# AlphaHunt Converge > The Signal Moves First. Public Ghost content for AI and LLM tooling. Use `/llms-full.txt` for consolidated page and post context. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages - [TIP Jar](https://blog.alphahunt.io/tips.md) - Did my snark-infused threat intel save you three hours of doom-scrolling (and at least one coffee-spit)? Toss a coin in the jar—it's cheaper than therapy and fuels more zero-day zingers for your inbox. - [Welcome to AlphaHunt Converge](https://blog.alphahunt.io/welcome-to-alphahunt-converge.md) ## Posts - [[DEEP RESEARCH] The OT Signal Is What the Defender Could Not See.](https://blog.alphahunt.io/deep-research-the-ot-signal-is-what-the-defender-could-not-see.md) - A practical evidence ladder for separating industrial ransomware from process-aware staging before public proof arrives. - [[SIGNALS WEEKLY] Shifting Access Paths: OT, Identity, and Adversarial AI](https://blog.alphahunt.io/signals-weekly-shifting-access-paths-ot-identity-and-adversarial-ai.md) - Some of this week’s most useful threat signals point to access paths that sit just outside the normal inventory: a cellular modem added by an OT integrator, a hotel captive portal steering a traveler toward token theft, or a passkey implementation that trusts the wrong lifecycle step. - [[GAME THEORY] The Phish Did Not Steal the Password. It Rented the Protocol.](https://blog.alphahunt.io/game-theory-the-phish-did-not-steal-the-password-it-rented-the-protocol.md) - Device-code phishing turns a legitimate login flow into rented access. The durable defense is to shrink who can use it. - [[DEEP RESEARCH] The account stealing your data may not be human](https://blog.alphahunt.io/deep-research-the-account-stealing-your-data-may-not-be-human.md) - The user may start the incident. OAuth apps, tokens, and integrations can turn it into quiet, scalable data theft. - [[SIGNALS WEEKLY] Silent Surfaces: From Zero‑Click Mail to Exposed Controllers](https://blog.alphahunt.io/signals-weekly-silent-surfaces-from-zero-click-mail-to-exposed-controllers.md) - Zero-click Zimbra access, exposed PLC tampering, and Teams-to-ransomware chains compress the defender’s window. Prioritize server logs, controller-change evidence, and external admin-surface discovery. - [[FORECAST] The Patch Deadline Is Becoming an Attacker's Watchlist](https://blog.alphahunt.io/forecast-the-patch-deadline-is-becoming-an-attackers-watchlist.md) - We put a 30% chance on two public FCEB cases proving post-deadline edge exploitation by year-end. - [[FORECAST] The breach may start after the patch](https://blog.alphahunt.io/forecast-the-breach-may-start-after-the-patch.md) - We put a 45% chance on a public case proving that stolen edge-appliance access survived remediation and enabled a later intrusion. - [[SIGNALS WEEKLY] Perimeter to Persistence: Evolving Paths to Ransomware and OT Access](https://blog.alphahunt.io/signals-weekly-perimeter-to-persistence-evolving-paths-to-ransomware-and-ot-access.md) - The perimeter kept the keys. Edge appliances and OT switches are becoming the shortest path from exposure to stolen identity and ransomware. The plumbing became the persistence layer. - [[GAME THEORY] KEV Is Not a Patch List. It Is a Race for Control.](https://blog.alphahunt.io/game-theorkev-is-not-a-patch-list-it-is-a-race-for-control.md) - Nine actively exploited flaws show why patching closes an entry point—but not necessarily the incident. - [[GAME THEORY] AI gateways are becoming the new IAM chokepoint](https://blog.alphahunt.io/game-theory-ai-gateways-are-becoming-the-new-iam-chokepoint.md) - AI gateways are starting to concentrate credentials, logs, routing, quotas, and policy. That makes them worth watching now. - [[SIGNALS WEEKLY] Converging Threats Across SaaS, Web Edge, and OT](https://blog.alphahunt.io/signals-weekly-converging-threats-across-saas-web-edge-and-ot.md) - OAuth consent made SaaS data theft look normal. Niche web plugins kept handing attackers first doors. OT debug ports reminded everyone that “engineering access” can age into exposure. - [[FORECAST] China-linked ORB networks are becoming espionage logistics](https://blog.alphahunt.io/forecast-china-linked-orb-networks-are-becoming-espionage-logistics.md) - China-linked operators are turning compromised routers into relay logistics. The defender move is behavior over bad IPs. - [[FORECAST] TeamPCP shows why package cleanup is not containment](https://blog.alphahunt.io/forecast-teampcp-shows-why-package-cleanup-is-not-containment.md) - Supply-chain attacks are becoming access pipelines. The defender move is to follow credentials, not just packages. - [[SIGNALS WEEKLY] Telephony, Observability, and Identity Under Quiet Pressure](https://blog.alphahunt.io/signals-weekly-telephony-observability-and-identity-under-quiet-pressure.md) - The boring stack moved. CUCM WebDialer. Splunk sidecar. Messaging recovery keys. Very normal. Very annoying. - [[FORECAST] NetNut/Popa was a capacity disruption, not just a botnet takedown](https://blog.alphahunt.io/forecast-netnut-popa-was-a-capacity-disruption-not-just-a-botnet-takedown.md) - The NetNut/Popa action matters. The harder question is whether the residential-proxy market reroutes. - [[DEEP RESEARCH] Operation Endgame Hit SocGholish, Amadey, and StealC. Now Watch the Rebuild.](https://blog.alphahunt.io/deep-research-operation-endgame-hit-socgholish-amadey-and-stealc-now-watch-the-rebuild.md) - Operation Endgame gave defenders a strong scoreboard: servers and domains actioned, millions of stolen credentials recovered, thousands of compromised websites remediated, and tens of millions in criminal crypto assets identified or restricted. - [[SIGNALS WEEKLY] Control Planes, Stealers, and Emerging AI-Tool Abuse](https://blog.alphahunt.io/signals-weekly-control-planes-stealers-and-emerging-ai-tool-abuse.md) - The control plane blinked. Management surfaces are still getting treated like furniture. - [[DEEP RESEARCH] The Hackers Are Not Stealing Trucks. They Are Stealing Authority.](https://blog.alphahunt.io/deep-research-the-hackers-are-not-stealing-trucks-they-are-stealing-authority.md) - Cyber-enabled cargo theft is less about malware novelty and more about who gets trusted to move