#threathunting

17 posts· Last used 4d

What does Mythic C2 look like across the public Internet? Censys ARC sees 131 Mythic-associated hosts, and many leave recognizable fingerprints. The infrastructure also tells a deeper story. One cluster appeared consistent with a shared lab environment. Another revealed custom Rust implants, Discord-based C2 transport, steganographic staging, and infrastructure designed to blend with legitimate telemetry traffic. This new Censys Threat Overview maps Mythic across the Internet and shares detection signals defenders can use to hunt for it: https://censys.com/blog/mythic-c2/ #ThreatIntelligence #ThreatHunting #C2 #CensysARC
3
0
3
0
Sendmail sits in the path of every email transaction your organization sends or receives. It logs auth attempts, TLS negotiations, relay IPs, forged hostnames, and rejections. Most teams treat that as noise. It's early-warning threat telemetry. The Sendmail Content Pack for Graylog parses those logs into GIM-mapped events and a six-tab Illuminate dashboard, automatically. https://graylog.org/post/sendmail-data-in-graylog/ #SIEM #ThreatHunting #EmailSecurity
0
0
0
0
Threat Actor Claims 130GB Microsoft Corporate Data Breach A threat actor claims to have breached Microsoft and exfiltrated approximately 130 GB of corporate data, allegedly published on a TOR-based leak site. Full technical analysis: https://thecybersecguru.com/news/alleged-microsoft-data-breach-130gb-leak/ The claimed dataset reportedly includes PII, authentication-related information, password hashes, employee and customer records, internal service tickets, access permissions, and other corporate data. These claims remain unverified. Microsoft has not publicly confirmed that a breach occurred or that the alleged dataset is authentic. If validated, the exposure could enable credential attacks, phishing, business email compromise (BEC), identity theft, and other follow-on intrusions. #InfoSec #CyberSecurity #Microsoft #DataBreach #ThreatIntelligence #BlueTeam #DFIR #SOC #ThreatHunting #DarkWeb
1
0
0
0
Threat Actor Claims 130GB Microsoft Corporate Data Breach A threat actor claims to have breached Microsoft and exfiltrated approximately 130 GB of corporate data, allegedly published on a TOR-based leak site. The claimed dataset reportedly includes PII, authentication-related information, password hashes, employee and customer records, internal service tickets, access permissions, and other corporate data. These claims remain unverified. Microsoft has not publicly confirmed that a breach occurred or that the alleged dataset is authentic. If validated, the exposure could enable credential attacks, phishing, business email compromise (BEC), identity theft, and other follow-on intrusions. Full technical analysis: https://thecybersecguru.com/news/alleged-microsoft-data-breach-130gb-leak/ #InfoSec #CyberSecurity #Microsoft #DataBreach #ThreatIntelligence #BlueTeam #DFIR #SOC #ThreatHunting #DarkWeb
0
0
0
0
🚨 Alleged Microsoft Data Breach Claims Surface A threat actor claims to have breached Microsoft and exfiltrated approximately 130GB of corporate data, which is allegedly being published on a TOR-based leak site. The claimed dataset reportedly includes PII, employee and customer contact information, authentication-related data, password hashes, portal identities, corporate account information, internal service tickets, access permissions, and other internal records. At this time, these claims remain unverified, and Microsoft has not publicly confirmed that a breach occurred or that the alleged data is authentic. If validated, such information could significantly increase the risk of credential abuse, targeted phishing, business email compromise (BEC), identity theft, and follow-on intrusion attempts. Technical analysis and what defenders should know: 🔗 https://thecybersecguru.com/news/alleged-microsoft-data-breach-130gb-leak/ #CyberSecurity #InfoSec #DataBreach #Microsoft #ThreatIntelligence #BlueTeam #SOC #DFIR #ThreatHunting #IdentitySecurity #DarkWeb #BEC #OSINT
0
0
1
0
🕸️ Hoy Jueves 23 de Julio a las 3:00 pm (UTC -05:00) iniciamos el Curso Forense de Redes 2026 🕷️ 🚀 Jueves 23, Martes 28, Jueves 30 Julio y Martes 4 agosto 🎯 De 3:00 pm a 6:00 pm (UTC -05:00) 👁‍🗨 WhatsApp: https://wa.me/51949304030 👌 Info: https://www.reydes.com/archivos/cursos/Curso_Forense_Redes.pdf #DFIR #NetworkForensics #IncidentResponse #CyberSecurity #Wireshark #NetworkSecurity #ThreatHunting #PCAP
0
0
0
0
I don't want to push anyone, but I'd definitely apply for it. SRLabs is doing cool research and rather thrilling projects like [REDACTED]. I can personally vouch for @LisaLobmeyer@infosec.exchange as the responsible team lead for this position and in general the people at SRLabs are pretty chill, top tier hackers. https://security-research-labs.jobs.personio.de/job/2726007 PS: The only downside is, I'll be your colleague. But if you want to do some s*ck #threathunting and collect more CTI about threats like [REDACTED] and the incredible cool tooling of [REDACTED], then here's your chance. #getfedihired #DFIR #advertising
