home.social

#threatresearch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.

  1. Socket, posted yesterday, if you missed it:

    PolinRider Spreads Through Compromised GitHub Accounts and Packagist socket.dev/blog/polinrider-git @SocketSecurity #infosec #threatresearch #GitHub

  2. Socket, posted yesterday, if you missed it:

    PolinRider Spreads Through Compromised GitHub Accounts and Packagist socket.dev/blog/polinrider-git @SocketSecurity #infosec #threatresearch #GitHub

  3. Socket, posted yesterday, if you missed it:

    PolinRider Spreads Through Compromised GitHub Accounts and Packagist socket.dev/blog/polinrider-git @SocketSecurity #infosec #threatresearch #GitHub

  4. Socket, posted yesterday, if you missed it:

    PolinRider Spreads Through Compromised GitHub Accounts and Packagist socket.dev/blog/polinrider-git @SocketSecurity #infosec #threatresearch #GitHub

  5. Socket, posted yesterday, if you missed it:

    PolinRider Spreads Through Compromised GitHub Accounts and Packagist socket.dev/blog/polinrider-git @SocketSecurity #infosec #threatresearch #GitHub

  6. New.

    Huntress: Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM huntress.com/blog/new-settra-r @huntress

    More:

    Infosecurity-Magazine: New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing infosecurity-magazine.com/news #infosec #ransomware #threatresearch

  7. New.

    Huntress: Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM huntress.com/blog/new-settra-r @huntress

    More:

    Infosecurity-Magazine: New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing infosecurity-magazine.com/news #infosec #ransomware #threatresearch

  8. New.

    Huntress: Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM huntress.com/blog/new-settra-r @huntress

    More:

    Infosecurity-Magazine: New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing infosecurity-magazine.com/news #infosec #ransomware #threatresearch

  9. New.

    Huntress: Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM huntress.com/blog/new-settra-r @huntress

    More:

    Infosecurity-Magazine: New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing infosecurity-magazine.com/news #infosec #ransomware #threatresearch

  10. New.

    Huntress: Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM huntress.com/blog/new-settra-r @huntress

    More:

    Infosecurity-Magazine: New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing infosecurity-magazine.com/news #infosec #ransomware #threatresearch

  11. New.

    "During our analysis of malware that leverages blockchain networks for its C2 infrastructure, we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper."

    Kaspersky: The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents securelist.com/moviereaper-mal @Kaspersky #infosec #threatresearch #malware

  12. New.

    "During our analysis of malware that leverages blockchain networks for its C2 infrastructure, we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper."

    Kaspersky: The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents securelist.com/moviereaper-mal @Kaspersky #infosec #threatresearch #malware

  13. New.

    "During our analysis of malware that leverages blockchain networks for its C2 infrastructure, we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper."

    Kaspersky: The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents securelist.com/moviereaper-mal @Kaspersky #infosec #threatresearch #malware

  14. New.

    "During our analysis of malware that leverages blockchain networks for its C2 infrastructure, we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper."

    Kaspersky: The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents securelist.com/moviereaper-mal @Kaspersky #infosec #threatresearch #malware

  15. New.

    "During our analysis of malware that leverages blockchain networks for its C2 infrastructure, we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper."

    Kaspersky: The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents securelist.com/moviereaper-mal @Kaspersky #infosec #threatresearch #malware

  16. New.

    "Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025."

    ESET: Beware the SparroWock: The backdoor that bites, the commands that catch welivesecurity.com/en/eset-res @ESETresearch #infosec #threatresearch

  17. New.

    "Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025."

    ESET: Beware the SparroWock: The backdoor that bites, the commands that catch welivesecurity.com/en/eset-res @ESETresearch #infosec #threatresearch

  18. New.

    "Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025."

    ESET: Beware the SparroWock: The backdoor that bites, the commands that catch welivesecurity.com/en/eset-res @ESETresearch #infosec #threatresearch

  19. New.

    "Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025."

    ESET: Beware the SparroWock: The backdoor that bites, the commands that catch welivesecurity.com/en/eset-res @ESETresearch #infosec #threatresearch

  20. New.

    "Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow has switched to a new backdoor, SparroWocky, and has been deploying it to several countries in Latin America since at least August 2025."

