Active Threats

Explore the latest active threats being deployed by malicious actors as of 2026. Each report may offer attack flows, actionable detection rules, and simulation instructions to help SOC teams stay ahead of evolving adversary techniques.

01 Sep 2026 19:43

Blind Eagle’s GitHub Loader Reveals a Persistent Operator

SOC Prime Bias: High

source icon

levelbluecyber

01 Sep 2026 19:38

Carry-On Compromise: TA4922 Packs PackClient

SOC Prime Bias: High

source icon

Proofpoint

01 Sep 2026 19:33

TerminalFix Campaign Builds Reverse Tunnels for Persistent Access

SOC Prime Bias: High

source icon

Microsoft Security Blog

01 Sep 2026 19:29

Guildma (Astaroth) malware infection from Brazilian Portuguese email

SOC Prime Bias: High

source icon

SANS Internet Storm Center

01 Sep 2026 19:25

The Aurora Files: Inside a High-Resolution Malware Investigation

SOC Prime Bias: Critical

source icon

cloudsek.com

01 Sep 2026 19:21

Inside SHADOW-WATER-084: A Steganographic Loader-as-a-Service Delivering Remcos, LXBASE, and More

SOC Prime Bias: High

source icon

TrendAI

31 Aug 2026 16:10

CVE-2026-62911 Enables Pre-Auth RCE on Exchange Server

SOC Prime Bias: Critical

source icon

GitHub

31 Aug 2026 16:05

Ditto: A PowerShell and JavaScript Obfuscator

SOC Prime Bias: Medium

source icon

GitHub

31 Aug 2026 09:27

Inhospitable: Mapping Russian Cyber Espionage Infrastructure

SOC Prime Bias: Critical

source icon

Validin

31 Aug 2026 09:23

Play Ransomware Encryption: How It Works

SOC Prime Bias: Critical

source icon

GuidePoint Security