Hunter Strategy
  • Trending Topics
  • Threat Intelligence
  • Contact Us
  • Hunter Website
Sign in Subscribe
PamStealer Targets macOS, SalesBleed Hijacks Salesforce Agents, and a 14-Year-Old Linux Bug Hits CISA KEV
Trending Topics

PamStealer Targets macOS, SalesBleed Hijacks Salesforce Agents, and a 14-Year-Old Linux Bug Hits CISA KEV

A new PamStealer variant targets macOS through a fake crypto wallet, a Cloudflare flaw left customer data on reused disks, SalesBleed hijacked Salesforce agents via a web form, Windows 11 updates caused AVD black screens, and a 14-year-old Linux bug landed on CISA's KEV list.
Read more
William Elchert and Antonio Rivera
F5 BIG-IP Zero-Day Exploited, Plus Critical cPanel, Ubuntu, Chrome, and Next.js Flaws
Trending Topics

F5 BIG-IP Zero-Day Exploited, Plus Critical cPanel, Ubuntu, Chrome, and Next.js Flaws

Attackers are exploiting an F5 BIG-IP APM zero-day. cPanel patched a flaw giving any hosting account root, and a public exploit targets unpatched Ubuntu container hosts. A China-nexus actor is chaining Chrome and Windows zero-days, and Next.js fixed a 9.5 CVSS code execution bug.
Read more
William Elchert and Antonio Rivera
Critical Patches, Supply Chain Risks, and a New Ransomware Campaign
Trending Topics

Critical Patches, Supply Chain Risks, and a New Ransomware Campaign

Microsoft and Check Point patch maximum-severity flaws, researchers expose a plugin-pinning bypass in AI coding agents and a credential-stealing npm campaign tied to bogus bug bounty claims, and a ransomware actor chains Confluence and 1C exploits into full compromises.
Read more
William Elchert and Antonio Rivera
Cisco 0-Day Under Attack, Token-Stealing Phishing Kits, and a $250 RAT Subscription
Trending Topics

Cisco 0-Day Under Attack, Token-Stealing Phishing Kits, and a $250 RAT Subscription

A critical Cisco Secure Email Gateway 0-day is under active exploitation ahead of a CISA deadline, two new phishing kits are hijacking real login flows to steal SSO tokens and Entra device trust, and a $250-a-month RAT subscription is lowering the bar for full-featured remote access attacks.
Read more
William Elchert and Antonio Rivera
GitLab, JFrog, and Cisco Flaws Under Active Attack
Trending Topics

GitLab, JFrog, and Cisco Flaws Under Active Attack

GitLab, JFrog Artifactory, and Cisco FMC are under active attack, a Windows 11 update is breaking VPNs, and Trezor users are facing a newsletter phishing wave.
Read more
William Elchert and Antonio Rivera
Defender Bypass, Chrome 0-Day, and Fake Recruiters: This Cycle's Top Threats
Trending Topics

Defender Bypass, Chrome 0-Day, and Fake Recruiters: This Cycle's Top Threats

This roundup covers a Windows Defender bypass with SYSTEM-level exposure, an actively exploited Chrome 0-day, a critical flaw in an AI coding agent framework, a cPanel bug that lets one hosting account escalate to root, and a fake-recruiter campaign delivering new malware to developers.
Read more
William Elchert and Antonio Rivera
Medusa Ransomware: Threat Intelligence Brief
Threat Intelligence

Medusa Ransomware: Threat Intelligence Brief

TLP: WHITECYBER THREAT INTELLIGENCE BRIEF RANSOMWARE-AS-A-SERVICE THREAT SERIES Medusa
Read more
William Elchert and Antonio Rivera
Zero-Days and Critical Flaws: CrowdStrike Falcon, Chrome, Elementor Pro, Super Forms, Plex, Cisco Nexus
Trending Topics

Zero-Days and Critical Flaws: CrowdStrike Falcon, Chrome, Elementor Pro, Super Forms, Plex, Cisco Nexus

CrowdStrike Falcon Zero-Day Abuses Macro Remediation for SYSTEM Access A researcher
Read more
William Elchert and Antonio Rivera
Critical Vulnerability Roundup: SonicWall, Dropbox, JFrog, and Redis
Trending Topics

Critical Vulnerability Roundup: SonicWall, Dropbox, JFrog, and Redis

SonicWall SMA1000 zero-days under active attack, a Dropbox breach via a Lenovo identity flaw, Microsoft Defender Safe Links false-flagging Google links, a Redis TLS use-after-free bug, and a critical JFrog Artifactory auth bypass already being exploited.
Read more
William Elchert and Antonio Rivera
ServiceNow CVSS 10.0 Flaws, PaperCut Zero-Day, and New Tortoiseshell Malware
Trending Topics

ServiceNow CVSS 10.0 Flaws, PaperCut Zero-Day, and New Tortoiseshell Malware

ServiceNow, PaperCut, and cPanel all patched critical vulnerabilities, one under active exploitation. Plus: malicious Chrome and Edge extensions draining crypto wallets, and Iranian group Tortoiseshell's new SSH tunneling backdoor.
Read more
William Elchert and Antonio Rivera
Water Utilities Under Attack, Plus Unauthenticated RCE Flaws in WatchGuard and SonicWall
Trending Topics

Water Utilities Under Attack, Plus Unauthenticated RCE Flaws in WatchGuard and SonicWall

CISA warns of Iranian attacks on exposed water systems, plus critical patches for Ubiquiti UniFi, GitLab EE, WatchGuard Agent, and SonicWall NetExtender Linux Client covering unauthenticated RCE and root-level file-write flaws.
Read more
William Elchert and Antonio Rivera
Rust Supply Chain Attack, Entra ID Zero-Day, and Cisco, TrueConf Patches
Trending Topics

Rust Supply Chain Attack, Entra ID Zero-Day, and Cisco, TrueConf Patches

This week: a crates.io compromise spread malware via arrayref, Microsoft fixed an exploited Entra ID zero-day, CISA flagged actively exploited TrueConf Server flaws, FTP-banner malware delivered E4del and PINHOLE, and Cisco patched nine Crosswork/Secure Workload bugs.
Read more
William Elchert and Antonio Rivera
Hunter Strategy © 2026
Powered by Ghost