Running a SOC often feels like drowning in alerts. Every morning, dashboards light up with thousands of signals; some urgent, many irrelevant. The job is to find the real threats fast enough to keep cases from piling up, prevent analyst burnout, and maintain client or leadership confidence.
The toughest challenges, however, aren’t the alerts that can be dismissed quickly, but the ones that hide
Two new spyware campaigns that researchers call ProSpy and ToSpy lured Android users with fake upgrades or plugins for the Signal and ToTok messaging apps to steal sensitive data. [...]
The cybercrime group calling itself the Crimson Collective claimed to have compromised Red Hat ‘s private GitHub repositories. The Crimson Collective claimed it had stolen 570GB from Red Hat ’s private GitHub repositories, including 28,000 projects and approximately 800 Customer Engagement Reports (CERs) with sensitive network data. CERs often contain sensitive info, including infrastructure details, […]
A vulnerability was found in SUSE Rancher up to 2.9.11/2.10.9/2.11.5/2.12.1. It has been classified as problematic. Affected by this issue is some unknown functionality of the file /meta/proxy of the component Endpoint. The manipulation leads to information disclosure.
This vulnerability is listed as CVE-2025-54468. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability was found in ViDay and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /api/reserva/web/clients of the component HTTP GET Request Handler. Executing manipulation of the argument phone can lead to information disclosure.
This vulnerability is tracked as CVE-2025-40645. The attack can be launched remotely. No exploit exists.
A vulnerability has been found in ViDay and classified as problematic. Affected is an unknown function. Performing manipulation results in information disclosure.
This vulnerability is identified as CVE-2025-40646. The attack can only be performed from the local network. There is not any exploit available.
A vulnerability identified as critical has been detected in Schweitzer Engineering Laboratories SEL Blueframe OS up to 1.11.x. The impacted element is an unknown function. This manipulation causes improper privilege management.
The identification of this vulnerability is CVE-2025-46741. The attack can only be executed locally. There is no exploit available.
You should upgrade the affected component.
A vulnerability labeled as critical has been found in Schweitzer Engineering Laboratories SEL Blueframe OS up to 1.11.x. This affects an unknown function of the component Password Handler. Such manipulation leads to improper access controls.
This vulnerability is referenced as CVE-2025-46742. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
A vulnerability marked as critical has been reported in Schweitzer Engineering Laboratories SEL Blueframe OS up to 1.11.x. This impacts an unknown function. Performing manipulation results in improper privilege management.
This vulnerability is identified as CVE-2025-46744. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability described as critical has been identified in Schweitzer Engineering Laboratories SEL Blueframe OS up to 1.11.x. Affected is an unknown function. Executing manipulation can lead to improper privilege management.
This vulnerability is tracked as CVE-2025-46745. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability has been found in Adobe ColdFusion up to 2021.19/2023.13/2025.1 and classified as critical. Affected by this vulnerability is an unknown functionality. Performing manipulation results in server-side request forgery.
This vulnerability was named CVE-2025-54234. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
A vulnerability labeled as problematic has been found in OpenPLC v3. This issue affects the function enipThread of the component ud2 Instruction Handler. Such manipulation leads to reliance on undefined, unspecified, or implementation-defined behavior.
This vulnerability is uniquely identified as CVE-2025-54811. Local access is required to approach this attack. No exploit exists.
It is best practice to apply a patch to resolve this issue.
A vulnerability was found in LabRedesCefetRJ WeGIA up to 3.2.7. It has been declared as problematic. This issue affects some unknown processing of the file CobrancaController.php. The manipulation of the argument local_recepcao results in cross site scripting.
This vulnerability was named CVE-2025-22597. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.