Install
SOC Prime builds collective cyber defense by fusing Detection as Code, Sigma, and MITRE ATT&CK® to help teams proactively defend against emerging threats.
- 25articles · 30d
- 2+ day agolatest article
- Aug 19, 2026earliest in window
- 88%with images
- 253avg words
- science and technology 21
- SOF 18
- CE 16
- BI 5
- conflict war and peace 4
- CRL 4
- IT 4
- SOD 2
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Operation ASTERIX Exposes a Crypto Fraud Pipeline
3+ week, 3+ day ago (115+ words) SOC Prime Bias: High Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim to generate the exact telemetry expected…...
Guildma (Astaroth) Spreads via Brazilian Phishing Email
1+ week, 4+ day ago (343+ words) SOC Prime Bias: High A Windows host was infected with Guildma (Astaroth) malware through a malicious Brazilian Portuguese email containing a geofenced link. The attack delivers a ZIP archive with a Windows shortcut that downloads content into an alternate data…...
Agent Tesla BEC Attack Delivers In-Memory Infostealer
2+ week, 4+ day ago (323+ words) SOC Prime Bias: High A Business Email Compromise (BEC) campaign is using a sophisticated JScript dropper to distribute Agent Tesla v4 malware. The attack relies on Unicode emoji obfuscation to evade signature-based detection and uses DonutLoader to execute a reflective payload…...
UAT-10147 Uses Agentic AI for Post-Compromise Attacks
2+ week, 4+ day ago (268+ words) SOC Prime Bias: High UAT-10147 is a Chinese-speaking cybercrime group using agentic AI to automate and scale post-compromise operations. The actor targets Windows and Linux web servers for SEO fraud and data theft. Its AI-driven tooling supports exploit refinement, reconnaissance,…...
Kimsuky Abuses Remote Access Tools Across Northeast Asia
2+ week, 4+ day ago (215+ words) SOC Prime Bias: Critical Users should exercise caution when opening LNK files or links received from unknown sources, especially because Windows can hide file extensions. Organizations should regularly audit installed software for unauthorized Chrome Remote Desktop or AnyDesk deployments. Monitoring…...
SilkParasite China-Nexus APT Targets Central Asia
3+ week, 1+ day ago (147+ words) SOC Prime Bias: High We are still updating this part. Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim…...
CVE-2026-44756 SAP Kernel RCE Vulnerability
3+ day, 16+ hour ago (429+ words) Security teams seeking CVE-2026-44756 detection content can use the SOC Prime Platform to explore behavior-based detection rules and hunting queries mapped to MITRE ATT&CK®. Teams can also use Uncoder AI to convert threat intelligence into detection logic and hunting…...
CVE-2026-63520 SharePoint RCE Vulnerability Explained
1+ week, 6+ day ago (250+ words) SOC Prime Bias: Critical A critical remote code execution vulnerability affects the Microsoft SharePoint Business Data Connectivity (BDC) subsystem. Attackers can abuse unrestricted.NET type instantiation within the DbTypeReflector class to execute arbitrary operating system commands. When combined with an…...
Google Search for Claude Delivers MacSync Stealer
3+ week, 3+ day ago (166+ words) SOC Prime Bias: High Users should avoid copying and executing unverified commands in Terminal, even when instructions appear on legitimate or trusted domains. Security teams should monitor for suspicious curl activity and Base64-encoded content within shell processes. Tools such as…...
CVE-2026-75650: Critical Magento Zero-Day RCE
4+ day, 17+ hour ago (1042+ words) Adobe has released an emergency security update addressing a maximum-severity vulnerability in Adobe Commerce and Magento Open Source that attackers are already exploiting in the wild. Tracked as CVE-2026-75650 and rated 10.0 on the CVSS scale, the flaw enables unauthenticated remote…...