#threatresearch — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.
-
New.
Proofpoint: Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit #infosec #Windows #Microsoft #zeroday #Chrome #Google #threatresearch
-
New.
Group-IB: Vwork: Weaponized Open-source Software as an Addon for Gigabud https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/
More:
Infosecurity-Magazine: Gigabud Uses Android App Cloning to Evade Fraud Detection https://www.infosecurity-magazine.com/news/gigabud-android-app-cloning-fraud/ #infosec #fraud #Android #threatresearch
-
New.
Any.Run: HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures https://any.run/cybersecurity-blog/hvnc-backdoor-targets-latam/ @anyrun_app #infosec #malware #threatresearch #fraud #cybercrime
-
New.
Any.Run: HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures https://any.run/cybersecurity-blog/hvnc-backdoor-targets-latam/ @anyrun_app #infosec #malware #threatresearch #fraud #cybercrime
-
New.
Any.Run: HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures https://any.run/cybersecurity-blog/hvnc-backdoor-targets-latam/ @anyrun_app #infosec #malware #threatresearch #fraud #cybercrime
-
New.
Any.Run: HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures https://any.run/cybersecurity-blog/hvnc-backdoor-targets-latam/ @anyrun_app #infosec #malware #threatresearch #fraud #cybercrime
-
New.
Any.Run: HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures https://any.run/cybersecurity-blog/hvnc-backdoor-targets-latam/ @anyrun_app #infosec #malware #threatresearch #fraud #cybercrime
-
New.
Sekoia: Beyond Lazarus: Organization of DPRK cyber capabilities https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities @sekoia_io #threatresearch #threatintel #threatintelligence
-
New.
Sekoia: Beyond Lazarus: Organization of DPRK cyber capabilities https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities @sekoia_io #threatresearch #threatintel #threatintelligence
-
New.
Sekoia: Beyond Lazarus: Organization of DPRK cyber capabilities https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities @sekoia_io #threatresearch #threatintel #threatintelligence
-
New.
Sekoia: Beyond Lazarus: Organization of DPRK cyber capabilities https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities @sekoia_io #threatresearch #threatintel #threatintelligence
-
New.
Sekoia: Beyond Lazarus: Organization of DPRK cyber capabilities https://www.sekoia.com/blog/beyond-lazarus-organization-of-dprk-cyber-capabilities @sekoia_io #threatresearch #threatintel #threatintelligence
-
New.
Rapid7: CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED) https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/ @Rapid7Official #infosec #vulnerability #threatresearch
-
New.
Rapid7: CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED) https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/ @Rapid7Official #infosec #vulnerability #threatresearch
-
New.
Rapid7: CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED) https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/ @Rapid7Official #infosec #vulnerability #threatresearch
-
New.
Rapid7: CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED) https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/ @Rapid7Official #infosec #vulnerability #threatresearch
-
New.
Rapid7: CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED) https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/ @Rapid7Official #infosec #vulnerability #threatresearch
-
New.
Cisco: ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 https://blog.talosintelligence.com/clickfix-moves-into-the-browser/ @TalosSecurity #infosec #threatresearch #cybercrime #Google
-
New.
Cisco: ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 https://blog.talosintelligence.com/clickfix-moves-into-the-browser/ @TalosSecurity #infosec #threatresearch #cybercrime #Google
-
New.
Cisco: ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 https://blog.talosintelligence.com/clickfix-moves-into-the-browser/ @TalosSecurity #infosec #threatresearch #cybercrime #Google
-
New.
Cisco: ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 https://blog.talosintelligence.com/clickfix-moves-into-the-browser/ @TalosSecurity #infosec #threatresearch #cybercrime #Google
-
New.
Cisco: ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 https://blog.talosintelligence.com/clickfix-moves-into-the-browser/ @TalosSecurity #infosec #threatresearch #cybercrime #Google
-
CloudSek, from yesterday: Tracking BigBear 2.0 Evilginx2 Phishing Campaign https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign
More:
Infosecurity-Magazine: BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials https://www.infosecurity-magazine.com/news/bigbear-2-phaas-5000-microsoft/ #infosec #phishing #Microsoft #databreach #cybercrime #threatresearch
-
CloudSek, from yesterday: Tracking BigBear 2.0 Evilginx2 Phishing Campaign https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign
More:
Infosecurity-Magazine: BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials https://www.infosecurity-magazine.com/news/bigbear-2-phaas-5000-microsoft/ #infosec #phishing #Microsoft #databreach #cybercrime #threatresearch
-
CloudSek, from yesterday: Tracking BigBear 2.0 Evilginx2 Phishing Campaign https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign
More:
Infosecurity-Magazine: BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials https://www.infosecurity-magazine.com/news/bigbear-2-phaas-5000-microsoft/ #infosec #phishing #Microsoft #databreach #cybercrime #threatresearch
-
CloudSek, from yesterday: Tracking BigBear 2.0 Evilginx2 Phishing Campaign https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign
More:
Infosecurity-Magazine: BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials https://www.infosecurity-magazine.com/news/bigbear-2-phaas-5000-microsoft/ #infosec #phishing #Microsoft #databreach #cybercrime #threatresearch
-
CloudSek, from yesterday: Tracking BigBear 2.0 Evilginx2 Phishing Campaign https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign
More:
Infosecurity-Magazine: BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials https://www.infosecurity-magazine.com/news/bigbear-2-phaas-5000-microsoft/ #infosec #phishing #Microsoft #databreach #cybercrime #threatresearch
-
New.
