#Huntio
What up folks! Its'a me! Huntio!
September 2, 2026 at 4:51 PM
Research from March: How We Uncovered 33K Exposed LiteLLM Instances

https://
hunt.io/blog/33k-expos
ed-litellm-teampcp-c2-supply-chain-attack
…

In late March, we published our investigation into the TeamPCP s…

🔁 RT @Huntio | reposted by @HackingLZ
https://x.com/Huntio/status/2045200730592620629
33K Exposed LiteLLM Deployments and the C2 Servers Behind TeamPCP's Supply Chain Attack
t.co
April 17, 2026 at 6:36 PM
🚩 #malicious #opendir hosted on on 129.159.135.190

AttackCapture URL: https://portal.hunt.io/attackcapture/reports/v2/129.159.135.190…

Original find by @Yusufcancakiir https://x.com/Yusufcancakiir/status/2098487180494815400?s=20……

— from @Huntio (https://x.com/Huntio/status/2100941909506015402)
September 18, 2026 at 1:40 PM
New #threatintel research using @Huntio 🔥

Two exposed #opendir revealed targeting #Vietnamese & #Pakistani government/military infrastructure, NDU, #Mexican systems, and self-hosted #LLM gateways.

Link: https://infrahunter…

— from @volrant136 (https://x.com/volrant136/status/2099124721589895358)
September 14, 2026 at 1:00 PM
🔥New research using @Huntio Intelligence

An exposed #opendir revealed credential harvesting, brute-force tools, reconnaissance and Java exploitation targeting government infrastructure across 🇳🇬 #Nigeria, 🇰🇪 #Kenya and othe…

— from @volrant136 (https://x.com/volrant136/status/2095234180473070026)
September 9, 2026 at 10:18 PM
🚨 Malicious #opendir 192.159.99[.]164:80

AttackCapture URL: https://bit.ly/3SWS6Mp

Spotted by @BlinkzSec https://x.com/BlinkzSec/status/2093009520217805177?s=20…

🇮🇳 Turns out it's a fake NextGen mParivahan (India's official tra…

— from @Huntio (https://x.com/Huntio/status/2093447443144667460)
September 9, 2026 at 10:18 PM
😈 Malicious #opendir https[:]//safe-pdf-viewer[.]lat

AttackCapture URL: https://bit.ly/4cksj7s

Found by @JAMESWT_WT https://x.com/JAMESWT_WT/status/2092495547584127370?s=20…

🇧🇷 Brazilian invoice and Caixa banking lures sitting o…

— from @Huntio (https://x.com/Huntio/status/2093446418744655950)
September 9, 2026 at 10:17 PM
🚩Malicious #opendir 45.94.31[:]41:443

AttackCapture URL: https://bit.ly/4y6WxTE

Found by @BlinkzSec https://x.com/BlinkzSec/status/2092996102878302337…

Fake Microsoft Teams meeting site; serves a ClickOnce installer branded as Te…

— from @Huntio (https://x.com/Huntio/status/2093445048717185336)
September 9, 2026 at 10:17 PM
CameraSwarm compromised 14,500+ Dahua IP cameras in a 35-day campaign, mainly in Ukraine and Russia, using brute force, CVE-2021-33044, CVE-2021-33045, and offline recovery codes. #Ukraine #Dahua #CameraSwarm
Hackers compromise 14,500 Dahua web cameras in 35-day campaign
Researchers uncovered CameraSwarm, a 35-day campaign that compromised more than 14,500 Dahua IP cameras, mainly in Ukraine and Russia, using brute-force logins, vulnerability exploits, and offline recovery codes. Hunt.io traced the operation after finding exposed attacker files, and Dahua camera owners are urged to check for the persistent p2pwn account and apply firmware fixes. #CameraSwarm #Dahua #Huntio #CVE-2021-33044 #CVE-2021-33045
www.hendryadrian.com
August 19, 2026 at 6:45 PM
#opendir spotted by
@skocherhan

https://
x.com/skocherhan/sta
tus/2079989351388238147
… → AttackCapture URL:
https://
portal.hunt.io/attackcapture/
filemanager?host=https://eye-cardiovascular-biological-fru…

🔁 RT @Huntio | reposted by @HackingLZ
https://x.com/Huntio/status/2082808073513574843
July 30, 2026 at 7:29 PM
Hermes AI agent was allegedly used in unattended mode to automate post-exploitation during a Thai Finance Ministry intrusion. Exposed attacker files held web shells, credentials, payloads, and logs showing escalation and traversal. #Thailand #Hermes
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor allegedly used the open-source Hermes AI agent in unattended YOLO mode to automate post-exploitation tasks during an intrusion tied to Thailand’s Ministry of Finance. Hunt.io and Bob Diachenko found exposed directories with web shells, stolen credentials, and logs showing Hermes was used for privilege escalation, enumeration, and internal system traversal. #Hermes #ThailandMinistryofFinance #Huntio #BobDiachenko #Hades
www.hendryadrian.com
July 25, 2026 at 12:00 AM
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, "Hades" Implant Staged

Together with Bob Diachenko (
@MayhemDayOne
), we caught an intrusion while it was still running. Three op…

🔁 RT @Huntio | reposted by @HackingLZ
https://x.com/Huntio/status/2080333628769243327
July 24, 2026 at 12:18 PM
Recently saw some criticism of
@Huntio
about the use of the phrase "advanced threat hunting" with regards to their platform. I think some of the criticism is from a perception that identifying infrastructure characteristic…

