Skip to content

company

SOCRadar

SOCRadar is a cybersecurity firm offering extended threat intelligence, including dark web monitoring, attack surface management, and breach research.

Known aliases

  • SOCRadar
  • SOCRadar STRU
  • SOCRadar Threat Research Unit
  • SOCRadar TRU
  • STRU

Relationships

No evidence-backed relationships are recorded.

Current stories

security5 publishers

ShinyHunters phished the firm that had just profiled it, and device trust was the only thing that mattered

A ReliaQuest employee gave up a password and an MFA push five days after the company named the .claims campaign. Device trust, not training, kept the session worthless.

Perspective Coverage

5 publishers
Builder
Builder 29%
Operator
Operator 56%
Investor
Investor 15%

Reality

Evidence58
Adoption
Insufficient
Hype gap+25
Incentives70
Confidence62
security4 publishers

Ten cents a call: Activation Lock bypass now ships with its own voice agent

SOCRadar's teardown of the AnonyMousKIT service found 200 AI-voiced calls at about $0.10 each, most of them to Brazil. The skill in phone social engineering is now a script file.

Perspective Coverage

4 publishers
Builder
Builder 19%
Operator
Operator 76%
Investor
Investor 5%

Reality

Evidence70
Adoption40
Hype gap+35
Incentives40
Confidence65
security4 publishers

A CVSS 10.0 Cisco FMC bypass tops the four flaws CISA moved into KEV

CISA says all four are under active exploitation, and three of them are unauthenticated flaws in edge and management appliances. Its own alert cites BOD 26-04 and prints no due date for any of them.

Perspective Coverage

4 publishers
Builder
Builder 14%
Operator
Operator 80%
Investor
Investor 6%

Reality

Evidence72
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence70
security5 publishers

A hijacked HBO Max Reddit account pushed 108 ClickFix ads to Windows and macOS users

Hudson Rock and ADAMnetworks link the ads to an operation they call PasteSwitch, which hands Windows and macOS visitors different paste-this-command lures and swaps payloads on the backend depending on who arrives.

Perspective Coverage

5 publishers
Builder
Builder 29%
Operator
Operator 65%
Investor
Investor 6%

Reality

Evidence74
Adoption
Insufficient
Hype gap+8
Incentives50
Confidence72
security3 publishers

Malicious npm package indexed-btree fires its loader from a runtime library call

Checkmarx says a fake sorted-btree clone reached 2 million weekly downloads with clean install scripts, starting its loader only when an application calls BTree.prototype.set with a particular key. Nine related packages have been pulled.

Perspective Coverage

3 publishers
Builder
Builder 43%
Operator
Operator 45%
Investor
Investor 12%

Reality

Evidence62
Adoption45
Hype gap+20
Incentives45
Confidence60