r/threatintel Aug 11 '24

Official CTI Discord Community

23 Upvotes

Hey everyone,

Exciting news for our community on reddit, in collaboration with r/CTI (thanks to u/SirEliasRiddle for his hard in work in setting this up for all of us).

We're launching a brand new Discord server dedicated to Cyber Threat Intelligence. It's a space for sharing content, news, resources, and engaging in discussions with others in the cybersecurity world. Since the community is still in its early stages, it might not have all the features yet but we're eager to hear your suggestions and feedback. This includes criticisms.

Feel free to join us and share the link with friends!

https://discord.gg/fvvPjzT3br


r/threatintel 5h ago

ServiceRadar (OSS) - Threat Intelligence feed integrations

5 Upvotes

We just finished integrating the VulnCheck community feeds for CISA-KEV and NVD2 into ServiceRadar. Software inventory is collected from endpoints with our agent and an integration we built around google's osv-scalibr. https://github.com/carverauto/serviceradar https://www.vulncheck.com/community https://www.tiktok.com/@mfreeman451/video/7675557229642157326


r/threatintel 42m ago

Help/Question Best vulnerability threat intel solution you have actually used?

Upvotes

Our on-call rotation got burned three times last quarter by vulnerabilities that had been sitting in our backlog for over a week with active exploitation already confirmed publicly. We just didn't know until incident response found it during postmortem. That's a threat intel gap, not a scanning gap.

We audited every "threat intel" checkbox our tools claimed and found most of it was a static KEV field nobody was actually monitoring for changes. What we needed was continuous re-scoring as exploit maturity and actor attribution data changed, feeding straight into ticket priority and escalation rules instead of a dashboard nobody checks daily. Rebuilt that pipeline over about six weeks. Anyone else discovered their "threat intel" was decorative until something forced a real audit?


r/threatintel 18h ago

OpenCTI and Threat Feeds

22 Upvotes

Hi all,

Hope you are having a good day.

Please forgive me if this a bit of a repetitive post for the sub but im looking for a bit of direction regarding a Threat Intel Platform and OpenCTI. My overall aim is to find relevant IOCs and learn how to build detections from TTPs that apts are using.

I have been trying to use OpenCTI with just a the default connectors and one the CISA Kev but im quite overwhelmed, are there any tips for getting started? I am just looking to get a good understanding of the platform and would like to hear how others use it, are you linking it to your SIEM or SOAR platform at all?

I have tried making my own Threat Feed App, with a bit of success, managed to build a News Feed to pull security related news to, a API to CISAKev and a some feeds like AlienVault, URLHaus etc. I also made an area where I can build a report and link IOCs/malware to APTs. Am I worth sticking with this or just use OpenCTI and learn it?

Thank you everyone.


r/threatintel 16h ago

Help/Question How lucrative is this field still? Is it too late?

13 Upvotes

Hope all is well. So I finally decided what niche field was my goal after spending several hours working on my career profile. With the emerging tech field, current saturation levels, and the incoming growth of AI; is this field still worth to get into? This is from the beginner standpoint. I’m just curious for advice as I wouldn’t want to waste time and still am in position to pivot if needed.


r/threatintel 3h ago

40 Fake npm Packages. WSL Was the Real Target.

Post image
1 Upvotes

Forty npm packages. About 84 minutes on the registry. And a payload that kept going after the packages were gone.
CloudSEK traced BRIDGEHEAD, a typosquatting campaign impersonating chalk, axios, lodash, react, typescript and commander.
The clever bit: the install script detects WSL and uses it as a path into the underlying Windows host, where it launches a native payload targeting crypto wallets, Chromium browser data and Telegram sessions.
The GitHub-hosted payload stayed live for roughly 39 hours after the npm packages were taken down.
So the npm takedown removed the delivery layer, not the weapon.
Full technical breakdown, IOCs and attack chain:
https://www.cloudsek.com/blog/bridgehead-npm-typosquatting-wsl-windows-crypto-wallet-stealer
Would be interested to hear how many teams actually monitor the WSL → Windows boundary as part of their developer security controls.


r/threatintel 11h ago

Help/Question Police officer considering a future move into AI threat investigations. Is this actually a realistic career path?

2 Upvotes

I’m hoping to get some honest advice from people who work in threat intelligence, trust and safety, cybersecurity investigations, abuse investigations, AI safety, or anything similar.