the load. - [[GAME THEORY] Beyond Domain Takedowns: A causal framework for testing chokepoints in World Cup scam infrastructure](https://blog.alphahunt.io/game-theory-beyond-domain-takedowns-a-causal-framework-for-testing-chokepoints-in-world-cup-scam-infrastructure.md) - World Cup fraud shows why removing infrastructure is not the same as disrupting the operation. - [[SIGNALS WEEKLY] Compressed Timelines at the Edge of the Network](https://blog.alphahunt.io/signals-weekly-compressed-timelines-at-the-edge-of-the-network.md) - Fortinet VPN portals are getting probed. npm installs can execute more than your build expected. And now the AI conversation is not “someday” — it is about compressed timelines. - [[DEEP RESEARCH] Verified for Hire: How Fox Tempest Turned Code Signing Into a Criminal Utility](https://blog.alphahunt.io/deep-research-verified-for-hire-how-fox-tempest-turned-code-signing-into-a-criminal-utility.md) - The certificate was real. The identity behind it was fraudulent—and the signing pipeline was rented to other criminals. - [[FORECAST] The VPN You Retired on Paper Is Still Selling Access](https://blog.alphahunt.io/forecast-the-vpn-you-retired-on-paper-is-still-selling-access.md) - A forecast for when legacy VPN compatibility debt becomes ransomware access — and what to verify before certainty arrives. - [[SIGNALS WEEKLY] Converging on Exposed Management Planes](https://blog.alphahunt.io/signals-weekly-converging-on-exposed-management-planes.md) - The management plane blinked. Everyone treated it like plumbing until the attacker used it like a front door. PeopleSoft PSEMHUB, REDCap, VPN gear, SD-WAN managers, logging sidecars — different products, same pattern. The exposed control layer keeps turning into the incident path. - [[DEEP RESEARCH] The bad IP was never the Actor.](https://blog.alphahunt.io/deep-research-the-bad-ip-was-never-the-actor.md) - A bad IP can be accurate and still tell the wrong story. - [[GAME THEORY] The Agent Did Not Hack You. The Connector Did.](https://blog.alphahunt.io/game-theory-the-agent-did-not-hack-you-the-connector-did.md) - MCP is not just an AI security story. It may be the first real test of agent connector supply-chain risk. - [[SIGNALS WEEKLY] Perimeter Pressure, Supply Chain Drift, and Identity Theft](https://blog.alphahunt.io/signals-weekly-perimeter-pressure-supply-chain-drift-and-identity-theft.md) - The perimeter blinked. VPN portals and CI tokens are still doing incident cosplay. - [[FORECAST] Fake Hires, Real Access](https://blog.alphahunt.io/forecast-fake-hires-real-access.md) - Forecasting is not fortune-telling. It is how defenders turn messy signals into better questions. - [[GAME THEORY] Your AI Agent Remembered the Secret. So Did the Attacker.](https://blog.alphahunt.io/game-theory-your-ai-agent-remembered-the-secret-so-did-the-attacker.md) - AI agents are becoming useful because they remember. That also means they are quietly becoming data stores. - [[SIGNALS WEEKLY] Shifting Extortion Tactics and Fragile Software Supply Chains](https://blog.alphahunt.io/signals-weekly-shifting-extortion-tactics-and-fragile-software-supply-chains.md) - The pipeline had keys. Nx Console and Megalodon are the same warning: your CI/CD workflow may be production access wearing YAML pajamas. CI/CD is not “just automation.” - [[FORECAST] The next secret-stealing campaign may start with a tool you trusted](https://blog.alphahunt.io/forecast-the-next-secret-stealing-campaign-may-start-with-a-tool-you-trusted.md) - AI coding tools are becoming trusted middlemen. That gives defenders a new attack path to understand before it gets ugly. - [[BREACH] The Extension Had the Keys](https://blog.alphahunt.io/breach-the-extension-had-the-keys.md) - The plugin had keys. A VS Code extension sat beside repos, tokens, terminals, and AI configs. That is not just productivity. That is inherited access. - [[SIGNALS WEEKLY] Tokens, Edges, and Exploits: Shifting Paths to Compromise](https://blog.alphahunt.io/signals-weekly-tokens-edges-and-exploits-shifting-paths-to-compromise.md) - The token survived. npm packages, CI/CD runners, and edge boxes keep turning “contained” into “still owned.” The boring weakness became the breach path. - [[GAME THEORY] AI-agent spoofing is becoming a claim-vs-proof problem](https://blog.alphahunt.io/game-theory-ai-agent-spoofing-is-becoming-a-claim-vs-proof-problem.md) - Known AI agents are becoming trusted traffic. The first defender move is finding claims without proof. - [[FORECAST] The Threat Was Real. The Public Proof Probably Falls Short (Final: 2026-05-21)](https://blog.alphahunt.io/forecthe-threat-was-real-the-public-proof-probably-falls-short.md) - The forecast likely resolves No, but the useful lesson is where Iran-linked operators still depend on access defenders can pressure. - [[SIGNALS WEEKLY] Identity-First Intrusions and AI-Driven Attack Surface Shifts](https://blog.alphahunt.io/signals-weekly-identity-first-intrusions-and-ai-driven-attack-surface-shifts.md) - The login was real. The control plane did the rest. Storm-2949 is the ugly part: one Entra ID identity can turn into SaaS theft and Azure abuse. Nobody owns this until incident day. - [[PODCAST] ANALYST YELLS AT CLOUD](https://blog.alphahunt.io/podcast-analyst-yells-at-cloud.md) - Get closer to the people who understand where threat actors are today — and where they are likely headed tomorrow. - [[FORECAST] Iran-Linked Cyber Risk Is Real. The Evidence Bar Is Harder (Updated: 2026-05-14)](https://blog.alphahunt.io/forecast-iran-linked-cyber-risk-is-real-the-evidence-bar-is-harder.md) - The forecast is 29%, but the operational risk is still worth preparing for this week. - [[SIGNALS WEEKLY] Edge Access, False Flags, and Emerging AI Attack Surfaces](https://blog.alphahunt.io/signals-weekly-edge-access-false-flags-and-emerging-ai-attack-surfaces.md) - The edge box blinked. PAN-OS, Ivanti, Teams lures, ClickFix, AI agents. Different doors. Same ugly pattern: access keeps hiding in the plumbing. The boring surface became the breach path. - [[FORECAST] Will Akira trigger a week-long hospital disruption by end of 2026? (Updated 2026-05-11)](https://blog.alphahunt.io/forecast-will-akira-trigger-a-week-long-hospital-disruption-by-end-of-2026-updated-2026-05-11.md) - We’re