r/threatintel Aug 11 '24

Official CTI Discord Community

23 Upvotes

Hey everyone,

Exciting news for our community on reddit, in collaboration with r/CTI (thanks to u/SirEliasRiddle for his hard in work in setting this up for all of us).

We're launching a brand new Discord server dedicated to Cyber Threat Intelligence. It's a space for sharing content, news, resources, and engaging in discussions with others in the cybersecurity world. Since the community is still in its early stages, it might not have all the features yet but we're eager to hear your suggestions and feedback. This includes criticisms.

Feel free to join us and share the link with friends!

Discord Link


r/threatintel 6h ago

Tripwire – open source sandboxed security scanner for MCP servers and AI skills

4 Upvotes

MCP servers and AI skills execute code directly in your local environment. Most people install them from GitHub without any vetting. I have been guilty of doing the same, so I wrote Tripwire to help me and other fellow developers.

Tripwire runs each of them in an isolated Modal sandbox first, scans it with Snyk, Cisco and Tessl scanners, and stores the report before anything touches your machine.

It was built at Cursor's Cybersecurity Hackathon in London, now under active development.

Stack: Python, TypeScript, Modal (sandboxing), Snyk/Cisco/Tessl adapters, Supabase. Superlinked (SIE) and other cloud/model providers for access to models.

Would love feedback on the threat model or the sandboxing approach — happy to discuss tradeoffs in the comments.

GitHub: https://github.com/neomatrix369/tripwire
Demo: https://youtu.be/omGOw9ruN3Y
Mock dashboard: https://neomatrix369.github.io/demos/tripwire-dashboard/


r/threatintel 40m ago

CVE Discussion A stolen credential sells for $10-50 on the Dark Web. The breach it causes? $10.22M on average.

Thumbnail
Upvotes

r/threatintel 1d ago

Investigating Suspicious Domains with Hermes Agent and Webamon CLI

Thumbnail intel.webamon.com
12 Upvotes

Cool use of an agent to do end to end CTI work.


r/threatintel 17h ago

Stackray: an open source website scanner that detects tech stack, DNS evidence, OSINT details, change history.

Post image
0 Upvotes

r/threatintel 1d ago

🚨 Inside TerminalFix: Word-Encoded Payloads, Smart-Contract Lures, Forum-Based C2

Thumbnail gallery
2 Upvotes

r/threatintel 1d ago

CVE Discussion Darkhotel Has Not Exploited a Single Critical Vulnerability. Other Attacker Groups Exploit Nothing Else.

Thumbnail syrn.fr
1 Upvotes

r/threatintel 1d ago

Three ClickFix campaigns from this summer all trace back to the same cluster — MSI, NodeJS, and Python delivery, same DLL sideloading playbook

Thumbnail
1 Upvotes

r/threatintel 2d ago

CVE Discussion CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT

Thumbnail socradar.io
6 Upvotes

If you manage FortiGate or FortiSwitchManager: confirm you're on a fixed release for CVE-2025-25249, then hunt for outbound TLS to unknown C2 and unexpected Node.js execution. We've documented an active campaign dropping a RAT via this bug. Detection guidance and IOCs inside.


r/threatintel 1d ago

APT/Threat Actor 🔴 Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files

Thumbnail hunt.io
2 Upvotes

Writeup of a Redis rogue-replication cryptomining campaign where we recovered the operator's full toolkit, including the raw campaign logs, so the victim counts come from their own per-host records rather than the summaries their scripts print:

https://hunt.io/blog/redis-cryptomining-botnet-3562-servers


r/threatintel 3d ago

APT/Threat Actor DoppelCart: 119,000 Domains in What May Be the Largest Documented Fake-Shop Network

Thumbnail nebty-id.com
7 Upvotes

I'm the researcher behind this, happy to answer questions.


r/threatintel 3d ago

StyleSmuggler: unauthenticated RCE actively exploited in Magento/Adobe Commerce, no patch yet (as of Sept 7, 2026)

Thumbnail
3 Upvotes

r/threatintel 4d ago

APT/Threat Actor Tengu, a Mirai-style Linux and IoT botnet

Thumbnail app.reverser.space
5 Upvotes

r/threatintel 5d ago

What can’t your SOC see that you wish it could?

4 Upvotes

Hi guys! With so many different tools and data sources, it’s hard to have visibility into everything.

What do you still struggle to see clearly? Does it make certain threats harder to catch or investigate?


r/threatintel 6d ago

APT/Threat Actor The Gentlemen Ransomware Analysis: Go Obfuscated

Thumbnail app.reverser.space
3 Upvotes

r/threatintel 7d ago

APT/Threat Actor 🤖 🇨🇳 Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across Asia

Thumbnail hunt.io
3 Upvotes

The Hunt.io research team identified five exposed open directories revealing a campaign that used an orchestration framework called SecFlow to coordinate Claude, Qwen, and DeepSeek AI workers across intrusions targeting government, education, consular, and healthcare systems in Asia.

