Blog

Latest articles from SOCRadar

What You Need to Know About the Alleged Sony Breach
September 26, 2023

What You Need to Know About the Alleged Sony Breach

The RansomedVC group has announced that it successfully breached Sony, the renowned Japanese multinational electronics giant. The group claims to have infiltrated all of Sony's systems in their victim listing, posted both on its clearnet… Continue Reading

New Botnet Sale and Recruitment Post, US and Canada RDP Access Sales, Dymocks Database
September 26, 2023

New Botnet Sale and Recruitment Post, US and Canada RDP Access Sale, Dymocks Database

In this week's dark web update, the SOCRadar Dark Web Team has revealed a series of troubling developments; among their recent findings, databases from a Brazilian travel company and Dymocks have come to light. Additionally,… Continue Reading

September 25, 2023

TeamCity Authentication Bypass Flaw: CVE-2023-42793

[Update] October 6, 2023: A PoC exploit for the TeamCity vulnerability has surfaced. Further details are in the blog post. In recent cyber news, a critical security flaw has been unearthed in JetBrains TeamCity. With… Continue Reading

Over 400K Buckets and 10.4B Files Are Public Due to Cloud Misconfigurations
September 25, 2023

Over 400K Buckets and 10.4B Files Are Public Due to Cloud Misconfigurations

In today's cloud-centric era, the migration of digital assets to cloud storage has become widespread, driven by the demand for high availability and performance. However, this transition has not been without its challenges. One significant… Continue Reading

Critical DICOM Server Misconfigurations Lead to Exposure of 1.6M Medical Records
September 22, 2023

Critical DICOM Server Misconfigurations Lead to Exposure of 1.6M Medical Records

In a regular threat and vulnerability hunting activity, SOCRadar has discovered during their research that thousands of DICOM servers were exposed on the internet due to misconfigurations, resulting in the exposure of patient data for… Continue Reading

Joint Advisory by CISA and FBI: Snatch Ransomware
September 21, 2023

Joint Advisory by CISA and FBI: Snatch Ransomware

The FBI and CISA have recently issued a joint cybersecurity advisory (CSA) concerning the Snatch ransomware variant. The advisory provides comprehensive insights into Snatch ransomware operations, encompassing its Indicators of Compromise (IoCs) and Tactics, Techniques,… Continue Reading

Dark Web Profile: NoEscape Ransomware
September 20, 2023

Dark Web Profile: NoEscape Ransomware

Avaddon, a notorious Ransomware-as-a-Service (RaaS) that emerged in early 2019 was known for its double-extortion tactics. It not only encrypted victims' files but also threatened to release stolen data publicly. Avaddon's modus operandi involved targeting… Continue Reading

Unmasking USDoD: The Enigma of the Cyber Realm
September 20, 2023

Unmasking USDoD: The Enigma of the Cyber Realm

[Update] November 7, 2023: See the subheading: "UsDoD Continues Ambitious Claims; Now Its LinkedIn’s Turn." Emerging from the shadows of the cyber realm, "USDoD" first caught attention by exposing the data of 80,000 InfraGard members,… Continue Reading

Mastodon Vulnerabilities and Critical Zero-Day in TrendMicro’s Apex One, Fixed: (CVE-2023-41179, CVE-2023-42451, CVE-2023-42452)
September 20, 2023

Mastodon Vulnerabilities and Critical Zero-Day in TrendMicro’s Apex One, Fixed: CVE-2023-41179, CVE-2023-42451, CVE-2023-42452

Mastodon recently addressed two vulnerabilities, namely CVE-2023-42451 and CVE-2023-42452. In addition, a zero-day vulnerability, identified as CVE-2023-41179, was promptly resolved in TrendMicro's Endpoint Security product, Apex One. Critical Zero-Day in TrendMicro Apex One: CVE-2023-41179  The… Continue Reading

Critical RCE Flaw Fixed in New Versions of GitLab
September 20, 2023

GitLab’s Critical Security Update: What You Need to Know (CVE-2023-5009)

