threat-intel Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th) Attackers are increasingly using hostname-based IP address obfuscation, specifically leveraging services like 1u.ms to bypass security measures. This tactic is used to exploit vulnerabilities like Server Side Request Forgery (SSRF) and requires careful monitoring of DNS logs and blocklists. SANS Internet Storm Center · 5d ago Medium ssrfdnsobfuscation
threat-intel Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic The Cavern C2 framework, used by Iranian nation-state hackers linked to the Ministry of Intelligence and Security (MOIS) and associated with groups like MuddyWater and OilRig (Lyceum), is undergoing continuous evolution.… The Hacker News · Aug 17, 2026 High IRc2dnsgoogle
threat-intel Hacking Public Wi-Fi DNS to Steal Credentials Attackers are exploiting vulnerabilities in public Wi-Fi networks to hijack DNS settings, leading to users being redirected to fraudulent login pages and having their credentials stolen. This technique bypasses standard… Schneier on Security · Aug 17, 2026 Medium dnswificredential theft
vulnerability Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack Microsoft released a security update containing 398 new vulnerabilities, with one zero-day flaw actively being exploited by Check Point Research's Lazarus group as part of Operation Dream Job. This zero-day (CVE-2026-688… The Hacker News · Aug 11, 2026 High CVE-2026-68820CVE-2026-62878CVE-2026-62893zero-dayrceexploit
vulnerability Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports Two critical vulnerabilities in Paperclip, an AI agent control plane, allow attackers to execute commands on a server or a developer's computer. The first vulnerability (CVE-2026-41679) requires no prior account or inter… The Hacker News · Aug 5, 2026 Critical CVE-2026-41679agentauthenticationdns
threat-intel Almost Half of Malware Samples Communicate Direct to IP Almost half (45.32%) of malware samples with Command & Control (C2) activity bypass DNS entirely, communicating directly to IP addresses. This behavior, known as D2IP, is prevalent across various threat types, including… Palo Alto Unit 42 · Aug 4, 2026 High BRd2ipdnsc2
threat-intel Wi-Fi public : ce que votre fournisseur, pirates et marketing peuvent voir This article highlights the significant data collection practices of Wi-Fi providers, even when users are using HTTPS. While HTTPS protects content, providers can still track domains visited, connection times, data trans… ZATAZ · Jul 28, 2026 Medium wifiprivacydns
threat-intel Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials A threat actor is exploiting vulnerabilities in public Wi-Fi gateways, particularly at hotels and conference centers, to steal corporate credentials, including Microsoft 365 accounts, and is leveraging tactics similar to… SecurityWeek · Jul 27, 2026 High USINSAdnscaptive portalcredential theft
threat-intel New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery Kaspersky researchers have uncovered a sophisticated new module, Project CAV3RN, leveraging Outlook calendar events accessed through Microsoft Graph for C2 communication and DNS AAAA records to recover configuration data… Securelist · Jul 21, 2026 High ISc2microsoftdns
threat-intel HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 A sophisticated espionage implant, dubbed HollowGraph, is using a hijacked Microsoft 365 calendar as its command and control channel to steal data and deliver instructions. The malware, linked to the Iranian threat group… The Hacker News · Jul 20, 2026 High ISIRespionagecommand-and-controlmicrosoft 365
threat-intel More Odd DNS Records: NIMLOC, (Tue, Jul 7th) This article discusses the continued use of NIMLOC DNS records, an obsolete record type originally designed for the Nimrod routing architecture. Despite the demise of NetBIOS and the shift to modern DNS and SMB protocols… SANS Internet Storm Center · Jul 7, 2026 Info dnsnetbiosmac
threat-intel RCS and DNS: The NAPTR Record, (Mon, Jul 6th) This article details the observation of NAPTR records being utilized in RCS (Rich Communication Services) communications, specifically within Verizon’s network. NAPTR records, defined in RFC 2915, are typically used to r… SANS Internet Storm Center · Jul 6, 2026 Medium USrcsdnsnaptr
threat-intel New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns A new stealthy backdoor, Mistic (MLTBackdoor), linked to the KongTuke IAB has been used in financially motivated attacks targeting organizations across insurance, education, IT, and professional services since April 2026… The Hacker News · Jun 25, 2026 High USbackdoorremote access trojanclickfix
malware AryStinger botnet infected thousands of D-Link routers worldwide A new botnet, named AryStinger, has been discovered compromising over 4,000 outdated D-Link routers worldwide, turning them into proxies for malicious traffic. The malware utilizes multiple vulnerabilities to perform sca… BleepingComputer · Jun 21, 2026 High CVE-2013-3307CVE-2016-5681CVE-2025-11837KRCNSErouterbotnetdns
threat-intel Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites An international law enforcement operation, dubbed Operation Endgame, successfully disrupted SocGholish’s infrastructure and removed malware from nearly 15,000 WordPress websites. The takedown, involving agencies from mu… The Hacker News · Jun 19, 2026 High NLCADEbotnetwordpressmalware
threat-intel ISC Stormcast For Thursday, June 18th, 2026 https://isc.sans.edu/podcastdetail/9978, (Thu, Jun 18th) The SANS Internet Storm Center's June 18th, 2026 Stormcast reported a heightened level of online threats and unusual network activity across various sectors. The broadcast highlighted several emerging trends, including i… SANS Internet Storm Center · Jun 18, 2026 Medium phishingdnsthreat-monitoring
threat-intel ISC Stormcast For Friday, June 12th, 2026 https://isc.sans.edu/podcastdetail/9970, (Fri, Jun 12th) The SANS Internet Storm Center's June 12th, 2026 Stormcast reported a heightened level of online threats and unusual network activity across various sectors. The broadcast highlighted several emerging trends, including i… SANS Internet Storm Center · Jun 12, 2026 Medium phishingdnsvulnerability
threat-intel Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address This article details a vulnerability in Microsoft Exchange, dubbed "Ghost-Sender," that allows attackers to spoof any email address by exploiting misconfigurations in Exchange Online and on-premises hybrid environments u… Dark Reading · Jun 9, 2026 High email spoofingexchangephishing
threat-intel Content Delivery Exploit Opens Websites to Brand Hijacking This article details a new exploit, dubbed "Underminr," that leverages vulnerabilities in Internet infrastructure to allow attackers to hijack websites and conceal malicious activity. The technique, a successor to domain… Dark Reading · May 21, 2026 High USEUCNcdndnsdomain fronting
vulnerability Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilities Microsoft released its May 2026 Patch Tuesday update, addressing 137 vulnerabilities across its product suite. The update includes a significant number of critical vulnerabilities, primarily remote code execution (RCE) f… Cisco Talos · May 12, 2026 High CVE-2026-32161CVE-2026-33109CVE-2026-33844rcebuffer overflowuse after free