurrency #CyberHunter_NL
-
OkoBot framework infection chain | Securelist
Kaspersky has identified a new sophisticated malware framework and orchestrate an attack via an SSH tunnel, which it believes is being used to capture the contents of cryptocurrency users' wallets and steal their money.
Pulse ID: 6a58a078dd8cb6b5d6a74978
Pulse Link: https://otx.alienvault.com/pulse/6a58a078dd8cb6b5d6a74978
Pulse Author: CyberHunter_NL
Created: 2026-07-16 09:12:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Kaspersky #Malware #OTX #OpenThreatExchange #RAT #SSH #SecureList #bot #cryptocurrency #CyberHunter_NL
-
Malicious AI Gateway Exposes Data Through Supply Chain Breach
A recent analysis of LiteLLM, a popular AI gateway, revealed a supply chain breach that embedded malicious code designed to steal sensitive data, highlighting the vulnerability of even the most trusted components. This breach turned a multifunctional gateway meant to enhance AI agents into a vector for data theft, putting countless users…
https://osintsights.com/malicious-ai-gateway-exposes-data-through-supply-chain-breach
#Litellm #SupplyChainBreach #AiAgents #DataExfiltration #Securelist
-
How attackers adapt to built-in macOS protection – Source: securelist.com https://ciso2ciso.com/how-attackers-adapt-to-built-in-macos-protection-source-securelist-com/ #securelist.com #0CISO2CISO
-
How attackers adapt to built-in macOS protection – Source: securelist.com https://ciso2ciso.com/how-attackers-adapt-to-built-in-macos-protection-source-securelist-com/ #securelist.com #0CISO2CISO
-
Exploits and vulnerabilities in Q2 2025 – Source: securelist.com https://ciso2ciso.com/exploits-and-vulnerabilities-in-q2-2025-source-securelist-com/ #securelist.com #0CISO2CISO
-
Exploits and vulnerabilities in Q2 2025 – Source: securelist.com https://ciso2ciso.com/exploits-and-vulnerabilities-in-q2-2025-source-securelist-com/ #securelist.com #0CISO2CISO
-
GodRAT – New RAT targeting financial institutions – Source: securelist.com https://ciso2ciso.com/godrat-new-rat-targeting-financial-institutions-source-securelist-com/ #securelist.com #0CISO2CISO
-
GodRAT – New RAT targeting financial institutions – Source: securelist.com https://ciso2ciso.com/godrat-new-rat-targeting-financial-institutions-source-securelist-com/ #securelist.com #0CISO2CISO
-
Efimer Trojan Steals Crypto, Hacks WordPress Sites via Torrents and Phishing – Source:hackread.com https://ciso2ciso.com/efimer-trojan-steals-crypto-hacks-wordpress-sites-via-torrents-and-phishing-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #Securelist #Kaspersky #Hackread #Phishing #security #malware #Crypto #Efimer #trojan #Fraud
-
Efimer Trojan Steals Crypto, Hacks WordPress Sites via Torrents and Phishing – Source:hackread.com https://ciso2ciso.com/efimer-trojan-steals-crypto-hacks-wordpress-sites-via-torrents-and-phishing-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #Securelist #Kaspersky #Hackread #Phishing #security #malware #Crypto #Efimer #trojan #Fraud
-
Efimer Trojan Steals Crypto, Hacks WordPress Sites via Torrents and Phishing https://hackread.com/efimer-trojan-crypto-hacks-wordpress-torrents-phishing/ #Cybersecurity #Securelist #Kaspersky #Security #Phishing #Malware #Crypto #Efimer #TROJAN #Fraud
-
Efimer Trojan Steals Crypto, Hacks WordPress Sites via Torrents and Phishing https://hackread.com/efimer-trojan-crypto-hacks-wordpress-torrents-phishing/ #Cybersecurity #Securelist #Kaspersky #Security #Phishing #Malware #Crypto #Efimer #TROJAN #Fraud
-
New trends in phishing and scams: how AI and social media are changing the game – Source: securelist.com https://ciso2ciso.com/new-trends-in-phishing-and-scams-how-ai-and-social-media-are-changing-the-game-source-securelist-com/ #securelist.com #0CISO2CISO