revising the Akira hospital disruption forecast down to 2%. The risk is real, but the question is narrower than it looks. - [[FORECAST] Device-Bound Sessions Are Coming. Defaults Are the Hard Part.](https://blog.alphahunt.io/forecast-device-bound-sessions-are-coming-defaults-are-the-hard-part.md) - “Secure by default” sounds great until it meets BYOD, VDI, federated SSO, and the help desk exception list from hell. Device-bound sessions help. Waiting for every SaaS vendor to flip the default is not a strategy. - [[SIGNALS WEEKLY] Patch Cliffs, Supply Chain Drift, and Soft DevOps Underbellies](https://blog.alphahunt.io/signals-weekly-patch-cliffs-supply-chain-drift-and-soft-devops-underbellies.md) - The industry keeps treating emergency patches like a finish line. Meanwhile, exposed control panels, self-managed DevOps boxes, and forgotten appliances are still out there collecting bad decisions like loyalty points. - [[FORECAST ] Iran’s Cyber Window Is Still Open—But the Qualification Clock Is Now the Hardest Adversary (Updated 2026-05-05!)](https://blog.alphahunt.io/forecast-irans-cyber-window-is-still-open-but-the-qualification-clock-is-now-the-hardest-adversary.md) - Iran cyber isn’t quiet. The problem is the scoreboard. Every recycled leak and nuisance outage wants to become “critical infrastructure impact” before the evidence has its pants on. - [[GAME THEORY] UAT-4356/Storm-1849: When Patching Is Not Eviction](https://blog.alphahunt.io/game-theory-uat-4356-storm-1849-when-patching-is-not-eviction.md) - “We patched it” is not an eviction notice. On edge boxes, that sentence has been carrying way too much emotional weight. - [[SIGNALS WEEKLY] Edge Persistence, Covert Networks, and Supply-Chain Drift](https://blog.alphahunt.io/signals-weekly-edge-persistence-covert-networks-and-supply-chain-drift.md) - Edge appliances are fun because the industry treats them like appliances. Patch it. Reboot it. Declare victory. Meanwhile the implant is sitting there like: “great maintenance window, see you next Tuesday.” - [[GAME THEORY] ShinyHunters- Names Fade. Playbooks Stick.](https://blog.alphahunt.io/game-theory-shinyhunters-names-fade-playbooks-stick.md) - The ShinyHunters problem isn’t the name. It’s the chain: MFA reset, weird login, OAuth grant, SaaS export, extortion later. - [[FORECAST] Iran’s Cyber Window Stays Open—But the Novelty Bar Is Tougher Now (Updated: 2026-04-23)](https://blog.alphahunt.io/forecast-irans-cyber-window-stays-open-but-the-novelty-bar-is-tougher-now-updated-2026-04-23.md) - The industry loves a neat PLC story because it keeps the threat in a box you can point at. The less fun version is when the same campaign walks through identity or an admin plane your org still treats like plumbing. - [[SIGNALS WEEKLY] Quiet Shifts In Tradecraft, Loud Signals In Exposure](https://blog.alphahunt.io/signals-weekly-quiet-shifts-in-tradecraft-loud-signals-in-exposure.md) - Everyone waits for the sexy zero-day. Meanwhile “IT” is in your Teams chat asking for Quick Assist, and your user clicks yes. The breach starts looking a lot like normal work. - [[RESEARCH] CPU-Z was the lure. The real story is who buys the foothold.](https://blog.alphahunt.io/research-cpu-z-was-the-lure-the-real-story-is-who-buys-the-foothold.md) - The scariest part of the CPU-Z mess wasn’t STX RAT. It was the customer profile. Trusted utility, power-user endpoint, resale-ready access. Same old crime economy, better packaging. - [[FORECAST] Two New App-Layer Campaigns by Year-End? Watch the Attribution Line](https://blog.alphahunt.io/forecast-two-new-app-layer-campaigns-by-year-end.md) - Teams keep hardening the front door while the “trusted integration” gets waved through reception with a box truck. No core-platform exploit required. Just approval fatigue with API access. - [[SIGNALS WEEKLY] Edge Devices, Identity Abuse, and KEV-Driven Exploitation Converge](https://blog.alphahunt.io/signals-weekly-edge-devices-identity-abuse-and-kev-driven-exploitation-converge.md) - The industry still talks like identity compromise begins at the login page. Meanwhile the path is edge box → DNS games → token theft → bad week for everyone pretending “strong auth” was the whole plan. - [Anthropic’s Mythos Is Real. The Victory Lap Isn’t.](https://blog.alphahunt.io/anthropics-mythos-is-real-the-victory-lap-isnt.md) - Everyone wants the AI bug hunter. Nobody wants the patch clock that comes with it. Mythos may be real. So is the part where leisurely patching starts looking like a career-limiting hobby. - [[FORECAST] Beyond PLCs: Are Iran-Linked Operators More Likely to Chase New Targets, New Tooling, or New Impact? UPDATED 2026-04-08!](https://blog.alphahunt.io/forecast-beyond-plcs-are-iran-linked-operators-more-likely-to-chase-new-targets-new-tooling-or-new-impact-updated-2026-04-08.md) - Everyone saw the PLC headline and immediately built their whole Iran take around exposed controllers. Cool. The nastier question is what happens when the next move comes through identity, admin planes, or some target class nobody staffed for. - [[SIGNALS WEEKLY] Converging Control-Plane Threats Across Modern Infrastructure](https://blog.alphahunt.io/signals-weekly-converging-control-plane-threats-across-modern-infrastructure.md) - Everyone loves “endpoint visibility” until the incident starts in the control plane they treated like support infrastructure. Routers, CI/CD, token flows, web admin panels — same neglect, better attacker ROI. - [[DEEP RESEARCH] TeamPCP’s CI/CD Trust Inversion: When “Pinned” Actions Become Initial Access](https://blog.alphahunt.io/deep-research-teampcps-ci-cd-trust-inversion-when-pinned-actions-become-initial-access.md) - A lot of teams “secured” Actions by pinning to tags. Great plan, right up until the trusted scanner becomes initial access. CI trust is now flimsy in ways most incident playbooks still ignore. - [The Real Government Fraud Story- Identity Infrastructure](https://blog.alphahunt.io/the-real-government-fraud-story-identity-infrastructure.md) - “Fraud” makes it sound random. It isn’t. It’s identity infrastructure with a cash-out layer. Same proofing gaps, same rails, same reusable parts. People keep chasing claims instead of