#threatresearch — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.
-
Socket, posted yesterday, if you missed it:
PolinRider Spreads Through Compromised GitHub Accounts and Packagist https://socket.dev/blog/polinrider-github-packagist @SocketSecurity #infosec #threatresearch #GitHub
-
Socket, posted yesterday, if you missed it:
PolinRider Spreads Through Compromised GitHub Accounts and Packagist https://socket.dev/blog/polinrider-github-packagist @SocketSecurity #infosec #threatresearch #GitHub
-
Socket, posted yesterday, if you missed it:
PolinRider Spreads Through Compromised GitHub Accounts and Packagist https://socket.dev/blog/polinrider-github-packagist @SocketSecurity #infosec #threatresearch #GitHub
-
Socket, posted yesterday, if you missed it:
PolinRider Spreads Through Compromised GitHub Accounts and Packagist https://socket.dev/blog/polinrider-github-packagist @SocketSecurity #infosec #threatresearch #GitHub
-
Socket, posted yesterday, if you missed it:
PolinRider Spreads Through Compromised GitHub Accounts and Packagist https://socket.dev/blog/polinrider-github-packagist @SocketSecurity #infosec #threatresearch #GitHub
-
New.
Huntress: Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM https://www.huntress.com/blog/new-settra-ransomware-variant @huntress
More:
Infosecurity-Magazine: New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing https://www.infosecurity-magazine.com/news/settra-ransomware-retail/ #infosec #ransomware #threatresearch
-
New.
Huntress: Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM https://www.huntress.com/blog/new-settra-ransomware-variant @huntress
More:
Infosecurity-Magazine: New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing https://www.infosecurity-magazine.com/news/settra-ransomware-retail/ #infosec #ransomware #threatresearch
-
New.
Huntress: Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM https://www.huntress.com/blog/new-settra-ransomware-variant @huntress
More:
Infosecurity-Magazine: New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing https://www.infosecurity-magazine.com/news/settra-ransomware-retail/ #infosec #ransomware #threatresearch
-
New.
Huntress: Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM https://www.huntress.com/blog/new-settra-ransomware-variant @huntress
More:
Infosecurity-Magazine: New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing https://www.infosecurity-magazine.com/news/settra-ransomware-retail/ #infosec #ransomware #threatresearch
-
New.
Huntress: Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM https://www.huntress.com/blog/new-settra-ransomware-variant @huntress
More:
Infosecurity-Magazine: New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing https://www.infosecurity-magazine.com/news/settra-ransomware-retail/ #infosec #ransomware #threatresearch
-
New.
"During our analysis of malware that leverages blockchain networks for its C2 infrastructure, we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper."
Kaspersky: The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/ @Kaspersky #infosec #threatresearch #malware
-
New.
"During our analysis of malware that leverages blockchain networks for its C2 infrastructure, we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper."
Kaspersky: The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/ @Kaspersky #infosec #threatresearch #malware
-
New.
"During our analysis of malware that leverages blockchain networks for its C2 infrastructure, we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper."
Kaspersky: The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/ @Kaspersky #infosec #threatresearch #malware
-
New.
"During our analysis of malware that leverages blockchain networks for its C2 infrastructure, we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper."
Kaspersky: The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/ @Kaspersky #infosec #threatresearch #malware
-
New.
"During our analysis of malware that leverages blockchain networks for its C2 infrastructure, we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper."
Kaspersky: The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/ @Kaspersky #infosec #threatresearch #malware
-
New.
"Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025."
ESET: Beware the SparroWock: The backdoor that bites, the commands that catch https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/ @ESETresearch #infosec #threatresearch
-
New.
"Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025."
ESET: Beware the SparroWock: The backdoor that bites, the commands that catch https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/ @ESETresearch #infosec #threatresearch
-
New.
"Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025."
ESET: Beware the SparroWock: The backdoor that bites, the commands that catch https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/ @ESETresearch #infosec #threatresearch
-
New.
"Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025."
ESET: Beware the SparroWock: The backdoor that bites, the commands that catch https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/ @ESETresearch #infosec #threatresearch
-
New.
"Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025."
ESET: Beware the SparroWock: The backdoor that bites, the commands that catch https://www.welivesecurity.com/en/eset-research/beware-sparrowock-backdoor-bites-commands-catch/ @ESETresearch #infosec #threatresearch
-
Zimperium, from yesterday: RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
More:
Infosecurity-Magazine: New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/ #infosec #malware #Android #cybercrime #threatresearch
-
Zimperium, from yesterday: RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
More:
Infosecurity-Magazine: New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/ #infosec #malware #Android #cybercrime #threatresearch
-
Zimperium, from yesterday: RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
More:
Infosecurity-Magazine: New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/ #infosec #malware #Android #cybercrime #threatresearch
-
Zimperium, from yesterday: RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
More:
Infosecurity-Magazine: New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/ #infosec #malware #Android #cybercrime #threatresearch
-
Zimperium, from yesterday: RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts https://zimperium.com/blog/rathat-ai-powered-mobile-threat-is-here-for-your-credentials-bank-accounts
More:
Infosecurity-Magazine: New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/ #infosec #malware #Android #cybercrime #threatresearch
-
Fake “verify you’re human” prompts are being used to deliver NightshadeC2/CastleRAT.