-
New trends in phishing and scams: how AI and social media are changing the game – Source: securelist.com https://ciso2ciso.com/new-trends-in-phishing-and-scams-how-ai-and-social-media-are-changing-the-game-source-securelist-com/ #securelist.com #0CISO2CISO
-
Scammers mass-mailing the Efimer Trojan to steal crypto – Source: securelist.com https://ciso2ciso.com/scammers-mass-mailing-the-efimer-trojan-to-steal-crypto-source-securelist-com/ #securelist.com #0CISO2CISO
-
Scammers mass-mailing the Efimer Trojan to steal crypto – Source: securelist.com https://ciso2ciso.com/scammers-mass-mailing-the-efimer-trojan-to-steal-crypto-source-securelist-com/ #securelist.com #0CISO2CISO
-
Driver of destruction: How a legitimate driver is being used to take down AV processes – Source: securelist.com https://ciso2ciso.com/driver-of-destruction-how-a-legitimate-driver-is-being-used-to-take-down-av-processes-source-securelist-com/ #securelist.com #0CISO2CISO
-
Driver of destruction: How a legitimate driver is being used to take down AV processes – Source: securelist.com https://ciso2ciso.com/driver-of-destruction-how-a-legitimate-driver-is-being-used-to-take-down-av-processes-source-securelist-com/ #securelist.com #0CISO2CISO
-
Kaspersky hat die durch ToolShell ausgenutzten Schwachstellen in Microsofts on-premise SharePont-Server intensiver aufgearbeitet.
Da bleibst staunend zurück.
https://securelist.com/toolshell-explained/117045/
#infosec #microsoft #toolshell #sharepoint #BeDiS #kaspersky #securelist -
Approach to mainframe penetration testing on z/OS. Deep dive into RACF – Source: securelist.com https://ciso2ciso.com/approach-to-mainframe-penetration-testing-on-z-os-deep-dive-into-racf-source-securelist-com/ #securelist.com #0CISO2CISO
-
Approach to mainframe penetration testing on z/OS. Deep dive into RACF – Source: securelist.com https://ciso2ciso.com/approach-to-mainframe-penetration-testing-on-z-os-deep-dive-into-racf-source-securelist-com/ #securelist.com #0CISO2CISO
-
SparkKitty, SparkCat’s little brother: A new Trojan spy found in the App Store and Google Play – Source: securelist.com https://ciso2ciso.com/sparkkitty-sparkcats-little-brother-a-new-trojan-spy-found-in-the-app-store-and-google-play-source-securelist-com/ #securelist.com #0CISO2CISO
-
SparkKitty, SparkCat’s little brother: A new Trojan spy found in the App Store and Google Play – Source: securelist.com https://ciso2ciso.com/sparkkitty-sparkcats-little-brother-a-new-trojan-spy-found-in-the-app-store-and-google-play-source-securelist-com/ #securelist.com #0CISO2CISO
-
Zanubis in motion: Tracing the active evolution of the Android banking malware – Source: securelist.com https://ciso2ciso.com/zanubis-in-motion-tracing-the-active-evolution-of-the-android-banking-malware-source-securelist-com/ #securelist.com #0CISO2CISO
-
Zanubis in motion: Tracing the active evolution of the Android banking malware – Source: securelist.com https://ciso2ciso.com/zanubis-in-motion-tracing-the-active-evolution-of-the-android-banking-malware-source-securelist-com/ #securelist.com #0CISO2CISO
-
GOFFEE continues to attack organizations in Russia – Source: securelist.com https://ciso2ciso.com/goffee-continues-to-attack-organizations-in-russia-source-securelist-com/ #securelist.com #0CISO2CISO
-
GOFFEE continues to attack organizations in Russia – Source: securelist.com https://ciso2ciso.com/goffee-continues-to-attack-organizations-in-russia-source-securelist-com/ #securelist.com #0CISO2CISO
-
