threat-intel UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations Chinese-speaking cybercrime group UAT-10147 is leveraging AI-powered tools to automate complex post-compromise operations targeting web servers globally. The group, active since early 2026, utilizes a combination of publicly disclosed vulnerabilities and AI-generated exploitation guidance, reconnaissance, and payload g… Cisco Talos · Aug 20, 2026 High CVE-2022-0995CVE-2021-3156CVE-2015-5287CHBRBOaiautomationpost-exploitation
threat-intel Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers Researchers have discovered a post-exploitation technique leveraging Chrome DevTools Protocol (CDP) to steal cookies and sensitive data from running instances of Chrome and Edge on Windows. This method bypasses standard… The Hacker News · Aug 14, 2026 High cdpdevtoolscookie theft
threat-intel Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access Attackers exploited a SQL injection vulnerability in a public-facing web application to gain access to an Oracle database. They then leveraged a post-exploitation toolkit, ‘khunt,’ to execute commands on the underlying W… The Hacker News · Aug 6, 2026 High sql injectionkhuntpost-exploitation
threat-intel 22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th) A threat actor successfully exploited a vulnerable SSH honeypot within 22 seconds, injecting a backdoor SSH key, changing the root password, and clearing host-based access restrictions. This rapid post-exploitation seque… SANS Internet Storm Center · Aug 6, 2026 High CHsshautomationpost-exploitation
threat-intel StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader A new malware family, named SharkLoader, has been identified as part of a broader campaign targeting organizations globally, including diplomatic entities, government organizations, and software development companies. Th… Securelist · Jun 24, 2026 Medium CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikeexploitloader
threat-intel Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit An unknown threat actor exploited CVE-2026-39987 in Marimo to gain initial access, subsequently using a large language model (LLM) agent to conduct post-exploitation activities, including stealing credentials and exfiltr… The Hacker News · May 29, 2026 High CVE-2026-39987CNllmpost-exploitationcredential theft
malware Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor A new Linux malware, dubbed Showboat, has been used in a campaign targeting a telecommunications provider in the Middle East since at least 2022. The malware, developed by a China-linked threat actor group known as Calyp… The Hacker News · May 21, 2026 High CVE-2021-26855AFAZCHlinuxsocks5c2
threat-intel Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks This article details the discovery of "Showboat" (kworker), a Linux post-exploitation framework being shared among Chinese Advanced Persistent Threat (APT) groups, primarily Calypso and Red Lamassu. The malware has been… Dark Reading · May 21, 2026 Medium CHAFUKaptlinuxspyware