soc

📅 Kalender

< August 2026 >
Mo
Di
Mi
Do
Fr
Sa
So
1
2
34567
8
9
1011121314
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
soc

Dark Web Profile: BlindEagle

Dark Web Profile: BlindEagle BlindEagle (APT-C-36 / AguilaCiega / TAG-144 / G0099 / APT-Q-98) is a threat actor believed to be operating from Latin America. Tracked since 2018, the group runs a hybrid espionage-and-cybercrime operation that has compromised many organizations across Latin America and the U.S. Additionally, the Red Akodon cluster also overlaps via shared […]

Mehr lesen →
soc

Italian Hospitality and AT&T Data Claims, Hinge Dump Sale, Meta Llama Leak, and MobiFriend Dataset

Italian Hospitality and AT&T Data Claims, Hinge Dump Sale, Meta Llama Leak, and MobiFriend Dataset SOCRadar’s Dark Web Team identified several new underground posts, including an alleged 230,000-customer dataset tied to an Italian hospitality business and a separate listing promoting a 500,000+ record AT&T mobile consumer dataset. Other posts advertised an alleged 8 million-record Hinge […]

Mehr lesen →
soc

Charter Data Breach: ShinyHunters Claims 42 Million Records Stolen on the Dark Web

Charter Data Breach: ShinyHunters Claims 42 Million Records Stolen on the Dark Web Charter Communications, the U.S. telecommunications company behind the Spectrum brand, has confirmed a cybersecurity incident after the ShinyHunters extortion group claimed it stole and listed 42 million Charter records on the Dark Web. The breach gained wider attention after Have I Been […]

Mehr lesen →
soc

April 2026: ShinyHunters Hits Medtronic and ADT as North Korean Hackers Drain DeFi Protocols

April 2026: ShinyHunters Hits Medtronic and ADT as North Korean Hackers Drain DeFi Protocols April 2026 delivered a concentrated wave of high-impact incidents across healthcare, financial services, consumer platforms, and the decentralized finance ecosystem. ShinyHunters dominated the month’s breach headlines with a mass extortion campaign that swept up a global medical device manufacturer, a major […]

Mehr lesen →
soc

Top 10 Identity Attack Techniques Used by Hackers

Top 10 Identity Attack Techniques Used by Hackers Most cyberattacks today start with a compromised identity. Stolen passwords, hijacked sessions, forged authentication tokens, and bypassed MFA are now the primary tools in a threat actor’s arsenal. As organizations move to cloud and hybrid environments, the identity layer has become the most targeted attack surface in […]

Mehr lesen →
soc

CVE-2026-48095: 7-Zip Heap Buffer Overflow Can Lead to Code Execution

CVE-2026-48095 in 7-Zip has raised fresh concerns around malicious archive handling and user-driven exploitation. According to GitHub Security Lab, the flaw is a heap buffer write overflow in 7-Zip’s NTFS archive handler that affects version 26.00 and can potentially lead to arbitrary code execution or application crashes. The issue was fixed in 7-Zip 26.01, released […]

Mehr lesen →
soc

UAC-0057 Attack Detection: OYSTERFRESH, OYSTERSHUCK, and OYSTERBLUES Fuel Phishing Campaigns Against Ukrainian State Organizations

Phishing remains one of the most effective tools in the cybercriminal arsenal, especially when threat actors abuse trusted identities, compromised legitimate accounts, and familiar online services to increase victim interaction. Europol notes that phishing techniques remain a main distribution vector for data-stealing malware, while CERT-UA’s latest advisory shows that the same social engineering logic continues […]

Mehr lesen →
soc

WhatsApp 3B Dump, OnlyFans 340M Records Sale, BlockFi Email Leak, Ramen Kuroda Data Leak, and VSP Security Wholesale Breach

WhatsApp 3B Dump, OnlyFans 340M Records Sale, BlockFi Email Leak, Ramen Kuroda Data Leak, and VSP Security Wholesale Breach SOCRadar Dark Web Team detected several new underground posts this week, including a 7.1 million leak from the Philippine restaurant chain Ramen Kuroda, an alleged 340 million user record sale tied to OnlyFans, a 3 billion […]

Mehr lesen →
soc

TrapDoor: Malicious npm, PyPI, Crates.io Packages Target Developer Secrets & AI Tooling

TrapDoor: Malicious npm, PyPI, Crates.io Packages Target Developer Secrets & AI Tooling Researchers identified a coordinated supply chain malware campaign named TrapDoor, involving waves of malicious packages across npm, PyPI, and Crates.io. Public reports tie the activity to credential theft and environment compromise, with an emphasis on developer secrets, crypto assets, and persistence on workstations […]

Mehr lesen →
soc

CVE-2026-9082: Highly Critical Drupal Core SQL Injection Flaw Threatens PostgreSQL Sites

Drupal has released security updates for a “highly critical” security vulnerability in Drupal Core that can be exploited by anonymous attackers against sites using PostgreSQL databases. Tracked as the CVE-2026-9082 vulnerability, the issue resides in Drupal’s database abstraction API, which is supposed to sanitize queries before they reach the backend database. Drupal rates the flaw […]

Mehr lesen →