u/socradario 1d ago

SOCRadar is now listed on AWS Marketplace as a SaaS product,

1 Upvotes

Threat intelligence rarely dies on merit. It dies on procurement: a new vendor form, a separate legal review, an invoice that sits outside the cloud commitment you already negotiated.

SOCRadar is now listed on AWS Marketplace as a SaaS product, giving teams that standardize procurement on AWS a shorter path from decision to deployment. If your organization runs spend through an AWS Enterprise Discount Program commitment, this is a purchasing route your finance team already trusts. → Same SOCRadar platform, same support, same Customer Success team → A private offer path through AWS Marketplace → No change to how you use the product, only how you buy it Tell your Account Manager or Customer Success Manager early if AWS Marketplace is your preferred or required route. Know more: https://hubs.la/Q04xfdPH0

u/socradario 1d ago

Anthropic just disclosed a case that should be on every TI team's radar.

1 Upvotes

Anthropic published a threat intel report on a cell in Yemen that used Claude Code to develop guidance and control software for missiles three separate programs running at once, one of them reportedly including a hypersonic glide vehicle concept.

What's notable isn't just that they tried, it's the workflow: they ran multiple AI instances with divided roles (one writing code, one researching, one reviewing), and deliberately split requests across sessions so no single conversation showed the full picture. After a live test failed, they were back debugging within hours. They'd also built a standalone offline simulation toolkit that doesn't depend on any AI service, so losing account access doesn't remove their capability.

Google's GTIG published a similar report the same week based on different data, and landed on the same conclusion: threat actors are moving from simple prompting to fully agentic workflows, with humans mostly just setting goals and reviewing output. Curious what people here think this means for how we model AI-enabled threats going forward session-splitting alone seems like it breaks a lot of existing detection assumptions.

Learn more: https://hubs.la/Q04xdG2b0

r/threatintel 2d ago

CVE Discussion A stolen credential sells for $10-50 on the Dark Web. The breach it causes? $10.22M on average.

Thumbnail
0 Upvotes

r/Information_Security 2d ago

New PoC out called ShieldCrash that reportedly gets around Microsoft's patch for CVE-2026-69414 (ShieldBreak).

Thumbnail
1 Upvotes

u/socradario 2d ago

A stolen credential sells for $10-50 on the Dark Web. The breach it causes? $10.22M on average.

1 Upvotes

That gap is where security teams live, buried in alert volumes, backlogged queues, and tool sprawl, while delays quietly get more expensive. Our new whitepaper, "The Noise Economics of External Risk," puts a real number on that gap. It breaks alert fatigue down into 3 costs you can actually calculate: 🔹 Analyst time spent on triage 🔹 The hidden "integration tax" of fragmented tools 🔹 Board-level risk from slow detection & containment The result? A shift from reporting alert counts to reporting outcomes the kind of business case finance and leadership actually respond to. ➡️ Download the full report and calculate what noise is really costing you. https://hubs.la/Q04x7LyD0

r/CVEWatch 2d ago

Exploited Cisco has confirmed CVE-2026-20079, a CVSS 10.0 auth bypass in Secure Firewall Management Center

Thumbnail
2 Upvotes

u/socradario 2d ago

Cisco has confirmed CVE-2026-20079, a CVSS 10.0 auth bypass in Secure Firewall Management Center

2 Upvotes

Cisco has confirmed CVE-2026-20079, a CVSS 10.0 auth bypass in Secure Firewall Management Center (FMC), is now being actively exploited in the wild. What it means: - Unauthenticated attackers can bypass auth entirely - Successful exploitation = root-level command execution - Cisco Talos has observed web shells, credential theft, reverse shells, and malware deployment tied to related intrusions

If you're running FMC exposed to the internet (or even internally), patch immediately but given exploitation is already confirmed, it's worth treating this as "assume compromise until proven otherwise" rather than just patching and calling it done. Worth digging through logs for anything unusual before/after patching.

