Latest updates for Shodan

Fresh curated links around Shodan are collected here so marketers can spot useful updates and turn timely ideas into posts faster.

Recent items include:

  • SEO Poisoning Attack Uses Microsoft Binary to Install RMM Tool
  • Shai-Hulud Worm Steals Dev Secrets Across npm, GitHub, AWS & Kubernetes
  • New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials

Post angles to try

Share the most useful takeaway for your audience.
Turn one article into a quick practical checklist.
Ask your audience how this shift affects their work.
Turn angles into scheduled posts

Fresh articles and ideas

Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.

gbhackers.com /1 month ago

SEO Poisoning Attack Uses Microsoft Binary to Install RMM Tool

New research has exposed a search engine poisoning campaign that delivers a trojanized TestDisk installer, abuses a Microsoft-signed binary for DLL sideloading, and silently deploy...

Read source
gbhackers.com /2 weeks ago

Shai-Hulud Worm Steals Dev Secrets Across npm, GitHub, AWS & Kubernetes

Shai-Hulud is a major cybersecurity threat targeting the open-source software supply chain. Security researchers are raising alarms over “Shai-Hulud,” a self-propagating npm worm d...

Read source
thehackernews.com /3 weeks ago

New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials

Cybersecurity researchers have disclosed details of a new Linux backdoor named PamDOORa that's being advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor c...

Read source
dev.to /4 weeks ago

I Built a Tool That Detects SEO Poisoning Across Multiple Search Engines

By RUGERO Tesla (@404Saint). It started with an article I couldn't stop thinking about A few months back I read about how attackers were poisoning search results to pus...

Read source
venturebeat.com /3 weeks ago

One command turns any open-source repo into an AI agent backdoor. OpenClaw proved no supply-chain scanner has a detectio...

Just two months ago, researchers at the Data Intelligence Lab at the University of Hong Kong introduced CLI-Anything, a new state-of-the-art tool that analyzes any repo’s source co...

Read source
infosecurity-magazine.com /1 week ago

Mini Shai-Hulud Hits Hundreds of npm Packages in AntV Ecosystem

Mini Shai-Hulud worm hits Alibaba AntV ecosystem in largest npm supply chain wave to date

Read source
cybersecuritynews.com /17 hours ago

Pentest Swarm AI Tool With Live Access to nmap, sqlmap, Burp, Metasploit, and Others

Pentest Swarm AI is the first open-source autonomous penetration testing platform built on a swarm intelligence architecture, not just multiple agents firing in a fixed sequence. D...

Read source
venturebeat.com /4 weeks ago

200,000 MCP servers expose a command execution flaw that Anthropic calls a feature

Anthropic created the Model Context Protocol as the open standard for AI agent-to-tool communication. OpenAI adopted it in March 2025. Google DeepMind followed. Anthropic donated M...

Read source
3dnews.ru /1 month ago

ИИ-модель Claude обнаружила уязвимость и разработала рабочий эксплойт для FreeBSD

ИИ-модель Claude вместе с исследователем Николасом Карлини (Nicholas Carlini) примерно за 4 часа автономно создала два рабочих эксплойта для уязвимости CVE-2026-4747 в ядре FreeBSD...

Read source
venturebeat.com /1 month ago

Mythos autonomously exploited vulnerabilities that survived 27 years of human review. Security teams need a new detectio...

A 27-year-old bug sat inside OpenBSD’s TCP stack while auditors reviewed the code, fuzzers ran against it, and the operating system earned its reputation as one of the most securit...

Read source
pcworld.com /1 month ago

Anthropic’s new AI found thousands of zero-day flaws on its own

On Tuesday, Anthropic unveiled its latest AI model called Claude Mythos. This “general-purpose, unreleased frontier model” is so impressively powerful that Anthropic is wary of rel...

Read source
thehackernews.com /1 month ago

China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware

A China-based threat actor known for deploying Medusa ransomware has been linked to the weaponization of a combination of zero-day and N-day vulnerabilities to orchestrate "high-ve...

Read source
infosecurity-magazine.com /2 weeks ago

Mini Shai-Hulud Hits TanStack npm Packages

Mini Shai-Hulud compromises TanStack npm packages and spreads across PyPI

Read source
theregister.com /1 week ago

Megalodon chums the waters in 5.5K+ GitHub repo poisonings

Will Jason Statham save us?

Read source
schneier.com /3 weeks ago

DarkSword Malware

DarkSword is a sophisticated piece of malware—probably government designed—that targets iOS. Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit tha...

Read source
gbhackers.com /1 month ago

Sandworm Uses SSH-over-Tor Tunnel for Stealthy Long-Term Persistence

A significant evolution in Sandworm (APT-C-13) tradecraft, revealing the group’s use of SSH-over-Tor tunneling to achieve long-term, covert persistence inside targeted networks. Sa...

Read source
thehackernews.com /3 weeks ago

Mirai-Based xlabs_v1 Botnet Exploits ADB to Hijack IoT Devices for DDoS Attacks

Cybersecurity researchers have exposed a new Mirai-derived botnet that self-identifies as xlabs_v1 and targets internet-exposed devices running Android Debug Bridge (ADB) to enlist...

Read source
arstechnica.com /1 month ago

OpenClaw gives users yet another reason to be freaked out about security

The viral AI agentic tool let attackers silently gain admin unauthenticated access.

Read source
boingboing.net /1 month ago

Anthropic's "too dangerous" AI was accessed by guessing the URL

That Linux kernel bug Anthropic highlighted as proof of Mythos's hacking prowess? Researcher Devansh found it was actually discovered by Claude Opus 4.6 — Anthropic's publicly avai...

Read source
thehackernews.com /4 days ago

Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning

The Iranian state-sponsored threat actor known as Nimbus Manticore (aka Screening Serpens and UNC1549) has been attributed to a fresh campaign using lures impersonating organizatio...

Read source
insurancejournal.com /1 month ago

Chinas 360 Hunts Software Flaws With AI, Echoing Mythos

Chinas 360 Hunts Software Flaws With AI, Echoing Mythos

Read source
gbhackers.com /1 week ago

Hackers Use SEO Poisoning to Fake Gemini CLI, Claude Installers

Financially motivated threat actors are running an active campaign that impersonates Google’s Gemini CLI and Anthropic’s Claude Code, using SEO poisoning to deliver a fileless Powe...

Read source
3dnews.ru /1 month ago

Anthropic открыла ограниченный доступ к модели Claude Mythos Preview — она автономно ищет дыры в ПО, и уже нашла тысячи...

Компания Anthropic открыла ограниченный доступ к своей новой ИИ-модели Mythos, предназначенной для поиска критических уязвимостей и отражения киберугроз. Инструмент будет доступен...

Read source
singularityhub.com /1 month ago

Anthropic’s Mythos AI Uncovered Serious Security Holes in Every Major OS and Browser

It's a step change in cybersecurity. Exploits that would take experts weeks to develop can now be generated in hours. The post Anthropic’s Mythos AI Uncovered Serious Security Hole...

Read source

Turn fresh research into a full content calendar

Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.

Sources covering Shodan

feeds.arstechnica.com

Recent coverage from public sources
Public source

feeds.feedburner.com

Recent coverage from public sources
Public source

feeds.indiana.statenews.net

Recent coverage from public sources
Public source

3dnews.ru

Recent coverage from public sources
Public source

boingboing.net

Recent coverage from public sources
Public source

cybersecuritynews.com

Recent coverage from public sources
Public source