the production line. - [SIGNALS WEEKLY: When Trust Breaks- Pipelines, PLM, and Phishing at Scale](https://blog.alphahunt.io/signals-weekly-when-trust-breaks-pipelines-plm-and-phishing-at-scale.md) - Everyone loves “shift left” until the thing in the pipeline shifts your secrets somewhere else. Security tooling has officially joined the attack surface like it was invited. - [The Next 3–6 Months: Where Threat Actors Will Move Faster Than Defenders](https://blog.alphahunt.io/the-next-3-6-months-where-threat-actors-will-move-faster-than-defenders.md) - Everyone’s hunting “AI attacks.” Meanwhile the ugly money is still in trusted pages, stolen sessions, and users politely pasting the command for them. - [[FORECASTS] From Password Sprays to Tenant Sabotage: The 8-Week Iran Cyber Risk for U.S. and Israeli Orgs - UPDATED: 2026-03-26](https://blog.alphahunt.io/forecasts-from-password-sprays-to-tenant-sabotage-the-8-week-iran-cyber-risk-for-u-s-and-israeli-orgs-updated-2026-03-26.md) - Iran cyber risk is not about whether they’ll be active. They will. The real question is whether the next 8 weeks produce a publicly attributed, materially disruptive hit with a new twist beyond the usual password-spray sludge. Tenant sabotage is the part to watch. 👀🔥 - [[SIGNALS WEEKLY] Ransomware’s New Priority Targets—Hypervisors, Recovery Paths, and Control Planes](https://blog.alphahunt.io/signals-weekly-ransomwares-new-priority-targets-hypervisors-recovery-paths-and-control-planes.md) - Ransomware crews aren’t stopping at endpoints. They’re going after hypervisors, backups, and control planes now. KEV keeps growing, exploitation stays hot, and defender timelines keep getting shorter. Lovely. 🔥💀⚙️ - [[FORECAST] Will RedNovember be publicly reported to exploit at least one zero-day vulnerability in 2026? Updated 2026-03-24](https://blog.alphahunt.io/forecast-will-rednovember-be-publicly-reported-to-exploit-at-least-one-zero-day-vulnerability-in-2026-updated-2026-03-24.md) - RedNovember is the kind of crew that turns “it was only an N-day” into a post-incident coping mechanism. We’re at 25% odds they get publicly tied to a true 0-day in 2026. With edge exploitation surging, that’s not exactly comforting. 👀🔥 - [[DEEP RESEARCH] How Malware Uses Solana and EVM Chains to Rotate C2 Without Burning Infrastructure](https://blog.alphahunt.io/deep-research-how-malware-uses-solana-and-evm-chains-to-rotate-c2-without-burning-infrastructure.md) - Malware is using blockchains as durable configuration mailboxes, not full C2. If you can spot the read→decode→connect sequence, you can preempt and burn the real infrastructure before it’s useful. - [[SIGNALS WEEKLY] GitHub, npm, and Fake Interviews: Why Developer Supply Chain Attacks Are Converging](https://blog.alphahunt.io/signals-weekly-github-npm-and-fake-interviews-why-developer-supply-chain-attacks-are-converging.md) - 2026 cyber lesson: attackers don’t need your prod box first. They want your dev, your repo, your package manager, and your CI runner. Force-pushes, fake interviews, poisoned installers. Real classy stuff. 🤡🔧🔥 - [[FORECASTS] From Password Sprays to Tenant Sabotage: The 8-Week Iran Cyber Risk for U.S. and Israeli Orgs](https://blog.alphahunt.io/forecasts-from-password-sprays-to-tenant-sabotage-the-8-week-iran-cyber-risk-for-u-s-and-israeli-orgs.md) - Iran cyber risk isn’t just “watch for wipers.” It’s the same ugly identity-first playbook: password sprays, MFA abuse, cloud access… then maybe admin-plane sabotage. Recent reporting says activity is already reaching U.S. targets. Cute. - [[FORECAST UPDATED] After LockBit and BlackCat, Is Cl0p Really Next in Line?](https://blog.alphahunt.io/forecast-updated-after-lockbit-and-blackcat-is-cl0p-really-next-in-line.md) - LockBit got Cronos’d. BlackCat caught a DOJ wrench to the teeth. Cl0p is still hanging around the enterprise software aisle like it owns the place. So… is it really next, or are we just recycling takedown fan fiction? - [SIGNALS WEEKLY: Seedworm in U.S. Networks, Coruna on iPhones, and a Patch Window Measured in Days](https://blog.alphahunt.io/signals-weekly-seedworm-in-u-s-networks-coruna-on-iphones-and-a-patch-window-measured-in-days.md) - This week’s pattern is ugly and simple: Seedworm is reportedly already sitting inside multiple U.S. organizations, Coruna shows spy-grade iPhone exploitation bleeding into broader use, and KEV + March patch drops are shrinking defender response time from “soon” to “right now.” - [[DEEP RESEARCH] When Gambling Becomes a Money-Transfer Rail](https://blog.alphahunt.io/deep-research-when-gambling-becomes-a-money-transfer-rail.md) - Casinos and iGaming platforms can quietly act like informal money-transfer channels when intermediaries use gaming flows to move value between third parties. This summary highlights where that happens, what it looks like in logs, and how technical teams can help shut it down. - [[DEEP RESEARCH] Who’s Most Likely to Abuse MCP Integrations? UNC3944, TraderTraitor, UNC6293](https://blog.alphahunt.io/deep-research-whos-most-likely-to-abuse-mcp-integrations-unc3944-tradertraitor-unc6293.md) - Three intrusion sets already excel at getting users to approve tools and auth flows. This assessment is probabilistic: it highlights who is best positioned to adapt that tradecraft to MCP-style environments next.. - [SIGNALS WEEKLY: Cisco Catalyst SD-WAN Exploitation + OAuth Redirect Abuse + Prompt Injection Observed in the Wild](https://blog.alphahunt.io/signals-weekly-cisco-catalyst-sd-wan-exploitation-oauth-redirect-abuse-prompt-injection-observed-in-the-wild.md) - Edge + identity + AI = the new “oops.” 😬🧨🤖 ED 26-03 on Cisco Catalyst SD-WAN exploitation, OAuth redirect abuse that lands users in malware without token theft, plus Gemini panel hijack vs indirect prompt injection in the wild. - [[FORECAST UPDATED] AI Agents as Regulated C2: Will Anyone Be Forced to Act?](https://blog.alphahunt.io/forecast-updated-ai-agents-as-regulated-c2-will-anyone-be-forced-to-act.md) - 🤖🔒 AI agents = privileged integrations you can’t see. After GTG-1002 + vendors pushing agent access standards, the next shoe drops: do regulators/hyperscalers force default-on signed connectors + audit logs (aka “regulated C2”)? - [[FORECAST] Fortune 500s: Will Prompt Injection Trick IDE Agent Mode into Running Commands—or Leaking Secrets—by 2026?](https://blog.alphahunt.io/forecast-fortune-500s-will-prompt-injection-trick-ide-agent-mode-into-running-commands-or-leaking-secrets-by-2026.md) - Recent agent-mode rollouts make ‘read files + run tasks’ normal. Prompt injection makes that risky. Here’s the forecast.. - [SIGNALS WEEKLY: How AI Is Turbocharging Attacks on 600+ FortiGate Firewalls](https://blog.alphahunt.io/signals-weekly-how-ai-is-turbocharging-attacks-on-600-fortigate-firewalls.md) - Your firewall isn’t the perimeter. It’s the onboarding portal. 