See WatchGuard Threat Lab’s latest ClickFix + EtherHiding research: https://wgrd.tech/3VfneYa
-
In case you didn't have enough problems with cameras, here's another one.
OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras
More:
Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/ #infosec #vulnerability #spyware #zeroday #threatresearch
-
In case you didn't have enough problems with cameras, here's another one.
OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras
More:
Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/ #infosec #vulnerability #spyware #zeroday #threatresearch
-
In case you didn't have enough problems with cameras, here's another one.
OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras
More:
Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/ #infosec #vulnerability #spyware #zeroday #threatresearch
-
In case you didn't have enough problems with cameras, here's another one.
OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras
More:
Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/ #infosec #vulnerability #spyware #zeroday #threatresearch
-
In case you didn't have enough problems with cameras, here's another one.
OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras https://www.opswat.com/blog/authentication-bypass-and-dos-vulnerabilities-opswat-discovers-cve-2026-15315-cve-2026-15316-in-tp-link-tapo-cameras
More:
Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/ #infosec #vulnerability #spyware #zeroday #threatresearch
-
A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.
New.
"In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."
Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? https://www.picussecurity.com/resource/blog/openai-rubygems-incident-ai-agents #infosec #threatresearch #RubyGems #cyberattack #OpenAI
-
A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.
New.
"In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."
Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? https://www.picussecurity.com/resource/blog/openai-rubygems-incident-ai-agents #infosec #threatresearch #RubyGems #cyberattack #OpenAI
-
A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.
New.
"In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."
Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? https://www.picussecurity.com/resource/blog/openai-rubygems-incident-ai-agents #infosec #threatresearch #RubyGems #cyberattack #OpenAI
-
A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.
New.
"In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."
Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? https://www.picussecurity.com/resource/blog/openai-rubygems-incident-ai-agents #infosec #threatresearch #RubyGems #cyberattack #OpenAI
-
A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.
New.
"In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."
Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? https://www.picussecurity.com/resource/blog/openai-rubygems-incident-ai-agents #infosec #threatresearch #RubyGems #cyberattack #OpenAI
-
Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
-
Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
-
Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
-
Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
-
Cisco has addressed a critical September 2 vulnerability.
CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM @TalosSecurity
More related to Cisco:
Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/ @Rapid7Official #threatresearch #infosec #Cisco #vulnerability
-
New.
Sophos: Devil’s advocate? Uncensored Luciferus AI service advertised underground https://www.sophos.com/en-us/blog/uncensored-luciferus-ai-service-advertised-underground @SophosXOps #infosec #threatresearch #scam
-
New.
Sophos: Devil’s advocate? Uncensored Luciferus AI service advertised underground https://www.sophos.com/en-us/blog/uncensored-luciferus-ai-service-advertised-underground @SophosXOps #infosec #threatresearch #scam
-
New.
Sophos: Devil’s advocate? Uncensored Luciferus AI service advertised underground https://www.sophos.com/en-us/blog/uncensored-luciferus-ai-service-advertised-underground @SophosXOps #infosec #threatresearch #scam
-
New.
Sophos: Devil’s advocate? Uncensored Luciferus AI service advertised underground https://www.sophos.com/en-us/blog/uncensored-luciferus-ai-service-advertised-underground @SophosXOps #infosec #threatresearch #scam
-
New.
Sophos: Devil’s advocate? Uncensored Luciferus AI service advertised underground https://www.sophos.com/en-us/blog/uncensored-luciferus-ai-service-advertised-underground @SophosXOps #infosec #threatresearch #scam
-
New.
Group-IB: Smish. Click. Drained: Inside the Smishing Triad's Phishing Cockpit https://www.group-ib.com/blog/smishing-triad-outsider-jwr/ #infosec #threatresearch #phishing
-
New.
Group-IB: Smish. Click. Drained: Inside the Smishing Triad's Phishing Cockpit https://www.group-ib.com/blog/smishing-triad-outsider-jwr/ #infosec #threatresearch #phishing
-
New.
Group-IB: Smish. Click. Drained: Inside the Smishing Triad's Phishing Cockpit https://www.group-ib.com/blog/smishing-triad-outsider-jwr/ #infosec #threatresearch #phishing
-
New.
Group-IB: Smish. Click. Drained: Inside the Smishing Triad's Phishing Cockpit https://www.group-ib.com/blog/smishing-triad-outsider-jwr/ #infosec #threatresearch #phishing