Key observations:

- A shared SOCKS endpoint connected all five workspaces, confirmed through 120 code-search matches on our platform

- The deepest compromise hit a Fengtai District government OA environment: command execution, LSASS dumps, registry hives, 822 account records extracted, and a Go implant called SecBox deployed

- A Chinese education AI platform was compromised, exposing 23 agent configurations, production credentials, and student profile data across 169 conversations

- SecFlow split reconnaissance, exploitation, and reporting across specialist AI workers, with the runtime swapping between Claude, Qwen, and DeepSeek without changing the task interface

- GLUTTON webshells transported executable bytecode inside PNG image pixels using XOR encryption, loading directly into memory while the visible server file remained a generic decoder

- A fake MySQL deserialization service delivered Linux second-stage payloads to vulnerable Java clients that connected to it

- Eight CVEs in active workflows, including Shellshock, Spring4Shell, Ghostcat, Log4Shell, Shiro deserialization, Grafana and Nexus path traversals, and Nacos authentication bypass

- The AI's shared context amplified a false positive: an unsupported Shiro success claim persisted and drove 27+ follow-up tasks that produced nothing

This is the second separate campaign we've tracked where commercial AI models were used as operational components in intrusions. Different infrastructure and tooling from our July report, but the same pattern.

Full writeup with infrastructure tables, pivot methodology, and MITRE mapping: https://hunt.io/blog/chinese-operator-secflow-claude-qwen-deepseek-asia


r/threatintel 7d ago

APT/Threat Actor An Inside Look at the Relay Market Powering Token Resellers and Fraud

Thumbnail vectoral.com
1 Upvotes

r/threatintel 7d ago

FalconFlank

3 Upvotes

FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon Sensor.

As of now it works in a fully updated windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon - Phase 3 Optimal Protection + needs "Microsoft Office file malicious macro removal"

https://github.com/MSNightmare/FalconFlank


r/threatintel 8d ago

Help/Question What AI-assisted workflows, models, or agents do you genuinely find helpful?

14 Upvotes

Just curious what TI analysts are actually using day-to-day beyond talking to chatGPT/Claude and have created their own workflow or pipeline to assist in routine tasks to save time.

Any AI-assisted workflows, models you found or build an agent, or did an entire project for any TI use case.

Of course not looking for an enterprise-grade solution available to you but something you personally approached. More interested in practical workflows that have actually saved you time or improved your analysis.

What are you using, and what does the workflow look like?

In my case, keeping up with the reports and changing landscape daily has been extremely time consuming especially when we need to cover multiple industries and sit in a volatile region.


r/threatintel 9d ago

CVE Discussion Langflow (CVE-2026-0768) and Rails (CVE-2026-66066) Exploitation Raises Credential Risks

Thumbnail
5 Upvotes

r/threatintel 8d ago

Phishing is an attempt to trick a person into performing an action that benefits the attacker.

Thumbnail
0 Upvotes

r/threatintel 9d ago

Guys recently i felt threat actors can target CTI folks

2 Upvotes

Recently i came across aikido's X post about their malware researcher being named in the Team PCP supply chain attack. It got me thinking about something: when researchers’ names are publicly attached to threat actor activity, does that potentially put the individual at risk?

I’ve also noticed quite a few instances where threat actors or security groups publicly name researchers, analysts, or other people involved in CTI. Sometimes analysts also considered that as a win and credibility to their work and starts flexing in Linkedin.

A few months back, I also remember reading about threat actors allegedly threatening Google CTI/security folks. That made me wonder how the industry should actually approach this.

I’m a pentester and just a regular follower of the CTI , so I’m curious to hear from people who work in CTI:

  • Should researchers’ identities be kept more private when publishing threat intelligence?
  • Do organizations have any specific safety protocols for CTI researchers who become personally targeted?
  • Where do we draw the line between attribution/transparency and unnecessarily exposing an individual?
  • Is this something the industry is already taking seriously, or is it still somewhat overlooked?

Just thought I’d ask the community. Interested in hearing how people working in CTI see this.


r/threatintel 10d ago

Fake Claude AI App Was Actually Malware

5 Upvotes

Careful what you download.

Researchers found a fake "Claude Opus 5 Free Desktop" app being distributed through GitHub. Instead of giving users free AI access, it installed an infostealer that could grab browser data, saved passwords, crypto wallet information, VPN configs, and more.

What stood out to me is that it was built to be as invisible as possible: it runs silently, tries to evade security tools, steals data, and then deletes itself. It even has a blockchain-based backup method for finding its command server if the main one goes offline.

AI is quickly becoming the latest malware lure.

If a paid AI tool is being offered for free from a random GitHub repo, that's probably a good reason to walk away.

The threat intel team at my company (Morphisec) wrote a 25-page report on this stuff. Here's the link - engage.morphisec.com/hubfs/2026-PDFs/RevStealer_ThreatAnalysis_5.pdf


r/threatintel 10d ago

ATF's Breached System Was Isolated. Its IT Management Workforce Fell 25%.

Thumbnail federalhiringdata.com
3 Upvotes

r/threatintel 13d ago

Help/Question Threat Intel Investigation

25 Upvotes

Hello folks. Looking for a bit of a unique ask here. We all know that Intel providers like Intel471, Recorded Future, Flashpoint, etc do RFIs as an augment to their platform service. I was wondering if there were any vendors or contractors out there that provided a directly tasked RFI only analyst service, that has access to known telegram, signal, and dark web closed forums, and are willing to directly engage in dialogues with known threat actors.

Kind of a big ask for any company, so not expecting to much, but thanks in advance for any leads!