SOCRadar (Threat Research Unit)
socradar · C · candidate
Discovered 2026-07-03 via S3: primary source for the FortiBleed campaign (this brief's own long-running thread) and its exposure-checker/whitepaper research; repeatedly cited by press covering a thread this brief tracks. Single-vendor investigative claims should be corroborated. Candidate — promote to active after 3 runs with content contribution. | 2026-07-05 admiralty audit: C (MEDIUM->C) — CTI blog mostly aggregation with occasional original TRU research; corroborate single-vendor claims. Keep candidate.
Cited in 6 entries
Citation cadence
Citation days per ISO week (8 weeks of coverage span, total 5).
- WP-SHELLSTORM: an exposed webshell-brokerage toolkit reveals 27 weaponized CVEs fired at 1.4M WordPress/Joomla sites plus a parallel Nacos/Spring Boot credential-theft track2026-07-10
- Ubiquiti UniFi SAB-066 — 25 vulnerabilities incl. unauthenticated CVSS 10.0 command injection in UniFi Connect (CVE-2026-50746)2026-07-08
- Accenture confirms a data-theft incident after '888' advertises 35 GB of internal source code, keys and Azure credentials2026-07-08
- FortiBleed status update — the FortiGate credential-theft campaign is now attributed to INC Ransom / Lynx, with a scaled-up victim count and an unconfirmed Nextcloud zero-day claim2026-07-05
- FortiBleed — first full tool-chain disclosure (FortigateSniffer, SNIFTRAN, GPU cracking cluster); Fortinet confirms no new CVE2026-06-23
- B1ack's Stash carding marketplace publicly releases 4.6M card records — SOCRadar attributes collection to e-skimming and phishing; not confirmed by issuing banks2026-05-21