#threathunting

12 posts · Last used 3d

Back to Timeline
Alonso Caballero / ReYDeS @Alonso_ReYDeS@infosec.exchange · 3d ago
🕸️ Hoy Jueves 23 de Julio a las 3:00 pm (UTC -05:00) iniciamos el Curso Forense de Redes 2026 🕷️ 🚀 Jueves 23, Martes 28, Jueves 30 Julio y Martes 4 agosto 🎯 De 3:00 pm a 6:00 pm (UTC -05:00) 👁‍🗨 WhatsApp: https://wa.me/51949304030 👌 Info: https://www.reydes.com/archivos/cursos/Curso_Forense_Redes.pdf #DFIR #NetworkForensics #IncidentResponse #CyberSecurity #Wireshark #NetworkSecurity #ThreatHunting #PCAP
0
0
0
G0rb :possum: @g0rb@infosec.exchange · 3d ago
I don't want to push anyone, but I'd definitely apply for it. SRLabs is doing cool research and rather thrilling projects like [REDACTED]. I can personally vouch for @LisaLobmeyer@infosec.exchange as the responsible team lead for this position and in general the people at SRLabs are pretty chill, top tier hackers. https://security-research-labs.jobs.personio.de/job/2726007 PS: The only downside is, I'll be your colleague. But if you want to do some s*ck #threathunting and collect more CTI about threats like [REDACTED] and the incredible cool tooling of [REDACTED], then here's your chance. #getfedihired #DFIR #advertising
0
1
0
HoneyLabs @HoneyLabs@infosec.exchange · 3d ago
Some IPs probe a CVE's exact exploit path weeks before it's public, and if you're recording, you can see it. On April 11 one of our honeypots logged 16 requests for the cPanel WHM login path on port 2087 from 85[.]122[.]114[.]177, an address that has never touched us otherwise, before or since. 17 days later cPanel disclosed CVE-2026-41940, a 9.8 auth bypass in exactly that flow. Method, formulas, and the live table: https://honeylabs.net/blog/probe-17-days-before-the-cve #ThreatIntel #ThreatHunting #Honeypots #CVE #InfoSec #DFIR
0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · 4d ago
A third SharePoint vulnerability is now being actively exploited. CVE-2026-50522 (CVSS 9.8) is a critical .NET deserialization vulnerability affecting on-premises SharePoint Server. Following the release of a public PoC, researchers observed attackers exploiting the flaw to extract ASP.NET machine keys, enabling persistent access beyond simply achieving RCE. One important point: applying Microsoft's patch may not be sufficient if a server was already compromised. Incident response should include reviewing IIS logs, investigating potential machine key exposure, and rotating compromised cryptographic secrets where necessary. I published a technical deep dive covering everything. Read here: https://thecybersecguru.com/news/sharepoint-cve-2026-50522-active-exploitation/ #InfoSec #CyberSecurity #SharePoint #Microsoft #DFIR #ThreatHunting #BlueTeam #Vulnerability
0
0
0
technicalCISO💥​ @technicalciso@infosec.exchange · 4d ago
𝗪𝗵𝗮𝘁 𝗶𝗳 𝗲𝘃𝗲𝗿𝘆 𝗮𝗻𝗮𝗹𝘆𝘀𝘁 𝗵𝗮𝗱 𝗮𝗻 𝗲𝗻𝘁𝗶𝗿𝗲 𝗔𝗜 𝗦𝗢𝗖 𝘄𝗼𝗿𝗸𝗶𝗻𝗴 𝗮𝗹𝗼𝗻𝗴𝘀𝗶𝗱𝗲 𝘁𝗵𝗲𝗺? https://technicalciso.com/tc-visual-ai-soc-agents/ #CyberSecurity #SOC #SecurityOperations #AgenticAI #ArtificialIntelligence #ThreatDetection #ThreatHunting #IncidentResponse
0
0
0
Wes Lambert @weslambert@infosec.exchange · Jul 16, 2026
📢 Come join us in Atlanta, GA November 13-14 at Monday Night Brewing - The Grove, for #DEATHCon 2026 on-site! 📢 We'll have a ton of excellent workshops and interesting environments to explore, focusing on #threathunting and #detectionengineering! 🔍 🏹 Meet fellow practitioners, learn something new, and enjoy some great food and beverages in a relaxed, friendly setting! 🤝 🥪 https://www.simpletix.com/e/deathcon-atlanta-2026-tickets-280161
