https://
hunt.io/blog/33k-expos
ed-litellm-teampcp-c2-supply-chain-attack
…
In late March, we published our investigation into the TeamPCP s…
🔁 RT @Huntio | reposted by @HackingLZ
https://x.com/Huntio/status/2045200730592620629
https://
hunt.io/blog/33k-expos
ed-litellm-teampcp-c2-supply-chain-attack
…
In late March, we published our investigation into the TeamPCP s…
🔁 RT @Huntio | reposted by @HackingLZ
https://x.com/Huntio/status/2045200730592620629
AttackCapture URL: https://portal.hunt.io/attackcapture/reports/v2/129.159.135.190…
Original find by @Yusufcancakiir https://x.com/Yusufcancakiir/status/2098487180494815400?s=20……
— from @Huntio (https://x.com/Huntio/status/2100941909506015402)
AttackCapture URL: https://portal.hunt.io/attackcapture/reports/v2/129.159.135.190…
Original find by @Yusufcancakiir https://x.com/Yusufcancakiir/status/2098487180494815400?s=20……
— from @Huntio (https://x.com/Huntio/status/2100941909506015402)
Two exposed #opendir revealed targeting #Vietnamese & #Pakistani government/military infrastructure, NDU, #Mexican systems, and self-hosted #LLM gateways.
Link: https://infrahunter…
— from @volrant136 (https://x.com/volrant136/status/2099124721589895358)
Two exposed #opendir revealed targeting #Vietnamese & #Pakistani government/military infrastructure, NDU, #Mexican systems, and self-hosted #LLM gateways.
Link: https://infrahunter…
— from @volrant136 (https://x.com/volrant136/status/2099124721589895358)
An exposed #opendir revealed credential harvesting, brute-force tools, reconnaissance and Java exploitation targeting government infrastructure across 🇳🇬 #Nigeria, 🇰🇪 #Kenya and othe…
— from @volrant136 (https://x.com/volrant136/status/2095234180473070026)
An exposed #opendir revealed credential harvesting, brute-force tools, reconnaissance and Java exploitation targeting government infrastructure across 🇳🇬 #Nigeria, 🇰🇪 #Kenya and othe…
— from @volrant136 (https://x.com/volrant136/status/2095234180473070026)
AttackCapture URL: https://bit.ly/3SWS6Mp
Spotted by @BlinkzSec https://x.com/BlinkzSec/status/2093009520217805177?s=20…
🇮🇳 Turns out it's a fake NextGen mParivahan (India's official tra…
— from @Huntio (https://x.com/Huntio/status/2093447443144667460)
AttackCapture URL: https://bit.ly/3SWS6Mp
Spotted by @BlinkzSec https://x.com/BlinkzSec/status/2093009520217805177?s=20…
🇮🇳 Turns out it's a fake NextGen mParivahan (India's official tra…
— from @Huntio (https://x.com/Huntio/status/2093447443144667460)
AttackCapture URL: https://bit.ly/4cksj7s
Found by @JAMESWT_WT https://x.com/JAMESWT_WT/status/2092495547584127370?s=20…
🇧🇷 Brazilian invoice and Caixa banking lures sitting o…
— from @Huntio (https://x.com/Huntio/status/2093446418744655950)
AttackCapture URL: https://bit.ly/4cksj7s
Found by @JAMESWT_WT https://x.com/JAMESWT_WT/status/2092495547584127370?s=20…
🇧🇷 Brazilian invoice and Caixa banking lures sitting o…
— from @Huntio (https://x.com/Huntio/status/2093446418744655950)
AttackCapture URL: https://bit.ly/4y6WxTE
Found by @BlinkzSec https://x.com/BlinkzSec/status/2092996102878302337…
Fake Microsoft Teams meeting site; serves a ClickOnce installer branded as Te…
— from @Huntio (https://x.com/Huntio/status/2093445048717185336)
AttackCapture URL: https://bit.ly/4y6WxTE
Found by @BlinkzSec https://x.com/BlinkzSec/status/2092996102878302337…
Fake Microsoft Teams meeting site; serves a ClickOnce installer branded as Te…
— from @Huntio (https://x.com/Huntio/status/2093445048717185336)
@skocherhan
https://
x.com/skocherhan/sta
tus/2079989351388238147
… → AttackCapture URL:
https://
portal.hunt.io/attackcapture/
filemanager?host=https://eye-cardiovascular-biological-fru…
🔁 RT @Huntio | reposted by @HackingLZ
https://x.com/Huntio/status/2082808073513574843
@skocherhan
https://
x.com/skocherhan/sta
tus/2079989351388238147
… → AttackCapture URL:
https://
portal.hunt.io/attackcapture/
filemanager?host=https://eye-cardiovascular-biological-fru…
🔁 RT @Huntio | reposted by @HackingLZ
https://x.com/Huntio/status/2082808073513574843
Together with Bob Diachenko (
@MayhemDayOne
), we caught an intrusion while it was still running. Three op…
🔁 RT @Huntio | reposted by @HackingLZ
https://x.com/Huntio/status/2080333628769243327
Together with Bob Diachenko (
@MayhemDayOne
), we caught an intrusion while it was still running. Three op…
🔁 RT @Huntio | reposted by @HackingLZ
https://x.com/Huntio/status/2080333628769243327
@Huntio
about the use of the phrase "advanced threat hunting" with regards to their platform. I think some of the criticism is from a perception that identifying infrastructure characteristic…
