The Threat Research Unit (STRU) at SOCRadar’s Extended Threat Intelligence (XTI) platform identified and analyzed PEEP, a Chromium-based emerging post-exploitation toolkit disguised as “Smart ...
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable ...
The SOCRadar Threat Research Unit (STRU) has conducted an “inside-out” analysis of AnonyMousKIT, an AI-powered Phishing-as-a-Service (PhaaS) ecosystem specifically engineered to disable Apple’s ...
A critical vulnerability in Elementor Pro, a widely used WordPress page builder plugin, allowed unauthenticated attackers to upload files through the plugin’s Forms module. Tracked as CVE-2026-32475, ...
Ransomware attack on Newton County Schools, attributed to Qilin. Domain, industry, country, and victim status tracked in real time.
The extortion group shinyhunters claimed Jack Henry & Associates as a victim on August 30, 2026. Jack Henry & Associates is a critical provider of financial technology infrastructure, operating with ...
Ransomware attack on ダイキョーニシカワ, attributed to Lockbit5. Domain, industry, country, and victim status tracked in real time.
In a recent spate of phishing campaigns, attackers have been leveraging a tool called Tycoon 2FA to deceive users and bypass security measures. These campaigns frequently employ convincing login pages ...
CISA entered 2026 under pressure. The agency responsible for helping defend U.S. civilian networks, critical infrastructure, and public-sector organizations is facing a smaller budget, fewer staff, ...
What looks like a wave of disconnected phishing incidents – some impersonating the IRS, others mimicking the Social Security Administration or DocuSign – can trace back to a single developer selling a ...
Ransomware attack on City of Atlanta, attributed to ExfilSquad. Domain, industry, country, and victim status tracked in real time.
STRU found threat actors using FTP banners as Dead Drop Resolvers – legitimate services or protocols abused to host C2 addresses and commands, so the stager never carries them itself. Live since early ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results