Jan 02, 2023
Dark Web Profile: MuddyWater APT Group

Dark Web Profile: MuddyWater APT Group [Update] April 19, 2023: Added subheading: “MuddyWater Uses SimpleHelp Tool for Persistence on Victim Devices” Security concerns grow day by day with the rise of...

Learn More
Dec 28, 2022
4 Lessons Learned from Supply Chain Attacks in 2022

4 Lessons Learned from Supply Chain Attacks in 2022 At the BlackBerry Security Summit in 2022, four-fifths of IT decision-makers said they had been notified of an attack or vulnerability in ...

Learn More
Dec 28, 2022
RCE Vulnerability (CVE-2022-45359) in Yith WooCommerce Gift Cards Plug...

RCE Vulnerability (CVE-2022-45359) in Yith WooCommerce Gift Cards Plugin Exploited in Attacks In late November, security researchers found a critical vulnerability in Yith’s WooCommerce Gif...

Learn More
Dec 26, 2022
Gartner Recognizes SOCRadar as an EASM Vendor in Hype Cycle for Endpoi...

Gartner Recognizes SOCRadar as an EASM Vendor in Hype Cycle for Endpoint Security Report Gartner’s report with comprehensive analysis and insights for endpoint security has been published. ...

Learn More
Dec 26, 2022
CVE-2022-47633 Vulnerability Allows Attackers to Bypass Kyverno Signat...

CVE-2022-47633 Vulnerability Allows Attackers to Bypass Kyverno Signature Verification The Kyverno admission controller for container images has been found to have a high-severity security v...

Learn More
Dec 26, 2022
The Week in Dark Web – 26 December 2022 – Data Leaks and Access Sales...

The Week in Dark Web – 26 December 2022 – Data Leaks and Access Sales Powered by DarkMirror™ We’re in the last week of the year. Most of us have already gone to visit our loved ones for a holida...

Learn More
Dec 24, 2022
All You Need to Know About the Linux Kernel ksmbd Remote Code Executio...

All You Need to Know About the Linux Kernel ksmbd Remote Code Execution (ZDI-22-1690) Vulnerability Five new vulnerabilities, one of which has a severity rating of 10 according to the Common Vulnerabi...

Learn More
Dec 24, 2022
400 Million Twitter Users Data Allegedly Breached for Extortion 

400 Million Twitter Users Data Allegedly Breached for Extortion  On December 23, 2022, a threat actor shared a post on a dark web forum monitored by SOCRadar, claiming to possess 400 million Twitter u...

Learn More
Dec 23, 2022
Top 10 Targeted Industries and Countries in 2022

Top 10 Targeted Industries and Countries in 2022 No matter the industry, cyberattacks can cause various problems, ranging from minor disruptions to significant losses or, even worse, lawsuits against ...

Learn More
Dec 23, 2022
AWS Elastic IP Transfer Feature Could Be Exploited in Attacks

AWS Elastic IP Transfer Feature Could Be Exploited in Attacks Researchers have discovered a new security risk to a recently added feature in Amazon Web Services (AWS).  Elastic IP transfer, ...

Learn More
Dec 22, 2022
Increasing Cyberattacks Targeting the Gaming Industry in 2022

Increasing Cyberattacks Targeting the Gaming Industry in 2022 By SOCRadar Research The gaming industry has recently emerged as a preferred target for cyberattacks. The industry is constantly...

Learn More
Dec 22, 2022
Top 10 Cyber Incidents in 2022

Top 10 Cyber Incidents in 2022 2022 was a year in which everyone worked to overcome the COVID-19 pandemic and a year in which threat actors simply tried to profit more from it. Threat actors...

Learn More
Dec 21, 2022
An Analysis of Central Banks Hackings: Who is Next?

An Analysis of Central Banks Hackings: Who is Next? By SOCRadar Research Critical infrastructures are the basis for the functioning of the countries’ system, and they are essential to continue t...

Learn More
Dec 21, 2022
Reports of ProxyNotShell Vulnerabilities Being Actively Exploited (CVE...

Reports of ProxyNotShell Vulnerabilities Being Actively Exploited (CVE-2022-41040 and CVE-2022-41082) According to reports, the zero-day vulnerabilities CVE-2022-41040 and CVE-2022-4108...

Learn More
Dec 20, 2022
Top 10 Data Leaks in 2022

Top 10 Data Leaks in 2022 Threat actors need sensitive information to carry out most of their malicious activity. They typically obtain the information by conducting various cyberattacks or simply gat...

Learn More
Dec 19, 2022
The Week in Dark Web – 19 December 2022 – Access Sales and Leaks

The Week in Dark Web – 19 December 2022 – Access Sales and Leaks Powered by DarkMirror™ Threat actors always search for something profitable for their malicious activities, whether a government instit...

Learn More
Dec 19, 2022
Veeam Fixes Critical Vulnerabilities in Backup & Replication Software ...

Veeam Fixes Critical Vulnerabilities in Backup & Replication Software (CVE-2022-26500 & CVE-2022-26501) Veeam has recently fixed two security vulnerabilities (CVE-2022-26500 and CV...

Learn More
Dec 16, 2022
Dark Web Profile: Killnet - Russian Hacktivist Group

Dark Web Profile: Killnet – Russian Hacktivist Group By SOCRadar Research The ongoing conflict between Ukraine and Russia has attracted the attention of various cybercriminal groups and pushed them to...

Learn More
Dec 16, 2022
Dark Web Profile: Black Basta Ransomware

Dark Web Profile: Black Basta Ransomware By SOCRadar Research [Update] May 13, 2024: Read the subheading “CISA’s Advisory for Black Basta”  [Update] January 3, 2024: Read the subheading “Turning the T...

Learn More
Dec 16, 2022
Microsoft Reevaluates SPNEGO NEGOEX Vulnerability CVE-2022-37958 as Cr...

Microsoft Reevaluates SPNEGO NEGOEX Vulnerability CVE-2022-37958 as Critical   Microsoft reassessed the severity score of a vulnerability fixed in September 2022 Patch Tuesday. The vulnerabi...

Learn More