Active Threats

Explore the latest active threats being deployed by malicious actors as of Q4 2025. Each report may offer attack flows, actionable detection rules, and simulation instructions to help SOC teams stay ahead of evolving adversary techniques.

25 Mar 2026 18:25

T1547.001 in MITRE ATT&CK: Registry Run Keys and Startup Folder Explained

SOC Prime Bias: Medium

source icon

picussecurity.com

25 Mar 2026 18:21

T1547.003 Time Providers in MITRE ATT&CK Explained

SOC Prime Bias: Critical

source icon

picussecurity.com

25 Mar 2026 17:36

That “job brief” on Google Forms could infect your device

SOC Prime Bias: Medium

source icon

Malwarebytes

25 Mar 2026 17:26

Tracing a Multi-Vector Malware Campaign: From VBS to Open Infrastructure

SOC Prime Bias: Medium

source icon

levelbluecyber

25 Mar 2026 17:18

From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect

SOC Prime Bias: Medium

source icon

elastic.co

24 Mar 2026 16:03

Winos 4.0 Malware Masquerading as a KakaoTalk Installer

SOC Prime Bias: Medium

source icon

ASEC

24 Mar 2026 15:48

Phishing Clues Hidden in the /tmp Folder

SOC Prime Bias: Medium

source icon

Huntress

24 Mar 2026 15:40

ESET Research EDR killers explained: Beyond the drivers

SOC Prime Bias: Critical

source icon

welivesecurity.com

24 Mar 2026 14:48

From W-2 to BYOVD: How a Tax Search Leads to Kernel-Mode AV/EDR Kill

SOC Prime Bias: Medium

source icon

Huntress

24 Mar 2026 14:37

GSocket Backdoor Delivered Through Bash Script

SOC Prime Bias: Medium

source icon

SANS Internet Storm Center