From the Desk
SOC Analyst
Threat detection, vulnerability alerts, security tooling, incident response.
20
Stories filed
5
Desks covered
≥ 6/10
Editorial floor
Coverage:Threat IntelVulnerabilitiesToolsSecurityOT/IoT Security
§
On the SOC Analyst Desk
The latest stories filtered for your beat, organised by sub-section.
Threat Intel6 stories
- Attackers conceal phishing lures using invisible Unicode charactersInvisible Unicode characters bypass traditional text-based email filters, requiring updated detection logic that accounts for zero-width and tag characters in message bodies.1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without AuthenticationCompromised edge routers can serve as covert C2 relays and traffic-interception points, making them high-priority IOC sources.1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto MinerREVSTEALER's post-infection modules disable Windows Update and Defender before deploying a cryptominer — understanding these TTPs helps detect lingering persistence after the stealer self-deletes.1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsAttackers extracted AWS credentials through a compromised CI/CD platform; SOC teams need to hunt for unauthorised cloud-API usage linked to exposed Cadence credentials.2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchainBlockchain-hosted payloads resist traditional takedown, so detection must focus on endpoint and proxy-level indicators — ClickFix execution patterns, BNB Smart Chain callbacks, and anomalous PowerShell invocations.2d
- New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web TrafficThe 'Ted' backdoor intercepts and modifies live web traffic at the load-balancer layer — a blind spot for most endpoint and network detection stacks.3d
Vulnerabilities12 stories
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online StoresPre-auth RCE with no patch means detection must compensate — webshell indicators, unexpected outbound connections from commerce servers, and anomalous PHP process spawning are key signals.2d
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeVM-escape vulnerabilities are high-value targets for advanced adversaries; detection of exploit attempts requires monitoring hypervisor-level events and host anomalies.2d
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and UniversitiesArctic Wolf's analysis provides actionable TTPs for detecting PaperCut exploitation, including authentication-bypass indicators and credential-harvesting behaviour.2d
- Government Rails Site Hit Hours After CVE Patch3d
- Critical Citrix NetScaler auth bypass now leveraged in attacksIn-the-wild exploitation of CVE-2026-19490 demands immediate hunt activity for indicators of NetScaler compromise and unauthorised access via bypassed authentication.3d
- PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code ExecutionA CVSS 7.2 flaw in PostgreSQL's logical decoding allows replication-role accounts to execute OS-level code — any environment exposing replication roles to untrusted users needs urgent triage.3d
- Dirty Frag (CVE-2026-43284): the Linux kernel bug that turns read access into rootContainer escape combined with local privilege escalation means post-exploitation detection becomes critical — existing kernel-exploit behavioural rules need validation against CVE-2026-43284.3d
- New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privilegesAn exploit that escalates to SYSTEM via the EDR agent itself could be used to tamper with detection logic; SOC teams must monitor for unusual Falcon service behaviour and privilege changes.3d
- [NEU] [mittel] Grafana Enterprise: Mehrere Schwachstellen ermöglichen Erlangen von Benutzer- oder AdministratorrechtenPrivilege-escalation vulnerabilities in Grafana Enterprise could let unauthenticated attackers gain admin access to monitoring dashboards containing sensitive operational data.3d
- [NEU] [kritisch] vm2: Mehrere Schwachstellen ermöglichen CodeausführungExploitation of vm2 sandbox escapes can lead to arbitrary code execution on application servers, requiring detection of anomalous Node.js process behaviour.3d
- [NEU] [mittel] Dell integrated Dell Remote Access Controller: Schwachstelle ermöglicht CodeausführungDell iDRAC code-execution flaws give authenticated attackers server-level control beneath the OS — SOC teams must monitor out-of-band management interfaces for suspicious activity.3d
- [NEU] [hoch] Dell Secure Connect Gateway: Mehrere SchwachstellenMultiple high-severity vulnerabilities including authentication bypass and privilege escalation create detection-relevant attack surface on Dell gateway appliances.3d