Attackers distributing a miner and the ClipBanker Trojan via SourceForge – Source: securelist.com https://ciso2ciso.com/attackers-distributing-a-miner-and-the-clipbanker-trojan-via-sourceforge-source-securelist-com/ #securelist.com #0CISO2CISO
-
Attackers distributing a miner and the ClipBanker Trojan via SourceForge – Source: securelist.com https://ciso2ciso.com/attackers-distributing-a-miner-and-the-clipbanker-trojan-via-sourceforge-source-securelist-com/ #securelist.com #0CISO2CISO
-
A journey into forgotten Null Session and MS-RPC interfaces, part 2 – Source: securelist.com https://ciso2ciso.com/a-journey-into-forgotten-null-session-and-ms-rpc-interfaces-part-2-source-securelist-com/ #securelist.com #0CISO2CISO
-
A journey into forgotten Null Session and MS-RPC interfaces, part 2 – Source: securelist.com https://ciso2ciso.com/a-journey-into-forgotten-null-session-and-ms-rpc-interfaces-part-2-source-securelist-com/ #securelist.com #0CISO2CISO
-
TookPS: DeepSeek isn’t the only game in town – Source: securelist.com https://ciso2ciso.com/tookps-deepseek-isnt-the-only-game-in-town-source-securelist-com/ #securelist.com #0CISO2CISO
-
TookPS: DeepSeek isn’t the only game in town – Source: securelist.com https://ciso2ciso.com/tookps-deepseek-isnt-the-only-game-in-town-source-securelist-com/ #securelist.com #0CISO2CISO
-
Operation ForumTroll: APT attack with Google Chrome zero-day exploit chain – Source: securelist.com https://ciso2ciso.com/operation-forumtroll-apt-attack-with-google-chrome-zero-day-exploit-chain-source-securelist-com/ #securelist.com #0CISO2CISO
-
Operation ForumTroll: APT attack with Google Chrome zero-day exploit chain – Source: securelist.com https://ciso2ciso.com/operation-forumtroll-apt-attack-with-google-chrome-zero-day-exploit-chain-source-securelist-com/ #securelist.com #0CISO2CISO
-
DCRat backdoor returns – Source: securelist.com https://ciso2ciso.com/dcrat-backdoor-returns-source-securelist-com/ #securelist.com #0CISO2CISO
-
DCRat backdoor returns – Source: securelist.com https://ciso2ciso.com/dcrat-backdoor-returns-source-securelist-com/ #securelist.com #0CISO2CISO
-
Angry Likho APT Resurfaces with Lumma Stealer Attacks Against Russia – Source:hackread.com https://ciso2ciso.com/angry-likho-apt-resurfaces-with-lumma-stealer-attacks-against-russia-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #StickyWerewolf #cybersecurity #CyberAttacks #LummaStealer #Securelist #Kaspersky #Hackread #security #Belarus #malware #Russia #APT
-
Angry Likho APT Resurfaces with Lumma Stealer Attacks Against Russia – Source:hackread.com https://ciso2ciso.com/angry-likho-apt-resurfaces-with-lumma-stealer-attacks-against-russia-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #StickyWerewolf #cybersecurity #CyberAttacks #LummaStealer #Securelist #Kaspersky #Hackread #security #Belarus #malware #Russia #APT
-
Angry Likho APT Resurfaces with Lumma Stealer Attacks Against Russia https://hackread.com/angry-likho-apt-lumma-stealer-attacks-on-russia/ #StickyWerewolf #Cybersecurity #CyberAttacks #LummaStealer #Securelist #Kaspersky #Security #security #Malware #Belarus #Russia #APT
-
Angry Likho APT Resurfaces with Lumma Stealer Attacks Against Russia https://hackread.com/angry-likho-apt-lumma-stealer-attacks-on-russia/ #StickyWerewolf #Cybersecurity #CyberAttacks #LummaStealer #Securelist #Kaspersky #Security #security #Malware #Belarus #Russia #APT
-
Exploits and vulnerabilities in Q4 2024 – Source: securelist.com https://ciso2ciso.com/exploits-and-vulnerabilities-in-q4-2024-source-securelist-com/ #securelist.com #0CISO2CISO
-
Exploits and vulnerabilities in Q4 2024 – Source: securelist.com https://ciso2ciso.com/exploits-and-vulnerabilities-in-q4-2024-source-securelist-com/ #securelist.com #0CISO2CISO