soc

📅 Kalender

< August 2026 >
Mo
Di
Mi
Do
Fr
Sa
So
1
2
34567
8
9
101112
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
soc

UAC-0057 Attack Detection: OYSTERFRESH, OYSTERSHUCK, and OYSTERBLUES Fuel Phishing Campaigns Against Ukrainian State Organizations

Phishing remains one of the most effective tools in the cybercriminal arsenal, especially when threat actors abuse trusted identities, compromised legitimate accounts, and familiar online services to increase victim interaction. Europol notes that phishing techniques remain a main distribution vector for data-stealing malware, while CERT-UA’s latest advisory shows that the same social engineering logic continues […]

Mehr lesen →
soc

WhatsApp 3B Dump, OnlyFans 340M Records Sale, BlockFi Email Leak, Ramen Kuroda Data Leak, and VSP Security Wholesale Breach

WhatsApp 3B Dump, OnlyFans 340M Records Sale, BlockFi Email Leak, Ramen Kuroda Data Leak, and VSP Security Wholesale Breach SOCRadar Dark Web Team detected several new underground posts this week, including a 7.1 million leak from the Philippine restaurant chain Ramen Kuroda, an alleged 340 million user record sale tied to OnlyFans, a 3 billion […]

Mehr lesen →
soc

TrapDoor: Malicious npm, PyPI, Crates.io Packages Target Developer Secrets & AI Tooling

TrapDoor: Malicious npm, PyPI, Crates.io Packages Target Developer Secrets & AI Tooling Researchers identified a coordinated supply chain malware campaign named TrapDoor, involving waves of malicious packages across npm, PyPI, and Crates.io. Public reports tie the activity to credential theft and environment compromise, with an emphasis on developer secrets, crypto assets, and persistence on workstations […]

Mehr lesen →
soc

CVE-2026-9082: Highly Critical Drupal Core SQL Injection Flaw Threatens PostgreSQL Sites

Drupal has released security updates for a “highly critical” security vulnerability in Drupal Core that can be exploited by anonymous attackers against sites using PostgreSQL databases. Tracked as the CVE-2026-9082 vulnerability, the issue resides in Drupal’s database abstraction API, which is supposed to sanitize queries before they reach the backend database. Drupal rates the flaw […]

Mehr lesen →
soc

Dark Web Profile: CoinbaseCartel

Dark Web Profile: CoinbaseCartel CoinbaseCartel is a financially motivated threat actor that emerged on the Dark Web in September 2025. Unlike traditional ransomware groups, the group does not encrypt victim systems. Instead, it relies exclusively on data theft, threatening to publish exfiltrated data on its dark web leak site unless victims pay a ransom. This […]

Mehr lesen →
soc

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9082 Drupal Core SQL Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk […]

Mehr lesen →
soc

CVE-2026-20223: Cisco Secure Workload Auth Bypass Grants Site Admin Access

CVE-2026-20223: Cisco Secure Workload Auth Bypass Grants Site Admin Access Cisco has patched a maximum-severity vulnerability in Cisco Secure Workload (CSW) Cluster Software tracked as CVE-2026-20223. The issue is an authentication and access-control bypass affecting internal REST API endpoints, and it can allow a remote, unauthenticated attacker to obtain Site Admin privileges. Site Admin is […]

Mehr lesen →
soc

How Dark Data Leaves Security Teams One Step Behind

How Dark Data Leaves Security Teams One Step Behind Cyber Threat Intelligence has come a long way. In the past, real-time threat feeds, dark web monitoring, and indicator-sharing platforms were reserved for governments and Fortune 500 companies. Today, 90% of organizations have dedicated CTI resources, according to the 2026 SANS CTI Survey. The tools are […]

Mehr lesen →
soc

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-34291 Langflow Origin Validation Error Vulnerability CVE-2026-34926 Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding […]

Mehr lesen →