MDR
Managed Detection and Response
Overview
Overview
What to expect
Features
Bring calm and confidence
to your cyber security
Security needs
Security needs
What best describes your current situation?
Overview
Overview
Actively looking for a provider
Unhappy with current provider
Want to augment capabilities
Considering outsourcing
Case study
CymruSOC
Protecting vital public services in Wales by detecting and responding to threats, 24/7
Read more
Resources
All resources
Blogs
Case studies
About
About us
Explore our company and values
Company
Company
Partners
News
Careers
Latest insights
Sleepless in security: How stress impacts the wellbeing of cyber security leaders
Read more
Socura named one of the UK's Best Workplaces for Wellbeing and for Development 2026
Read more
Get in touch
Get in touch
Threat
alerts
Stay informed about the latest threats and vulnerabilites
Threat alert
August 6, 2026
Weaponisation of Microsoft Teams for IT Support Vishing & Ransomware Deployment
As secure email gateways (SEGs) and automated identity filters have increased in sophistication, advanced threat actors have adapted by migrating initial access operations directly into cloud-native Software-as-a-Service (SaaS) collaboration environments. Microsoft Teams has emerged as a primary target for social engineering, voice phishing (vishing), and administrative helpdesk impersonation campaigns.
August 6, 2026
Threat alert
July 29, 2026
VMSA-2026-0006: Multiple VMware ESX, vCenter, Workstation, and Fusion Vulnerabilities
On July 29, 2026, Broadcom published security advisory VMSA-2026-0006, documenting vulnerabilities spanning across multiple structural layers of the vSphere ecosystem, divided primarily between centralised management daemons running on vCenter Server and kernel-level device emulation drivers executing within the ESXi hypervisor.
July 29, 2026
Threat alert
July 17, 2026
LegacyHive Zero-Day: Privilege Escalation Exploiting Windows
Within hours of Microsoft releasing its monthly security updates on July 15, 2026, a critical zero-day vulnerability dubbed "LegacyHive" was publicly disclosed. The exploit takes advantage of a logic flaw in the Windows User Profile Service (profsvc), enabling a low-privileged standard user to deceive the SYSTEM-level service into mounting another user's registry hive with read privileges.
July 17, 2026
Threat alert
July 15, 2026
Attack Technique: OAuth Client ID Spoofing
Threat actors have been observed by researchers using a highly effective, stealthy mechanism for mass credential validation known as OAuth Client ID Spoofing. By manipulating the globally unique identifier (client_id) within legacy OAuth 2.0 authentication flows, adversaries can silently enumerate Microsoft Entra ID accounts, validate stolen credentials, and bypass standard security monitoring.
July 15, 2026
Threat alert
July 1, 2026
CVE-2026-8451: Pre-Authentication Memory Overread in Citrix NetScaler
On June 30, 2026, Citrix released security bulletin CTX696604, addressing a suite of high-severity vulnerabilities affecting customer-managed Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway appliances.
July 1, 2026
Threat alert
June 17, 2026
DragonForce Backdoor.Turn Campaign of Weaponisation Microsoft Teams
Ransomware cartel known as DragonForce, has been observed successfully weaponising Microsoft Teams' network relay infrastructure to mask command-and-control communications. By routing malicious operations through official Microsoft infrastructure, the threat actors rendered their activities virtually indistinguishable from legitimate business collaborations, evading traditional detection mechanisms.
June 18, 2026
Threat alert
June 3, 2026
Supply Chain Worm Campaign Updates (Miasma, TeamPCP, & VS Code Exploit)
Threat actors have officially moved beyond basic "nuisance" typosquatting through deploying sophisticated, automated, and self-propagating worms targeting trusted namespaces. By subverting continuous integration (CI/CD) pipelines and developer IDEs, they have turned the very systems designed to build and secure our code into automated distribution nodes. Recent threat landscape is dominated by TeamPCP and the Shai-Hulud worm, a self-propagating payload is engineered to steal publishing credentials, enumerate every package accessible to those credentials, inject malicious logic, and republish backdoor versions automatically.
June 3, 2026
Threat alert
May 14, 2026
Nightmare-Eclipse: GreenPlasma and YellowKey
In May 2026, a security researcher operating under the pseudonym "Nightmare-Eclipse" disclosed two new zero-day vulnerabilities targeting the Microsoft Windows ecosystem: GreenPlasma and YellowKey. This follows the researcher's previous zero-days (BlueHammer and RedSun) which were actively weaponised shortly after release.
May 20, 2026
Threat alert
May 6, 2026
CVE-2026-0300: Unauthenticated Remote Code Execution in the PAN-OS User-ID Authentication Portal
CVE-2026-0300 is a critical zero-day vulnerability affecting Palo Alto Networks PAN-OS firewalls. The flaw exists within the User-ID™ Authentication Portal and allows an unauthenticated, remote attacker to execute arbitrary code with root privileges via specially crafted network packets.
May 7, 2026
Next