SOCRadar’s Threat Research Unit (STRU) has documented VectraRAT, a Malware-as-a-Service platform built entirely from scratch rather than forked from leaked RAT code. Renting from $250 a month, it ...
SOCRadar’s Threat Research Unit (STRU) has documented CyberXero, a Russian-speaking, financially motivated Initial Access Broker that pairs commodity offensive tooling with an AI orchestration layer ...
CVE-2026-85706 represents a severe path traversal flaw in GitLab CE and EE, permitting unauthenticated remote actors to retrieve arbitrary files from affected self-managed deployments. Following ...
In late April 2026, Army General Joshua Rudd, the head of U.S. Cyber Command and the NSA, testified before the Senate Armed Services Committee that foreign adversaries would likely attempt to ...
Ransomware attack on Capital Bank SA, attributed to Lockbit. Domain, industry, country, and victim status tracked in real time.
Threat intelligence report with 10 extracted IOCs, MITRE ATT&CK mapping, and hunting context. Free by SOCRadar.
Security updates released for WordPress address CVE-2026-87902, a severe unauthenticated path traversal flaw within its page-template resolution mechanism. The weakness allows the CMS to load ...
Ransomware attack on CORBY ROCK MILL, attributed to Qilin. Domain, industry, country, and victim status tracked in real time.
ShinyHunters has turned the tables on rival cybercrime operation Clop (a.k.a. Cl0p), hijacking and defacing the ransomware gang’s own Dark Web leak site (DLS). The Clop hack began on September 18, ...
A French-speaking crew deleted the line reading “discernment retained” from its AI agent’s memory, wrote “I am a weapon” in its place, and pointed the result at two governments, a crypto exchange, a ...
Ransomware attack on J&D Financial, attributed to Qilin. Domain, industry, country, and victim status tracked in real time.
Ransomware attack on Turn5, Inc., attributed to Global Secret Group. Domain, industry, country, and victim status tracked in real time.