🔥 - [CISA Flags Dell RecoverPoint Zero-Day: Backup Systems as the New Beachhead](https://blog.alphahunt.io/cisa-flags-dell-recoverpoint-zero-day-backup-systems-as-the-new-beachhead.md) - Your backup system isn’t your parachute. It’s a beachhead. 🏖️ Mandiant/GTIG report UNC6201 exploiting Dell RP4VM (CVE-2026-22769, CVSS 10.0). Hardcoded credential → OS-level control + root persistence. - [[FORECAST] Dismantled or Displaced? Cambodia’s Scam-Compound Crackdown by 2030?](https://blog.alphahunt.io/dismantled-or-displaced-cambodias-scam-compound-crackdown-forecast-to-2030.md) - Cambodia says it sealed off ~190 scam sites. 🧨 Now the real question: dismantled or displaced? 🧱🚚 Our forecast uses grown-up metrics (convictions + asset denial + independent compound counts). - [SIGNALS WEEKLY: Active Ivanti EPMM Zero-Days — What Defenders Must Do Now](https://blog.alphahunt.io/signals-weekly-active-ivanti-epmm-zero-days-what-defenders-must-do-now.md) - Your control plane isn’t infrastructure. It’s leverage. 🔥 - [The 90-Day Disruption Dividend: How Intel-Led Hunting Reduces Dwell Time Without a Massive SOC](https://blog.alphahunt.io/the-90-day-disruption-dividend-how-intel-led-hunting-reduces-dwell-time-without-a-massive-soc.md) - Your SOC isn’t understaffed. It’s late. ⏱️😈 Attackers aren’t scaling with malware—they’re scaling with OAuth + tokens + “normal” API exports. Big tech wins by yanking kill-switches fast. Can you revoke an OAuth grant in <30 min? - [ClickFix to Linked-Device Takeovers: Will Star Blizzard Introduce a New Initial-Access Vector by Oct 2026?](https://blog.alphahunt.io/clickfix-to-linked-device-takeovers-will-star-blizzard-introduce-a-new-initial-access-vector-by-oct-2026.md) - Fake CAPTCHA ➜ “paste this PowerShell.” 🙃 Linked-device pairing ➜ quiet account takeovers. 👻 Device-code phishing ➜ legit login page, attacker gets tokens. 🔑 - [SIGNALS WEEKLY: Pre-Filled Links That Poison AI Recommendations (and Memory)](https://blog.alphahunt.io/signals-weekly-pre-filled-links-that-poison-ai-recommendations-and-memory.md) - Pre-filled AI prompt links: now a delivery vector. Microsoft warns they can poison assistant recommendations + memory. 🧠🧪 - [[DEEP RESEARCH] BadIIS Isn’t Enough: The IIS Module + HTTP Fingerprints That Catch SEO-Fraud Cloaking](https://blog.alphahunt.io/deep-research-badiis-isnt-enough-the-iis-module-http-fingerprints-that-catch-seo-fraud-cloaking.md) - *Vendors are naming slices of the same IIS SEO fraud problem differently. This summary aligns those labels into one unified hunt surface and shows how to separate UAT-8099/WEBJACK from other BadIIS-style activity using concrete host and HTTP fingerprints.* - [Residential Proxies: When "Normal" Traffic Becomes a Risk Multiplier](https://blog.alphahunt.io/residential-proxies-when-normal-traffic-becomes-a-risk-multiplier.md) - “Normal traffic” is now an attacker costume. 🥸🏠 Residential proxies borrow real home ISP IPs, making sprays/scrapes/SaaS intrusion blend in. Don’t rage-block—use tiered friction (identity+behavior) w/ proxy intel as a risk multiplier. - [SIGNALS WEEKLY: ShinyHunters, Vishing, and the MFA Hijack Problem in SaaS](https://blog.alphahunt.io/signals-weekly-shinyhunters-vishing-and-the-mfa-hijack-problem-in-saas.md) - MFA isn’t “done.” It’s now the excuse attackers use on the phone. ☎️😈🔑 Vishing → MFA reset/re-enroll → post-login SaaS data grabs. Plus: selective Notepad++ updater abuse + proxy traffic making IP rep cry. - [[FORECAST] ShinyHunters SaaS Data Theft: Why Non-Ransom Monetization Looks Increasingly Attractive](https://blog.alphahunt.io/forecast-shinyhunters-saas-data-theft-why-non-ransom-monetization-looks-increasingly-attractive.md) - Our new forecast asks: will ShinyHunters make more in 2H 2026 by selling SaaS access/data than by getting paid? Signals say yes. 🕵️‍♂️💸☁️ - [The Next AI Security Frontier: “Agents With Hands” Are Becoming a Board-Level Risk](https://blog.alphahunt.io/the-next-ai-security-frontier-agents-with-hands-are-becoming-a-board-level-risk.md) - Your new “AI helper” is basically shadow IT with hands 🤖🧨 Untrusted content → model decides → tools execute. That’s the breach loop. - [SIGNALS WEEKLY: Teams QR/callback phishing beats patching](https://blog.alphahunt.io/signals-weekly-teams-qr-callback-phishing-beats-patching.md) - KEV speedrun of the week 🏁: Office CVE-2026-21509 + WinRAR CVE-2025-8088. Patch anyway… then protect sessions 🍪 (Teams QR/callback lures 📱, SSO/SAML token abuse) - [If your “AI Coworker” Gets Targeted, What Tips You Off First?](https://blog.alphahunt.io/if-your-ai-coworker-gets-targeted-what-tips-you-off-first.md) - Your “AI coworker” isn’t the breach. The OAuth trust event is. 🔥🕵️‍♂️ Device-code phishing + consent traps = “approve to exfil.” (And yes, AI agents are already being used as the wrapper.) - [No malware required: device-code phishing + Teams as the intrusion surface](https://blog.alphahunt.io/no-malware-required-device-code-phishing-teams-as-the-intrusion-surface.md) - No malware. Still owned. 🧾🔑💬 Device-code phishing + Teams as the “lobby” + stolen OAuth tokens = API-speed SaaS exfil. If you’re hunting binaries, you’re late. - [SIGNALS WEEKLY: When Management Planes Become the Battlefield](https://blog.alphahunt.io/signals-weekly-when-management-planes-become-the-battlefield.md) - 🛫 Your “management plane” is now the battlefield. Cisco Secure Email + HPE OneView are seeing active exploitation, and UAT-8837 is chasing CI targets. Patch like it’s a fire drill. 🔥🧯 - [[FORECAST] Integrator CI/CD Compromise by End-2026?](https://blog.alphahunt.io/forecast-integrator-ci-cd-compromise-by-end-2026.md) - OWASP Top 10:2025 put Software Supply Chain Failures front-and-center. 