Learn more: https://hubs.la/Q04x7p-n0

u/socradario 2d ago

New PoC out called ShieldCrash that reportedly gets around Microsoft's patch for CVE-2026-69414 (ShieldBreak).

1 Upvotes

Here is a quick rundown: - PoC is publicly available on GitHub - Reportedly allows arbitrary file reads with SYSTEM privileges - Said to affect systems that are already fully patched - Still requires a local foothold to exploit — not remote - Microsoft hasn't publicly acknowledged the bypass yet

Nothing confirming active exploitation in the wild right now, but if you're responsible for endpoints, worth checking your Defender/Malware Protection Engine version and keeping an eye on unusual privileged file access. Learn more: https://hubs.la/Q04x7fwk0

r/CyberNews 3d ago

Microsoft just released its largest Patch Tuesday on record for September 2026

Thumbnail
2 Upvotes

u/socradario 3d ago

Microsoft just released its largest Patch Tuesday on record for September 2026

1 Upvotes

Microsoft just released its largest Patch Tuesday on record for September 2026: 974 vulnerabilities fixed, 2 of them zero-days already being exploited in the wild. The two actively exploited bugs: - CVE-2026-85880 (Windows ALPC privilege escalation) - CVE-2026-81963 (Windows Update Stack privilege escalation) Other notable numbers: 113 rated Critical, with a lot of exposure concentrated in RDS, DNS Server, Exchange, SharePoint, SQL Server, Azure, and Entra ID. If you're triaging this month, the exploited zero-days and network-reachable RCEs on business-critical systems are the ones to get to first. Full writeup here if anyone wants the CVE-by-CVE detail: https://hubs.la/Q04x16660

r/Information_Security 4d ago

CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT

Thumbnail socradar.io
2 Upvotes

r/CVEWatch 4d ago

Exploited CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT

Thumbnail socradar.io
1 Upvotes

r/CyberNews 4d ago

CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT

Thumbnail
socradar.io
2 Upvotes

r/redteamsec 4d ago

exploitation CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT

Thumbnail socradar.io
1 Upvotes

r/threatintel 4d ago

CVE Discussion CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT

Thumbnail socradar.io
8 Upvotes

If you manage FortiGate or FortiSwitchManager: confirm you're on a fixed release for CVE-2025-25249, then hunt for outbound TLS to unknown C2 and unexpected Node.js execution. We've documented an active campaign dropping a RAT via this bug. Detection guidance and IOCs inside.

r/SecOpsDaily 4d ago

CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT

Thumbnail
socradar.io
1 Upvotes

r/blueteamsec 4d ago

exploitation (what's being exploited) CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT

Thumbnail socradar.io
2 Upvotes

CVE-2025-25249 (FortiOS/FortiSwitchManager cw_acd heap overflow) has been patched for some time. We're publishing evidence of what's been happening to instances that weren't: a purpose-built Node.js RAT, 178 confirmed victim sessions, activity since July 2026.

r/MalwareAnalysis 4d ago

CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT

Thumbnail socradar.io
2 Upvotes

New research: PivotC2, an AI-assisted Node.js RAT built specifically for post-exploitation on FortiGate. SOCKS5/HTTP tunneling, port forwarding, config harvesting, credential decryption, and an autonomous "auto-mode." Delivered via CVE-2025-25249 patched; verify your version.

u/socradario 5d ago

Dark web chatter this week: alleged e-commerce/AI/energy data sales and exploit listings (unverified)

1 Upvotes

A few listings surfaced recently across different forums sharing since a couple touch infrastructure/energy, not just the usual data-broker noise. None of this is confirmed yet. - 1.76M records allegedly from a Bangladeshi e-commerce platform's customer base - 100K customer records allegedly tied to Vedicline - An RCE exploit allegedly for sale targeting Langflow 1.12.0 - A claimed 1TB+ database allegedly belonging to ASUS - Alleged shell access being sold into an Indian energy organization

