SOCRadar Alarms in Elastic | Investigate Threats Faster
Investigate SOCRadar Alarms Where Your Analysts Already Work, with SOCRadar and Elastic Your SOC runs on Elastic. Detections, logs, cases and dashboards all live in Kibana, and your analysts have buil...
CyberXero: An AI-Augmented Initial Access Broker Targeting Ukrainian C...
CyberXero: An AI-Augmented Initial Access Broker Targeting Ukrainian Critical Infrastructure SOCRadar’s Threat Research Unit (STRU) has documented CyberXero, a Russian-speaking, financially motivated ...
CVE-2026-88779: Citrix NetScaler Zero-Day
CVE-2026-88779: Citrix NetScaler Zero-Day Citrix has patched CVE-2026-88779, a high-severity NetScaler vulnerability that was exploited as a zero-day before fixes became available. The memory overflow...
CVE-2026-90970: GitLab AI Gateway RCE
CVE-2026-90970: GitLab AI Gateway RCE GitLab has patched CVE-2026-90970, a critical vulnerability in the Self-Hosted AI Gateway that can allow an authenticated user with Duo Agent Platform access to e...
IQUALIF France Leak, IUT Paris Seine Breach, US IAB Auction, SMTP Cred...
IQUALIF France Leak, IUT Paris Seine Breach, US IAB Auction, SMTP Credential Dump, and Apache Struts Exploit Sale SOCRadar Dark Web Team identified several new underground posts, including an alleged ...
FortiMail Zero-Day Under Active Exploitation
FortiMail Zero-Day Under Active Exploitation Fortinet has confirmed that CVE-2026-104286, a critical path traversal flaw in FortiMail, is being exploited in zero-day attacks, and CISA added it to the ...
TeamViewer Fixes Five Remote Access Flaws
TeamViewer Fixes Five Remote Access Flaws TeamViewer has patched five high-severity vulnerabilities in its Full Client and Host applications for Windows, Linux, and macOS. The flaws include local priv...
CVE-2026-76504: Cisco SD-WAN Flaw Exploited
CVE-2026-76504: Cisco SD-WAN Flaw Exploited Cisco has disclosed CVE-2026-76504, a critical authentication bypass vulnerability in Catalyst SD-WAN Manager, formerly known as vManage. The flaw allows an...
CVE-2026-86950: Apple CoreGraphics Zero-Day
CVE-2026-86950: Apple CoreGraphics Zero-Day Apple has issued an urgent security patch for CVE-2026-86950, a critical zero-day out-of-bounds write vulnerability in CoreGraphics that enables arbitrary c...
The 2026 U.S. Midterms Election Season, Weakened Defenses: The Cyber L...
The 2026 U.S. Midterms Election Season, Weakened Defenses: The Cyber Landscape Ahead In late April 2026, Army General Joshua Rudd, the head of U.S. Cyber Command and the NSA, testified before the Sena...
SOCRadar Attack Surface Management Now Integrates with ArmorCode ASPM
SOCRadar Attack Surface Management Now Integrates with ArmorCode ASPM Your team has a process for triaging vulnerabilities. The question is whether findings from your external attack surface ever reac...
Metree and WuBook Leaks, SonicWall Access, Campus.gov.il Data, and Ken...
Metree and WuBook Leaks, SonicWall Access, Campus.gov.il Data, and Kenya Vehicle Database SOCRadar Dark Web Team identified several new underground posts, including an alleged Metree e-commerce databa...
Citrix NetScaler Zero-Days FAQ: CVE-2026-88771 & 88772
Citrix NetScaler Zero-Days FAQ: CVE-2026-88771 & 88772 [Update] September 30, 2026: “Pre-Disclosure Exploitation of CVE-2026-88771,” “Attackers Deploy Web Shells and Tunneling Malware.” Citrix has...
Operation Talked: A Russia-Linked Cyber Espionage Campaign Targeting U...
Operation Talked: A Russia-Linked Cyber Espionage Campaign Targeting Ukraine’s Defense Industry TL;DR: OPERATION TALKED is an ongoing Russia-linked espionage campaign, exposed after the actor left the...
Dark Web Profile: Blue Locker Ransomware
Threat Actor Profile: Blue Locker Ransomware Blue Locker Ransomware, first detected in late 2021, the group stayed low-profile for years before making global headlines in August 2025 with a targeted a...
Roundcube SQLi (CVE-2026-48842) Exploited
Roundcube SQLi (CVE-2026-48842) Exploited A pre-authentication SQL injection vulnerability in Roundcube Webmail is reportedly being exploited in the wild months after patches became available. Tracked...
Check Point Pre-Auth Flaws Under Attack
Check Point Pre-Auth Flaws Under Attack Check Point has warned that two critical, pre-authentication vulnerabilities affecting its security products are being actively exploited. CVE-2026-85102 affect...
Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetiza...
Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline SOCRadar Threat Research Unit (STRU) has uncovered an end-to-end cybercrime operation dubbed Operation Master, in wh...
Closing the Dark Web Blind Spot in EclecticIQ Intelligence Center with...
Closing the Dark Web Blind Spot in EclecticIQ Intelligence Center with SOCRadar Your analysts start the morning in their threat intelligence platform, working the feeds, cases, and detections in front...
CVE-2026-94127: F5 BIG-IP APM RCE Under Active Exploitation
CVE-2026-94127: F5 BIG-IP APM RCE Under Active Exploitation F5 has released emergency engineering hotfixes for CVE-2026-94127, a critical heap-based buffer overflow in BIG-IP Access Policy Manager (AP...
