Huntbase Hub

Threat hunts from this week's research.

Each hunt turns a piece of public threat research into something you can run: a hypothesis, the queries that test it, what a hit looks like, and what the hunt cannot see.

Want to run them against your own data? Sign up to Huntbase, free →

207 of 207 hunts

  1. high
    Research by Cisco Talos

    AI-Integrated Malware Execution and Orchestration

    Adversaries use AI frameworks or local runtimes for autonomous malware orchestration, detectable through cognitive artifacts like framework-specific imports, natural-language evasion strings, and outbound provider API traffic.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · defense evasion · execution
  2. high
    Research by Rapid7

    Citrix NetScaler Authentication Bypass and Exposure

    An unauthenticated attacker has exploited CVE-2026-19490 on an internet-facing NetScaler appliance to bypass authentication and gain unauthorized remote access.

    3 query1 analytic1 checkpoint2 task
    initial access
  3. high
    Research by Rapid7

    F5 BIG-IP APM OAuth RCE Exploitation

    An unauthenticated attacker is exploiting a heap-based buffer overflow in F5 BIG-IP APM by sending crafted traffic to virtual servers configured with OAuth profiles to achieve code execution.

    3 query2 analytic2 checkpoint1 action2 task
    execution · initial access
  4. high Part 2 of 2
    Research by Rapid7

    Internal Coercion and Editor Persistence

    An adversary is using rogue DHCPv6 services to perform DNS takeover for Kerberos relaying, or has established persistence via unauthorized Kate editor plugins on compromised hosts.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · execution · initial access
  5. high Part 1 of 2
    Research by Rapid7

    Exploitation of Web-Facing GitLab and Langflow

    An adversary is exploiting GitLab unauthenticated file reads or Langflow authenticated RCE to access repository secrets or execute code on the server host, starting from public-facing assets.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · execution · initial access
  6. high
    Research by Sekoia

    Exvicy ClickFix Social Engineering and PowerShell Execution

    An adversary is using compromised WordPress sites to deliver Exvicy ClickFix lures that trick users into executing a PowerShell downloader via social engineering keyboard shortcuts.

    4 query2 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  7. high
    Research by Cisco Talos

    M365 Session Hijacking and Malware Execution

    An adversary has bypassed MFA by stealing M365 session tokens via DocuSign-themed phishing, enabling them to execute malicious droppers and deploy ransomware across the fleet.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · execution · impact
  8. high Part 2 of 2
    Research by Cisco Talos

    SSO Takeover and Data Impact

    An adversary has bypassed SSO protections using stolen credentials and is now performing bulk data exfiltration or deploying ransomware across the environment.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · execution · impact
  9. high Part 1 of 2
    Research by Cisco Talos

    Infostealer execution and browser credential harvesting

    An adversary has successfully phished a user and executed an infostealer, which is now harvesting browser credentials and cookies from local SQLite databases for exfiltration.

    5 query2 analytic2 checkpoint1 action2 task
    credential access · execution · impact
  10. medium Part 1 of 2
    Research by Cisco Talos

    ClickFix Browser Injection and Extension Persistence

    An intruder has used a social engineering lure to trick a user into manually injecting a JavaScript loader or installing a malicious Tampermonkey script that facilitates persistent cryptocurrency theft via the Google Visualization API.

    5 query2 analytic1 checkpoint1 action2 task
    collection · command and control · execution
  11. high
    Research by Cisco Talos

    Microsoft Patch Tuesday September 2026 Exposure

    An adversary is exploiting September 2026 zero-day or critical remote code execution vulnerabilities, such as those in DNS Server or the Windows Update Stack, to establish initial access or escalate privileges on unpatched systems.

