MDR
Managed Detection and Response
Overview
Overview
What to expect
Features
Bring calm and confidence
to your cyber security
Security needs
Security needs
What best describes your current situation?
Overview
Overview
Actively looking for a provider
Unhappy with current provider
Want to augment capabilities
Considering outsourcing
Case study
CymruSOC
Protecting vital public services in Wales by detecting and responding to threats, 24/7
Read more
Resources
All resources
Blogs
Case studies
About
About us
Explore our company and values
Company
Company
Partners
News
Careers
Latest insights
Sleepless in security: How stress impacts the wellbeing of cyber security leaders
Read more
Socura named one of the UK's Best Workplaces for Wellbeing and for Development 2026
Read more
Get in touch
Get in touch
Discover all our latest content
All
Blogs
Case studies
Datasheets
eBooks
News & press releases
Reports
Threat alerts
Webinars
Blogs
View all blogs
Blogs
Do you need a 24/7 Security Operations Centre? A complete guide
Blogs
Sleepless in security: How stress impacts the wellbeing of cyber security leaders
Blogs
Socura named one of the UK's Best Workplaces for Wellbeing and for Development 2026
Case studies
View all cases
Case study
Historic England
Securing England’s history with 24/7 threat detection and response
Case study
NHS Foundation Trust
Scaling detection and response to safeguard specialist patient care
Case study
interactive investor
Extending the security operations of the UK’s leading subscription-based investment platform
Datasheets
View all datasheets
Datasheet
Detection Rule Automation Engine
Learn how DRAE enhances Socura MDR, ensuring fast and effective deployment of threat detection rules.
Datasheet
Managed Detection and Response
An overview of our MDR service and the outcomes you can expect.
eBooks
View all ebooks
eBook
7 Deadly Sins of Cyber Security Services
Discover the tell-tale signs of low quality cyber security service providers.
News & press releases
View all news
News
Socura leaders named among the UK’s top 50 most ambitious business leaders for 2026
News
Protecting the digital future of Welsh football
News
Socura recognised as one of UK’s best workplaces by Great Place to Work
Reports
View all reports
Reports
Sleepless in security
Wellbeing in cyber and the challenges keeping security leaders awake at night.
Reports
A wave in cyber
Analysing the growth, diversity, and regional footprint of the UK cyber security workforce through ONS occupation data.
Reports
FTSE 100 for sale
An analysis of stolen credentials and passwords across the UK’s biggest businesses
Reports
UK employment trends report 2024: Their next job was in cyber
Learn about the latest cybersecurity employment trends in the UK.
Threat alerts
View all alerts
Threat alert
September 28, 2026
Citrix NetScaler Zero-Day Vulnerabilities (CVE-2026-88771 & CVE-2026-88772)
Citrix’s September 2026 security bulletin (CTX697096) resolves eight distinct vulnerabilities impacting NetScaler ADC and Gateway appliances, with severity scores ranging from CVSS 7.0 to 9.5. The bulletin is headlined by two actively exploited, maximum-severity zero-days. Because these edge devices manage remote access and hold highly sensitive cryptographic material in active memory, threat actors are leveraging these flaws to bypass authentication, harvest session tokens, and establish deep persistence within corporate networks.
September 28, 2026
Threat alert
September 16, 2026
BambooToken Framework and the Rise of MQTT-Based Command and Control
BambooToken is a sophisticated, cross-platform malware framework that leverages the Message Queuing Telemetry Transport (MQTT) protocol to maintain stealthy command and control over compromised systems. Active and evolving over a three-year span the framework primarily targets mobile application backends, software supply chains, and enterprise networks.
September 24, 2026
Threat alert
September 9, 2026
SAP OVERPASS (CVE-2026-44756): A Critical Vulnerability in the SAP Kernel
"OVERPASS" is a maximum-severity (CVSS 10.0) memory corruption vulnerability located within the SAP Extended Passport (EPP) processing library. Because EPP is a shared core component used for system tracing, this flaw impacts a massive array of SAP systems. It allows unauthenticated remote attackers to completely bypass standard identity defenses and gain full administrative control over the underlying operating system and SAP business applications.
September 24, 2026
Webinars
View all webinars
Webinar
FTSE 100 for sale: The scale of credential theft facing UK companies
How safe are UK companies from credential theft? Join experts from Socura and Flare as we unpack the findings of our joint report.