Active Threats

Explore the latest active threats being deployed by malicious actors as of 2026. Each report may offer attack flows, actionable detection rules, and simulation instructions to help SOC teams stay ahead of evolving adversary techniques.

tag icon THREAT OF THE MONTH
13 Aug 2026 09:08

StopRansomware: Gunra Ransomware Threat Analysis

SOC Prime Bias: Critical

source icon

CISA

01 Oct 2026 11:28

Citrix NetScaler PreAuth Command Injection CVE-2026-88771

SOC Prime Bias: Critical

source icon

watchTowr Labs

01 Oct 2026 11:24

UAT-11587 Targets Asian Government and Policy Organizations with Antino Backdoor

SOC Prime Bias: High

source icon

Cisco Talos Blog

01 Oct 2026 11:18

Star Blizzard Uses RedFlick to Enhance Phishing and Malware Deployment

SOC Prime Bias: Critical

source icon

Microsoft Security Blog

01 Oct 2026 11:13

Phishing Abuses RMM Tools for Persistent Access

SOC Prime Bias: High

source icon

Microsoft Security Blog

01 Oct 2026 11:02

Citrix NetScaler ADC and Gateway Appliances Targeted in Active Attacks

SOC Prime Bias: Critical

source icon

Google Cloud Blog

01 Oct 2026 10:53

ShinyHunters Resumes Large-Scale Attacks Targeting Oracle PeopleSoft

SOC Prime Bias: Critical

source icon

Google Cloud Blog

01 Oct 2026 10:43

TASK#STOMP: PowerShell Backdoor for Document Theft and Remote Access

SOC Prime Bias: High

source icon

Securonix

01 Oct 2026 10:37

Uncovering a SectopRAT Variant Embedded in Legitimate Software

SOC Prime Bias: High

source icon

Fortinet Blog

29 Sep 2026 17:12

Custom GPTs Abused in ClickFix Campaign to Deliver RAT Malware

SOC Prime Bias: High

source icon

Huntress

29 Sep 2026 17:08

APT36-Linked Campaign Uses KMS Auto in a Multi-Stage Intrusion

SOC Prime Bias: High

source icon

K7 Labs