Active Threats

Explore the latest active threats being deployed by malicious actors as of 2026. Each report may offer attack flows, actionable detection rules, and simulation instructions to help SOC teams stay ahead of evolving adversary techniques.

17 Sep 2026 11:32

The extension you never installed: KREMLIN forges Chrome’s own integrity checks to steal banking sessions

SOC Prime Bias: High

source icon

elastic

17 Sep 2026 11:26

Iranian cyber targeting of dissidents, activists and journalists

SOC Prime Bias: High

source icon

National Cyber Security Centre

17 Sep 2026 11:20

Malicious Twitch Extension Steals OAuth Tokens from 30,000 Users

SOC Prime Bias: High

source icon

socket.dev

17 Sep 2026 11:03

PAPERMILL Emerges as a Silver Fox-Like Threat Cluster

SOC Prime Bias: High

source icon

JUMPSEC

16 Sep 2026 10:45

RUSTGate: A Drone-Swarm Lure Points to Potential Defence-Sector Targeting

SOC Prime Bias: High

source icon

Ctrl-Alt-Intel

16 Sep 2026 10:16

AsyncRAT Campaign Uses AutoIt for Multi-Stage Malware Delivery

SOC Prime Bias: High

source icon

Point Wild

15 Sep 2026 17:59

LiteLLM Hack Triggers One of 2026’s Largest AI Supply Chain Breaches

SOC Prime Bias: Critical

source icon

Hudson Rock

15 Sep 2026 17:55

DPRK PolinRider Campaign Shows Hands-on-Keyboard Supply Chain Activity

SOC Prime Bias: Critical

source icon

Deception.Pro Blog

15 Sep 2026 17:50

E4del and PINHOLE Abuse FTP Banner Dead Drops for C2

SOC Prime Bias: High

source icon

RST Cloud - Threat Intelligence Solutions

15 Sep 2026 17:45

Browser-in-the-Browser Phishing Delivers Rogue RMM Tools for Persistence

SOC Prime Bias: High

source icon

Huntress