MDR
Managed Detection and Response
Overview
Overview
What to expect
Features
Bring calm and confidence
to your cyber security
Security needs
Security needs
What best describes your current situation?
Overview
Overview
Actively looking for a provider
Unhappy with current provider
Want to augment capabilities
Considering outsourcing
Case study
CymruSOC
Protecting vital public services in Wales by detecting and responding to threats, 24/7
Read more
Resources
All resources
Blogs
Case studies
About
About us
Explore our company and values
Company
Company
Partners
News
Careers
Latest insights
Socura recognised as a top performing scale-up in the UK tech sector
Read more
A wave in cyber: The ascent of cyber security as an essential UK occupation
Read more
Get in touch
Get in touch
Threat
alerts
Stay informed about the latest threats and vulnerabilites
Threat alert
October 30, 2024
Midnight Blizzard: Spear-Phishing Campaign Using RDP Files
Threat actor group “Midnight Blizzard” has been recently observed targeting several industries and sectors in a new highly sophisticated spear-phishing campaign that contains a signed Remote Desktop Protocol (RDP) configuration file. This operation targets individuals in government and non-governmental organizations across over 100 entities.
September 5, 2025
Threat alert
October 25, 2024
Critical Vulnerability in FortiManager: CVE-2024-47575
A critical vulnerability has been identified in the FortiManager fgfmd daemon, allowing remote unauthenticated attackers to execute arbitrary code or commands. The missing authentication vulnerability has been actively exploited in the wild, posing a severe risk to organizations using FortiManager and FortiAnalyzer models.
September 5, 2025
Threat alert
October 9, 2024
Ivanti Zero-Day vulnerabilities: CVE-2024-9379, CVE-2024-9380 and CVE-2024-9381
Ivanti issued a security update for three new zero-day vulnerabilities in its Cloud Services Appliance (CSA), which are being reported as exploited. These are tracked under CVE-2024-9379, CVE-2024-9380, and CVE-2024-9381.
September 5, 2025
Threat alert
September 19, 2024
CVE-2024-38812: Critical RCE Bug in VMware vCenter Server
Broadcom has patched a critical vulnerability in VMware vCenter Server, which could allow attackers to achieve remote code execution (RCE) by exploiting a heap overflow flaw in the DCE/RPC (Distributed Computing Environment/Remote Procedure Call) protocol. The vulnerability allows unauthenticated attackers to send specially crafted network packets to unpatched servers, leading to potential system compromise.
September 5, 2025
Threat alert
September 19, 2024
CVE-2024-29847: PoC Released for Critical Ivanti RCE Flaw
February 12, 2025
Threat alert
September 4, 2024
Malware Campaigns: WikiLoader Masquerading as Palo Alto GlobalProtect VPN
Palo Alto’s Unit 42 team has uncovered a WikiLoader loader variant delivered via SEO poisoning and spoofing their GlobalProtect VPN tool. Threat actors exploit users’ trust when downloading software by closely mimicking the legitimate download page. SEO poisoning and malicious ads are increasingly becoming a technique used by attackers to effectively deliver loaders to endpoints. The sophisticated campaign employs two stages: the infection process and leveraging advanced command-and-control (C&C) infrastructure.
September 5, 2025
Previous