Operation Master: one threat actor went from a VPN authentication bypass to 2.4 million fraud messages.
Same stolen data, sold twice.
SOCRadar's Threat Research Unit (STRU) mapped the full chain.
How it unraveled: a single operator email, cyberkill2025[@]gmail.()com, showed up in 5 operational contexts. Leaked database records tied it to the forum persona "masterblack."
The infrastructure went offline in mid-September.
SOCRadar Dark Web and underground intelligence now lands directly in EclecticIQ Intelligence Center.3 continuously updated feeds:
→ Dark Web news
→ Black market activity
→ PII exposureOne less tab open during triage.
Link in comments.
#ThreatIntel#DarkWeb
CVE-2026-94127 (CVSS 9.8) is being actively exploited against F5 BIG-IP APM.
It can allow unauthenticated RCE in specific APM and OAuth authorization-server setups.
Emergency hotfixes are out.
Patch, then check for signs of compromise.
Learn more: hubs.la/Q04ycRSW0#CyberSecurity#F5
ShinyHunters claims it breached FBI systems via an Oracle PeopleSoft zero-day, defaced hubs.la/Q04ycv5l0, and took 2–3 TB of data.
The FBI has only confirmed it's investigating activity affecting hubs.la/Q04ycv5W0. Everything else is unverified.
Learn more: hubs.la/Q04ycv6K0#ShinyHunters#FBI
WordPress Core versions 4.7.0–7.1.1 are affected by CVE-2026-87902, a critical vulnerability.
→ Unauthenticated attackers can exploit path traversal, and certain theme and server conditions open the door to RCE. → A public PoC exists, and scanning began within hours of disclosure. → Update to WordPress 7.1.2 or the fixed release for your branch.
Learn more: hubs.la/Q04y8PC40#CyberSecurity#WordPress#RCE
North Korea isn't just watching the war in Ukraine, it's collecting on it.
Operation Conflict Compass: assessed with moderate confidence to Konni (TA406, Opal Sleet), a DPRK-nexus group under the Kimsuky umbrella.
→ Spear-phishing with LNK files masquerading as PDFs
→ Trojanized Zoom installer
→ Payload VelvetCake pulls its capability from C2, runs it, exfils the output, deletes itself
Full report and IoCs in comments.
#ThreatIntel#DPRK#CyberEspionage