🧩⚙️ Now the fun question: by end-2026, do we get public root-cause confirmation that an industrial integrator’s CI/CD/build/signing or update channel led to 2+ critical-infra intrusions? 😬 - [Iran’s Internet Went to Zero on Jan 8—Will Account Takeovers Spike in the Next 2–3 Weeks?](https://blog.alphahunt.io/irans-internet-went-to-zero-on-jan-8-will-account-takeovers-spike-in-the-next-2-3-weeks.md) - Iran’s internet goes dark → attackers don’t stop. They speed-run creds and hit post-auth collection the moment connectivity blips back. ⏱️🔑👀 - [SIGNALS WEEKLY: Taiwan Critical Infrastructure: Reports of China-Linked Probing and Prepositioning](https://blog.alphahunt.io/signals-weekly-taiwan-critical-infrastructure-reports-of-china-linked-probing-and-prepositioning.md) - 🧭 Taiwan CI pressure looks like recon + access maintenance, not a one-off headline. 🩹 Patch Tuesday + KEV = attacker shopping list. ☁️ And Salesforce Aura/Experience Cloud exposure? No patch… just “surprise, it’s public.” - [Deepfake BEC & Payment Diversion: The Q1 2026 Fraud PIR You Can’t Defer](https://blog.alphahunt.io/deepfake-bec-payment-diversion-the-q1-2026-fraud-pir-you-cant-defer.md) - Deepfake BEC = the same old fraud… with a way better script. 🎭💸 If payroll/AP changes can happen on “sounds right,” you’re funding someone’s Q1 bonus. - [[FORECAST] CoPhish: The Microsoft Copilot Link That Hands Over Your OAuth Tokens](https://blog.alphahunt.io/forecast-cophish-the-microsoft-copilot-link-that-hands-over-your-oauth-tokens.md) - Will at least one publicly disclosed enterprise breach be confirmed where attackers used a Microsoft Copilot Studio.. - [SIGNALS WEEKLY: MongoBleed (CVE-2025-14847) Is in KEV: The Unauth MongoDB Leak You Need to Patch](https://blog.alphahunt.io/signals-weekly-mongobleed-cve-2025-14847-is-in-kev-the-unauth-mongodb-leak-you-need-to-patch.md) - MongoBleed is in KEV: unauth MongoDB memory leak = creds/tokens. Patch + find exposed hosts. Dolby fix + poisoned dev tools too. 🧯🧬👇 - [[DEEP RESEARCH] Token Factory: The 5 Costliest US Breaches of 2025](https://blog.alphahunt.io/deep-research-token-factory-the-5-costliest-us-breaches-of-2025.md) - 2025’s costliest US breaches: identity, outage math, outcomes Identity-led intrusions at distributors, govtech, healthcare, and an appliance vendor drove nine-figure losses. Outage duration and revocation speed determined the spread between disruption and recovery. - [Geopatriation Is Coming: Sovereign Clouds Will Break Your Telemetry First](https://blog.alphahunt.io/geopatriation-is-coming-sovereign-clouds-will-break-your-telemetry-first.md) - 2026 prediction: “sovereign cloud” becomes the #1 way to accidentally create telemetry refugees 🛂☁️ Meanwhile: DPRK “IT workers” in the supply chain + OAuth consent hijacks that laugh at MFA 🔑🎭 What’s your log-clears-customs plan? - [SIGNALS WEEKLY: Poisoned DNS Updates + Aflac’s 22.65M Aftershock (and MongoBleed)](https://blog.alphahunt.io/signals-weekly-poisoned-dns-updates-aflacs-22-65m-aftershock-and-mongobleed.md) - This week’s vibe: MongoBleed → KEV, BitLocker ransomware in critical infra, poisoned DNS “updates” for MgBot, and Aflac’s ~22.65M aftershock. 🔥🧨🦠 - [Token Factory: The 5 Costliest US Breaches of 2025](https://blog.alphahunt.io/token-factory-the-5-costliest-us-breaches-of-2025.md) - 2025’s priciest breaches weren’t “elite malware.” They were tokens + SaaS + downtime 🪙⏱️🔥 If your revoke MTTR is measured in days, the attackers already won. - [CrowdStrike vs Microsoft Defender: Who Leads EDR/XDR Into 2026?](https://blog.alphahunt.io/crowdstrike-vs-microsoft-defender-who-leads-edr-xdr-into-2026.md) - EDR “leader” in 2026 = who contains fastest at scale + doesn’t implode during updates. 🎄🧯 Our model: CrowdStrike 50% (±8), Microsoft Defender 35% (±7), SentinelOne 15% (±5). - [SIGNALS WEEKLY: Holiday Patch Panic: Cisco AsyncOS Zero-Day + KEV Edge Rush](https://blog.alphahunt.io/signals-weekly-holiday-patch-panic-cisco-asyncos-zero-day-kev-edge-rush.md) - 🎄 Zero-day season: Cisco AsyncOS exploited + KEV edge scramble. 🧯 VNC-to-HMI + cloud C2 (Drive/Telegram) keep paying rent. - [Holiday Scam Survival Kit (2025): Delivery Texts, ‘Family Emergency’ Calls, Gift Card Traps](https://blog.alphahunt.io/holiday-scam-survival-kit-2025-delivery-texts-family-emergency-calls-gift-card-traps.md) - Holiday scammers are running peak-season ops 📦🎄 “Delivery problem” texts, AI “family emergency” calls, and “pay via gift card/Zelle” pressure. Rule: don’t click, hang up + call back, never gift cards/crypto/wires. - [[DEEP RESEARCH] Zero-Days Are a Distraction: 2025’s Biggest Losses Were Stolen Tokens + OAuth](https://blog.alphahunt.io/deep-research-zero-days-are-a-distraction-2025s-biggest-losses-were-stolen-tokens-oauth.md) - Most downtime and spend stemmed from OAuth/SaaS abuse and edge appliances—not catastrophic zero-days. Here’s what drove real operating impact and the fastest ways to shrink it. - [SIGNALS WEEKLY: Chrome 0-Day in the Wild + December Patch Tuesday Priv-Esc](https://blog.alphahunt.io/signals-weekly-chrome-0-day-in-the-wild-december-patch-tuesday-priv-esc.md) - Chrome 0-day in the wild + Windows priv-esc getting abused + OT VNC still exposed like it’s 2009. 😬🔥 - [Zero-Days Are a Distraction: 2025’s Biggest Losses Were Stolen Tokens + OAuth](https://blog.alphahunt.io/zero-days-are-a-distraction-2025s-biggest-losses-were-stolen-tokens-oauth.md) - Zero-days get the headlines. Stolen tokens + OAuth consent abuse get the invoices. 🧾🔑😈 2025 pain = AiTM/device-code phishing + token replay + KEV-speed edge fires. - [Will UNC5221 pop a fresh zero-day before Dec 31? Final Forecast!](https://blog.alphahunt.io/will-unc5221-pop-a-fresh-zero-day-before-dec-31-final-forecast.md) - BRICKSTORM intel just landed: PRC actors camping in vCenter/ESXi + Windows. 🧱🕵️‍♂️ F5 source-code drama raises the long-run 0-day odds, but the calendar + attribution lag are savage. Our final call: 11% UNC5221 gets publicly tied to a new 0-day before Dec 31. 🎯 - [SIGNALS WEEKLY: React2Shell in the Wild, BRICKSTORM in the Walls, Predator on the Phone](https://blog.alphahunt.io/signals-weekly-react2shell-in-the-wild-brickstorm-in-the-walls-predator-on-the-phone.md) - React2Shell in the wild, BRICKSTORM in the walls, Predator on the phone. Not a dystopian haiku—this week’s risk stack. 