    3 query1 analytic1 checkpoint2 task
    execution · initial access · privilege escalation
  12. high Part 2 of 2
    Research by Cisco Talos

    Autonomous AI Command-and-Control and Impact

    An adversary is using autonomous AI-driven malware to orchestrate command-and-control decisions via LLM API calls, followed by high-volume data encryption for impact.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  13. high Part 1 of 2
    Research by Cisco Talos

    Socially Engineered Endpoint Infection and Evasion

    An attacker uses social engineering lures such as consultancy offers to trick users into running trojanised software that installs an EDR killer and steals credentials.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · credential access · defense evasion
  14. high Part 2 of 2
    Research by Huntress

    AI-Accelerated Post-Exploitation and Extortion

    An intruder is using AI-driven automation to conduct rapid internal reconnaissance, steal AI service tokens, and triage sensitive files for extortion at machine speed.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  15. high Part 1 of 2
    Research by Huntress

    Machine-Speed Perimeter and Identity Ingress

    An automated attacker is exploiting unpatched perimeter services or using AI-refined phishing to compromise identities, resulting in successful sign-ins from rare geolocations that correlate with known gateway vulnerabilities.

    3 query1 analytic1 checkpoint1 action2 task
    credential access · discovery · impact
  16. high
    Research by Rapid7

    SharePoint Business Data Connectivity Service Exploitation

    An attacker has exploited the SharePoint Business Data Connectivity service by uploading a malicious BDC model file to instantiate a .NET gadget chain, resulting in remote code execution within the IIS worker process context.

    3 query1 analytic1 checkpoint1 action2 task
    execution · initial access
  17. high
    Research by Rapid7

    Unauthenticated N-central Administrator Account Creation

    An intruder has exploited a routing discrepancy between Envoy and Jetty in an N-central server to bypass authentication and create a new administrative account for persistence.

    3 query2 analytic2 checkpoint1 action2 task
    credential access · initial access · persistence
  18. high
    Research by Rapid7

    Metasploit Framework Exploitation and Post-Exploitation

    An intruder has leveraged one of sixteen new Metasploit modules to exploit a public-facing web application and establish persistence or conduct Kerberos authentication relaying.

    5 query2 analytic1 checkpoint1 action2 task
    credential access · defense evasion · initial access
  19. high
    Research by ESET Research

    SparroWocky Backdoor and FamousSparrow APT Activity

    An adversary has established a beachhead on a web-facing server using a trident loader scheme and is communicating with SparroWocky C2 infrastructure.

    5 query2 analytic1 checkpoint1 action2 task
    execution · exfiltration · initial access
  20. high
    Research by Sekoia

    Gamaredon GammaLoad Intrusion Lifecycle

    An adversary is using multi-stage VBScript loaders to maintain persistent access by caching C2 configuration in HKCU registry keys and executing payloads from Alternate Data Streams via scheduled tasks.

    5 query2 analytic1 checkpoint1 action2 task
    execution · exfiltration · persistence
  21. high Part 2 of 2
    Research by Sekoia

    ErrTraffic ClickFix PowerShell and Infostealer Activity

    An intruder has tricked a user into running a PowerShell command via a ClickFix lure, which downloads an infostealer to harvest credentials and connect to blockchain-resolved C2 domains.

    3 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  22. high Part 1 of 2
    Research by Sekoia

    ErrTraffic Infrastructure and Delivery Monitoring

    An intruder has compromised WordPress servers to host the ErrTraffic framework, which currently resolves C2 via blockchain RPCs and serves ClickFix lures from specific JavaScript endpoints.

    4 query1 analytic1 checkpoint1 action2 task
    collection · command and control · credential access
  23. high Part 2 of 2
    Research by Sekoia

    APT28 Edge Hijacking and AI-Driven Exfiltration

    An adversary has hijacked local DNS settings via compromised edge infrastructure and is using a rare, non-browser process to automate the harvesting of documents for exfiltration via AI APIs or high-port tunnels.

    3 query1 analytic1 checkpoint1 action2 task
    command and control · credential access · execution
  24. high Part 1 of 2
    Research by Sekoia

    APT28: Outlook and Print Spooler Exploitation

    An adversary is exploiting unpatched Outlook or Print Spooler vulnerabilities to harvest NTLM credentials or escalate privileges, evidenced by outbound SMB connections to external IPs and rare child processes launched by the spooler service.

    4 query2 analytic2 checkpoint1 action2 task
    command and control · credential access · execution