Italy RDWeb Access, GBCSA Data Sale, SCHUFA Claim, and FLY Firebase Ex...
Italy RDWeb Access, GBCSA Data Sale, SCHUFA Claim, and FLY Firebase Exposure SOCRadar Dark Web Team identified several new underground posts involving alleged initial access sales and large-scale data...
From Blackwater to Cyber-Privateers: When States Outsource Force
From Blackwater to Cyber-Privateers: When States Outsource Force On August 12, 2026, President Donald Trump signed a National Security Presidential Memorandum titled “Expanding Capabilities to Combat ...
LiteLLM Supply Chain Attack: Inside the AI Breach That Exposed 2,500+ ...
LiteLLM Supply Chain Attack: Inside the AI Breach That Exposed 2,500+ Companies ...
August 2026 Patch Tuesday: 421 Flaws, 3 Zero-Days
August 2026 Patch Tuesday: 421 Flaws, 3 Zero-Days Microsoft’s August 2026 Patch Tuesday release addresses 421 vulnerabilities, including three zero-days. One zero-day was exploited in the wild, while ...
SAP Commerce Cloud CVE-2026-58231 Requires Urgent Patching
SAP Commerce Cloud CVE-2026-58231 Requires Urgent Patching SAP has addressed CVE-2026-58231, a maximum-severity improper authorization vulnerability in the Data Hub Adapter for SAP Commerce Cloud. The...
Cisco ASA and FTD CVE-2026-20349 Exploited
Cisco ASA and FTD CVE-2026-20349 Exploited Cisco has confirmed active exploitation of CVE-2026-20349, a High-severity denial-of-service (DoS) vulnerability affecting the Remote Access SSL VPN service ...
Top 10 Phishing Kits Used by Cybercriminals
Top 10 Phishing Kits Used by Cybercriminals Phishing kits have turned credential theft into a scalable service by packaging fake login pages, hosting, traffic filtering, victim management, and technic...
INC Ransom Targeted 24 Law Firms, but Only 10 are Listed
INC Ransom Targeted 24 Law Firms, but Only 10 are Listed INC was on an encryption streak against US law firms in March 2026. SOCRadar identified 24 individualized extortion sites, hosted across two IP...
Critical Metabase Zero-Day Exploited
Critical Metabase Zero-Day Exploited Metabase has disclosed a critical zero-day SQL injection (SQLi) vulnerability that can allow unauthenticated attackers to gain administrator access to vulnerable i...
Steam Customer Data Exposed in CEVA Logistics Cyberattack
Steam Customer Data Exposed in CEVA Logistics Cyberattack A cyberattack on CEVA Logistics, the company that distributes Steam hardware in Europe, may have exposed delivery and order information belong...
Brazil Fiscal Leak, US Fullz, Telecom Access, Endesa IBANs, and Mexico...
Brazil Fiscal Leak, US Fullz, Telecom Access, Endesa IBANs, and Mexico Fortinet Access SOCRadar Dark Web Team identified several new underground posts involving alleged large-scale data exposure and i...
XSS2Shell (CVE-2026-64638): Patch WordPress Now
XSS2Shell (CVE-2026-64638): Patch WordPress Now A new WordPress Core vulnerability chain called XSS2Shell turns a login page XSS bug into a much more serious risk for exposed WordPress sites. The issu...
Cracking Kynx: The Stealer Hunting for Your Wallets, Games, and AI Too...
Cracking Kynx: The Stealer Hunting for Your Wallets, Games, and AI Tools Kynx is a new Malware-as-a-Service infostealer, built in C++ with AI assistance and promoted on a Turkish game cheating forum. ...
Cisco Catalyst SD-WAN and IOS XE: Critical Flaws Fixed
Cisco Catalyst SD-WAN and IOS XE: Critical Flaws Fixed Cisco published a new set of security advisories, addressing vulnerabilities across Catalyst SD-WAN, IOS XE, Cisco Integrated Management Controll...
Snowflake Hacker Pleads Guilty, Faces 32 Years
Snowflake Hacker Pleads Guilty, Faces 32 Years Snowflake hacker Connor Riley Moucka pleaded guilty on August 5, 2026, in the U.S. District Court for the Western District of Washington, admitting to co...
Formula 1 Phishing Campaign & Kit Analysis
Formula 1 Phishing Campaign & Kit Analysis SOCRadar Threat Research Unit (STRU) has identified and analyzed a sophisticated, multi-stage phishing campaign that exploits the high-intensity demand f...
Dark Web Market: Vortex Market
Dark Web Market: Vortex Market Vortex Market describes itself as a “classic wallet escrow market,” and that self-description is accurate. It is a general-purpose Dark Web marketplace built around anon...
Why Was Telegram Removed From the App Store?
Why Was Telegram Removed From the App Store? [Update] August 5, 2026: Durov Claims “Takedown Extortionist” Triggered App Store Removal Telegram briefly disappeared from the App Store worldwide on Mond...
Dark Web Profile: Mustang Panda
Dark Web Profile: Mustang Panda Mustang Panda is one of the most persistent China-nexus cyber espionage groups operating today. Active since at least 2012, the group has targeted government agencies, ...
CVE-2026-48449: Adobe Campaign Classic RCE
CVE-2026-48449: Adobe Campaign Classic RCE Adobe Campaign Classic is affected by CVE-2026-48449, a critical incorrect authorization vulnerability allowing Remote Code Execution (RCE). With a maximum s...
