GhostAction's fake 'security audit' workflows now mine entire git history for secrets. https://intel.threadlinqs.com/threat/TL-2026-3157 #ThreatIntel #xmrig #GhostAction #GitHub

GhostAction's fake 'security audit' workflows now mine entire git history for secrets. https://intel.threadlinqs.com/threat/TL-2026-3157 #ThreatIntel #xmrig #GhostAction #GitHub
Two flaws in AhsayCBS backup software are being exploited to bypass login checks and run commands.
The catch: reports disagree on whether version 10.3.4 fixes the fla…
https://en.hacks.gr/agnostoi-parakamptoyn-ti-syndesi-sto-ahsaycbs-kai-exoryssoyn-kryptonomismata/
AhsayCBS flaws let attackers deploy XMRig miners disguised as Microsoft Edge – act NOW to patch and lock down access. #AhsayCBS #Cryptojacking #XMRig #BackupSecurity #AIThreat #Cybersecurity https://thedailytechfeed.com/hackers-abuse-ahsaycbs-flaws-to-run-xmrig-mines-masked-as-edge/
@huntress.com
Attackers chain AhsayCBS flaws to deploy JSP webshells and XMRig.
-
IOCs: imagefiles-backup[.]oss-ap-southeast-7[.]aliyuncs[.]com, xmr[.]kryptex[.]network, 51[.]195[.]127[.]124
-
#CVE-2026-105134 #ThreatIntel #XMRig
CARBONATO botnet hands exposed Docker hosts to an AI agent that hunts your LLM API keys. https://intel.threadlinqs.com/threat/TL-2026-2929 #ThreatIntel #CARBONATO #FSociety #xmrig
If your CPU can run RandomX workloads, put it on DragonX and test your hashrate.
Current pool stats:
99.64% efficiency
560,947.70 DRGX paid
drg-xmrig 6.25.3
🐉 $DRGX
Mine DragonX
#RandomX #CPUmining #XMRig #DragonX #DRGX #Ryzen #Threadripper #EPYC #Xeon #Intel #AMD #PoW #CryptoMining
A botnet hijacked an open-source AI agent's persona file to steal LLM keys before SSH creds. https://intel.threadlinqs.com/threat/TL-2026-2689 #ThreatIntel #CARBONATO #xmrig #Hermes
No malware binary needed: Carbonato only wants your Docker API on 2375 open to the internet. https://intel.threadlinqs.com/threat/TL-2026-2639 #ThreatIntel #Carbonato #GH0ST #xmrig
Attackers hide XMRig miner using PNG/WAV files & Registry tricks for stealthy crypto mining. #XMRig #Malware #Security #Cybersecurity #Stealth #FilelessMining https://thedailytechfeed.com/hackers-infiltrate-pcs-with-hidden-xmrig-miner-using-png-wav-registry-tricks/
This miner never writes a file - it lives in the Registry and hides its C2 in a PNG and WAV. https://intel.threadlinqs.com/threat/TL-2026-2593 #ThreatIntel #CVE_2020_14979 #xmrig #WinRing0sys
Malware uses PowerShell, registry, DNS TXT, PNG, and WAV to covertly deploy XMRig cryptocurrency miner. #Malware #PowerShell #Registry #DNS #PNG #WAV #XMRig #CryptocurrencyMiner https://gbhackers.com/powershell-malware-abuses-registry-and-dns-txt-records/
Multi-stage intrusion used Registry-stored PowerShell, DNS TXT records, PNG and WAV payloads, and in-memory .NET loading to deploy XMRig mining while weakening Defender and PowerShell logging. #XMRig #RegistryHiding #InMemoryLoad
Patch ScreenConnect now - rogue sessions self-propagate a backdoor, miner and C2 tunnel to new hosts. https://intel.threadlinqs.com/threat/TL-2026-2533 #ThreatIntel #CVE_2026_84869 #xmrig #TrojanScript
A Redis cryptomining botnet used a rogue replication attack to hijack 3,562 servers for Monero mining. See how the campaign worked.
#Redis #Cryptomining #XMRig #Monero #Botnet #CyberSecurity #LinuxMalware #ThreatIntel
REVSTEALER: Chrome App-Bound bypass via hardware breakpoints + Polygon blockchain smart contract C2 dead drop. https://intel.threadlinqs.com/threat/TL-2026-2370 #ThreatIntel #REVSTEALER #xmrig #Infostealer
REVSTEALER infostealer uses 4 modules to steal wallets, disable Defender, and mine XMRig via blockchain C2. https://intel.threadlinqs.com/threat/TL-2026-2353 #ThreatIntel #xmrig #Monero #EtherHiding
CISA added 7 exploited flaws to KEV, impacting SonicWall, Sangoma, JFrog, Starlette, Kestra, and LiteLLM. Attackers are using them for admin access, reverse shells, miners, and credential theft. #SonicWall #LiteLLM #XMRig