GitLab is a widely-used DevOps platform that allows for code hosting, continuous integration, and other collaborative features for both Community and Enterprise users. A new critical security release has just been rolled out for GitLab… Continue Reading

Your Data Is Not Safe: 8Base Deanonymized
September 19, 2023

Your Data Is Not Safe: 8Base Deanonymized

In the ever-evolving world of cybercrime, the 8Base ransomware group has recently come under the spotlight. Known for its victim-shaming website, this group inadvertently revealed more than they probably intended. This article delves into the unexpected information… Continue Reading

Microsoft AI Repository Exposes 38TB of Data: A Tale in AI and Cloud Security
September 19, 2023

Microsoft AI Repository Exposes 38TB of Data: A Tale in AI and Cloud Security

Wiz Research recently unveiled a startling incident involving Microsoft's AI research team: an accidental exposure of 38 terabytes of sensitive data. This case brings forth essential questions and lessons about data security, especially when operating… Continue Reading

September 19, 2023

Remote Administration Tool Sale, Ledger Database Leak, and Dark Strom DDoS Attack

In this week's dark web roundup, we bring you a series of concerning developments that the SOCRadar Dark Web Team has flagged. From the sale of sophisticated remote administration tools to a substantial database leak… Continue Reading

LockBit's New Regulations Sets Minimum For Ransom Demands
September 18, 2023

LockBit’s New Regulations Sets Minimum For Ransom Demands

Recently, the notorious LockBit ransomware group has initiated a significant discussion among its affiliates regarding potential changes to their ransom payment policies. The group has expressed growing frustration with ransomware negotiators and their handling of payment demands. Currently,… Continue Reading

Why are Threat Actors Targeting Indonesia?
September 16, 2023

Why are Threat Actors Targeting Indonesia?

On September 3, Indonesia hiked fuel prices by 30%, stating that petrol and diesel prices are still low by world standards, but subsidies are unsustainable. On the other hand, in the background of political decisions… Continue Reading

MGM Resorts Hacked by BlackCat Affiliate, ‘Scattered Spider’
September 15, 2023

MGM Resorts Hacked by BlackCat Affiliate, ‘Scattered Spider’

A cybercriminal gang employing a combination of impersonation and malware is the prime suspect behind the cyberattack that crippled the operations of MGM Resorts. MGM Resorts is a hospitality giant with numerous hotels and casinos… Continue Reading

Overview of TIBER-EU From Threat Intelligence Perspective
September 14, 2023

Overview of TIBER-EU From Threat Intelligence Perspective

Financial institutions are crucial for the global economy. They hold trillions of dollars in assets and billions of customer records. As such, they are one of the prime targets for cyberattacks. According to Statista, in… Continue Reading

LockBit Attack Fails, 3AM Ransomware Steps In as Plan B
September 14, 2023

LockBit Attack Fails, 3AM Ransomware Steps In as Plan B

Researchers have recently identified a new strain of ransomware called 3AM. Their investigation revealed that the first known usage of this ransomware occurred when threat actors substituted it for LockBit ransomware in a failed attack.… Continue Reading

Top 10 Facts About MOVEit Breach
September 13, 2023

Top 10 Facts About MOVEit Breach

In the ever-evolving cybersecurity landscape, breaches have become all too common, sending shockwaves through industries and leaving organizations scrambling to recover. One such significant breach that has recently dominated headlines is the MOVEit breach. MOVEit,… Continue Reading

September 2023 Patch Tuesday by Microsoft Fixes Five Critical, Two Zero-Day Vulnerabilities
September 13, 2023

September 2023 Patch Tuesday by Microsoft Fixes Five Critical, Two Zero-Day Vulnerabilities

[Update] September 15, 2023: See the subheading: “Proof-of-Concept (PoC) Exploit Available for CVE-2023-38146 (ThemeBleed).” Microsoft's Patch Tuesday for September 2023 has been released, addressing 59 security vulnerabilities. The update encompasses five critical vulnerabilities as well… Continue Reading

SOCRadar helps you visualize digital risk, and reduce your company's attack surface
Request Demo