Active Threats

Explore the latest active threats being deployed by malicious actors as of Q4 2025. Each report may offer attack flows, actionable detection rules, and simulation instructions to help SOC teams stay ahead of evolving adversary techniques.

21 May 2026 01:15

SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain

SOC Prime Bias: Medium

source icon

SentinelOne

21 May 2026 01:10

How Storm-2949 turned a compromised identity into a cloud-wide breach

SOC Prime Bias: High

source icon

Microsoft Security Blog

21 May 2026 01:01

Phantom Stealer Analysis: Inside a Two-Layer Attack Chain

SOC Prime Bias: Medium

source icon

Darkatlas

21 May 2026 00:56

Amatera Stealer 4.0.2 Beta: What’s New in This Variant

SOC Prime Bias: Medium

source icon

eSentire

19 May 2026 16:30

Click, Install, Compromised: The New Wave of Zoom-Themed Attacks

SOC Prime Bias: High

source icon

cofense.com

19 May 2026 16:18

Defending EDR Against Adversaries

SOC Prime Bias: Critical

source icon

Huntress

19 May 2026 16:14

UAC-0184: From HTA to a Signed Network Stack

SOC Prime Bias: Critical

source icon

Synaptic Security Blog

18 May 2026 22:04

VIP Keylogger and Its Multi-Layered Evasion Tactics

SOC Prime Bias: Medium

source icon

Splunk

18 May 2026 21:43

PureLogs Delivered Through PawsRunner Steganography

SOC Prime Bias: Medium

source icon

Fortinet Blog

18 May 2026 21:27

Investigating a Stealthy Intrusion Through Third-Party Compromise

SOC Prime Bias: Critical

source icon

Microsoft Security Blog