Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-10 01:38:52 EDT

Explore

PostsPeople
LatestRanked
@threadlinqs.bsky.socialOct 9, 2026, 9:44 PM

GhostAction's fake 'security audit' workflows now mine entire git history for secrets. https://intel.threadlinqs.com/threat/TL-2026-3157 #ThreatIntel #xmrig #GhostAction #GitHub

GhostAction: Credential-Stealing GitHub Actions Workflows Planted in Compromised Maintainer Repositories
@hacks.grOct 9, 2026, 4:02 PM

Two flaws in AhsayCBS backup software are being exploited to bypass login checks and run commands.

The catch: reports disagree on whether version 10.3.4 fixes the fla…

https://en.hacks.gr/agnostoi-parakamptoyn-ti-syndesi-sto-ahsaycbs-kai-exoryssoyn-kryptonomismata/

#AhsayCBS #CVE2026105133 #XMRig

Άγνωστοι παρακάμπτουν τη σύνδεση στο AhsayCBS και εξορύσσουν κρυπτονομίσματα
@thedailytechfeed.comOct 9, 2026, 1:04 PM

AhsayCBS flaws let attackers deploy XMRig miners disguised as Microsoft Edge – act NOW to patch and lock down access. #AhsayCBS #Cryptojacking #XMRig #BackupSecurity #AIThreat #Cybersecurity https://thedailytechfeed.com/hackers-abuse-ahsaycbs-flaws-to-run-xmrig-mines-masked-as-edge/

@cyfar.caOct 9, 2026, 12:36 PM

@huntress.com
Attackers chain AhsayCBS flaws to deploy JSP webshells and XMRig.
-
IOCs: imagefiles-backup[.]oss-ap-southeast-7[.]aliyuncs[.]com, xmr[.]kryptex[.]network, 51[.]195[.]127[.]124
-
#CVE-2026-105134 #ThreatIntel #XMRig

@threadlinqs.bsky.socialOct 5, 2026, 11:40 AM

CARBONATO botnet hands exposed Docker hosts to an AI agent that hunts your LLM API keys. https://intel.threadlinqs.com/threat/TL-2026-2929 #ThreatIntel #CARBONATO #FSociety #xmrig

CARBONATO: Botnet Built Around an AI Agent (Hermes Agent) Spreading via Exposed Docker APIs
@dragonxchain.bsky.socialOct 4, 2026, 7:36 AM

If your CPU can run RandomX workloads, put it on DragonX and test your hashrate.

Current pool stats:

99.64% efficiency
560,947.70 DRGX paid
drg-xmrig 6.25.3

🐉 $DRGX

Mine DragonX

#RandomX #CPUmining #XMRig #DragonX #DRGX #Ryzen #Threadripper #EPYC #Xeon #Intel #AMD #PoW #CryptoMining

@hendryadrian.bsky.socialSep 30, 2026, 11:45 AM

KMS Auto was abused as the entry point in a multi-stage intrusion that led to XMRig mining, remote access via ScreenConnect and MeshAgent, and a scareware payload posing as ransomware. #KMSAuto #XMRig #APT36

@threadlinqs.bsky.socialSep 27, 2026, 9:04 AM

A botnet hijacked an open-source AI agent's persona file to steal LLM keys before SSH creds. https://intel.threadlinqs.com/threat/TL-2026-2689 #ThreatIntel #CARBONATO #xmrig #Hermes

CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft
@threadlinqs.bsky.socialSep 24, 2026, 8:54 PM

No malware binary needed: Carbonato only wants your Docker API on 2375 open to the internet. https://intel.threadlinqs.com/threat/TL-2026-2639 #ThreatIntel #Carbonato #GH0ST #xmrig

Carbonato botnet: AI-agent-driven worm hijacks unauthenticated Docker daemons on port 2375 and installs the Hermes Agent 'GH0ST' implant
@thedailytechfeed.comSep 21, 2026, 8:43 AM

Attackers hide XMRig miner using PNG/WAV files & Registry tricks for stealthy crypto mining. #XMRig #Malware #Security #Cybersecurity #Stealth #FilelessMining https://thedailytechfeed.com/hackers-infiltrate-pcs-with-hidden-xmrig-miner-using-png-wav-registry-tricks/

@threadlinqs.bsky.socialSep 20, 2026, 11:31 PM

This miner never writes a file - it lives in the Registry and hides its C2 in a PNG and WAV. https://intel.threadlinqs.com/threat/TL-2026-2593 #ThreatIntel #CVE_2020_14979 #xmrig #WinRing0sys

PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography for Stealth C2
@intelnightowl.bsky.socialSep 20, 2026, 8:47 AM

Malware uses PowerShell, registry, DNS TXT, PNG, and WAV to covertly deploy XMRig cryptocurrency miner. #Malware #PowerShell #Registry #DNS #PNG #WAV #XMRig #CryptocurrencyMiner https://gbhackers.com/powershell-malware-abuses-registry-and-dns-txt-records/

@hendryadrian.bsky.socialSep 18, 2026, 7:45 AM

Multi-stage intrusion used Registry-stored PowerShell, DNS TXT records, PNG and WAV payloads, and in-memory .NET loading to deploy XMRig mining while weakening Defender and PowerShell logging. #XMRig #RegistryHiding #InMemoryLoad

@threadlinqs.bsky.socialSep 16, 2026, 11:58 AM

Patch ScreenConnect now - rogue sessions self-propagate a backdoor, miner and C2 tunnel to new hosts. https://intel.threadlinqs.com/threat/TL-2026-2533 #ThreatIntel #CVE_2026_84869 #xmrig #TrojanScript

CISA Warns of Active Exploitation of Critical ConnectWise ScreenConnect Flaw (CVE-2026-84869, CVSS 9.9)
@securityonline.bsky.socialSep 9, 2026, 1:31 AM

A Redis cryptomining botnet used a rogue replication attack to hijack 3,562 servers for Monero mining. See how the campaign worked.

#Redis #Cryptomining #XMRig #Monero #Botnet #CyberSecurity #LinuxMalware #ThreatIntel

@threadlinqs.bsky.socialSep 7, 2026, 2:25 PM

REVSTEALER: Chrome App-Bound bypass via hardware breakpoints + Polygon blockchain smart contract C2 dead drop. https://intel.threadlinqs.com/threat/TL-2026-2370 #ThreatIntel #REVSTEALER #xmrig #Infostealer

REVSTEALER (REF2859): Emerging Windows infostealer with App-Bound encryption bypass, Polygon blockchain C2, and gaming-focused social engineering
@threadlinqs.bsky.socialSep 6, 2026, 4:05 PM

REVSTEALER infostealer uses 4 modules to steal wallets, disable Defender, and mine XMRig via blockchain C2. https://intel.threadlinqs.com/threat/TL-2026-2353 #ThreatIntel #xmrig #Monero #EtherHiding

REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig Crypto Miner
@hendryadrian.bsky.socialSep 3, 2026, 8:00 AM

CISA added 7 exploited flaws to KEV, impacting SonicWall, Sangoma, JFrog, Starlette, Kestra, and LiteLLM. Attackers are using them for admin access, reverse shells, miners, and credential theft. #SonicWall #LiteLLM #XMRig