6
1
7
0
Some IPs probe a CVE's exact exploit path weeks before it's public, and if you're recording, you can see it. On April 11 one of our honeypots logged 16 requests for the cPanel WHM login path on port 2087 from 85[.]122[.]114[.]177, an address that has never touched us otherwise, before or since. 17 days later cPanel disclosed CVE-2026-41940, a 9.8 auth bypass in exactly that flow. Method, formulas, and the live table: https://honeylabs.net/blog/probe-17-days-before-the-cve #ThreatIntel #ThreatHunting #Honeypots #CVE #InfoSec #DFIR
0
0
0
0
A third SharePoint vulnerability is now being actively exploited. CVE-2026-50522 (CVSS 9.8) is a critical .NET deserialization vulnerability affecting on-premises SharePoint Server. Following the release of a public PoC, researchers observed attackers exploiting the flaw to extract ASP.NET machine keys, enabling persistent access beyond simply achieving RCE. One important point: applying Microsoft's patch may not be sufficient if a server was already compromised. Incident response should include reviewing IIS logs, investigating potential machine key exposure, and rotating compromised cryptographic secrets where necessary. I published a technical deep dive covering everything. Read here: https://thecybersecguru.com/news/sharepoint-cve-2026-50522-active-exploitation/ #InfoSec #CyberSecurity #SharePoint #Microsoft #DFIR #ThreatHunting #BlueTeam #Vulnerability
0
0
0
0
📢 Come join us in Atlanta, GA November 13-14 at Monday Night Brewing - The Grove, for #DEATHCon 2026 on-site! 📢 We'll have a ton of excellent workshops and interesting environments to explore, focusing on #threathunting and #detectionengineering! 🔍 🏹 Meet fellow practitioners, learn something new, and enjoy some great food and beverages in a relaxed, friendly setting! 🤝 🥪 https://www.simpletix.com/e/deathcon-atlanta-2026-tickets-280161
0
0
1
0
Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own. The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding. Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/ #Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity
1
0
0
0
Friendly reminder that the first round of DEATHCon tickets go on sale July 7th. I recommend setting a reminder and logging on earlier in the day (like, early morning) to purchase as they will sell out quick. DEATHCon is easily the best bang for your conference buck when it comes to the amount of presentations and available logs to cut your teeth on detection engineering and threat hunting. https://deathcon.io/tickets.html #deathcon #threathunting #detectionengineering #conference
0
0
0
0
🔵 THREAT INTELLIGENCE Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer Vulnerability | CRITICAL CVEs: CVE-2026-48558 An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously... Full analysis: https://www.yazoul.net/news/article/attackers-exploit-simplehelp-cve-2026-48558-to-deploy-taskweaver-and-djinn-steal #ThreatIntel #Malware #ThreatHunting
0
0
0
0
Network defenders should take a look at and hunt for Overlord RAT, a publicly-available and open-source Go-based RAT. Proofpoint recently published a blog post highlighting its adoption by UNK_DeadDrop, a DPRK-nexus threat group which appears to have used a lightly modified version but can still be detected via Shodan, Censys, or FOFA queries. Proofpoint notes minor operational overlaps with Contagious Interview, but UNK_DeadDrop appears to prefer Overlord while Contagious Interview sticks with OtterCookie/InvisibleFerret. Regardless, extraction of TTPs is super easy when the source code is available and great for folks who want an introduction into detection engineering and/or threat hunting. For example, Overlord RAT ships with default self-signed certificates/port configurations. While advanced adversaries will obviously alter these settings, many groups won’t, including UNK_DeadDrop. This makes developing a baseline detection within Censys/Shodan/FOFA trivial for monitoring. The Censys query in the screenshot is rudimentary, but you get the idea. Start with low-hanging fruit and tune your queries to hunt for advanced adversaries who might be using more bespoke Overlord configurations. Once found, ingest and retro-hunt the IOCs in your environment. Overlord clients will establish C2 communications with these servers. https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal https://github.com/vxaboveground/Overlord #overlord #unk_deaddrop #RAT #detectionengineering #threathunting #cti #threatintel
0
0
0
0
You've seen all posts