Sign in

Threadlinqs

@threadlinqs.bsky.social
42 followers 10 following 1.6K posts

The Unified Security Engineering and Intelligence platform threadlinqs.com

PostsRepliesMedia
Threadlinqs @threadlinqs.bsky.social · 6h
Nikkei's hijacked mailbox phished journalistic sources from a sender they already trusted. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Nikkei #M365Hijack #GoogleWorkspace
Nikkei discloses Microsoft 365 and Google Workspace employee account compromises; ~9,000 phishing emails sent
000
Threadlinqs @threadlinqs.bsky.social · 7h
Cyber Partisans hid in a Russian health network for 2 years, taking orders over Telegram. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Vasilek #PartisanDNS #DNSCat2
Belarusian Cyber Partisans maintain two-year undetected access to Russian healthcare network using Vasilek Telegram backdoor
000
Threadlinqs @threadlinqs.bsky.social · 7h
ShinyHunters' alleged admin 'Rey' is detained and reportedly talking to the FBI. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #ShinySp1d3r #scattered #telegram
ShinyHunters: alleged leader 'Rey' (Saif al-Din Khader) detained in Jordan and reportedly cooperating with the FBI; Dutch suspect Pepijn van der Stap ('Umbreon') arrested
000
Threadlinqs @threadlinqs.bsky.social · 8h
Citrix NetScaler SAML bug crashes gateways - attackers may be using it to speed up RCE. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_88779 #CVE_2026_88771 #NetScaler
Citrix NetScaler ADC/Gateway SAML memory-overflow DoS CVE-2026-88779 actively exploited; added to CISA KEV alongside still-exploited CVE-2026-88771/88772
000
Threadlinqs @threadlinqs.bsky.social · 11h
Booba ransomware claims 344 GB from UIC's medical school - a suspected Frag rebrand. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Booba #frag #Akira
Booba ransomware (reported Frag rebrand) hits University of Illinois Chicago College of Medicine
000
Threadlinqs @threadlinqs.bsky.social · 11h
Ploutus turns ATMs into cash dispensers via XFS - its alleged developer is now in a US court. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Ploutus #PloutusD #Prometheus
Alleged Ploutus ATM Malware Developer Anibal Canelon Aguirre ('Prometheus'/'The Engineer') Appears in US Court; Tren de Aragua ATM Jackpotting Campaign
000
Threadlinqs @threadlinqs.bsky.social · 11h
A crafted HEIC upload can turn a WordPress Author account into code execution via libheif. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #libheifunciwordpressrce #GHSAx8r2mggjj6wr #GHSA2jg24ch7h545
Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers via ImageMagick/libheif (GHSA-x8r2-mggj-j6wr)
000
Threadlinqs @threadlinqs.bsky.social · 12h
Dell's DSU update tool had an unauthenticated path traversal to root RCE. Patch to 2.3.0.0. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_86360 #CVE_2026_63697 #DSA2026324
Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS 9.6) allows unauthenticated root code execution, plus four high-severity flaws fixed in DSU 2.3.0.0
000
Threadlinqs @threadlinqs.bsky.social · 12h
ClingSTUN hides proxy-botnet C2 in public STUN traffic - routers and DVRs look like VoIP. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2022_36553 #CVE_2025_34035 #ClingSTUN
ClingSTUN Linux Backdoor Turns Unpatched IoT Devices Into Proxy Nodes via Public STUN Infrastructure
000
Threadlinqs @threadlinqs.bsky.social · 15h
A validly signed ScreenConnect installer, posing as a PDF, hands attackers remote access. No malware needed. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #ConnectWise #ScreenConnect #WireTransferPhish
Phishing Campaign Abuses Legitimate ScreenConnect Client for Remote Access via Fake Payment Notification
000
Threadlinqs @threadlinqs.bsky.social · 15h
Struts S2-045 still sells access in 2026, next to a 19M SMTP dump and a $2,200 RDP auction. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2017_5638 #French #IQUALIF
IQUALIF French Residential Data Leak, IUT Paris Seine Breach, 19M SMTP Credential Dump and Apache Struts CVE-2017-5638 Access Sale
000
Threadlinqs @threadlinqs.bsky.social · 15h
CARBONATO botnet hands exposed Docker hosts to an AI agent that hunts your LLM API keys. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CARBONATO #FSociety #xmrig
CARBONATO: Botnet Built Around an AI Agent (Hermes Agent) Spreading via Exposed Docker APIs
000
Threadlinqs @threadlinqs.bsky.social · 16h
Ransomware affiliate Azazel used MCP exec_in_session as C2 after raiding CI/CD secrets. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Gentlemen #azazel #Penelope
Azazel: Gentlemen Ransomware Affiliate Compromises 24+ Organizations via Stolen CI/CD Secrets, Abuses MCP as C2 and Runs LEAKNED Leak Site
000
Threadlinqs @threadlinqs.bsky.social · 16h
Google's AI agent proved 500+ XSS bugs with live exploits, then chained one into an admin console XSS. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Tag #PageBreak #CodeMender
Google's PageBreak AI Agent Finds 500+ Verified XSS Flaws and Builds Working Exploit Chains
000
Threadlinqs @threadlinqs.bsky.social · 17h
NetScaler's new SAML zero-day is hitting appliances that were patched just days ago. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_88779 #CVE_2026_88771 #PitScaler
Citrix NetScaler ADC/Gateway Zero-Day CVE-2026-88779 ("PitScaler 2") Exploited Against Appliances Patched Days Earlier (CISA KEV)
000
Threadlinqs @threadlinqs.bsky.social · 05/10/2026
Milk Dragon's fake discount shops relay your 3-D Secure OTP to the attacker live. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Milk #NaiLong #telegram
