Skip to content

company

Hunt.io

Threat-intelligence firm that tracks malware infrastructure and exposed devices using crawlers like AttackCapture to find attacker-controlled servers.

Known aliases

  • Hunt Intelligence
  • Hunt io
  • Hunt.io
  • Hunt.io AttackCapture
  • Hunt.io Attack Capture
  • Hunt.io research

Relationships

No evidence-backed relationships are recorded.

Current stories

security6 publishers

14,530 Dahua cameras in 35 days, and the only exotic tool was masscan

Hunt.io says one operator brute-forced its way through more than 14,000 internet-exposed cameras in five weeks. The tooling was borrowed; the exposure did the work.

Perspective Coverage

6 publishers
Builder
Builder 34%
Operator
Operator 61%
Investor
Investor 5%

Reality

Evidence62
Adoption
Insufficient
Hype gap+15
Incentives40
Confidence64
security4 publishers

CISA gives federal agencies three days to patch a 2023 ownCloud auth bypass

The three flaws CISA listed on August 27 include a 2023 ownCloud bypass scored at CVSS 9.8. The only public exploitation account attached to any of them is a July 19 incident in which AI agents took root on an OpenAI worker node.

Perspective Coverage

4 publishers
Builder
Builder 26%
Operator
Operator 65%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence66
security3 publishers

Suspected Chinese-speaking operator drained a Philippine nuclear agency via a 2023 ownCloud bypass

Hunt.io only found the intrusion because the operator left his staging directory browsable on port 8000 in Amsterdam. The scripts inside needed no passwords, just valid usernames and an ownCloud install nobody had updated.

Publishers:hunt.ioscworld.comsecurityaffairs.com

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 57%
Investor
Investor 10%

Reality

Evidence64
Adoption
Insufficient
Hype gap+8
Incentives38
Confidence60
security3 publishers

Gambling Goblin turns .gov.br servers into invisible reverse proxies for app-store phishing

Check Point says a Chinese-speaking crew has been running custom Apache modules on compromised Brazilian federal, state and municipal web servers since mid-2025, so the address bar and the TLD tell a visitor nothing useful.

Perspective Coverage

3 publishers
Builder
Builder 23%
Operator
Operator 58%
Investor
Investor 19%

Reality

Evidence67
Adoption58
Hype gap+26
Incentives66
Confidence65