SOCRadar (Threat Research Unit)
socradar · C · active
Discovered 2026-07-03 via S3: primary source for the FortiBleed campaign (this brief's own long-running thread) and its exposure-checker/whitepaper research; repeatedly cited by press covering a thread this brief tracks. Single-vendor investigative claims should be corroborated. Candidate; promote to active after 3 runs with content contribution. | 2026-07-05 admiralty audit: C (MEDIUM->C), CTI blog mostly aggregation with occasional original TRU research; corroborate single-vendor claims. Keep candidate. | 2026-07-26 weekly quality audit: promoted candidate → active on the documented lifecycle bar (cited by published entries from 6 distinct runs; the bar is 3). The promotion had never been executed because nothing counted contributing runs, the digest now emits sources.promotion_due (tools/run_summary.py). | 2026-09-13 quality audit (G3 broken-recipe duty, closing 2026-09-06 recommendation 3): RECIPE FIXED, with a caveat that matters. VERIFIED WORKING: `python3 tools/fetch_source.py extract https://socradar.io/blog/` returns clean titles/links/summaries. CAVEAT: the LISTING page's own date metadata is stale and wrong, always drill to the per-article URL and read its date there (verified: the ShieldCrash article extracts with its true date, 2026-09-10). fetch_method webfetch -> bridge (the `extract` subcommand).
Cited in 13 entries
Citation cadence
Citation days per ISO week (17 weeks of coverage span, total 12).
- CVE-2025-25249, Fortinet FortiOS/FortiSwitchManager: unauthenticated CAPWAP heap overflow added to CISA KEV, actively exploited since July via the PivotC2 RAT2026-09-10
- CVE-2026-21962: an unauthenticated request bypasses access control in the Oracle WebLogic Server Proxy Plug-in, CISA KEV-listed on 24 August with exploitation running since January2026-08-30
- A malware stager is reading its next instruction out of an FTP server's pre-login greeting, and the researchers who found it point out this is the rare command channel that is easier to catch, not harder2026-08-22
- The '2,500-organisation LiteLLM breach' was mostly not LiteLLM: 95% of the identified victims were collected before the poisoned packages existed, through the Trivy scanner their pipelines pulled unpinned2026-08-15
- ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 20252026-08-12
- CVE-2026-34486, Apache Tomcat: the fix for an earlier EncryptInterceptor flaw reintroduced a bypass, and CISA's KEV listing lands months after a China-nexus campaign was already exploiting it2026-08-05
- UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad, a five-day-old extortion brand whose other 14 claims look fabricated2026-07-31
- BravoX ransomware leaks 220 GB from a Vaud fiduciary, exposing ~15 municipalities' data and a cantonal minister's tax file2026-07-24
- WP-SHELLSTORM: an exposed webshell-brokerage toolkit reveals 27 weaponized CVEs fired at 1.4M WordPress/Joomla sites plus a parallel Nacos/Spring Boot credential-theft track2026-07-10
- Ubiquiti UniFi SAB-066, 25 vulnerabilities incl. unauthenticated CVSS 10.0 command injection in UniFi Connect (CVE-2026-50746)2026-07-08
- Accenture confirms a data-theft incident after '888' advertises 35 GB of internal source code, keys and Azure credentials2026-07-08
- FortiBleed, 73,932 internet-facing FortiGate devices exposed, Russian-speaking group cracking credentials into Active Directory2026-06-18
- B1ack's Stash carding marketplace publicly releases 4.6M card records, SOCRadar attributes collection to e-skimming and phishing; not confirmed by issuing banks2026-05-21