SonicWall has patched two actively exploited zero-days affecting SMA 1000 Series secure remote access appliances. The issues are CVE-2026-15409, a critical unauthenticated SSRF flaw in the Workplace interface, and CVE-2026-15410, a post-authentication code injection flaw in the Appliance Management Console that can lead to arbitrary OS command execution as administrator under certain conditions. Public reporting says the vulnerabilities have been exploited together in real attacks against SMA6210, SMA7210, and SMA8200v appliances. https://lnkd.in/dXTnsyy3 #Cybersecurity #Security #0day #CVE #CyberAttack
SOC Prime
Computer and Network Security
Boston, Massachusetts 32,447 followers
AI-turbocharged detection intelligence. Line-speed cyberattack detection with AI trained on 11 years of Detection Intel
About us
AI-turbocharged detection intelligence. Enable line-speed cyberattack detection with AI trained on 11 years of Detection Intelligence.
- Website
-
https://socprime.com/
External link for SOC Prime
- Industry
- Computer and Network Security
- Company size
- 51-200 employees
- Headquarters
- Boston, Massachusetts
- Type
- Privately Held
- Founded
- 2015
- Specialties
- Cyber Security, SIEM, Security Analytics, SOC, Digital Security Transformation, Threat Detection Marketplace, Proactive SOC, SIGMA, SIEM Apps & Use Cases, Humio, Chronicle Security, CrowdStrike, Sumo Logic, Splunk, MISP, Elasticsearch, Logstash, QRadar, Threat Hunting, Blue Team, ArcSight, Securonix, Continuous Content Management, and Microsoft Sentinel
Locations
-
Primary
Get directions
Boston, Massachusetts 02116, US
Employees at SOC Prime
Updates
-
⚠️ 𝗧𝗵𝗿𝗲𝗮𝘁 𝗼𝗳 𝘁𝗵𝗲 𝗠𝗼𝗻𝘁𝗵: "Gamaredon (Primitive Bear) APT Profile and MITRE ATT&CK Breakdown" Gamaredon (Primitive Bear) is a Russia-aligned APT group linked to Russia's Federal Security Service (FSB) that has targeted Ukrainian and NATO entities since 2013 in cyber espionage campaigns. The group utilizes advanced PowerShell-based toolsets and continuously evolving tactics, including exploiting WinRAR vulnerabilities and leveraging cloud services to infiltrate victim environments and provide initial access to the Turla APT. 🔗 Full Active Threat Intel – link in the first comment. #cybersecurity #soc #blueteam #detectionengineering #threatintelligence #APT
-
The era of agentic cyberattacks has arrived. JADEPUFFER is the first documented case of LLM-driven ransomware capable of autonomously performing reconnaissance, lateral movement, persistence, and database extortion, marking a significant evolution in ransomware operations. Explore the Attack Flow, detection content, and attack simulations in the Active Threats section: https://lnkd.in/dYtwHCyi #Cybersecurity #Ransomware #Cyberattack #AI #Malware
-
-
Agentic Threat Research in Uncoder AI just got even better. You can now upload project files (PDF, TXT, CSV, JSON, and images) to provide persistent context across AI chats, while detections from the Threat Detection Marketplace can be added directly via the chat into the Code Editor, making threat research and detection engineering faster and more seamless. #DetectionEngineering #CyberSecurity #AI #SOC
-
-
A child domain compromise can become a full Active Directory forest takeover faster than many defenders expect. Attackers may abuse forest trusts, Golden Tickets, SID History, pass-the-ticket, and unconstrained delegation to escalate privileges across domains in a multi-domain forest. Active Threat: https://lnkd.in/dzUJ56xT #CyberSecurity #DetectionEngineering #Security
-
-
North Korea-linked Kimsuky APT group continues to evolve its KimJongRAT malware. A recent campaign observed in May 2026 abused GitHub Releases and shortened URLs to distribute updated malware that combines information-stealing and remote access capabilities. Learn more about the campaign and its latest techniques: https://lnkd.in/d7WiEAS5 #ThreatIntelligence #Malware #Kimsuky #RAT #CyberSecurity
-
-
The Gentlemen ransomware-as-a-service operation uses an advanced EDR killer arsenal to disable or weaken endpoint security products. The toolkit includes the in-house GentleKiller framework, along with third-party utilities such as HexKiller and HavocKiller, relying on BYOVD techniques to gain kernel-level privileges and terminate security processes. Explore the Attack Flow and use detection rules to secure your organization from Gentlemen’s EDR killer framework. Active Threat: https://lnkd.in/dV6cPG-N #Cybersecurity #Ransomware #ThreatDetection
-
-
Threat actors are actively exploiting CVE-2026-35273, a critical Oracle PeopleSoft zero-day in the Updates Environment Management component, to achieve remote code execution. The campaign targets exposed PSEMHUB endpoints, abuses the SSRF flaw to compromise systems, and has been linked to ShinyHunters activity focused on higher education environments. Explore the Attack Flow and use detection rules to secure your organization from CVE-2026-35273 exploitation. Active Threat: https://lnkd.in/dCC6ggws #Cybersecurity #ZeroDay #OraclePeopleSoft #ThreatDetection
-
-
CVE-2026-11645 is a high-severity Chrome zero-day affecting the V8 JavaScript engine and exploited in the wild. The flaw stems from out-of-bounds memory access that can be triggered through a specially crafted HTML page, potentially leading to memory corruption, browser crashes, or code execution within the Chrome sandbox. Article: https://lnkd.in/gkAdyy6w #Cybersecurity #Chrome #ZeroDay #ThreatDetection
-
CVE-2026-42530 exposes NGINX HTTP/3 deployments to denial-of-service and possible remote code execution via a use-after-free flaw in the ngx_http_v3_module. A remote, unauthenticated attacker can trigger the issue through a crafted HTTP/3 session that reopens a QPACK encoder stream, causing worker-process restarts and potential memory corruption. Article: https://lnkd.in/dzVw-jgq #Cybersecurity #Vulnerability #ThreatDetection