Threats Tagged 't1046'
View all threats tagged with 't1046'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1046'
Click on any threat for detailed analysis and mitigation recommendations
Ongoing PLC Exploitation Against Critical U.S. Infrastructure 0 Multiple federal agencies have updated a joint advisory warning of active exploitation targeting programmable logic controllers (PLCs) in U.S. critical infrastructure. Attackers scan for internet-exposed industrial control systems and connect using legitimate engineering software with valid credentials, appearing as authorized technicians. Once inside, they alter controller logic and manipulate operator displays to hide anomalies. The campaign has expanded beyond Rockwell Automation to include Schneider Electric and Siemens equipment. Unlike a similar 2023 campaign that caused minimal disruption, this ongoing activity has resulted in confirmed operational disruption and financial losses. Targeted sectors include government facilities, water systems, and energy infrastructure. The exploitation leverages architectural weaknesses rather than software vulnerabilities, with attackers accessing systems through ports 22, 102, 502, 2222, and 44818. Join the discussion | AlienVault OTX General | 07/24/2026, 12:34:37 UTC Added: 07/24/2026, 14:52:06 UTC |
Upgrades MaaS Ecosystem with Modular Tools 0 Insikt Group identified four new malware families from TAG-195 (Golden Chickens, Venom Spider), a financially motivated malware-as-a-service developer. The families include TinyEgg, a lightweight initial-access backdoor; ChonkyChicken, which expands capabilities with browser credential theft and session automation; a modularized ChonkyChicken variant using controller-and-plugin architecture; and ChromEggscalator, a modified Chrome encryption-bypass tool. TAG-127 has been observed deploying TinyEgg via ClickFix campaigns using fake security verification pages. The modular architecture reduces static detection exposure and enables selective capability provisioning to operators. All families share consistent architectural traits including WebSocket command-and-control, Run key persistence, string obfuscation, and execution via legitimate Windows binaries. This represents a deliberate architectural transition toward operator-driven tooling within the TAG-195 MaaS ecosystem. Join the discussion | AlienVault OTX General | 07/23/2026, 16:30:34 UTC Added: 07/23/2026, 23:37:06 UTC |
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)CVE-2026-63030 0 Two chained vulnerabilities in WordPress Core, CVE-2026-63030 and CVE-2026-60137, allow unauthenticated remote code execution on WordPress 6.9.x and 7.0.x installations. The vulnerabilities were publicly disclosed on July 17, 2026, with active exploitation confirmed shortly thereafter. Patches addressing these issues were released on the same day, and WordPress.org has enforced automatic updates for supported affected versions. Temporary mitigations include blocking access to the vulnerable REST API batch endpoint. No specific threat actor attribution or public indicators of compromise have been released as of July 20, 2026. Join the discussion | SANS ISC Handlers Diary | 07/28/2026, 03:35:17 UTC Added: 07/20/2026, 22:52:57 UTC |
Showing 1 to 3 of 3 results