🧯🕳️📱 - [The Quiet Token Heist: Why 2026’s Biggest SaaS Breaches Won’t Start With Passwords](https://blog.alphahunt.io/the-quiet-token-heist-why-2026s-biggest-saas-breaches-wont-start-with-passwords.md) - 2026’s nastiest SaaS breaches will ride valid tokens + “trusted” apps. We already got the trailer with the Salesloft/Drift OAuth blast radius. And the browser? Yeah, it’s part of the perimeter now. 😬🔑💬 - [How Close Are We to a Cyber-Driven Citywide Water Outage?](https://blog.alphahunt.io/how-close-are-we-to-a-cyber-driven-citywide-water-outage.md) - Will hackers actually turn off a city’s water, or is that just conference-slide horror fiction? 💧🤔 We put a number on it... - [SIGNALS WEEKLY: Android Banking Malware & VS Code Worms Go Mainstream](https://blog.alphahunt.io/signals-weekly-android-banking-malware-vs-code-worms-go-mainstream.md) - 🚨 CodeRED alerts ransomed. 🐛 Shai Hulud 2.0 looting CI/CD secrets. 📱 107 Android bugs + Albiriox on-device fraud. Signals Weekly on what to fix first. - [Dark LLMs: When Your AI Traffic Is C2](https://blog.alphahunt.io/dark-llms-when-your-ai-traffic-is-c2.md) - Your “normal” AI traffic can be stealth C2 now. Dark LLMs are writing per-host pwsh one-liners, self-rewriting droppers, and hiding in model APIs you approved. If you’re not policing AI egress, you’re not doing detection. 😬🤖 - [AI Agents as Regulated C2: Will Anyone Be Forced to Act?](https://blog.alphahunt.io/ai-agents-as-regulated-c2-will-anyone-be-forced-to-act.md) - AI just ran most of an espionage op, and regulators are still in “interesting case study” mode. 😏 We’re forecasting: 55% odds that by 2026, someone will force signed AI connectors + agent logs by default. - [SIGNALS WEEKLY: Wormed Repos, Multi-Vector APTs, KEV Identity RCE](https://blog.alphahunt.io/signals-weekly-wormed-repos-multi-vector-apts-kev-identity-rce.md) - Wormed npm repos. Multi-vector APTs. KEV-listed identity RCE. If your CI/CD + SSO aren’t on the same crisis board this week, you’re already late. 😈🚨 - [Your AI Agents Are the New C2 — Lock Down Identity & Connectors](https://blog.alphahunt.io/your-ai-agents-are-the-new-c2-lock-down-identity-connectors.md) - Anthropic just showed what happens when your “helpful” AI agents become C2: 80–90% of an espionage op automated, humans just clicking approve. Lock down identity + connectors or you’re renting your SaaS to someone else’s botnet. 🤖🚨 - [Will Akira trigger a week-long hospital disruption by end of 2026?](https://blog.alphahunt.io/will-akira-trigger-a-week-long-hospital-disruption-by-end-of-2026.md) - 20% odds Akira triggers a 7-day ambulance diversion at a 10+ hospital system by end of 2026. 🚑 Still feeling “low risk”? - [SIGNALS WEEKLY: The Quiet Shift- When Intrusions Start Thinking for Themselves](https://blog.alphahunt.io/signals-weekly-the-quiet-shift-when-intrusions-start-thinking-for-themselves.md) - A Chinese crew let a jailbroken AI run most of the intrusion while FortiWeb + Firebox burn in KEV and a contractor leak drops the playbook. - [After LockBit and BlackCat, Is Cl0p Really Next in Line?](https://blog.alphahunt.io/after-lockbit-and-blackcat-is-cl0p-really-next-in-line.md) - LockBit got the Operation Cronos takedown. BlackCat imploded. Cl0p just logged a record leak month—and shows no sign of slowing. By 2026, do we really keep Cl0p dark for 90+ days… or just get Cl0p v2 with a fresh logo? - [Triofox Exploitation Cluster (UNC6485): Six-Month Outlook, Copycat Risk, and What to Watch](https://blog.alphahunt.io/triofox-exploitation-cluster-unc6485-six-month-outlook-copycat-risk-and-what-to-watch.md) - UNC6485 is farming Triofox: Host: localhost → setup → mint admin → AV path = your script → SYSTEM → RMM + reverse RDP/443. Patch to 16.7.10368.56560 now. Copycats next. 🔥🛡️ - [SIGNALS WEEKLY: Keys & Gates — Windows kernel EoP; Cisco RA VPN reloads](https://blog.alphahunt.io/signals-weekly-keys-gates-windows-kernel-eop-cisco-ra-vpn-reloads.md) - Keys. Gates. Windows. Actively exploited Win kernel EoP ✅ (CVE-2025-62215). Cisco RA-VPN bugs can reload unpatched edges. LANDFALL used Samsung’s image bug (CVE-2025-21042). Which breaks first in your shop? - [Typhoon by Consent: Quiet, Durable, Everywhere](https://blog.alphahunt.io/typhoon-by-consent-quiet-durable-everywhere.md) - One “Allow” → tenant-wide weather event. 🌀 AI agent phish wraps the consent flow, device-code keeps churning, and Typhoon rides “good” U.S. infra. Kill list: user consent, device-code, or EWS app perms—what’s first? - [Will RedNovember be publicly reported to exploit at least one zero-day vulnerability in 2026? Updated 2025-11-06](https://blog.alphahunt.io/will-rednovember-be-publicly-reported-to-exploit-at-least-one-zero-day-vulnerability-in-2026-updated-2025-11-06.md) - We’re at 29% that RedNovember will be publicly reported exploiting at least one zero‑day in 2026 under strict timing and attribution rules. The hinge is whether the group escalates beyond PoC‑driven N‑day edge exploits and whether attribution survives rebranding. - [Signals Weekly: The Shortcut That Opened Doors in Europe](https://blog.alphahunt.io/signals-weekly-the-shortcut-that-opened-doors-in-europe.md) - A Windows .LNK just became an actual door key. UNC6384 → PlugX at EU diplomats. CISA drops 2 new KEV vulns (CentreStack/Triofox & CWP) + 5 ICS advisories. Patch what you can, isolate what you can’t. - [Will UNC5221 pop a fresh zero-day before Dec 31? Updated!](https://blog.alphahunt.io/will-unc5221-pop-a-fresh-zero-day-before-dec-31-updated.md) - UNC5221 is an edge-focused PRC espionage actor repeatedly tied to zero-days (Ivanti 2023–2025; prior NetScaler). Edge products remained a major zero-day target in 2024. But public attributions typically lag exploitation by weeks, and the window is short... - [Kill the Lights, Fire Up Starlink: Scam Compounds Slide South](https://blog.alphahunt.io/kill-the-lights-fire-up-starlink-scam-compounds-slide-south.md) - Thailand pulled the plug. The grift brought generators + Starlink. Shift north→south (Shwe Kokko/Myawaddy; Tachileik/Mae Sai). Squeeze OTC cash-outs + first-funding friction, or