logo

SOC Prime Blog

ID: a386702a-200f-5d8e-a45a-1a90d3aff4e9

STIX ID: identity--a386702a-200f-5d8e-a45a-1a90d3aff4e9

Feed Type: rss

Earliest post: 2025-10-29

Latest post: 2026-05-26

Detection engineering insights, threat hunting guidance, and real-time coverage of emerging threats powered by the SOC Prime community.

01/01/2020
05/29/2026
Title Date Published Describes IncidentAuthorVisible
CVE-2026-48095: 7-Zip Heap Buffer Overflow Can Lead to Code Execution2026-05-26TrueSOC Prime TeamTrue
UAC-0057 Attack Detection: OYSTERFRESH, OYSTERSHUCK, and OYSTERBLUES Fuel Phishing Campaigns Against Ukrainian State Organizations2026-05-25TrueSOC Prime TeamTrue
CVE-2026-9082: Highly Critical Drupal Core SQL Injection Flaw Threatens PostgreSQL Sites2026-05-22TrueSOC Prime TeamTrue
CVE-2026-45585: YellowKey BitLocker Bypass Exposes Encrypted Data on Windows Devices2026-05-22TrueSOC Prime TeamTrue
CVE-2026-20182: Critical Authentication Bypass in Cisco SD-WAN Can Grant Admin Access2026-05-15TrueSOC Prime TeamTrue
CVE-2026-42897: Exchange Server OWA Spoofing Flaw Exploited via Crafted Email2026-05-15TrueSOC Prime TeamTrue
CVE-2026-42945: 18-Year-Old NGINX Rewrite Flaw May Enable Unauthenticated RCE2026-05-14TrueSOC Prime TeamTrue
CVE-2026-46300: Fragnesia Linux Kernel Flaw Grants Root via Page Cache Corruption2026-05-14TrueSOC Prime TeamTrue
CVE-2026-43500 and CVE-2026-43284: Dirty Frag Linux Privilege Escalation Flaw Raises Post-Compromise Risk2026-05-11TrueSOC Prime TeamTrue
CVE-2026-23918: Critical Apache HTTP/2 Flaw Can Trigger DoS and Possible RCE2026-05-06TrueSOC Prime TeamTrue
CVE-2026-23918: Critical Apache HTTP/2 Flaw Can Trigger DoS and Possible RCE2026-05-06TrueSOC Prime TeamTrue
CVE-2026-0300: Palo Alto PAN-OS Zero-Day Enables Root RCE on Exposed Firewalls2026-05-06TrueSOC Prime TeamTrue
CVE-2026-0300: Palo Alto PAN-OS Zero-Day Enables Root RCE on Exposed Firewalls2026-05-06TrueSOC Prime TeamTrue
CVE-2026-41940: Critical cPanel & WHM Authentication Bypass Exposes Hosting Servers to Admin Takeover2026-04-30TrueSOC Prime TeamTrue
CVE-2026-28950: Apple Fixes iOS Flaw That Retained Deleted Notification Data2026-04-23TrueSOC Prime TeamTrue
CVE-2026-40372: Critical ASP.NET Core Flaw May Let Attackers Gain SYSTEM Privileges2026-04-23TrueSOC Prime TeamTrue
UAC-0247 Attack Detection: AGINGFLY Malware Targets Hospitals, Local Governments, and FPV Operators in Ukraine2026-04-16TrueSOC Prime TeamTrue
UAC-0255 Attack Detection: Threat Actors Impersonate CERT-UA to Infect Ukrainian Public and Private Sector Organizations With AGEWHEEZE RAT2026-04-01TrueDaryna OlyniychukTrue
CVE-2026-20643: Vulnerability in WebKit Navigation API May Bypass Same Origin Policy2026-03-18TrueDaryna OlyniychukTrue
CVE-2026-3910: Chrome V8 Zero-Day Used for In-the-Wild Attacks2026-03-13TrueDaryna OlyniychukTrue
CVE-2026-21262: SQL Server Zero-Day Fixed in Microsoft’s March Patch Tuesday Release2026-03-12TrueDaryna OlyniychukTrue
CVE-2026-21385: Google Patches Qualcomm Zero-Day Exploited in Targeted Android Attacks2026-03-04TrueDaryna OlyniychukTrue
UAC-0252 Attack Detection: SHADOWSNIFF and SALATSTEALER Fuel Phishing Campaigns in Ukraine2026-03-03TrueDaryna OlyniychukTrue
CVE-2026-20127: Cisco SD-WAN Zero-Day Exploited Since 20232026-02-26TrueDaryna OlyniychukTrue
CVE-2026-22769: Critical Dell RecoverPoint Zero-Day Exploited in the Wild2026-02-18TrueDaryna OlyniychukTrue
CVE-2026-2441: Google Patches Chrome Zero-Day Exploited in the Wild2026-02-16TrueDaryna OlyniychukTrue
