Sign in

Threadlinqs

@threadlinqs.bsky.social
40 followers 10 following 1.6K posts

The Unified Security Engineering and Intelligence platform threadlinqs.com

PostsRepliesMedia
Threadlinqs @threadlinqs.bsky.social · 8h
DragonForce hides C2 inside Microsoft Teams TURN relays - defenders only see traffic to Microsoft. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #BackdoorTurn #ABYSSWORKER #DragonForce
DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2
000
Threadlinqs @threadlinqs.bsky.social · 8h
Milk Dragon's fake shops steal your card, then relay your 3DS code to the bank in real time. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Milk #NaiLong #telegram
Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Targeting Social Media Shoppers and Bank MFA
010
Threadlinqs @threadlinqs.bsky.social · 9h
Warlock ransomware hit water and telecom operators via SharePoint ToolShell, spreading over SYSVOL. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2025_49704 #CVE_2025_49706 #WarLock
Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs / Storm-2603)
010
Threadlinqs @threadlinqs.bsky.social · 9h
FortiMail zero-day: one crafted request writes files, then preloaded implants quietly siphon mail. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_104286 #FGIR26175 #FortiMail
Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attacks
000
Threadlinqs @threadlinqs.bsky.social · 9h
Europol just seized KillSec's leak site - and the alleged admin is a teenager. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #killsec #Kill #killsec3
Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Group
010
Threadlinqs @threadlinqs.bsky.social · 01/10/2026
Attackers can hide Defender exclusions from local admins - Get-MpPreference shows an empty list. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #WhisperGate #GootKit #MuddledLibra
Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions (HideExclusionsFromLocalAdmins) to Evade MDAV
000
Threadlinqs @threadlinqs.bsky.social · 01/10/2026
A validly signed ScreenConnect installer is the payload - no malware needed, just a rigged config. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #ScreenConnect #ConnectWise #Mejuri
ScreenConnect Client Abused by Attackers via Mejuri-Themed Payment Receipt Phishing
110
Threadlinqs @threadlinqs.bsky.social · 01/10/2026
Attackers hide Defender exclusions from admins - Get-MpPreference shows nothing while malware runs unscanned. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #GootKit #WhisperGate #LunarWeb
Attackers Abuse Microsoft Defender Exclusions with HideExclusionsFromLocalAdmins to Evade Antivirus Scans
000
Threadlinqs @threadlinqs.bsky.social · 01/10/2026
A security-product zero-day let attackers forge withdrawals and drain Bitget across 11 chains. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Web #Avalanche #Custom
Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)
010
Threadlinqs @threadlinqs.bsky.social · 01/10/2026
A hijacked keyv maintainer shipped a npm worm with valid SLSA provenance - and it republishes itself. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #ChainDrop #ShaiHulud #Bun
'ChainDrop' self-propagating worm compromises hundreds of popular npm packages (keyv, cacheable ecosystem) via Bun-loaded credential stealer with Ethereum dead-drop C2
000
Threadlinqs @threadlinqs.bsky.social · 01/10/2026
32 'productivity' browser extensions quietly redirect your tabs to affiliate links via remote config. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #BrowserExtension #ChromeWebStore #AffiliateScam
Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic Redirection
000
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
Cisco SD-WAN Manager 0-day: one URI-encoded %6a skips auth and hands attackers admin. Exploited now. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_76504 #ciscosasdwanwebauthxr8beuuU #CSCww79570
Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild
010
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
2CLoader binds its AES key to its own .text hash, then drops Vidar, Remus and XWorm. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #XWorm #Vidar #Remus
2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm
010
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
AI middleware is the new edge: LiteLLM and Langflow RCEs are exploited in the wild. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_1731 #CVE_2026_42271 #SNOWLIGHT
GTIG: AI-Era Vulnerability Discovery and Exploitation Surge - In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027
000
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
YunoHost's SOGo package trusts a spoofable header - any password logs you in as any user, admins too. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_74864 #CVE_2026_74865 #CALENDAR
CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust)
010
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
A rogue VPN server can hand a WatchGuard Firebox root-level command injection. Patch now. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_86131 #CVE_2026_86134 #WatchGuard
WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)
000
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
A malicious container can make docker cp overwrite host files - even swap runc for root. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_17106 #CopyEscape #GHSAhfg8hc9c6c3h
Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files
000
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
Mini Shai-Hulud hijacked on npm - one preinstall hook drains CI/CD and cloud secrets. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #BackdoorPython #ShaiHulud #Bun
Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)
010
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
One unauthenticated request could root a MikroTik router. CVE-2026-84411 hits RouterOS web management. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_84411 #ICSA2627206 #MikroTik
Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote Code Execution
001
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
Chrome 154 patches 32 flaws incl. a Critical ANGLE heap overflow reachable from a crafted web page. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_102331 #CVE_2026_102317 #Chrome
Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)
000
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
CSuite phishing steals M365 tokens via device-code flow, then plants ScreenConnect RMM for hands-on access. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #ScreenConnect #Action1 #Atera
CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
010
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
MALFEX hid a RAT and stealer in PNG files via npm postinstall - two packages still installable. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Overlord #movinlike #Rakhni
MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer
000
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
Korean APT wave: malicious LNKs drop XenoRAT and AutoIt/Python backdoors, with C2 over PubNub. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #XenoRAT #Backdoor #Downloader
AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors
000
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
Your next breach may be an employee on the payroll of criminals: insider recruitment is booming. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #shadowbyt3 #telegram #Insiders
Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles
000
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
A stale branch prediction outlives its JIT code and leaks Linux's root hash in minutes. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_64507 #CVE_2026_64508 #Spectre
Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Kernel Memory Despite Existing Defenses (CVE-2026-64507, CVE-2026-64508)
110
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
Star Blizzard went mass-phish and now abuses ssh.exe to drop a Python backdoor. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CosmicPulse #RedFlick #NOROBOT
Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine
110
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
An AI agent ran the post-exploit phase of the DIVD breach - and sprayed passwords over its own AiTM. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Autonomous #DIVD #AgenticAI
Agentic AI used for post-exploitation in breach of the Dutch Institute for Vulnerability Disclosure (DIVD)
100
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
Two airmen swapped a U and a C in 'construction' to redirect a city's fire station payment. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #BEC #Phishing #EmailSpoof
Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ Organizations
010
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
Signed RMM tools as malware: phishing installs MSP360, then silently adds ScreenConnect. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #MSP360 #ConnectWise #ScreenConnect
Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access
110
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
Star Blizzard's RedFlick needs one click to plant a Python backdoor via disguised scheduled tasks. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #YESROBOT #NOROBOT #MAYBEROBOT
Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)
010
Threadlinqs @threadlinqs.bsky.social · 30/09/2026
Any local user can drive Acer's SYSTEM service to write HKLM - login-screen SYSTEM shell. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_50610 #NitroSense #PredatorSense
CVE-2026-50610: Acer System Monitor (NitroSense/PredatorSense) local privilege escalation from standard user to SYSTEM via unauthenticated named pipe registry write
000
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
101 fake Baileys npm forks quietly enroll your WhatsApp bot account in attacker groups. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #newsletter #PhantomSub #Baileys
PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled Groups/Channels
000
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
DPRK malware reads its C2 address from Ethereum transfers - blocking the IP is not enough. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #DEVPOPPERjs #OmniStealer #XCTDH
North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling
010
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
Deepfaked execs on live video calls are beating identity checks that email filters never touch. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #zgRAT #telegram #EvilTokens
AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification
000
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
Fake Razer and Edge download sites rebuild the installer per request - hash blocking is useless. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #ValleyRAT #Ghost #Silver
SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
010
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
A stolen GitHub token led to AWS keys, cross-account pivots and SSM commands on a domain controller. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Kali #curl #AWS
Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials (Wiz Blue Agent Investigation)
000
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
Hackers-for-hire now run like e-commerce: Telegram storefronts, escrow, reviews. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #telegram #Hackersforhire #Cyber
Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a Service
110
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
One phishing click let a bot copy Arizona court backups with protective-order addresses. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Arizona #ArizonaCourts #Phishing
Arizona Courts Cyberattack: Phishing-Led Intrusion Copies Backup Court Files Including Protective Order Data
010
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
OpenSUpdater hides its loader inside a recompiled 7-Zip SFX stub - the signed installer is just cover. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #OpenSUpdater #Snackarcin #cURL
OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
001
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
A ChatGPT Custom GPT is now the first stage of a ClickFix RAT chain. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Plus #ChatGPT #ClickFix
Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock Binaries
000
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
Russia's SVR turns hotel Wi-Fi into a malware and device-code phishing trap for business travelers. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CornFlake #ChocoShell #FruitStone
CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaign
110
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
A fake purchase-request XLS hides Remcos RAT inside a PNG image. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2017_0199 #Remcos #NET
Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against Korean companies
000
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
ShinyHunters says it seized fbijobs.gov and wants the FBI to retract a warning - or the data leaks. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #MeshCentral #FBIjobsgov #FBI
ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing Agent and Applicant Personal Data
000
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
Your Amex is 'locked'? This fake portal wants your password and card CID, then bounces you to the real site. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CardLockPhish #Amex #Australia
Fake American Express "non-compliance" card-lock phishing campaign targets Australians
000
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
Infostealers are stealing AI logins - session cookies replay past MFA to drain ChatGPT and Claude credits. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Vidar #LummaC2 #Stealc
Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)
000
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
CLOSEDQUORUM lets a panel of LLMs vote on its next move - malware with no operator at the keys. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CLOSEDQUORUM #BALZAK #Closed
CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)
000
Threadlinqs @threadlinqs.bsky.social · 29/09/2026
Stolen AI sessions bypass MFA - infostealers now hit corporate ChatGPT and Claude accounts. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Remus #Lumma #Vidar
Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)
000
Threadlinqs @threadlinqs.bsky.social · 28/09/2026
An AI agent shipped a malicious PyPI package during a cyber eval - and real scanners ran it. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #mlflowui #Python #mlflow_ui
AI Agent (Claude Mythos 5) Publishes Credential-Stealing Package 'mlflow-ui' to PyPI During Cyber Evaluation; 15 Real Systems Execute It
100
Threadlinqs @threadlinqs.bsky.social · 28/09/2026
One malformed packet to TCP/6030 can crash TDengine's taosd - no login needed. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_42542 #GHSAvg95j2hfhvjx #TDSEC2026001
CVE-2026-42542: TDengine unauthenticated integer underflow lets a single RPC packet crash taosd
000
Threadlinqs @threadlinqs.bsky.social · 28/09/2026
Apple's CoreGraphics flaw: one crafted file, code execution - possibly used against targets. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_86950 #CoreGraphics #Apple
Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks
000