— from @ImposeCost (https://x.com/ImposeCost/status/2079947128499995050)
July 22, 2026 at 3:35 PM
JADEPUFFER Exploits Langflow Vulnerability to Deploy ENCFORGE AI Ransomware

https://
cybersecuritynews.com/agentic-jadepu
ffer-langflow-flaw/
…

The threat actor JADEPUFFER is targeting AI systems in a new campa…

🔁 RT @Huntio | reposted by @_subTee
https://x.com/Huntio/status/2079570859992248465
Agentic JADEPUFFER Exploits Langflow Flaw to Deploy ENCFORGE AI Ransomware
t.co
July 21, 2026 at 4:30 PM
Just discovered and reported a new zero-day in an open-source application with 1.3k stars on GitHub

274 results on
@censysio
and 739 results on
@Huntio

🔁 RT @canmustdie | reposted by @ImposeCost
https://x.com/canmustdie/status/2077336054462382234
July 15, 2026 at 12:20 PM
𝗦𝘂𝘀𝗽𝗲𝗰𝘁𝗲𝗱 𝗖𝗵𝗶𝗻𝗲𝘀𝗲 𝗼𝗽𝗲𝗿𝗮𝘁𝗼𝗿𝘀 𝘄𝗶𝗿𝗲𝗱 𝗖𝗹𝗮𝘂𝗱𝗲 𝗖𝗼𝗱𝗲 𝗮𝗻𝗱 𝗗𝗲𝗲𝗽𝗦𝗲𝗲𝗸 𝗶𝗻𝘁𝗼 𝗮 𝗹𝗶𝘃𝗲 𝗴𝗼𝘃𝗲𝗿𝗻𝗺𝗲𝗻𝘁 𝗶𝗻𝘁𝗿𝘂𝘀𝗶𝗼𝗻 𝗰𝗮𝗺𝗽𝗮𝗶𝗴𝗻

In June 2026, a pivot off known TencShell C2 infrastructure covered by Cato Networks,

🔁 RT @Huntio | reposted by @cyb3rops
https://x.com/Huntio/status/2077084921105989988
July 15, 2026 at 6:16 AM
Huntio v3 Unleashed: How Passive DNS, Cloudflare Buster, and 60+ API Endpoints Are Redefining C2 Infrastructure Hunting + Video

Introduction: In the cat-and-mouse game of cyber threat intelligence, a single IP address, domain, or file hash is rarely the full story—it is merely a doorway.…
Huntio v3 Unleashed: How Passive DNS, Cloudflare Buster, and 60+ API Endpoints Are Redefining C2 Infrastructure Hunting + Video
Introduction: In the cat-and-mouse game of cyber threat intelligence, a single IP address, domain, or file hash is rarely the full story—it is merely a doorway. Traditional indicator-of-compromise (IOC) enrichment stops at the lookup, leaving analysts to manually piece together fragmented data across multiple platforms. Hunt.io 3.0 fundamentally shifts this paradigm by transforming simple indicators into investigation-ready intelligence, delivering full infrastructure context from a single pivot point within one unified platform.
undercodetesting.com
July 2, 2026 at 9:57 PM
Leak del codice di Ermac v3 svela pannello, C2 e iniezioni su 700 app. Analisi tecnica e implicazioni per la sicurezza cibernetica.

#Android #comandoecontrollo(C2) #dataleak #Ermac #Huntio #malware #Trojan
www.matricedigitale.it/2025/08/17/e...
August 17, 2025 at 4:48 PM
APT36 lancia ClickFix: attacchi contro il Ministero della Difesa indiano con spoofing, clipboard hijacking e dropper HTA su Windows e Linux

#apt36 #bash #ClickFix #clipboard #dropper #evidenza #guerracibernetica #hijacking #HTA #Huntio #Linux #malware
www.matricedigitale.it/2025/05/13/a...
May 13, 2025 at 11:40 AM
𝗛𝘂𝗻𝘁 𝟯.𝟬 𝗶𝘀 𝗹𝗶𝘃𝗲. 𝗣𝘂𝗹𝗹 𝘁𝗵𝗲 𝘁𝗵𝗿𝗲𝗮𝗱.

Most threat hunting tools stop at the lookup. You get a result, maybe a tag, and then you're on your own figuring out what connects to what.

We built v3 to fix that. Every…

🔁 RT @Huntio | reposted by @HackingLZ
https://x.com/Huntio/status/2072370955318436331
July 1, 2026 at 5:56 PM
Can confirm
@Huntio
is super cool!

I combined this with
@defused
,
@GreyNoiseIO
,
@shodanhq
,
@censysio
and
@ipinfo


(i know there's probably some duplication in this but it's good to…

🔁 RT @UK_Daniel_Card | reposted by @thegrugq
https://x.com/UK_Daniel_Card/status/2067650461008617511
June 19, 2026 at 7:01 AM
Recent find by our team using
@Huntio

Akia: Exploiting CVE-2025-55182/66478, this French Claude-coded pipeline is a massive secret harvester:

13 Git/8 SMTP APIs
3k+ AWS Keys
250M JS URLs
EVM/BTC/…

🔁 RT @ctrlaltintel | reposted by @HackingLZ
https://x.com/ctrlaltintel/status/2051988848847298723
May 6, 2026 at 4:45 PM
We recently updated the
http://
Hunt.io website and brand direction.

Over time, the platform became more cohesive and more focused on infrastructure intelligence. OEM integrations became a larger part of how t…

🔁 RT @Huntio | reposted by @HackingLZ
https://x.com/Huntio/status/2026349055232688340
February 24, 2026 at 6:37 PM
People are smart enough to use LLMs for CVE research, but not smart enough to stop leaving open directories lying around. Finding all kinds of stuff with
@Huntio

— from @HackingLZ (https://x.com/HackingLZ/status/2024193776822919289)
February 18, 2026 at 6:57 PM