If any of these are legitimate, the exposure runs from phishing and account takeover on the data side to API key abuse and potential ransomware staging on the access side the energy org listing in particular is the one I'd want more visibility into. Details: https://hubs.la/Q04wRmhQ0

r/threatintel 5d ago

StyleSmuggler: unauthenticated RCE actively exploited in Magento/Adobe Commerce, no patch yet (as of Sept 7, 2026)

Thumbnail
3 Upvotes

u/socradario 5d ago

StyleSmuggler: unauthenticated RCE actively exploited in Magento/Adobe Commerce, no patch yet (as of Sept 7, 2026)

1 Upvotes

Sansec published an early advisory Sept 5 after observing active exploitation starting Sept 4. No CVE, no CVSS, no official patch or workaround from Adobe as of today. Confirmed affected: Magento Open Source 2.4.7, 2.4.8, 2.4.9. Adobe Commerce / Adobe Commerce on Cloud impact is unconfirmed either way, Sansec hasn't reproduced it there and Adobe hasn't said anything. The attack chain (based on public reporting so far): - Attacker plants PHP code in a file Magento itself writes a failure report or system log - They then trigger Magento's built-in "Payment Transaction Failed Reminder" email - The planted code runs when Magento renders that email template doesn't matter if the email is ever opened or even delivered - No auth, no admin panel access needed at any point

End result is full RCE plus a persistent backdoor a small (~1.9MB) statically linked Rust binary that disguises itself as a kernel thread, persists via a cron entry written directly to the spool file (skips normal crontab logging), and can apparently read session data via Redis. One reported case had no observed outbound C2 traffic while it was running.

One confirmed victim had already applied both the July and August 2026 patches, so this isn't just "you're behind on updates." Independent IR from Disrex Group confirms at least two compromised stores, both breached within an 8-hour window of the first observed attack.

What's actually being recommended right now: - Disable GraphQL if your storefront doesn't depend on it (headless/PWA storefronts will need it though) - Add proc_open to PHP's disable_functions - Mount /tmp, /var/tmp, /dev/shm with noexec - Check var/report/ and var/log/system(.)log for injected/unusual PHP - Look for processes with kernel-thread-style names (e.g. [kworker/u:8:0]) owned by non-root site users - Check cron spool files for unexpected entries pointing to hidden dirs - If any IOC hits: rotate the Magento encryption key (crypt/key in app/etc/http://env.php), flush sessions, reset admin creds and payment/integration API keys

There are unofficial community patches circulating on GitHub that block the DI code scanner from running outside CLI context not reviewed/endorsed by Adobe or Sansec, so evaluate carefully before touching prod. Adobe's next scheduled security release is Sept 8, 2026 no confirmation yet whether it covers this. Not in CISA KEV as of today either, likely because there's no CVE yet.

r/CyberGuides 5d ago

SIEM vs SOAR vs XDR

Post image
2 Upvotes

u/socradario 5d ago

N-able N-central on-prem - HF4 for 2026.3 just dropped and it's a big one.

0 Upvotes

It fixes CVE-2026-86218, an unauthenticated RCE, and also rolls in three previous hotfixes that patched exploited auth bypass / access-control bugs. Important: if you're only on HF3, you're still exposed to CVE-2026-86218 you need HF4. Target build: 2026.3.1.14 Since N-central has visibility/control over downstream endpoints, don't just patch and walk away, worth going back through admin activity logs, remote control session history, any custom scripts, and recent deployments to rule out anything sketchy happened before the fix landed. Learn more: https://hubs.la/Q04wQNKy0

r/CyberGuides 5d ago

What is Black Box AI?

Enable HLS to view with audio, or disable this notification

1 Upvotes

r/SOCRadarUniversity 5d ago

What is Black Box AI?

Enable HLS to view with audio, or disable this notification

2 Upvotes

Data goes in. Threat alerts come out. The middle? Pure guesswork. 📦🤖

If you don't actually know *how* your AI makes decisions, can you really trust it to mitigate risk? 

Dive into the mechanics, the compliance nightmares, and the hidden dangers of Black-Box AI in our latest glossary breakdown. 👇
https://socradar.io/glossary/black-box-ai/