Calif: WeWorm: The first zero-click worm to spread through WeChat calls across iOS and Android https://calif.io/research/weworm
More:
The Hacker News: WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html @thehackernews #infosec #threatresearch #Android #iOS #zeroclick
-
New.
Calif: WeWorm: The first zero-click worm to spread through WeChat calls across iOS and Android https://calif.io/research/weworm
More:
The Hacker News: WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html @thehackernews #infosec #threatresearch #Android #iOS #zeroclick
-
New.
Calif: WeWorm: The first zero-click worm to spread through WeChat calls across iOS and Android https://calif.io/research/weworm
More:
The Hacker News: WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html @thehackernews #infosec #threatresearch #Android #iOS #zeroclick
-
New.
Calif: WeWorm: The first zero-click worm to spread through WeChat calls across iOS and Android https://calif.io/research/weworm
More:
The Hacker News: WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html @thehackernews #infosec #threatresearch #Android #iOS #zeroclick
-
New.
Calif: WeWorm: The first zero-click worm to spread through WeChat calls across iOS and Android https://calif.io/research/weworm
More:
The Hacker News: WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html @thehackernews #infosec #threatresearch #Android #iOS #zeroclick
-
New.
Sophos: Dissecting a PHP web server rootkit https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit @SophosXOps
Broadcom: Attackers impersonate IT support in Microsoft Teams to deploy persistent Node.js backdoors https://www.broadcom.com/support/security-center/protection-bulletin/attackers-impersonate-it-support-in-microsoft-teams-to-deploy-persistent-node-js-backdoors #Broadcom #Microsoft #infosec #threatresearch #Teams #JavaScript
-
New.
Sophos: Dissecting a PHP web server rootkit https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit @SophosXOps
Broadcom: Attackers impersonate IT support in Microsoft Teams to deploy persistent Node.js backdoors https://www.broadcom.com/support/security-center/protection-bulletin/attackers-impersonate-it-support-in-microsoft-teams-to-deploy-persistent-node-js-backdoors #Broadcom #Microsoft #infosec #threatresearch #Teams #JavaScript
-
New.
Sophos: Dissecting a PHP web server rootkit https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit @SophosXOps
Broadcom: Attackers impersonate IT support in Microsoft Teams to deploy persistent Node.js backdoors https://www.broadcom.com/support/security-center/protection-bulletin/attackers-impersonate-it-support-in-microsoft-teams-to-deploy-persistent-node-js-backdoors #Broadcom #Microsoft #infosec #threatresearch #Teams #JavaScript
-
New.
Sophos: Dissecting a PHP web server rootkit https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit @SophosXOps
Broadcom: Attackers impersonate IT support in Microsoft Teams to deploy persistent Node.js backdoors https://www.broadcom.com/support/security-center/protection-bulletin/attackers-impersonate-it-support-in-microsoft-teams-to-deploy-persistent-node-js-backdoors #Broadcom #Microsoft #infosec #threatresearch #Teams #JavaScript
-
New.
Sophos: Dissecting a PHP web server rootkit https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit @SophosXOps
Broadcom: Attackers impersonate IT support in Microsoft Teams to deploy persistent Node.js backdoors https://www.broadcom.com/support/security-center/protection-bulletin/attackers-impersonate-it-support-in-microsoft-teams-to-deploy-persistent-node-js-backdoors #Broadcom #Microsoft #infosec #threatresearch #Teams #JavaScript
-
⚠️ Smishing alert for Greek citizens. 💳 🚨
Scammers are pushing fake AADE (Independent Authority for Public Revenue) “unpaid taxes” SMS that lead to cloned payment pages designed to steal credit‑card info. If a text suddenly demands urgent payment, treat it like a pop‑up from nowhere—don’t click, don’t trust, don’t pay. Share to protect others.mycargr[.]com
aadcar[.]com
aadgee[.]com
aadgre[.]com#CyberThreatIntel #Infoblox #DNS #ThreatResearch #phishing #smishing #Cybercrime #AADE #Greece
-
Sophos MDR tracks two ransomware campaigns using “email bombing,” Microsoft Teams “vishing” – Source: news.sophos.com https://ciso2ciso.com/sophos-mdr-tracks-two-ransomware-campaigns-using-email-bombing-microsoft-teams-vishing-source-news-sophos-com/ #rssfeedpostgeneratorecho #remotemachinemanagement #legitimateserviceabuse #MicrosoftOffice365 #SecurityOperations #CyberSecurityNews #ThreatResearch #nakedsecurity #pythonmalware #nakedsecurity #Javamalware #QuickAssist #blackbasta #BlackBasta