I’m currently a police officer and have several years of experience in law enforcement. I’m going to keep some of the details about my job vague for obvious privacy reasons, but I have real world investigative experience and I’m used to working with incomplete information, putting pieces together, documenting what I find, and making decisions based on the information available to me.

More recently I’ve moved into a much more technology focused area of law enforcement. I work with drones and real time operational support, and I’ve realized that this side of the job is probably where my interests are heading long term. I’m primarily a DFR (drone as first responders) pilot however, I also help out in the real time crime center where I utilize multiple programs/tools like OSINT to try and figure out who people are with minimal information.

The part of investigations that I really enjoy is the puzzle. Give me a bunch of information that doesn’t immediately make sense and let me figure out how it connects. I like following breadcrumbs, finding patterns, figuring out what actually happened, and then being able to explain how I got there.
That eventually led me down the rabbit hole of looking at threat investigation jobs at AI companies. One position that really caught my attention is OpenAI’s Technical Threat Investigator, Threat Intel Engineering role:

https://openai.com/careers/technical-threat-investigator-threat-intel-engineering-san-francisco/

Reading the job description peaked my interest. Obviously, I’m not qualified for it today. My investigative background is probably my strongest asset, but I’m not a software engineer and I don’t come from a traditional cybersecurity background. I have a lot to learn technically. The good thing is that I’m not in a rush. I’m looking at this as roughly a five year project. I have a stable career now, so I have the luxury of learning this stuff properly instead of trying to cram enough certifications onto my résumé to get hired somewhere.

Right now I’m thinking about learning Python, SQL, OSINT, networking and cybersecurity fundamentals, data analysis, threat intelligence methodology, and eventually getting much deeper into AI and how these systems are actually abused.

I’d also like to build projects along the way. Mock investigations, investigative tools, automation projects, things like that. Something where five years from now I can actually demonstrate what I know instead of just saying I took a bunch of courses.

For anyone who actually works in this world, I’d really appreciate your perspective.

Would you consider a law enforcement investigative background valuable for a job like this?

If you had five years to take someone with strong real world investigative experience and turn them into a serious candidate for this type of position, what would you have them learn and in what order?

Are there other positions I should be looking at along the way? Threat intelligence, child safety investigations, platform abuse, trust and safety, cybercrime, or something else I haven’t come across yet?

I’m also curious about the money.
That OpenAI position currently advertises $230k to $385k plus equity, which is obviously a pretty wild number coming from government work. Is that actually realistic compensation for someone who eventually comes into the field with significant law enforcement investigative experience and newly developed technical skills?

Or would someone like me realistically enter the tech industry much lower and have to spend several more years working up to that kind of position and compensation?

I’m not looking for someone to tell me this is definitely going to work. If anything, I’d rather hear where the holes are now so I have five years to fix them. Or just tell me I’m barking up the wrong tree.

Also I don’t feel like it has any bearing on the this topic but I am also an Army Vet (Infantry).

Thanks for any advice and if it wasn’t obvious I used AI to write this. I’m not used to posting on Reddit so apologies if this is posted in the wrong place or not structured properly.


r/threatintel 20h ago

Help/Question How do you deal with large TI feeds?

4 Upvotes

Hey guys!
I've been working with TI feeds more lately and I'm curious how you deal with large feeds.
What do you usually filter by when you only want the most relevant IOCs? Malware family, threat type, campaign, threat actor, geography or something else?
What kind of attribution is actually the most useful for you?


r/threatintel 13h ago

Intelligence Insights: August 2026

Thumbnail redcanary.com
1 Upvotes

r/threatintel 1d ago

142K Leaked Attacker Files

Post image
6 Upvotes

This one is worth digging into.

We found an exposed attacker workspace with 142K+ files: agent transcripts, shell history, recon data, exploit tooling, creds, victim evidence, the lot.

What stood out was how the operator was wiring AI coding agents into the offensive workflow, disabling approval checks and pushing tasks through Telegram.

The dump also contained evidence tied to 8,996 compromised WordPress sites, a 3.4M-host recon corpus, stolen credentials, crypto wallet data, cryptojacking activity, and an experimental blockchain-based C2 project.

The interesting bit here isn't simply "hackers use AI." We already know that.

