On October 6, 2026, the FBI and the U.S. Secret Service published a joint Cybersecurity Advisory on FortiBleed, the active global credential compromise campaign against internet-facing Fortinet ...
SOCRadar’s Threat Research Unit (STRU) has documented CyberXero, a Russian-speaking, financially motivated Initial Access Broker that pairs commodity offensive tooling with an AI orchestration layer ...
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an ...
In late April 2026, Army General Joshua Rudd, the head of U.S. Cyber Command and the NSA, testified before the Senate Armed Services Committee that foreign adversaries would likely attempt to ...
Ransomware attack on bnlawmacau.com, attributed to INC Ransom. Domain, industry, country, and victim status tracked in real time.
Ransomware attack on Charles Keith, attributed to Thegentlemen. Domain, industry, country, and victim status tracked in real time.
ShinyHunters has turned the tables on rival cybercrime operation Clop (a.k.a. Cl0p), hijacking and defacing the ransomware gang’s own Dark Web leak site (DLS). The Clop hack began on September 18, ...
CVE-2026-76460 represents a critical security flaw in Cisco’s Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Because the vulnerability bypasses authentication without ...
A French-speaking crew deleted the line reading “discernment retained” from its AI agent’s memory, wrote “I am a weapon” in its place, and pointed the result at two governments, a crypto exchange, a ...
PivotC2 is a feature-rich post-exploitation framework purpose-built for FortiGate appliances running FortiOS. It supports interactive shells, file transfers, SOCKS5 and HTTP proxy tunneling, local and ...
The Threat Research Unit (STRU) at SOCRadar’s Extended Threat Intelligence (XTI) platform identified and analyzed PEEP, a Chromium-based emerging post-exploitation toolkit disguised as “Smart ...
The SOCRadar Threat Research Unit (STRU) has conducted an “inside-out” analysis of AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) ecosystem specifically engineered to disable Apple’s ...