Explore the latest active threats being deployed by malicious actors as of Q4 2025. Each report may offer attack flows, actionable detection rules, and simulation instructions to help SOC teams stay ahead of evolving adversary techniques.
31 Mar 2026 15:28
Operation DualScript: Multi-Stage PowerShell Malware Targeting Crypto and Finance
SOC Prime Bias:
Critical
Seqrite
30 Mar 2026 18:08
33K Exposed LiteLLM Deployments and the C2 Servers Behind TeamPCP’s Supply Chain Attack
SOC Prime Bias:
High
hunt.io
30 Mar 2026 17:07
T1547.006 Kernel Modules and Extensions in MITRE ATT&CK Explained
SOC Prime Bias:
Critical
picussecurity.com
30 Mar 2026 16:46
Abusing Legitimate Low-Level Tools to Help Ransomware Evade Antivirus Detection
SOC Prime Bias:
High
Seqrite
30 Mar 2026 16:15
T1547.008 LSASS Driver in MITRE ATT&CK Explained
SOC Prime Bias:
Critical
picussecurity.com
30 Mar 2026 16:01
Cyberattack UAC-0255 disguised as a notification from CERT-UA using the AGEWHEEZE tool
SOC Prime Bias:
Medium
cert.gov.ua
30 Mar 2026 15:52
Infiniti Stealer: a new macOS infostealer using ClickFix and Python/Nuitka
SOC Prime Bias:
Medium
Malwarebytes
30 Mar 2026 15:41
Say My Name: How MioLab is building MacOS Stealer Empire
SOC Prime Bias:
Medium
levelbluecyber
27 Mar 2026 17:11
InterLock: Full Tooling Breakdown of a Ransomware Operation
SOC Prime Bias:
High
Derp
27 Mar 2026 16:57
Pawn Storm Campaign Deploys PRISMEX, Targets Government and Critical Infrastructure Entities