Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

Threat Intel

Threat intelligence and threat hunting as they inform daily security operations.

Cisco Talos Threat Spotlight branded graphic for the UAT-11985 AI-assisted phishing report.
Graphic: Cisco Talos, Threat Spotlight header art for the Oct 8, 2026 UAT-11985 post (fair use).

THREAT INTEL · SINGAPORE

Cisco Talos Tracks UAT-11985 Phishing Taiwan Researchers With AI-Assisted Invites and Real-Time Google Login Relays

Cisco Talos says the campaign reused real public event details, likely AI-assisted invitation templates, and an adversary-in-the-middle kit that relays Google authentication including MFA challenges over HTTP and WebSocket. ClamAV and Snort coverage plus IOCs are published.

Priya Shah, Threat Intel, Singapore

Read the story
A small Windows application window titled Dairy with the heading DailyPlanner, a date picker reading Wednesday, April 22, 2026, two text boxes each labeled Today containing keyboard gibberish, and a large photo of an orange tabby kitten with its mouth wide open.
Screenshot: ESET Research, the fake daily planner window, titled Dairy, that late 2025 MATCHBOIL samples display when opened directly, from MATCHBOIL: New tricks, same old evil intentions, Oct 8, 2026 (fair use).

THREAT INTEL · SINGAPORE

Russia-Aligned Spies Retool MATCHBOIL Malware and Widen Attacks to Ukrainian Transport, Manufacturing and Energy Firms

ESET says UAC-0099, a group it describes as able to act as an initial access broker for Sandworm, planted its rebuilt MATCHBOIL downloader at Ukrainian transportation, manufacturing and energy companies, adding fake planner screens, sandbox checks and a new DLL variant while leaving a trail of file paths, scheduled tasks and HTTP headers defenders can hunt.

Priya Shah, Threat Intel, Singapore

Read the story
FBI screenshot of a Chinese-language web dashboard titled E-commerce Order Management, served from 127.0.0.1:8080, showing counts of 694 low, 160 medium and 1,138 high threats, 649 completed scans and 21,851 total reports, a redacted list of the five most vulnerable hosts and a top-five plugin list led by sensitive information collection.
Screenshot: FBI, via joint Cybersecurity Advisory AA26-281A, a MicroScan account dashboard showing detected vulnerabilities, recovered in FBI investigations of Integrity Technology Group, Oct 8, 2026 (fair use).

THREAT INTEL · SINGAPORE

FBI Seizes Integrity Tech Hacking Tools as Allies Detail How China-Linked Hackers Steal Government Email

The FBI and nine partner agencies said on October 8 that hackers tied to Integrity Technology Group, a China-based company with links to the Chinese government, stole email from government, law enforcement, healthcare and religious organizations in Southeast Asia, as the Justice Department seized domains behind the company's Microscan scanner and FishHub phishing tool.

Priya Shah, Threat Intel, Singapore

Read the story
Login screen headed Dubai Airports Careers Login, with User Name and Password fields, a yellow LOGIN button and a laptop illustration on the left.
Screenshot: Unit 42 (Palo Alto Networks), the fake Dubai Airports careers portal the attackers had the target install before sending a trojanized coding test, Oct 6, 2026 (fair use).

THREAT INTEL · SINGAPORE

Iran-Linked Hackers Posing as Dubai Airports Recruiters Hide Malware in a Visual Studio Coding Test

Unit 42 researchers said on October 6 that an Iranian state-aligned group it tracks as CL-STA-1178 sent an Iraq-based engineer a fake coding assessment that ran malware as soon as Visual Studio opened the project, then took its orders through GitHub repositories and issue comments.

Priya Shah, Threat Intel, Singapore

Read the story
Chrome window on gemini-beta-invites.com showing a second, fake Chrome window inside the page with a lock icon, an accounts.google.com address bar and a Google Sign in form.
Screenshot: Island, clicking Connect on a spoofed Gemini Ads page opens a fake Google sign-in window drawn inside the page while the real address bar still shows gemini-beta-invites.com, Oct 6, 2026 (fair use).

THREAT INTEL · SINGAPORE

Fake ChatGPT and Gemini Ad Portals Use Browser-in-the-Browser Pop-Ups to Steal Logins and MFA Codes

Island researchers said on October 6 that a human-operated phishing platform posing as AI advertising products for Gemini, ChatGPT, Claude, Perplexity and a fake Muse Ads draws a counterfeit Google sign-in window inside the page, then lets a live operator choose which MFA prompt the victim sees next.

Priya Shah, Threat Intel, Singapore

Read the story
Wireshark capture of STUN packets with the transaction ID annotated as command, method, target IP, port and duration.
Screenshot: Nozomi Networks Labs packet capture of a spoofed STUN reply carrying a flood command in its transaction ID, Oct 1, 2026 (fair use).

THREAT INTEL · SINGAPORE

ClingSTUN Backdoor Turns Unpatched IoT Devices Into Proxies Hidden in Public STUN Traffic

FortiGuard Labs said on October 5 that ClingSTUN, a Linux backdoor spread through 24 known flaws in routers, cameras and other edge devices, uses legitimate public STUN servers so its traffic blends with VoIP and WebRTC. Nozomi Networks, tracking the same malware as Cling, found operator commands hidden in STUN transaction IDs.

Priya Shah, Threat Intel, Singapore

Read the story
Rapid7 Labs investigation title card over a dark field.
Photo/figure: Rapid7 Labs research art, Sleeper Cells in the Telecom Backbone hero (fair use).

THREAT INTEL · SINGAPORE

Rapid7 Tracks BPFDoor and AVERAT Implants Mimicking Asian Mail Gateways

Rapid7 Intelligence published its first research drop on October 2, 2026, documenting Linux implants that impersonate South Korean SpamSniper and Taiwanese ShareTech mail-security appliances, with BPFDoor, Rekoobe, and a modular tool Rapid7 tracks as AVERAT blending command-and-control into SMTP traffic on the network edge.

Priya Shah, Threat Intel, Singapore

Read the story

THREAT INTEL · SINGAPORE

Arista Confirms Actively Exploited VeloCloud Orchestrator Flaw

SINGAPORE - Arista Advisory 0183, published September 22, 2026 and revised to 1.1 on September 23, 2026, covers CVE-2026-93952 in the on-premises VeloCloud Orchestrator. The flaw was discovered externally and is actively exploited.

Priya Shah, Threat Intel, Singapore

Read the story
A technician at monitors in a data-center monitoring room. Not a photograph of an Arista or VeloCloud incident.
Photo: Derrick Coetzee

THREAT INTEL · SAN JOSE

Talos Documents CLOSEDQUORUM, Windows Implant That Lets AI Models Vote on C2 Moves

SAN JOSE - Cisco Talos researchers have documented CLOSEDQUORUM, which they describe as the first publicly reported Windows implant in their knowledge that uses a panel of commercial large language models as tactical command and control after deployment. The finding appears in a Talos blog by Ryan Fetterman dated Tuesday, September 22, 2026, and was uncovered with CAIRN, Talos' new open-source toolkit for tracking AI-integrated malware. Talos has not confirmed in-the-wild deployment.

Priya Shah, Threat Intel, Singapore

Read the story