MDR
Managed Detection and Response
Overview
Overview
What to expect
Features
Bring calm and confidence
to your cyber security
Security needs
Security needs
What best describes your current situation?
Overview
Overview
Actively looking for a provider
Unhappy with current provider
Want to augment capabilities
Considering outsourcing
Case study
CymruSOC
Protecting vital public services in Wales by detecting and responding to threats, 24/7
Read more
Resources
All resources
Blogs
Case studies
About
About us
Explore our company and values
Company
Company
Partners
News
Careers
Latest insights
Digital transformation and resilience: Join Socura at Socitm President’s Conference 2026
Read more
Andrew Kays and Jamie Brummell announced as joint EY Entrepreneur of the Year 2026 finalists
Read more
Get in touch
Get in touch
Threat
alerts
Stay informed about the latest threats and vulnerabilites
Threat alert
May 14, 2026
Nightmare-Eclipse: GreenPlasma and YellowKey
In May 2026, a security researcher operating under the pseudonym "Nightmare-Eclipse" disclosed two new zero-day vulnerabilities targeting the Microsoft Windows ecosystem: GreenPlasma and YellowKey. This follows the researcher's previous zero-days (BlueHammer and RedSun) which were actively weaponised shortly after release.
May 14, 2026
Threat alert
May 6, 2026
CVE-2026-0300: Unauthenticated Remote Code Execution in the PAN-OS User-ID Authentication Portal
CVE-2026-0300 is a critical zero-day vulnerability affecting Palo Alto Networks PAN-OS firewalls. The flaw exists within the User-ID™ Authentication Portal and allows an unauthenticated, remote attacker to execute arbitrary code with root privileges via specially crafted network packets.
May 7, 2026
Threat alert
April 29, 2026
Windows Architecture Vulnerabilities: CVE-2026-32202 & PhantomRPC
As traditional security defences improve, advanced threat actors are increasingly targeting foundational architectural components within the Microsoft Windows operating system. Two recent vulnerabilities—CVE-2026-32202 and an unpatched flaw known as "PhantomRPC"—highlight this shift. Attackers are using logical flaws and protocol abuses to achieve stealthy initial access and rapid privilege escalation.
April 29, 2026
Threat alert
April 23, 2026
npm Supply-Chain Worm Attack
A sophisticated, self-propagating supply-chain worm has been identified within the Node Package Manager (npm) ecosystem. Initially spotted on 21 April 2026, the attack targets high-value endpoints, including AI agent tooling and database operations. Threat actors compromised multiple packages linked to Namastex Labs, most notably the embedded PostgreSQL server utility, pgserve. The malware behaves as a highly aggressive infostealer, harvesting developer credentials, browser data, cloud service keys, and cryptocurrency wallets. Crucially, the attack leverages a worm-like mechanism to recursively spread across both the npm and PyPI ecosystems using stolen publish tokens. To ensure persistence and evade law enforcement takedowns, the attackers exfiltrate stolen data to a decentralised Internet Computer Protocol blockchain canister.
April 23, 2026
Threat alert
April 17, 2026
Microsoft Defender Vulnerability Suite (CVE-2026-33825, RedSun, UnDefend)
The April 2026 security landscape was effectively upended by a researcher known as "Nightmare-Eclipse". Driven by a public grievance with Microsoft’s Security Response Center (MSRC) over their vulnerability disclosure process, the researcher released a triad of weaponised zero-day exploits on GitHub. These tools ( BlueHammer, RedSun, and UnDefend ) turned the operating system’s primary defence mechanism into its greatest vulnerability. While Microsoft addressed BlueHammer in its April 2026 Patch Tuesday update, RedSun and UnDefend remain critically unpatched and are actively being exploited in the wild.
April 17, 2026
Threat alert
April 15, 2026
CVE-2026-34621: Adobe Acrobat Reader Prototype Pollution
Adobe released a security update (APSB26-43) to address CVE-2026-34621, a critical zero-day vulnerability in Adobe Acrobat and Reader. Flaw lies in an improperly Controlled Modification of Object Prototype Attributes within the embedded JavaScript engine, has been exploited in the wild since at least November.
April 16, 2026
Threat alert
April 8, 2026
Qilin Ransomware Group
The Qilin ransomware group has recently emerged as one of the most active ransomware operations, executing highly sophisticated campaigns that leverage the "Bring Your Own Vulnerable Driver" (BYOVD) technique. This method is used to systematically disable or bypass endpoint detection and response (EDR) solutions. By side-loading a malicious dynamic-link library (DLL) named msimg32.dll, Qilin initiates a complex, multi-stage infection chain capable of blinding and terminating over 300 different EDR drivers from nearly every security vendor on the market. The group typically gains initial access via stolen credentials and operates methodically, deploying the ransomware payload an average of six days after the initial compromise to maximise impact.
April 8, 2026
Threat alert
March 31, 2026
Axios Supply Chain Attack
A highly critical supply chain attack was identified targeting the axios npm package, a widely utilised HTTP client library. The attack involved the hijack of a lead maintainer’s npm account, which was subsequently used to publish malicious versions of the library. These poisoned releases bypassed established GitHub Actions, CI/CD pipelines, and injected a hidden dependency designed to drop a cross-platform Remote Access Trojan (RAT).
April 7, 2026
Threat alert
March 26, 2026
Citrix NetScaler Vulnerabilities CVE-2026-3055 & CVE-2026-4368
A critical out-of-bounds (OOB) read vulnerability, identified as CVE-2026-3055, has been discovered in Citrix NetScaler ADC and NetScaler Gateway. The vulnerability allows unauthenticated attackers to remotely siphon sensitive data directly from the appliance's memory. A sibling vulnerability (CVE-2026-4368) was also identified, which can cause "session mixup," allowing low-privilege users to hijack high-privilege sessions.
April 7, 2026
Next