INTEL_REPORT
The Hacker News · published 7/9/2026, 3:09:28 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst part is how normal it all looks until the bill arrives. The full ThreatsDay list is below. Global ThreatsDay: …
https://thehackernews.com/2026/07/threatsday-cloud-bucket-hijacking.html
sha256:fcdc7487f2c151c6993c70a998d355af6027e3f2941c90aa504dc2ae8508c804
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| camorreado.click |
| Open → |
| domain | rtsper.sys | Open → |
| cve | CVE-2026-9181 | Open → |
| cve | CVE-2025-49760 | Open → |
| cve | CVE-2025-59200 | Open → |
| cve | CVE-2022-25477 | Open → |
| cve | CVE-2022-25478 | Open → |
| cve | CVE-2022-25479 | Open → |
| cve | CVE-2022-25480 | Open → |
| cve | CVE-2024-40431 | Open → |
| cve | CVE-2024-40432 | Open → |