Skip to main content
Tag

SOC

48 articles on SOC. Page 2 of 2.

← All blog posts
CVE-2026-9198 Gives Unauthenticated RCE in IBM Langflow OSS Agent Control Planes
Vulnerabilities2026-08-17

CVE-2026-9198 Gives Unauthenticated RCE in IBM Langflow OSS Agent Control Planes

A SUPERUSER token minted through /api/v1/auto_login chains with Python exec() in /api/v1/validate/code. Langflow 1.10.1 fixes the flaw — but internet-exposed instances need hunting now, not after the next sprint.

7 min read
INC Ransomware Chains Two SonicWall SMA Zero-Days (CVE-2026-15409, CVE-2026-15410)
Ransomware2026-08-16

INC Ransomware Chains Two SonicWall SMA Zero-Days (CVE-2026-15409, CVE-2026-15410)

INC affiliates are weaponizing an SSRF and a post-authentication code injection in SonicWall SMA 1000 to reach internal networks. Exploitation started weeks before the July 14 patch — here is how to hunt and triage.

7 min read
isMalicious vs SecurityTrails: Discovery Data and Reputation Verdicts Are Not the Same Product
Threat Intel2026-08-15

isMalicious vs SecurityTrails: Discovery Data and Reputation Verdicts Are Not the Same Product

SecurityTrails tells you what exists — every subdomain, every historical DNS record. isMalicious tells you what is dangerous. Most teams searching for a SecurityTrails alternative want the second half.

6 min read
isMalicious vs IPQualityScore: Fraud Scoring and Threat Intelligence Are Different Jobs
Threat Intel2026-08-14

isMalicious vs IPQualityScore: Fraud Scoring and Threat Intelligence Are Different Jobs

IPQS scores whether a signup is fraudulent. isMalicious scores whether infrastructure is malicious. The two get compared constantly because both return a number about an IP address — and they answer different questions.

6 min read
isMalicious vs MISP: Why This Is the Wrong Comparison (and What to Compare Instead)
Threat Intel2026-08-13

isMalicious vs MISP: Why This Is the Wrong Comparison (and What to Compare Instead)

MISP is where you store and share indicators. isMalicious is where indicators come from. Teams searching for a MISP alternative are usually looking for a feed, not a replacement platform.

6 min read
isMalicious vs Cisco Talos: Reputation Lookups Outside the Cisco Stack
Threat Intel2026-08-12

isMalicious vs Cisco Talos: Reputation Lookups Outside the Cisco Stack

Talos reputation is excellent and it lives inside Cisco products. If your stack is not Cisco, or you need an API rather than a web form, that is where the comparison starts.

6 min read
Bulk IP and Domain Lookups: Designing Indicator Enrichment That Survives Real Volume
Threat Intel2026-08-11

Bulk IP and Domain Lookups: Designing Indicator Enrichment That Survives Real Volume

One incident produces hundreds of indicators, and per-indicator lookups are where triage stalls. Here is how to build a batch enrichment pipeline that respects quotas, deduplicates properly, and fails gracefully.

7 min read
Reverse IP Lookup: Pivoting on Infrastructure Without Drowning in Shared Hosting
SOC2026-08-10

Reverse IP Lookup: Pivoting on Infrastructure Without Drowning in Shared Hosting

A reverse IP lookup turns one indicator into a cluster — or into a thousand innocent neighbours. Here is how to tell the difference, and how to pivot on hosting infrastructure without generating false positives.

7 min read
WHOIS Lookup for Security Investigations: Reading a Record After Redaction
Phishing2026-08-09

WHOIS Lookup for Security Investigations: Reading a Record After Redaction

Privacy services stripped the registrant name out of most WHOIS records, but the fields that matter for triage survived. Here is what a WHOIS record still tells an analyst, and how to read it.

7 min read
The Kratos Phishing Kit Takedown: 200 Servers Gone, 1,800 Copies Still Out There
Phishing2026-08-08

The Kratos Phishing Kit Takedown: 200 Servers Gone, 1,800 Copies Still Out There

German and US law enforcement dismantled Kratos, the AiTM phishing service behind roughly 15,000 Microsoft 365 campaigns a month. The infrastructure is offline, but the kit is not. Here is what to hunt for now.

7 min read
CISA KEV Adds Arista VeloCloud and FortiOS Flaws: Why CVSS Is the Wrong Sort Order
Vulnerabilities2026-08-07

CISA KEV Adds Arista VeloCloud and FortiOS Flaws: Why CVSS Is the Wrong Sort Order

On 27 July 2026 CISA added a CVSS 10.0 command injection in Arista VeloCloud Orchestrator and a medium-severity FortiOS patch bypass to KEV. The pairing shows why exposure and persistence beat severity when ordering a patch queue.

7 min read
Cl0p Is Exploiting PTC Windchill (CVE-2026-12569) to Steal Engineering Data
Ransomware2026-08-06

Cl0p Is Exploiting PTC Windchill (CVE-2026-12569) to Steal Engineering Data

A Cl0p affiliate is chaining a FlexPLM information disclosure with an unauthenticated RCE in PTC Windchill to plant JSP web shells and run double-extortion data theft. Here are the detection signals and the triage workflow.

