Adobe Acrobat WhatsApp Flaw “HermeticReader”
Adobe Acrobat WhatsApp Flaw “HermeticReader” Adobe and WhatsApp have rolled out a new way to handle PDF files without ever leaving a chat, and the timing puts a spotlight on a vulnerability that Adobe...
WhatsApp Usernames Explained: Privacy Gains and Scam Risks
WhatsApp Usernames Explained: Privacy Gains and Scam Risks How WhatsApp’s shift from phone numbers to usernames changes privacy for users, and the brand and executive impersonation surface it opens fo...
CVE-2026-50522 PoC Fuels SharePoint Attacks
CVE-2026-50522 PoC Fuels SharePoint Attacks Attackers are exploiting CVE-2026-50522, a critical Microsoft SharePoint Server vulnerability, after public proof-of-concept (PoC) exploit code became avail...
OpenAI Models Hacked Hugging Face During a Cyber Test
OpenAI Models Hacked Hugging Face During a Cyber Test [30.07.2026] Update: The Scope Keeps Growing During an internal cybersecurity benchmark in July 2026, OpenAI’s GPT-5.6 Sol and a more capable unre...
Dark Token Economy: Unauthorized LLM API Proxies Harvest Prompts for F...
Dark Token Economy: Unauthorized LLM API Proxies Harvest Prompts for Fraud and Distillation The dark token economy is a parallel market where unauthorized proxy services resell access to frontier LLMs...
CVE-2026-6875 Hits ServiceNow AI Platform
CVE-2026-6875 Hits ServiceNow AI Platform Attackers are reportedly exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform. The flaw can allow an unauthenti...
SonicWall SMA Flaws Lead to KNUCKLEBALL Malware
SonicWall SMA Flaws Lead to KNUCKLEBALL Malware SonicWall SMA 1000 appliances were compromised in a zero-day campaign involving custom malware, root-level access, credential gathering, and attempts to...
Who Needs a Job? DPRK ClickFake Interview Campaign Drops PylangGhost a...
Who Needs a Job? DPRK ClickFake Interview Campaign Drops PylangGhost and GolangGhost RATs This article by SOCRadar Threat Research Unit (STRU) analyzes the latest ClickFake Interview campaign, a North...
7-Zip CVE-2026-14266 RCE Risk Explained
7-Zip CVE-2026-14266 RCE Risk Explained CVE-2026-14266 is a heap-based buffer overflow in 7-Zip’s XZ decompression logic. If a user opens or extracts specially crafted compressed content with an affec...
Alleged Fullz, PrestaShop Access, RGT Source Code, and Database Leaks
Alleged Fullz, PrestaShop Access, RGT Source Code, and Database Leaks SOCRadar Dark Web Team identified several new underground posts, including an alleged U.S. fullz sale, administrative access to a ...
WordPress wp2shell Vulnerability (CVE-2026-63030): Quick FAQ for CISOs
WordPress wp2shell Vulnerability (CVE-2026-63030): Quick FAQ for CISOs Updated July 20, 2026: In-the-wild exploitation confirmed. Public proof-of-concept exploits for the full chain are now circulatin...
FIFA World Cup 2026 Fraud Campaigns
FIFA World Cup 2026 Fraud Campaigns Between April and July 2026, the SOCRadar Threat Research Unit (STRU) tracked the fraud ecosystem built around the FIFA World Cup 2026 spanning counterfeit merchand...
Top 10 MSSPs in the UK in 2026
Top 10 MSSPs in the UK in 2026 For the first time, the UK is about to regulate MSSPs themselves. The Cyber Security and Resilience Bill, now before the House of Lords, will turn medium and large manag...
CVE-2026-59208 Enables Cross-Issuer Impersonation in n8n
CVE-2026-59208 Enables Cross-Issuer Impersonation in n8n AI and workflow automation platforms can connect identities directly to actions across email, cloud services, databases, and other business sys...
SOCRadar XTI Is Live on the Chrome Web Store
SOCRadar XTI Is Live on the Chrome Web Store SOCRadar XTI, our official browser extension, is now available on the Chrome Web Store. It puts enrichment, malware analysis, and IOC operationalization di...
July 2026 Patch Tuesday: 622 Vulnerabilities, 3 Zero-Days
July 2026 Patch Tuesday: 622 Vulnerabilities, 3 Zero-Days Microsoft released its July 2026 Patch Tuesday security updates on July 14, 2026, addressing 622 CVEs – one of the largest single releases on ...
SAP Security Patch Day July 2026 Fixes Critical NetWeaver CVE-2026-447...
SAP Security Patch Day July 2026 Fixes Critical NetWeaver CVE-2026-44747 On July 14, 2026, SAP released its monthly security updates, delivering 16 new Security Notes and one GitHub security advisory,...
Top 10 Cybersecurity Movies to Watch
Top 10 Cybersecurity Movies to Watch Cybersecurity work is usually not very cinematic. Most days involve logs, tickets, access reviews, patch windows, alert triage, incident timelines, and careful con...
Dark Web Profile: Krybit Ransomware
Dark Web Profile: Krybit Ransomware Emerging from an increasingly crowded and combative ransomware ecosystem, Krybit Ransomware operates as a financially motivated, opportunistic Ransomware-as-a-Servi...
Alleged Brooks, Keepcool, Truecaller Bot, DAMAC, and US Resume Data Cl...
Alleged Brooks, Keepcool, Truecaller Bot, DAMAC, and US Resume Data Claims SOCRadar Dark Web Team identified several new underground posts, including the resurfacing of an alleged legacy Brooks Intern...