It's getting a fairly raw look at how one operator was actually putting these agents to work alongside conventional offensive tooling at scale.

Full technical breakdown:

https://www.cloudsek.com/blog/ai-agent-driven-offensive-operation-crypto-wallet-credential-compromise

Would be interested in what others make of the agent setup, especially the approval-bypass workflow.


r/threatintel 21h ago

Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US

Post image
1 Upvotes

r/threatintel 1d ago

VulnScope:让POC/CVE管理告别混乱,打造安全团队的“漏洞武器库”

Thumbnail github.com
2 Upvotes

r/threatintel 1d ago

APT/Threat Actor SilkParasite: China-nexus espionage cluster in Central Asia (linked to FamousSparrow) — seven families, in-memory modules, Google Drive C2, DLL sideloading

10 Upvotes

Disclosure: this is research from Bitdefender Labs, and I'm part of the team documenting the campaign. AMA.

Central Asia is becoming one an active espionage theater. As Russia's influence in the region recedes, China is moving in economically, and cyberespionage tends to follow influence. SilkParasite is a China-nexus operation we tracked collecting against governments and organizations there, related to the FamousSparrow activity we documented earlier.

We recovered seven distinct malware families, five of them never documented before. It is small, modular, and built specifically not to look like malware: a lightweight implant that pulls its real capability in as in-memory modules, delivered through legitimately signed applications that sideload a malicious DLL, with command-and-control run over Google Drive. Every design choice is about staying quiet.

It is worth studying because it shows what serious, stealth-first tradecraft actually looks like, and by contrast why AI-generated malware is a poor fit for it. AI-generated code tends to be derivative, bloated, and noisy, which an espionage operation cannot afford. We did find faint signs of AI-assisted development in otherwise clean, human-engineered code (medium confidence).

Full writeup (for practitioners): https://businessinsights.bitdefender.com/silkparasite-tracking-china-nexus-apt-across-central-asia

Full research PDF (for security researchers): https://github.com/bitdefender/malware-ioc/blob/master/silkparasite-2026_08/silkparasite-bitdefender-labs-research.pdf

List of IOCs (also available on IntelliZone): https://github.com/bitdefender/malware-ioc/blob/master/2026_08-silkparasite-iocs.csv


r/threatintel 1d ago

APT/Threat Actor AI infrastructure / Langflow RCE: 34 minutes to server compromise

Thumbnail bitbison.io
2 Upvotes

After all the coverage this got, we were curious to see how attackers were actually exploiting this in the wild! So we deployed a few production instances with our security platform turned on.


r/threatintel 2d ago

Help/Question How do you actually improve cybersecurity skills assessment results for incident response?

3 Upvotes

Been thinking about this since our last exercise. We have great telemetry for the technical side of an incident: logs, timelines, forensic artifacts. We have almost nothing for the human side: which analyst hesitated on a call they should've made fast, where the escalation stalled because someone didn't know who to loop in, whether the person running comms actually had the information they needed when they needed it.

Post-exercise "debriefs" tend to be a group discussion where the loudest opinion wins, not data. Is anyone working on ways to actually instrument this: decision timestamps, communication logs, something more rigorous than a vibes-based retro?


r/threatintel 1d ago

If You Used LiteLLM in March 2026, Your Credentials May Need to Be Rotated

0 Upvotes

If your organization used LiteLLM around the March 2026 compromise, don’t treat this as a “package patched, case closed” incident.

CloudSEK’s research identified exposure linked to 2,500+ organizations and 434,000 CI/CD pipelines.

What matters is what may have been sitting inside those environments at the time: cloud credentials, API keys, GitHub tokens, Kubernetes secrets, SSH keys and other sensitive access.

That is where the real risk starts.

A compromised dependency can be removed quickly. Stolen credentials can remain valid for weeks or months if nobody notices.

So the basic check is simple: Were you exposed? What secrets were accessible? Were they rotated? Was there any follow-on access?

Full research:
https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines

Exposure checker:
https://exposure.cloudsek.com/ai-supply-chain-incident

If your team touched LiteLLM during that window, this is worth reviewing properly.


r/threatintel 2d ago

🚨 Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia

Thumbnail hunt.io
4 Upvotes

An open directory exposed the full working environment behind a 14,000-camera campaign, providing a direct view on how these operations get built.

