From the Desk
SOC Analyst
Threat detection, vulnerability alerts, security tooling, incident response.
20
Stories filed
5
Desks covered
≥ 6/10
Editorial floor
Coverage:Threat IntelVulnerabilitiesToolsSecurityOT/IoT Security
§
On the SOC Analyst Desk
The latest stories filtered for your beat, organised by sub-section.
Security2 stories
Threat Intel8 stories
- Attackers Combo Up Evasion Tactics for BEC PhishingThe 'TFF Trap' campaign chains fileless loaders with Agent Tesla, Remcos, XWorm, and other RATs — SOC teams need updated detection logic for the specific evasion technique combinations described.20 Jul
- New HollowGraph malware uses Microsoft Graph for stealthy C2 commsHollowGraph's use of Microsoft Graph calendar events as a C2 channel requires new detection rules targeting unusual Graph API patterns and mailbox calendar anomalies.20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware CampaignA fully exposed attacker server gave Rapid7 visibility into an active WebDAV-based malware campaign — the published IOCs and TTPs can be immediately operationalised for detection.20 Jul
- Hackers were inside South Korea's diplomat training system for 9 months20 Jul
- Romania races to restore land registry after cyberattack disrupts property market20 Jul
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050This implant uses hijacked M365 calendar events dated to 2050 as a covert C2 and exfiltration channel, blending into legitimate cloud traffic and evading traditional network-based detection.20 Jul
- Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday TrustWith scams constituting nearly half of all malware detections in H1 2026, SOC teams must recalibrate alert priorities toward social-engineering-based delivery vectors that bypass technical controls.20 Jul
- Software provider to more than 2,000 US hospitals says hackers stole employee and customer data20 Jul
Vulnerabilities10 stories
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and MoreThis weekly roundup consolidates multiple critical and zero-day vulnerabilities across WordPress, SonicWall, and SharePoint — any of which could be actively exploited and require immediate triage.20 Jul
- Mythos Didn't Break Your Security Program. Your Exposure Window Could.AI-accelerated CVE discovery is shrinking the gap between disclosure and exploitation; SOC teams need faster triage loops to keep pace.20 Jul
- [NEU] [hoch] Extreme Networks ExtremeXOS: Mehrere SchwachstellenHigh-severity flaws in network switching OS enabling admin-level access demand immediate detection and response prioritisation.20 Jul
- [NEU] [hoch] Grafana: Schwachstelle ermöglicht Manipulation von DateienGrafana is a core observability tool; a file-manipulation flaw could let authenticated attackers tamper with dashboards or configs, undermining SOC visibility.20 Jul
- [NEU] [hoch] IBM Langflow Desktop OSS: Mehrere SchwachstellenMultiple high-severity flaws in IBM Langflow Desktop OSS could lead to RCE and privilege escalation, requiring immediate detection coverage.20 Jul
- Critical ServiceNow code execution flaw now exploited in attacksActive exploitation in the wild means SOC teams need to immediately hunt for signs of compromise in ServiceNow environments and monitor for exploitation indicators.20 Jul
- [NEU] [UNGEPATCHT] [mittel] Keycloak: Mehrere Schwachstellen20 Jul
- [UPDATE] [hoch] Composer: Mehrere Schwachstellen ermöglichen Codeausführung20 Jul
- [NEU] [mittel] IBM WebSphere Application Server: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen20 Jul
- [UPDATE] [hoch] Mozilla Firefox und Firefox ESR: Mehrere SchwachstellenMultiple high-severity flaws in Firefox and Firefox ESR could enable code execution; SOC teams need to watch for exploitation attempts against unpatched endpoints.20 Jul