soc

📅 Kalender

< August 2026 >
Mo
Di
Mi
Do
Fr
Sa
So
1
2
34567
8
9
1011121314
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
soc

SOCRadar Launches Free FortiBleed Exposure Checker and Publishes the Most Extensive Dataset on the Fortinet Credential Leak

SOCRadar Launches Free FortiBleed Exposure Checker and Publishes the Most Extensive Dataset on the Fortinet Credential Leak The team that first analyzed the FortiBleed leak now opens its research to the public, having already alerted thousands of customers and national CERTs — and invites every government cybersecurity agency to coordinate on the data. SOCRadar, the […]

Mehr lesen →
soc

FortiSandbox Vulnerabilities Expose Systems to Auth Bypass and Command Execution

FortiSandbox Vulnerabilities Expose Systems to Auth Bypass and Command Execution Fortinet FortiSandbox administrators should review their environments after several critical vulnerabilities raised concern around authentication bypass and command execution risks. The flaws affect FortiSandbox API and Web UI components. In vulnerable deployments, attackers may be able to bypass authentication, escalate privileges, or execute commands without […]

Mehr lesen →
soc

May 2026: TeamPCP’s Supply Chain Blitz Hits Checkmarx, GitHub, and npm

May 2026: TeamPCP’s Supply Chain Blitz Hits Checkmarx, GitHub, and npm May 2026 was defined by two threat actors operating at full intensity in parallel. ShinyHunters executed a major education-sector attack, exploiting a low-friction account program to breach Instructure’s Canvas platform, defacing login portals at hundreds of universities, and ultimately forcing a settlement. A separate […]

Mehr lesen →
soc

The Compromise of 30,000 Fortinet Firewalls

The Compromise of 30,000 Fortinet Firewalls Fortinet firewalls and VPN gateways are among the most widely deployed network security devices in the world. Organizations across every sector rely on them to control access to their networks and protect sensitive infrastructure. SOCRadar researchers recently discovered that a threat actor has been systematically compromising these devices at […]

Mehr lesen →
soc

CVE-2026-20262: Cisco SD-WAN Manager Zero-Day Can Lead to Root Privilege Escalation

Cisco has released security updates for an SD-WAN vManage flaw exploited in zero-day attacks. The issue, tracked as CVE-2026-20262, affects Cisco Catalyst SD-WAN Manager and can allow an authenticated remote attacker to create or overwrite files on the underlying operating system, opening a path to root privilege escalation. Public reporting says the flaw was exploited […]

Mehr lesen →
soc

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-48907 Widget Factory Joomla Content Editor Improper Access Control Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: […]

Mehr lesen →
soc

Top 5 Phishing Domain Takedown Service

Top 5 Phishing Domain Takedown Service Phishing attacks remain one of the most persistent and scalable threats facing organizations today. In Q1 2026 alone, approximately 8.3 billion email-based phishing threats detected. Phishing-as-a-Service (PhaaS) platforms now account for a growing share of campaigns, enabling threat actors with minimal technical skill to launch credential-harvesting operations at an […]

Mehr lesen →
soc

CVE-2026-20262: Cisco Catalyst SD-WAN Manager Zero-Day Leads to Root

CVE-2026-20262: Cisco Catalyst SD-WAN Manager Zero-Day Leads to Root CVE-2026-20262 is a zero-day vulnerability in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that lets an authenticated attacker with low privileges (at least write access) write files to unintended locations on the server. The flaw sits in the web UI / API file upload flow, where […]

Mehr lesen →
soc

The Quarry: Inside the PhaaS Operation Behind Hundreds of IRS and SSA Phishing Campaigns

The Quarry: Inside the PhaaS Operation Behind Hundreds of IRS and SSA Phishing Campaigns What looks like a wave of disconnected phishing incidents – some impersonating the IRS, others mimicking the Social Security Administration or DocuSign – can trace back to a single developer selling a Phishing-as-a-Service (PhaaS) toolkit to nearly 200 operators. SOCRadar’s Threat […]

Mehr lesen →
soc

Dark Web Profile: Fox Kitten

Dark Web Profile: Fox Kitten Fox Kitten stands out among Iranian Advanced Persistent Threat (APT) groups for operating on two tracks simultaneously: collecting intelligence for the Iranian regime while brokering network access to ransomware affiliates for profit. That dual mission, combined with a persistent focus on exploiting internet-facing VPN and firewall devices, makes Fox Kitten […]

Mehr lesen →