Agentic Ransomware: From Human-Operated to AI-Operated Attacks
Agentic Ransomware: From Human-Operated to AI-Operated Attacks Ransomware has always needed a human involved somewhere: an affiliate navigating a network by hand, or at minimum, a person who wrote the...
Simplify Threat Intelligence Procurement with SOCRadar and Microsoft M...
Simplify Threat Intelligence Procurement with SOCRadar and Microsoft Marketplace Your security team has already made the case for external threat intelligence. The budget owner agrees. Then the deal s...
VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch
VectraRAT: An Undocumented Full-Stack MaaS Built From Scratch SOCRadar’s Threat Research Unit (STRU) has documented VectraRAT, a Malware-as-a-Service platform built entirely from scratch rather than f...
UCQ Leak, Israeli GlobalProtect Access, Digital Nirvana Dump, 32baar, ...
UCQ Leak, Israeli GlobalProtect Access, Digital Nirvana Dump, 32baar, and Ghorer Bazar SOCRadar Dark Web Team identified several new underground posts, including an alleged Universidad Cuauhtémoc data...
GitLab CVE-2026-85706 Added to CISA KEV
GitLab CVE-2026-85706 Added to CISA KEV CVE-2026-85706 represents a severe path traversal flaw in GitLab CE and EE, permitting unauthenticated remote actors to retrieve arbitrary files from affected s...
Simplify Threat Intelligence Procurement with SOCRadar and AWS Marketp...
Simplify Threat Intelligence Procurement with SOCRadar and AWS Marketplace Your security team has already made the case for external threat intelligence. The budget owner agrees. Then the deal stalls ...
Vibe-Terrorism: Inside the Yemen Cell That Used Claude to Build Guided...
Vibe-Terrorism: Inside the Yemen Cell That Used Claude to Build Guided Weapons In Anthropic’s September 2026 threat intelligence report, one case stands apart from the rest. A small cell based in nort...
Cisco FMC CVE-2026-20079 Actively Exploited
Cisco FMC CVE-2026-20079 Actively Exploited Cisco has confirmed active exploitation of CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) w...
ShieldCrash PoC: Microsoft Defender Fix Bypass
ShieldCrash PoC: Microsoft Defender Fix Bypass Microsoft recently fixed CVE-2026-69414 (ShieldBreak), a High-severity elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine. N...
September 2026 Patch Tuesday: 974 Flaws, 2 Zero-Days
September 2026 Patch Tuesday: 974 Flaws, 2 Zero-Days Microsoft’s September 2026 Patch Tuesday release addresses 974 vulnerabilities, including two actively exploited zero-days. Both zero-days are Wind...
Dark Web Market: Anubis Market
Dark Web Market: Anubis Market Anubis Market is a multi-category Dark Web marketplace operating as a Tor hidden service, with escrow-backed trading in Bitcoin (BTC) and Monero (XMR). Its visible categ...
CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploit...
CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT One of the most common entry points for attackers is the exploitation of public-facing edge devices (such as VPNs, route...
FBI Investigates Nexus Claim of 153M+ Driver’s License Records
FBI Investigates Nexus Claim of 153M+ Driver’s License Records Update 7/9/2026: ShinyHunters Seeks to Purchase the Nexus Dataset A Dark Web service called Nexus has claimed to offer access to more tha...
StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploited
StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploited Attackers are actively exploiting an unpatched zero-day vulnerability in Magento Open Source and Adobe Commerce that allows unaut...
Bring Licensed Threat Intelligence into Every Conversation with SOCRad...
Bring Licensed Threat Intelligence into Every Conversation with SOCRadar and ChatGPT The SOCRadar Threat Intelligence MCP app connects ChatGPT to the SOCRadar MCP server over OAuth, exposing your lice...
E-Commerce Access, Vedicline Data, Langflow RCE, ASUS Claim, and Energ...
E-Commerce Access, Vedicline Data, Langflow RCE, ASUS Claim, and Energy Shell Access SOCRadar Dark Web Team identified several new underground posts, including an alleged Bangladeshi e-commerce custom...
N-able N-central HF4 Fixes Critical RCE After Series of Authentication...
N-able N-central HF4 Fixes Critical RCE After Series of Authentication Flaws N-able has released N-central 2026.3 Hotfix 4 (build 2026.3.1.14) to fix CVE-2026-86218, a critical pre-authentication remo...
CVE-2026-73749: HPE ArubaOS-CX RCE
CVE-2026-73749: HPE ArubaOS-CX RCE HPE patched CVE-2026-73749, a critical unauthenticated Remote Code Execution (RCE) vulnerability in HPE Aruba Networking AOS-CX, also known as ArubaOS-CX. The flaw a...
CVE-2026-20212: Cisco Nexus 9000 RCE Flaw
CVE-2026-20212: Cisco Nexus 9000 RCE Flaw Cisco has disclosed a critical vulnerability, CVE-2026-20212, in the Silicon One integration used by certain Nexus 9000 switches. The flaw allows an unauthent...
Elementor Pro RCE Flaw Under Active Attack
Elementor Pro RCE Flaw Under Active Attack A critical vulnerability in Elementor Pro, a widely used WordPress page builder plugin, allowed unauthenticated attackers to upload files through the plugin’...