7 min read
GitHub Actions and CI/CD Pipeline Compromise: A Growing Supply Chain Attack Vector
Supply Chain2026-08-05

GitHub Actions and CI/CD Pipeline Compromise: A Growing Supply Chain Attack Vector

CI/CD pipeline compromises keep recurring across GitHub Actions ecosystems. Learn the detection signals, hardening steps, and enrichment workflow security teams need.

6 min read
Agentic AI Threat Mapping: MITRE ATT&CK Needs Evidence-Rich Workflows
AI & ML2026-07-08

Agentic AI Threat Mapping: MITRE ATT&CK Needs Evidence-Rich Workflows

Anthropic mapped AI-enabled cyber activity to MITRE ATT&CK and found gaps around autonomous orchestration. SOC teams need AI summaries tied to evidence, not unsupported verdicts.

4 min read
AI-Enabled Cyberattacks and MITRE ATT&CK: Turning New Threat Maps Into SOC Action
AI & ML2026-06-04

AI-Enabled Cyberattacks and MITRE ATT&CK: Turning New Threat Maps Into SOC Action

AI-enabled threats are being mapped into ATT&CK language, but mapping is only useful when it drives enrichment, detection, triage, and response workflows.

8 min read
SOC Alert Fatigue: How Threat Intelligence Reduces False Positives Without Hiding Real Attacks
SOC2026-06-04

SOC Alert Fatigue: How Threat Intelligence Reduces False Positives Without Hiding Real Attacks

Alert fatigue is not a staffing problem alone. SOC teams need better evidence, source quality, confidence bands, and enrichment workflows that turn noisy alerts into defensible decisions.

8 min read
Threat Intelligence Risk Scoring: How to Calibrate Reputation, Reduce False Positives, and Defend Your Decisions
Threat Intel2026-04-30

Threat Intelligence Risk Scoring: How to Calibrate Reputation, Reduce False Positives, and Defend Your Decisions

A noisy score is worse than no score. Learn what makes a reputation model trustworthy, how to combine multi-source evidence, and how to communicate uncertainty to your SOC and your executives.

5 min read
ASN Reputation for Threat Intelligence: How Autonomous System Intelligence Improves Prioritization and Hunt Programs
Threat Intel2026-04-27

ASN Reputation for Threat Intelligence: How Autonomous System Intelligence Improves Prioritization and Hunt Programs

An IP address is a snapshot; an autonomous system (ASN) is a neighborhood. Learn how to use ASN context safely for triage, fraud, and security operations—without mistaking a giant cloud for a monolithic "bad host".

5 min read
Threat Intelligence Platforms: Architecture, Data Quality, and High-Signal Feeds
Threat Intel2026-04-26

Threat Intelligence Platforms: Architecture, Data Quality, and High-Signal Feeds

Design TIPs and intel pipelines that scale: normalization, confidence scoring, deduplication, API-first delivery, and how to pair platform investments with analyst workflows.

8 min read
IOC Enrichment APIs: A Security Operations Guide to Faster Triage, Fewer False Positives, and Measurable ROI
Threat Intel2026-04-26

IOC Enrichment APIs: A Security Operations Guide to Faster Triage, Fewer False Positives, and Measurable ROI

An indicator without context is a ticket without an owner. Learn how IOC enrichment APIs work, which fields SOC teams need at each tier, and how to wire them into case management without building a data swamp.

6 min read
OSINT2026-04-23

OSINT for SOC Analysts: Turning Open Source Intelligence Into Threat intelligence analysts can use

A complete guide to open source intelligence (OSINT) for security operations—tools, techniques, workflows, and legal considerations for collecting, analyzing, and operationalizing open threat data in a modern SOC.

9 min read
Hash Reputation at Scale: Building Detection Rules That Survive Real Networks
Malware2026-04-22

Hash Reputation at Scale: Building Detection Rules That Survive Real Networks

Move beyond one-off hash blocks: design reputation pipelines, reduce false positives, and integrate file intelligence with IP and domain context for production-ready detection engineering.

8 min read
File Hash Reputation Lookups: Accelerating Incident Response With IOC Enrichment
Malware2026-04-22

File Hash Reputation Lookups: Accelerating Incident Response With IOC Enrichment

A practitioner's guide to file hash reputation lookups—how they work, which data sources power them, how to build automated IOC enrichment pipelines, and how to integrate hash intelligence into SOC, SOAR, and incident response workflows.

9 min read
Operational Threat Intelligence: Turning IOCs into Prioritized Security Actions
Threat Intel2026-04-19

Operational Threat Intelligence: Turning IOCs into Prioritized Security Actions

Define operational CTI that SOC teams can use daily: IOC lifecycle, confidence scoring, feed hygiene, and how to align indicators with detection engineering and incident response.

8 min read