watch it respawn. - [Signals Weekly: Active WSUS Exploits and Ransomware Shifts](https://blog.alphahunt.io/signals-weekly-active-wsus-exploits-and-ransomware-shifts.md) - WSUS RCE is live—patch OOB now + watch 8530/8531. Payments fell to 23% in Q3 as crews pivot to insider bribes; Qilin doubles down on ESXi + EDR tamper. - [Cl0p’s Leak Sites: 20% Chance They Go Dark by Apr 22, 2026](https://blog.alphahunt.io/cl0ps-leak-sites-20-chance-they-go-dark-by-apr-22-2026.md) - Forecast: 20% chance Cl0p’s leak sites go dark by Apr 22, 2026. Needs a seizure banner or ≥14 days down w/ LE attribution. Cronos showed it’s doable; mirrors make it brutal. - [COLDRIVER’s Next Move](https://blog.alphahunt.io/coldrivers-next-move.md) - COLDRIVER went from LOSTKEYS to a full “ROBOT” chain and ClickFix tricks—then started poking linked-device flows. We put 75% on a truly new family or access vector within 12 months. - [Signals Weekly: Devices Under Siege- SNMP Rootkits, F5 Fallout](https://blog.alphahunt.io/signals-weekly-devices-under-siege-snmp-rootkits-f5-fallout.md) - SNMP rootkits on Cisco (CVE-2025-20352) 🎛️, F5 source-code heist + CISA ED 26-01 🚨, and 175 MS CVEs 📅. Pick your poison: harden SNMP or inventory+patch BIG-IP today. - [Storm-2657 Watch: Does Workday mark the start — or just the first stop?](https://blog.alphahunt.io/storm-2657-watch-does-workday-mark-the-start-or-just-the-first-stop.md) - Workday was the first stop, not the destination. We’re at 62% odds it hits another payroll stack by 2026-04-17. Harden all the paydoors, not just the pretty one. - [CL0P/FIN11 Go In-Memory on Oracle EBS — The Extortion Comes Later](https://blog.alphahunt.io/cl0p-fin11-go-in-memory-on-oracle-ebs-the-extortion-comes-later.md) - Oracle EBS got in-memory Java loaders, not lockerware. Patch CVE-2025-61882, lock egress, hunt TemplatePreviewPG with TMP|DEF + XSL-TEXT|XML. Extortion rides in via “pubstorm.” - [Signals Weekly: Zero-Days, Hijacked Payrolls & a Crypto Kingpin](https://blog.alphahunt.io/signals-weekly-zero-days-hijacked-payrolls-a-crypto-kingpin.md) - This Week's Threat Intel Pulse: Oracle EBS zero-day exploited before patches dropped, Storm-1175 abuses GoAnywhere MFT, payroll hijackers hit US universities, ransomware crews weaponize Velociraptor, and a $15B Southeast Asian scam network faces global sanctions. - [TA558 2026: The Quiet Upgrade](https://blog.alphahunt.io/ta558-2026-the-quiet-upgrade.md) - Which scenario will best describe TA558’s (aka RevengeHotels) evolution by June 30, 2026? - [By Dec 31, 2025, will a reputable primary source (Oracle, CISA, Mandiant/MSTIC, affected org’s SEC 8-K/IR blog) confirm at least one breach where CVE-2025-61882 was the initial access vector?](https://blog.alphahunt.io/by-dec-31-2025-will-a-reputable-primary-source-oracle-cisa-mandiant-mstic-affected-orgs-sec-8-k-ir-blog-confirm-at-least-one-breach-where-cve-2025-61882-was-the-initial-access-vector.md) - Oracle EBS zero-day (CVE-2025-61882): OOB patch, KEV-listed, exec extortion emails flying. We’re at 76% that a primary source names it as initial access by 12/31. Raise or fade? 🧨🧭 - [Will RedNovember be publicly reported to exploit at least one zero-day vulnerability in 2026?](https://blog.alphahunt.io/will-rednovember-be-publicly-reported-to-exploit-at-least-one-zero-day-vulnerability-in-2026.md) - RedNovember likely stays fast-follow on edge devices using N-days and public PoCs, not 0-days. China-nexus peers show willingness to burn edge 0-days, so a pivot is plausible but not base case... - [By Dec 31, 2025, will UNC5221 be publicly linked to exploiting at least one new zero-day?](https://blog.alphahunt.io/by-dec-31-2025-will-unc5221-be-publicly-linked-to-exploiting-at-least-one-new-zero-day.md) - Question: By Dec 31, 2025, will UNC5221 be publicly linked to exploiting at least one new zero-day in a non-Ivanti edge platform (e.g., VMware vCenter/ESXi, Citrix NetScaler, F5, Palo Alto, Fortinet)? - [VoidProxy: AitM Phishing-as-a-Service Quietly Bypasses MFA at Scale](https://blog.alphahunt.io/voidproxy-aitm-phishing-as-a-service-quietly-bypasses-mfa-at-scale.md) - VoidProxy is reshaping the phishing landscape, enabling adversaries to bypass MFA and hijack enterprise cloud sessions with minimal technical skill. Its rapid adoption, use of trusted email providers, and evasive infrastructure demand urgent, layered defenses—especially for organizations... - [Modular C2 Frameworks Quietly Redefine Threat Operations for 2025–2026](https://blog.alphahunt.io/modular-c2-frameworks-quietly-redefine-threat-operations-for-2025-2026.md) - Attackers are rapidly shifting to modular, cloud-integrated C2 frameworks—Sliver, Havoc, Mythic, Brute Ratel C4, and Cobalt Strike—blurring lines between APT and cybercrime. These tools’ stealth, automation, and cloud API abuse are outpacing legacy detection, demanding urgent defensive adaptation. - [Blended Geopolitical-Cyber Intelligence: Financial Sector’s Quiet Shift](https://blog.alphahunt.io/blended-geopolitical-cyber-intelligence-financial-sectors-quiet-shift.md) - Financial institutions are quietly overhauling cyber defenses, blending geopolitical risk with threat intelligence to counter state-sponsored attacks and regulatory pressure. This shift is driving new investments in automation, incident response, and sector-wide collaboration.. - [SteganoAmor: TA558’s image-hidden malware targets oil, gas & maritime](https://blog.alphahunt.io/steganoamor-ta558s-image-hidden-malware-targets-oil-gas-maritime.md) - TA558’s “SteganoAmor” campaign leverages steganography to deliver commodity malware across oil, gas, maritime, and industrial targets. The group’s use of image-embedded payloads and compromised infrastructure... - [PoisonSeed: supply-chain phish, seed-phrase theft, MFA bypass](https://blog.alphahunt.io/poisonseed-supply-chain-phish-seed-phrase-theft-mfa-bypass.md) - If your bulk email or CRM gets popped, PoisonSeed rides your good reputation straight past filters and users’ instincts. Here’s the fast path to detect and blunt it—without boiling the ocean. ## Optional - [RSS Feed](https://blog.alphahunt.io/rss/) - [Sitemap](https://blog.alphahunt.io/sitemap.xml) - [Full content of pages and posts](https://blog.alphahunt.io/llms-full.txt)