— from @ImposeCost (https://x.com/ImposeCost/status/2079947128499995050)
@Huntio
about the use of the phrase "advanced threat hunting" with regards to their platform. I think some of the criticism is from a perception that identifying infrastructure characteristic…
— from @ImposeCost (https://x.com/ImposeCost/status/2079947128499995050)
https://
cybersecuritynews.com/agentic-jadepu
ffer-langflow-flaw/
…
The threat actor JADEPUFFER is targeting AI systems in a new campa…
🔁 RT @Huntio | reposted by @_subTee
https://x.com/Huntio/status/2079570859992248465
https://
cybersecuritynews.com/agentic-jadepu
ffer-langflow-flaw/
…
The threat actor JADEPUFFER is targeting AI systems in a new campa…
🔁 RT @Huntio | reposted by @_subTee
https://x.com/Huntio/status/2079570859992248465
274 results on
@censysio
and 739 results on
@Huntio
🔁 RT @canmustdie | reposted by @ImposeCost
https://x.com/canmustdie/status/2077336054462382234
274 results on
@censysio
and 739 results on
@Huntio
🔁 RT @canmustdie | reposted by @ImposeCost
https://x.com/canmustdie/status/2077336054462382234
In June 2026, a pivot off known TencShell C2 infrastructure covered by Cato Networks,
🔁 RT @Huntio | reposted by @cyb3rops
https://x.com/Huntio/status/2077084921105989988
In June 2026, a pivot off known TencShell C2 infrastructure covered by Cato Networks,
🔁 RT @Huntio | reposted by @cyb3rops
https://x.com/Huntio/status/2077084921105989988
Introduction: In the cat-and-mouse game of cyber threat intelligence, a single IP address, domain, or file hash is rarely the full story—it is merely a doorway.…
Introduction: In the cat-and-mouse game of cyber threat intelligence, a single IP address, domain, or file hash is rarely the full story—it is merely a doorway.…
#Android #comandoecontrollo(C2) #dataleak #Ermac #Huntio #malware #Trojan
www.matricedigitale.it/2025/08/17/e...
#Android #comandoecontrollo(C2) #dataleak #Ermac #Huntio #malware #Trojan
www.matricedigitale.it/2025/08/17/e...
#apt36 #bash #ClickFix #clipboard #dropper #evidenza #guerracibernetica #hijacking #HTA #Huntio #Linux #malware
www.matricedigitale.it/2025/05/13/a...
#apt36 #bash #ClickFix #clipboard #dropper #evidenza #guerracibernetica #hijacking #HTA #Huntio #Linux #malware
www.matricedigitale.it/2025/05/13/a...
Most threat hunting tools stop at the lookup. You get a result, maybe a tag, and then you're on your own figuring out what connects to what.
We built v3 to fix that. Every…
🔁 RT @Huntio | reposted by @HackingLZ
https://x.com/Huntio/status/2072370955318436331
Most threat hunting tools stop at the lookup. You get a result, maybe a tag, and then you're on your own figuring out what connects to what.
We built v3 to fix that. Every…
🔁 RT @Huntio | reposted by @HackingLZ
https://x.com/Huntio/status/2072370955318436331
@Huntio
is super cool!
I combined this with
@defused
,
@GreyNoiseIO
,
@shodanhq
,
@censysio
and
@ipinfo
(i know there's probably some duplication in this but it's good to…
🔁 RT @UK_Daniel_Card | reposted by @thegrugq
https://x.com/UK_Daniel_Card/status/2067650461008617511
@Huntio
is super cool!
I combined this with
@defused
,
@GreyNoiseIO
,
@shodanhq
,
@censysio
and
@ipinfo
(i know there's probably some duplication in this but it's good to…
🔁 RT @UK_Daniel_Card | reposted by @thegrugq
https://x.com/UK_Daniel_Card/status/2067650461008617511
@Huntio
Akia: Exploiting CVE-2025-55182/66478, this French Claude-coded pipeline is a massive secret harvester:
13 Git/8 SMTP APIs
3k+ AWS Keys
250M JS URLs
EVM/BTC/…
🔁 RT @ctrlaltintel | reposted by @HackingLZ
https://x.com/ctrlaltintel/status/2051988848847298723
@Huntio
Akia: Exploiting CVE-2025-55182/66478, this French Claude-coded pipeline is a massive secret harvester:
13 Git/8 SMTP APIs
3k+ AWS Keys
250M JS URLs
EVM/BTC/…
🔁 RT @ctrlaltintel | reposted by @HackingLZ
https://x.com/ctrlaltintel/status/2051988848847298723
http://
Hunt.io website and brand direction.
Over time, the platform became more cohesive and more focused on infrastructure intelligence. OEM integrations became a larger part of how t…
🔁 RT @Huntio | reposted by @HackingLZ
https://x.com/Huntio/status/2026349055232688340
http://
Hunt.io website and brand direction.
Over time, the platform became more cohesive and more focused on infrastructure intelligence. OEM integrations became a larger part of how t…
🔁 RT @Huntio | reposted by @HackingLZ
https://x.com/Huntio/status/2026349055232688340
@Huntio
— from @HackingLZ (https://x.com/HackingLZ/status/2024193776822919289)
@Huntio
— from @HackingLZ (https://x.com/HackingLZ/status/2024193776822919289)