CVE-2026-20700: Apple Patches Zero-Day Exploited in Sophisticated Cyber Attacks2026-02-12TrueDaryna OlyniychukTrue
CVE-2026-20841: Windows Notepad RCE Fixed in Microsoft’s February Patch Tuesday Release2026-02-11TrueDaryna OlyniychukTrue
CVE-2026-21643: Critical FortiClient EMS Vulnerability Enables Unauthenticated Remote Code Execution2026-02-10TrueDaryna OlyniychukTrue
UAC-0001 (APT28) Attack Detection: russia-Backed Actor Actively Exploits CVE-2026-21509 Targeting Ukraine and the EU2026-02-02TrueDaryna OlyniychukTrue
CVE-2025-15467: OpenSSL Vulnerability Leads to Denial-of-Service, Remote Code Execution2026-01-29TrueDaryna OlyniychukTrue
CVE-2026-24858: FortiOS SSO Zero-Day Exploited in the Wild2026-01-28TrueDaryna OlyniychukTrue
CVE-2026-21509: Actively Exploited Microsoft Office Zero-Day Forces Emergency Patch2026-01-27TrueDaryna OlyniychukTrue
CVE-2026-24061: Decade-Old Vulnerability in GNU InetUtils telnetd Enables Remote Root Access2026-01-23TrueDaryna OlyniychukTrue
CVE-2026-20045: Critical Zero-Day in Cisco Products Is Actively Exploited in the Wild2026-01-22TrueDaryna OlyniychukTrue
CVE-2026-0227: Palo Alto Networks Fixes GlobalProtect DoS Flaw Allowing Remote Firewall Disruption2026-01-16TrueDaryna OlyniychukTrue
CVE-2026-20805: Microsoft Fixes Actively Exploited Windows Desktop Manager Zero-Day2026-01-15TrueDaryna OlyniychukTrue
UAC-0190 Attack Detection: Fake Charity Lures Used to Deploy the PLUGGYAPE Backdoor Against the Ukrainian Armed Forces2026-01-14TrueDaryna OlyniychukTrue
CVE-2026-21858 aka Ni8mare: Critical Unauthenticated Remote Code Execution Vulnerability in n8n Platform2026-01-09TrueDaryna OlyniychukTrue
CVE-2025-14733 Vulnerability: WatchGuard Addresses a Critical RCE Affecting Firebox Firewalls, Actively Exploited for Real-World Attacks2025-12-23TrueDaryna OlyniychukTrue
CVE-2025-20393 Exploitation: A Maximum-Severity Zero-Day Vulnerability in Cisco AsyncOS Software Abused in Attacks by the China-Backed APT UAT-9686 2025-12-18TrueVeronika TelychkoTrue
CVE-2025-14174 Vulnerability: A New Memory Corruption Zero-Day Vulnerability in Apple WebKit Exploited in Targeted Attacks2025-12-16TrueVeronika TelychkoTrue
CVE-2025-55183 and CVE-2025-55184: New React RSC Vulnerabilities Expose Applications to Denial of Service Attacks and Source Code Leaks2025-12-15TrueVeronika TelychkoTrue
CVE-2025-62221 and CVE-2025-54100: Windows Elevation of Privilege and RCE Zero-Day Vulnerabilities Patched2025-12-11TrueVeronika TelychkoTrue
CVE-2025-66516: Maximum-Severity Vulnerability in Apache Tika Could Lead to XML External Entity Injection Attack2025-12-08TrueVeronika TelychkoTrue
React2Shell Vulnerability: Maximum-Severity Flaw in React Server Components Actively Exploited by China-Backed Groups 2025-12-05TrueVeronika TelychkoTrue
CVE-2025-48633 and CVE-2025-48572: Android Framework Information Disclosure and Privilege Escalation Vulnerabilities Exploited in the Wild2025-12-04TrueVeronika TelychkoTrue
CVE-2025-41115: A Maximum-Severity Privilege Escalation Vulnerability in the Grafana SCIM Component 2025-11-24TrueVeronika TelychkoTrue
CVE-2025-62215: Microsoft Patches Windows Kernel Zero-Day Vulnerability Under Active Exploitation2025-11-12TrueDaryna OlyniychukTrue
CVE-2025-12480 Detection: Hackers Exploit the Now-Patched Unauthenticated Access Control Vulnerability in Gladinet’s Triofox 2025-11-11TrueVeronika TelychkoTrue

1–50 of 56