0
0
1
Graylog @Graylog@infosec.exchange · Jul 14, 2026
Suricata produces rich network telemetry, alerts, anomalies, flow data, DNS, TLS, SSH, Kerberos, and more, but raw EVE JSON isn't investigation ready on its own. The Suricata IDS/IPS Content Pack for Graylog parses, enriches, and maps that data to the Graylog Information Model, with a dashboard built in. Setup covers Filebeat via Sidecar or syslog forwarding. Full breakdown here: https://graylog.org/post/suricata-ids-ips-data-in-graylog/ #Graylog #Suricata #SIEM #ThreatHunting #InfoSec #NetworkSecurity
1
0
0
Taylor Parizo @taylorparizo@infosec.exchange · Jul 06, 2026
Is anyone using OpenSearch for homelab use? What log ingest tool did you go with? Fluent Bit seems to be the recommended approach for opensearch V3 since beats are too outdated at this point. Documentation / recommendations seem to be all over the place. #opensearch #ThreatHunting
0
4
0
Saltmyhash @saltmyhash@infosec.exchange · Jul 01, 2026
Friendly reminder that the first round of DEATHCon tickets go on sale July 7th. I recommend setting a reminder and logging on earlier in the day (like, early morning) to purchase as they will sell out quick. DEATHCon is easily the best bang for your conference buck when it comes to the amount of presentations and available logs to cut your teeth on detection engineering and threat hunting. https://deathcon.io/tickets.html #deathcon #threathunting #detectionengineering #conference
0
0
0
Yazoul - Cybersecurity Alerts @Matchbook3469@infosec.exchange · Jun 30, 2026
🔵 THREAT INTELLIGENCE Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer Vulnerability | CRITICAL CVEs: CVE-2026-48558 An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously... Full analysis: https://www.yazoul.net/news/article/attackers-exploit-simplehelp-cve-2026-48558-to-deploy-taskweaver-and-djinn-steal #ThreatIntel #Malware #ThreatHunting
0
0
0
Saltmyhash @saltmyhash@infosec.exchange · Jun 27, 2026
Network defenders should take a look at and hunt for Overlord RAT, a publicly-available and open-source Go-based RAT. Proofpoint recently published a blog post highlighting its adoption by UNK_DeadDrop, a DPRK-nexus threat group which appears to have used a lightly modified version but can still be detected via Shodan, Censys, or FOFA queries. Proofpoint notes minor operational overlaps with Contagious Interview, but UNK_DeadDrop appears to prefer Overlord while Contagious Interview sticks with OtterCookie/InvisibleFerret. Regardless, extraction of TTPs is super easy when the source code is available and great for folks who want an introduction into detection engineering and/or threat hunting. For example, Overlord RAT ships with default self-signed certificates/port configurations. While advanced adversaries will obviously alter these settings, many groups won’t, including UNK_DeadDrop. This makes developing a baseline detection within Censys/Shodan/FOFA trivial for monitoring. The Censys query in the screenshot is rudimentary, but you get the idea. Start with low-hanging fruit and tune your queries to hunt for advanced adversaries who might be using more bespoke Overlord configurations. Once found, ingest and retro-hunt the IOCs in your environment. Overlord clients will establish C2 communications with these servers. https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal https://github.com/vxaboveground/Overlord #overlord #unk_deaddrop #RAT #detectionengineering #threathunting #cti #threatintel
0
0
0

You've seen all posts