Milk Dragon (NaiLong) Phishing-as-a-Service Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA
000
Threadlinqs @threadlinqs.bsky.social · 05/10/2026
A fake Claude Code ad tells Mac devs to paste a Terminal command. It installs AMOS Stealer. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #AMOS #MacSync #Atomic
Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)
000
Threadlinqs @threadlinqs.bsky.social · 05/10/2026
OpenAI says Moonshot-linked accounts replayed encrypted reasoning to steal its hidden chain-of-thought. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #OpenAI #Encrypted #Moonshot
Coordinated model-distillation campaign against OpenAI: 15,000+ accounts attempt to extract protected model reasoning, linked to Moonshot AI-associated individuals
000
Threadlinqs @threadlinqs.bsky.social · 05/10/2026
A low-privileged cPanel account can reach root via the Multilang adminbin. Patch WHM now. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_93698 #CVE_2026_93029 #cPanel
Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698, CVE-2026-93029, CVE-2026-93697) Enable Root Code Execution and Admin Session Hijacking
000
Threadlinqs @threadlinqs.bsky.social · 05/10/2026
No MFA, stolen infostealer creds: 165 Snowflake tenants looted. The extortionist just pleaded guilty. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Vidar #RisePro #REDLINE
Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guilty
000
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
TeamViewer patches a session permission bypass that can lead to RCE, plus four local privesc bugs. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_92370 #CVE_2026_19743 #TeamViewer
Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371, CVE-2026-19743)
000
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
Kiteworks 9.5.1 patches two critical account-takeover flaws, one needing no authentication. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_102141 #CVE_2026_102142 #Kiteworks
Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)
000
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
Milk Dragon's phishing kit watches you type your card in real time, then relays your 3DS OTP. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Milk #NaiLong #telegram
Milk Dragon (NaiLong) AiTM Phishing-as-a-Service Kit Uses Real-Time OTP Relay and WebSocket Keylogging to Bypass MFA
000
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
Kairos says it holds 762 GB of Vermont school data. The board refused to pay - the leak clock is running. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #kairos #K12Ransomware #Extortion
Kairos Data-Extortion Group Claims Slate Valley Unified School District (Vermont); 762 GB Claimed, Board Declines Ransom, Leak Imminent
010
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
Ransomware is going after managers: fake IT on Teams, then ClickFix in the Run box. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #ClickFix #Ransomware #Teams
Ransomware Moves up the Org Chart: Managers Are Prime Targets (Zscaler ThreatLabz, 351 Victims / 334 Organizations)
000
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
Unauthenticated SAML bug lets attackers reboot-loop Citrix NetScaler gateways - now in CISA KEV. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_88779 #Citrix #NetScaler
CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Catalog
000
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
One tapped link in a Capacitor app WebView can run attacker script at the app's own origin. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_103922 #CapacitorHttp #GHSArvm3566mv7fv
Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features (CVE-2026-103922)
000
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
One week, four campaigns: SonicWall 0-days, ClickFix cache PNGs, and C2 hidden in Ethereum. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_15409 #CVE_2026_15410 #DOUBLECUP
QuoIntelligence Weekly Snapshot W32 2026: DOUBLECUP ClickFix loader, UTA0533 SonicWall SMA1000 zero-day chain (CVE-2026-15409/15410), Greatness AiTM/device-code PhaaS, EtherRAT blockchain C2
000
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
A cookie secret named after the cookie itself let attackers skip Entra MFA and become admin. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #YMS #EntraID #SessionForgery
Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and Enables User and Admin Impersonation
000
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
A free iCloud account could send mail as tim.cook@icloud.com and still pass DMARC. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #smtpsmugglingcom #iCloud #From
Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC
000
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
A WordPress toolkit mines forgotten backup and .env files for live AWS keys and SMTP logins. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_60137 #CVE_2026_63030 #TIKTOUK
TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files (CVE-2026-60137, CVE-2026-63030)
000
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
A fake Anthropic employee is phishing AI policy experts, and MFA will not save them. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #Evilginx #Frameless #TA419
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)
000
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
AI agents now weaponize Citrix NetScaler bugs within hours - HexStrike-AI automates the whole kill chain. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2025_7775 #CVE_2025_7776 #ATLAS
Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated Large-Scale Attacks, incl. CVE-2025-7775 Citrix NetScaler
000
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
An LLM agent ran ransomware end to end - Langflow RCE to wiped AI models. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2025_3248 #CVE_2021_29441 #ENCFORGE
AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app exploitation, and AI-enabled attacker tooling (s1ngularity, PromptLock, JADEPUFFER/ENCFORGE)
000
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
Vercel confirms a KVM 0-day: full guest-to-host root escape. No CVE or patch yet. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #KVM #Vercel #VMEscape
Vercel Confirms KVM Zero-Day Guest-to-Host VM Escape (Root on Host) via Sandbox Bug Bounty; $50,000 Bounty Awarded
010
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
Apache httpd 2.4.69 patches 20 CVEs, from Host header stack overflow to WebDAV corruption. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_42356 #CVE_2026_42528 #Apache
Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69)
000
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
New Linux implants pose as mail security appliances and hide C2 in SMTP on port 25. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #BPFDoor #Rekoobe #AVERAT
BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances (SMTP/TCP 25 C2)
001
Threadlinqs @threadlinqs.bsky.social · 04/10/2026
A Viewer account on Red Hat Satellite can read host root passwords. Patch now. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_96659 #CVE_2026_96658 #Foreman
Red Hat Satellite Foreman template preview authorization flaw (CVE-2026-96659) enables root password theft and code execution
000
Threadlinqs @threadlinqs.bsky.social · 03/10/2026
EvilTokens phishes the real Microsoft login page - victims type the code, attackers get the tokens. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #EvilTokens #telegram #Storm
EvilTokens (Storm-2992): AI-Chatbot Device-Code Phishing Service Disrupted by Microsoft DCU, Plus AI-Enabled Deepfake and Crypto Drainer Fraud (TRM Labs)
000
Threadlinqs @threadlinqs.bsky.social · 03/10/2026
Attackers turned SQL Server xp_cmdshell into C2 and exfil - files leave as Base64 in query output. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #MimiKatz #cmd #MSSQL
Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva Aerobus-Linked Intrusion
000
Threadlinqs @threadlinqs.bsky.social · 03/10/2026
A predictable Math.random() key lets attackers forge HFS admin cookies and run code. Exploited now. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_61500 #Z3 #Rejetto
Rejetto HTTP File Server (HFS) 3.x session forgery via predictable Math.random() signing key leads to unauthenticated admin access and RCE (CVE-2026-61500) under active exploitation
000
Threadlinqs @threadlinqs.bsky.social · 03/10/2026
Patched Exchange in September? Microsoft's V2 reissue adds a mailbox access fix the first release missed. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_96940 #Exchange #Microsoft
Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization Flaw
000
Threadlinqs @threadlinqs.bsky.social · 03/10/2026
A Mississippi city pulled its networks offline after ransomware. 911 stayed up, utility billing did not. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #MEDUSA #Grief #Vicksburg
City of Vicksburg, Mississippi shuts down systems after ransomware attack
000
Threadlinqs @threadlinqs.bsky.social · 03/10/2026
AWS Loom shipped a fixed super-admin identity: no IdP configured, full control plane open. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_103956 #CVE_2026_103957 #GHSAvgmj998fr8mp
AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal Credentials - CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019
000
Threadlinqs @threadlinqs.bsky.social · 03/10/2026
ClickFix now hides its script in the browser cache as a fake PNG - the pasted command downloads nothing. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #TrojanWin32 #Trojan #ClickFix
ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows (Trojan:Win32/ClickFix, TermFix)
000
Threadlinqs @threadlinqs.bsky.social · 03/10/2026
Cling botnet hides C2 in STUN transaction IDs, spoofing Google's server. Reputation checks won't catch it. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2021_35394 #CVE_2014_8361 #Cling
Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394
000
Threadlinqs @threadlinqs.bsky.social · 03/10/2026
Fortra's BoKS PAM Master can be rooted via a CRL URL, or hit unauthenticated. Patch now. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_79901 #CVE_2026_79898 #Fortra
Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Manager (CVE-2026-79901, CVE-2026-79898, CVE-2026-12627)
000
Threadlinqs @threadlinqs.bsky.social · 03/10/2026
Akira's playbook: VPN with no MFA, data gone in ~2 hours, then backups wiped before encryption. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2024_40766 #CVE_2023_28252 #Akira
The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira, REDBIKE, AGENDA)
000
Threadlinqs @threadlinqs.bsky.social · 03/10/2026
Dell Container Storage Modules. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2026_63688 #CVE_2026_63692 #DSA2026448
Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)
000
Threadlinqs @threadlinqs.bsky.social · 03/10/2026
Debian patched 1,000+ Linux kernel flaws in one trixie update. Upgrade and reboot. intel.threadlinqs.com/threat/TL-202… #ThreatIntel #CVE_2024_52560 #CVE_2024_58094 #DSA65281
Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux kernel CVEs (privilege escalation, DoS, information leaks)
000