soc

📅 Kalender

< August 2026 >
Mo
Di
Mi
Do
Fr
Sa
So
1
2
34567
8
9
1011121314
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
soc

WhatsApp VBScript Campaign Installs ManageEngine Endpoint Central for Persistent Remote Access

WhatsApp VBScript Campaign Installs ManageEngine Endpoint Central for Persistent Remote Access A newly reported malware campaign uses WhatsApp direct messages to deliver VBScript (VBS/VBE) attachments that look like routine business documents. If a recipient downloads and then opens the attachment in WhatsApp Desktop or WhatsApp Web, the script starts a staged infection chain that ends […]

Mehr lesen →
soc

Top Dark Web Telegram Groups & Channels 2026

Top Dark Web Telegram Groups & Channels 2026 Note: This article is intended for cybersecurity awareness and research purposes only. It does not promote or endorse illegal content. The top Dark Web Telegram channels and groups monitored in 2026 are CTI Now, NoName057(16), RipperSec, Observer Cloud, Omega Cloud, Data Leak Monitoring, BidenCash Shop, EMP/mailpass/sqli Chat, […]

Mehr lesen →
soc

Top 10 Dark Web Markets in 2026: List & Threat Analysis

Top Dark Web Marketplaces in 2026 Dark Web marketplaces in 2026 are underground platforms where cybercriminals buy and sell stolen data, credentials, stealer logs, payment card records, malware, fraud services, counterfeit documents, drugs, and access to compromised systems. Also known as Dark Web markets or darknet markets, these platforms are increasingly specialized, with some operating […]

Mehr lesen →
soc

Alleged FortiBleed Access Auction, Sens Unique Paris Data Sale, and libsodium DoS Claims

Alleged FortiBleed Access Auction, Sens Unique Paris Data Sale, and libsodium DoS Claims SOCRadar Dark Web Team identified new underground activity involving alleged FortiBleed-related access, an alleged 529,892-record customer database linked to French retailer Sens Unique Paris, and a claimed libsodium and NaCl zero-day package. Additional listings advertised alleged KodexGlobal portal access, a 2 million-card […]

Mehr lesen →
soc

CVE-2026-20253: CISA Warns of Actively Exploited Splunk Enterprise RCE

CVE-2026-20253: CISA Warns of Actively Exploited Splunk Enterprise RCE Splunk Enterprise admins should prioritize patching CVE-2026-20253, a critical vulnerability that allows a network-reachable, unauthenticated attacker to create or truncate arbitrary files on the Splunk server. Under certain conditions, this can be chained into remote code execution (RCE), making exposure the main risk driver. CISA has […]

Mehr lesen →
soc

CVE-2026-42530: Critical NGINX HTTP/3 Flaw Can Trigger DoS and Possible RCE

F5 has released out-of-band security updates to address multiple NGINX Vulnerabilities, including CVE-2026-42530, a critical issue in the ngx_http_v3_module that can be exploited by a remote, unauthenticated attacker. The flaw is a use-after-free condition in NGINX’s HTTP/3 implementation that can cause worker-process restarts and denial of service, and in environments where ASLR is disabled or […]

Mehr lesen →
soc

FortiBleed: Everything You Need to Know

FortiBleed: Everything You Need to Know This is a developing story. Figures and findings are updated as the investigation continues. 1. What is FortiBleed? FortiBleed is an active, large-scale credential theft campaign targeting internet-exposed Fortinet FortiGate firewalls and SSL VPN gateways. The same threat actor has also been observed targeting FortiWeb and MSSQL services as […]

Mehr lesen →
soc

CVE-2026-42530 & CVE-2026-42055: F5 Patches NGINX Vulnerabilities

CVE-2026-42530 & CVE-2026-42055: F5 Patches NGINX Vulnerabilities F5 has released out-of-band security updates for two NGINX vulnerabilities that can affect exposed web infrastructure: CVE-2026-42530 and CVE-2026-42055. The first issue affects NGINX’s HTTP/3 QUIC handling. The second affects specific HTTP/2 and gRPC proxying configurations. Both can be triggered remotely and may cause NGINX worker processes to […]

Mehr lesen →
soc

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20253 Splunk Enterprise Missing Authentication for Critical Function Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing […]

Mehr lesen →
soc

CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure

CISA is aware of global reports that malicious cyber actors have targeted internet-accessible Fortinet devices across government and private sector organizations using compromised credentials. This activity, referred to as FortiBleed, involves the exposure of leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways.   To defend against this […]

Mehr lesen →