Threats Tagged 't1609'
View all threats tagged with 't1609'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 't1609'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-46316 is a guest-to-host escape vulnerability in the vGIC-ITS emulation within KVM on ARM64 platforms. It is caused by a race condition in the vgic_its_invalidate_cache() function leading to a double-put use-after-free, which allows execution of code in the host kernel context. This flaw resides in the in-kernel KVM module, enabling successful exploitation to gain host kernel privileges. The vulnerability affects multi-tenant ARM64 cloud environments and can be chained with local privilege escalation when guest root access is unavailable. A patch fixing this vulnerability was applied in the Linux kernel at commit 13031fb6b835. Two YARA rules have been developed to detect exploitation attempts based on specific constants and behavioral patterns. There are no known exploits in the wild as of the latest information. Join the discussion | AlienVault OTX General | 06/12/2026, 16:57:58 UTC Added: 06/15/2026, 18:45:13 UTC |
A sophisticated phishing campaign targets Colombian users by impersonating the Attorney General's Office with judicial notification lures. The attack uses a multi-stage infection chain starting with a malicious . SVG file attachment that triggers HTA, VBS, and PowerShell scripts, ultimately injecting the AsyncRAT malware into MSBuild.exe. AsyncRAT establishes command and control (C2) communications, steals data, and can dynamically load plugins. The campaign employs anti-virtual machine (VM) techniques, persistence mechanisms, and heavy obfuscation to evade detection. Although primarily focused on Colombia, the advanced tactics and malware capabilities pose risks to any organization exposed to similar phishing vectors. The threat demonstrates extensive use of MITRE ATT&CK techniques, including execution, persistence, defense evasion, credential access, and command and control. No known exploits or CVEs are associated, and the severity is assessed as medium based on current information. Join the discussion | AlienVault OTX General | 10/13/2025, 19:01:41 UTC Added: 10/13/2025, 19:43:32 UTC |
This investigation delves into information operations conducted by Russian actors known as Doppelgänger, focusing on their activities from early June to late-July 2024. It examines their tactics, associated infrastructure, and motivations, particularly in relation to the unexpected snap general election in France during this period. The analysis reveals a persistent and complex effort to disseminate disinformation through social media, impersonating legitimate news websites and employing intricate redirection chains. The operations primarily target conservative and nationalist sentiments, aiming to destabilize Western democracies by exploiting existing societal and political divisions. Join the discussion | AlienVault OTX General | 07/30/2024, 14:44:01 UTC Added: 08/07/2025, 13:02:45 UTC |
Showing 1 to 3 of 3 results