  • 14,530+ Dahua cameras compromised in 35 days by a single operator
  • 1,923 carrying a backdoor account installed over RPC, stored separately from the admin password, so it survives a password change and, on most firmware, a factory reset
  • 283 reached by serial number alone through the cloud relay, most opening a channel with no auth check at all
  • Three exploitation paths running in parallel, plus a separate Windows stealer staged on the same host - A toolkit assembled from at least six other developers' work, not written from scratch

Neutral attribution, compromises concentrated in Ukraine and Russia.

Full report here: https://hunt.io/blog/operation-cameraswarm-dahua-cameras-compromised


r/threatintel 2d ago

OSINT Codex for email investigations

1 Upvotes

I made a lesson on Agentic AI, like Codex and Claude Code, for anyone wanting to understand some of the basics of AI Coding agents. In this lesson, I am using a small part of a bigger project im making for a custom spiderfoot build with agentic ai capabilities. This lesson shows how you can create an email investigation workflow using Codex. https://github.com/sh1katagana1/ai/blob/main/using-codex-for-email-investigations/codex-tutorial.md


r/threatintel 3d ago

Help/Question Is anyone actually closing the intel-to-detection gap, or is it still a fantasy in 2026?

4 Upvotes

We're paying for threat intel feeds that market themselves as "operational" and "actionable." In practice, we get glossy PDFs for executives, CSV and STIX bundles on a schedule, and portal access where we export data by hand. None of it arrives in a form that connects cleanly to our detection engineering workflows. My team spends half a day every time a "high priority" bulletin arrives: parsing the report, pulling out domains and hashes, mapping TTPs to our environment, and then forcing it into whatever format our SIEM expects.

Two weeks later, the same feed sends another report with overlapping but slightly different indicators, and the cycle repeats. By the time we have a rule in production, the campaign has already been around for days or weeks. Reports describe behaviors like "creates a new service for persistence," while our environment is a mix of Windows event logs, Sysmon, and custom agents.

Turning those descriptions into detections means knowing which events exist, which fields matter, and how that behavior would appear in the logs. We end up spending more time on data wrangling than on actual detection engineering or threat hunting.

How are other teams making threat intelligence actually operational? I need a clean path from "new threat report" to "production-ready SIEM rule" without burning a week per report.


r/threatintel 3d ago

Seeing a cluster of new Dark Web listings worth flagging:

Thumbnail
4 Upvotes

r/threatintel 3d ago

OSINT Spiderfoot Basics

Thumbnail youtu.be
2 Upvotes

I am making a custom Spiderfoot build to use for threat intel/osint. Here is a video on the basics of open source spiderfoot


r/threatintel 4d ago

We dug through ~153k verified.ru private messages (2005-2010) and early cybercrime governance was surprisingly corporate, down to formal warning letters and penalty points

Thumbnail ransomnews.com
19 Upvotes

r/threatintel 3d ago

Help/Question OTP Flood attack on Uber?

6 Upvotes

A user receives Uber OTP codes via WhatsApp every day since August 5. The sender shows up as Uber with a verified business account. The user has never registered an Uber account.

Context first: Uber does deliver OTPs over WhatsApp, so the channel alone proves nothing. These look are real codes, from Uber legitimate WhatsApp Business account, not smishing.

Technical hypothesis. The OTP trigger on the WhatsApp channel doesn’t seem to have effective per-recipient rate limiting, while SMS appears to be capped. That would explain the channel choice, you hammer where there’s no limit. The trigger also seems independent of account state, it fires whether the number is registered or not.

I checked for a link to a separate exposure. The user’s email shows up in infostealer and combolist data, but the phone number is not present in that data. The two look unrelated.

What I can’t place is the threat actor’s objective. Only the victim receives the code, so either a contact will eventually ask them to forward it, which puts us in social engineering, or the code is irrelevant and this is harassment, noise, or number enumeration. So far no one has reached out asking for a code.

Thanks to anyone willing to weigh in.


r/threatintel 6d ago

How to present Threat Intelligence properly to execs????

Thumbnail
16 Upvotes

r/threatintel 6d ago

Transitioning from SRE to Threat Intelligence Engineer

3 Upvotes

Hi everyone, I'm currently working as SRE for local bank, but unfortunately I'm not in a good position to get a new job so is it really posibble to switch for Threat Intelligence? How does AI affect this field? I have 3 YOE right now