    ESET: Beware the SparroWock: The backdoor that bites, the commands that catch welivesecurity.com/en/eset-res @ESETresearch #infosec #threatresearch

  21. Zimperium, from yesterday: RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts zimperium.com/blog/rathat-ai-p

    More:

    Infosecurity-Magazine: New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data infosecurity-magazine.com/news #infosec #malware #Android #cybercrime #threatresearch

  22. Zimperium, from yesterday: RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts zimperium.com/blog/rathat-ai-p

    More:

    Infosecurity-Magazine: New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data infosecurity-magazine.com/news #infosec #malware #Android #cybercrime #threatresearch

  23. Zimperium, from yesterday: RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts zimperium.com/blog/rathat-ai-p

    More:

    Infosecurity-Magazine: New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data infosecurity-magazine.com/news #infosec #malware #Android #cybercrime #threatresearch

  24. Zimperium, from yesterday: RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts zimperium.com/blog/rathat-ai-p

    More:

    Infosecurity-Magazine: New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data infosecurity-magazine.com/news #infosec #malware #Android #cybercrime #threatresearch

  25. Zimperium, from yesterday: RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts zimperium.com/blog/rathat-ai-p

    More:

    Infosecurity-Magazine: New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data infosecurity-magazine.com/news #infosec #malware #Android #cybercrime #threatresearch

  26. Fake “verify you’re human” prompts are being used to deliver NightshadeC2/CastleRAT.

    See WatchGuard Threat Lab’s latest ClickFix + EtherHiding research: wgrd.tech/3VfneYa

    #Cybersecurity #ThreatIntelligence #Malware #ThreatResearch

  27. In case you didn't have enough problems with cameras, here's another one.

    OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras opswat.com/blog/authentication

    More:

    Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping infosecurity-magazine.com/news #infosec #vulnerability #spyware #zeroday #threatresearch

  28. In case you didn't have enough problems with cameras, here's another one.

    OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras opswat.com/blog/authentication

    More:

    Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping infosecurity-magazine.com/news #infosec #vulnerability #spyware #zeroday #threatresearch

  29. In case you didn't have enough problems with cameras, here's another one.

    OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras opswat.com/blog/authentication

    More:

    Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping infosecurity-magazine.com/news #infosec #vulnerability #spyware #zeroday #threatresearch

  30. In case you didn't have enough problems with cameras, here's another one.

    OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras opswat.com/blog/authentication

    More:

    Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping infosecurity-magazine.com/news #infosec #vulnerability #spyware #zeroday #threatresearch

  31. In case you didn't have enough problems with cameras, here's another one.

    OPSWAT, posted yesterday: Authentication Bypass and DoS Vulnerabilities: OPSWAT Discovers CVE-2026-15315 & CVE-2026-15316 in TP-Link Tapo Cameras opswat.com/blog/authentication

    More:

    Infosecurity-Magazine: Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping infosecurity-magazine.com/news #infosec #vulnerability #spyware #zeroday #threatresearch

  32. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  33. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  34. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  35. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  36. A reexamination of recent OpenAI sins: 1) a cyberattack and 2) attempted theft of data.

    New.

    "In May 2026, a malicious package campaign forced RubyGems to suspend new registrations and remove hundreds of packages [1]. Researchers later linked the activity to OpenAI agents, reporting unauthorized code execution and attempted API-key theft [2]. OpenAI acknowledged its agents’ use of RubyGems to retrieve public information [3]. RubyGems could not independently confirm attribution and found no evidence of successful key theft."

    Picus: Inside the OpenAI-RubyGems Incident: Did AI Agents Attack RubyGems? picussecurity.com/resource/blo #infosec #threatresearch #RubyGems #cyberattack #OpenAI

  37. Cisco has addressed a critical September 2 vulnerability.

    CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

    More related to Cisco:

    Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

  38. Cisco has addressed a critical September 2 vulnerability.

    CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

    More related to Cisco:

    Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

  39. Cisco has addressed a critical September 2 vulnerability.

    CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

    More related to Cisco:

    Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

  40. Cisco has addressed a critical September 2 vulnerability.

    CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

    More related to Cisco:

    Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability

  41. Cisco has addressed a critical September 2 vulnerability.

    CRITICAL: CVE-2026-20274, CVE-2026-20275, and CVE-2026-20276: Cisco IOS XR Software Security Hardening Release: September 2026 sec.cloudapps.cisco.com/securi @TalosSecurity

    More related to Cisco:

    Rapid7: CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild rapid7.com/blog/post/etr-cve-2 @Rapid7Official #threatresearch #infosec #Cisco #vulnerability