Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SOC Prime
socprime.com > active-threats > def-con-themed-phishing-abuses-google-apps-script-for-malware-delivery

Post-DEF CON Phishing Abuses Google Apps Script

5+ hour, 52+ min ago   (169+ words) SOC Prime Bias: High Users should treat unexpected requests to execute terminal commands, bypass Gatekeeper, or install manual updates from document sidebars as suspicious. Organizations should monitor for unusual Google Apps Script activity and unauthorized use of code-signing certificates. Strong…...

SOC Prime
socprime.com > active-threats > malware-campaign-targets-korean-web-servers-running-softether-vpn

SoftEther VPN Malware Targets Korean Web Servers

1+ day, 14+ hour ago   (274+ words) SOC Prime Bias: High The Larva-26010 threat actor is targeting web and MS-SQL servers in South Korea to deploy SoftEther VPN. Compromised systems are repurposed as VPN servers, potentially using cascade connections to conceal the attackers’ true C&C infrastructure....

SOC Prime
socprime.com > active-threats > fake-claude-search-results-lead-macos-users-to-macsync-stealer

Google Search for Claude Delivers MacSync Stealer

1+ day, 14+ hour ago   (166+ words) SOC Prime Bias: High Users should avoid copying and executing unverified commands in Terminal, even when instructions appear on legitimate or trusted domains. Security teams should monitor for suspicious curl activity and Base64-encoded content within shell processes. Tools such as…...

SOC Prime
socprime.com > blog > cve-2026-15748-analysis

CVE-2026-15748: Forminator File Upload Flaw

2+ day, 6+ hour ago   (1056+ words) A critical security vulnerability in the popular Forminator Forms plugin for WordPress can allow unauthenticated attackers to upload executable PHP files and potentially take complete control of vulnerable websites. Tracked as CVE-2026-15748, the arbitrary file upload flaw carries a CVSS…...

SOC Prime
socprime.com > active-threats > malware-phishing-scam-phishing-emails-disguised-as-transaction-receipts

Fake Transaction Receipt Emails Deliver ScreenConnect

2+ day, 13+ hour ago   (218+ words) SOC Prime Bias: High AhnLab Security Intelligence Center (ASEC) identified the campaign by examining the phishing email content and behavior of the attached PDF. The investigation traced the execution chain from the malicious VBScript to background payload retrieval and silent…...

SOC Prime
socprime.com > blog > cve-2026-20349-actively-exploited-cisco-asa-and-ftd-flaw-enables-remote-dos

CVE-2026-20349: Cisco ASA and FTD VPN DoS Flaw

1+ week, 2+ day ago   (930+ words) Add to my AI research Cisco has disclosed a high-severity vulnerability in Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software that is already being exploited in the wild. Tracked as CVE-2026-20349, the flaw carries a…...

SOC Prime
socprime.com > active-threats > crowdstrike-hunts-shell-command-obfuscation-on-vmware-esxi

VMware ESX Shell Command Obfuscation Threat Hunting

1+ week, 3+ day ago   (161+ words) SOC Prime Bias: Critical Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim to generate the exact telemetry expected…...

SOC Prime
socprime.com > active-threats > screenconnect-spread-at-scale-through-app-store-themed-phishing

Fake App Store Phishing Deploys ScreenConnect at Scale

1+ week, 3+ day ago   (295+ words) SOC Prime Bias: High A large-scale phishing campaign is using advanced social engineering techniques to deploy unauthorized ConnectWise ScreenConnect clients. Attackers impersonate trusted services such as the Microsoft Store, Apple App Store, and Google Meet through dynamic web content and…...

SOC Prime
socprime.com > active-threats > macos-infostealer-targets-cryptocurrency-wallets

macOS Stealer Uses ClickFix to Drain Crypto Wallets

1+ week, 4+ day ago   (219+ words) SOC Prime Bias: High A Go-based macOS stealer is targeting cryptocurrency users through a ClickFix social engineering campaign. The malware steals sensitive credentials from Apple Keychain and browser stores while also featuring the ability to gradually drain cryptocurrency balances from…...

SOC Prime
socprime.com > active-threats > xeno-roblox-cheat-lures-deploy-a-java-based-infostealer

Fake Xeno Roblox Cheats Deliver Java Stealer

2+ week, 1+ day ago   (115+ words) SOC Prime Bias: High Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim to generate the exact telemetry expected…...