soc

📅 Kalender

< August 2026 >
Mo
Di
Mi
Do
Fr
Sa
So
1
2
34567
8
9
101112
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
soc

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2024-21182 Oracle WebLogic Server Unspecified Vulnerability This type of vulnerability is a frequent attack vectors for malicious cyber actors and poses significant risks to the federal enterprise.  Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of […]

Mehr lesen →
soc

Italian Hospitality and AT&T Data Claims, Hinge Dump Sale, Meta Llama Leak, and MobiFriend Dataset

Italian Hospitality and AT&T Data Claims, Hinge Dump Sale, Meta Llama Leak, and MobiFriend Dataset SOCRadar’s Dark Web Team identified several new underground posts, including an alleged 230,000-customer dataset tied to an Italian hospitality business and a separate listing promoting a 500,000+ record AT&T mobile consumer dataset. Other posts advertised an alleged 8 million-record Hinge […]

Mehr lesen →
soc

Charter Data Breach: ShinyHunters Claims 42 Million Records Stolen on the Dark Web

Charter Data Breach: ShinyHunters Claims 42 Million Records Stolen on the Dark Web Charter Communications, the U.S. telecommunications company behind the Spectrum brand, has confirmed a cybersecurity incident after the ShinyHunters extortion group claimed it stole and listed 42 million Charter records on the Dark Web. The breach gained wider attention after Have I Been […]

Mehr lesen →
soc

April 2026: ShinyHunters Hits Medtronic and ADT as North Korean Hackers Drain DeFi Protocols

April 2026: ShinyHunters Hits Medtronic and ADT as North Korean Hackers Drain DeFi Protocols April 2026 delivered a concentrated wave of high-impact incidents across healthcare, financial services, consumer platforms, and the decentralized finance ecosystem. ShinyHunters dominated the month’s breach headlines with a mass extortion campaign that swept up a global medical device manufacturer, a major […]

Mehr lesen →
soc

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-0257 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability This type of vulnerability is a frequent attack vectors for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the […]

Mehr lesen →
soc

Supply Chain Compromises Impact Nx Console and GitHub Repositories

CISA is prioritizing the response to multiple emerging software supply chain intrusion campaigns targeting developer ecosystems Continuous Integration/Continuous Development (CI/CD) pipelines. These recent incidents, including the GitHub compromise via a malicious Nx Console Visual Studio Code (VS Code) extension and the “Megalodon” supply chain intrusion campaign, demonstrate how cyber threat actors are abusing tools and […]

Mehr lesen →
soc

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code Vulnerability CVE-2026-45321 TanStack Unspecified Vulnerability CVE-2026-48027 Nx Console Embedded Malicious Code Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk […]

Mehr lesen →
soc

Top 10 Identity Attack Techniques Used by Hackers

Top 10 Identity Attack Techniques Used by Hackers Most cyberattacks today start with a compromised identity. Stolen passwords, hijacked sessions, forged authentication tokens, and bypassed MFA are now the primary tools in a threat actor’s arsenal. As organizations move to cloud and hybrid environments, the identity layer has become the most targeted attack surface in […]

Mehr lesen →
soc

CVE-2026-48095: 7-Zip Heap Buffer Overflow Can Lead to Code Execution

CVE-2026-48095 in 7-Zip has raised fresh concerns around malicious archive handling and user-driven exploitation. According to GitHub Security Lab, the flaw is a heap buffer write overflow in 7-Zip’s NTFS archive handler that affects version 26.00 and can potentially lead to arbitrary code execution or application crashes. The issue was fixed in 7-Zip 26.01, released […]

Mehr lesen →
soc

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.  CVE-2026-48172 LiteSpeed cPanel Plugin Privilege Escalation Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as […]

Mehr lesen →