What Happens to MSSPs and MDRs in the Age of the AI-SOC?

AI-SOC platforms automate triage, correlation, and enrichment to handle large alert volumes, enabling machine-speed operations and a sustainable hybrid SOC with human oversight. The article argues for a co-managed transition where AI handles scale and speed while humans provide context, accountability, and ROI-focused paths for MSSPs and MDRs. #RadiantSecurity #AI_SOC #MSSP #MDR #PagerDuty

Read More
Ransom! trailridgeenergy

The threat actor Lynx claims to have compromised Trail Ridge Energy Partners II LLC, a Texas-based oil and gas exploration company, by infiltrating their systems amid the ongoing development of the Permian Basin’s resource-rich formations. This cyberattack potentially exposes sensitive operational data and threatens the company’s critical infrastructure, impacting the US.

Read More
China claims it caught US attempting cyberattack on national time center

Chinese authorities accused the NSA of attempting to hack the National Time Service Center in China, accusing it of cyber espionage and sabotage efforts. The U.S. government did not confirm these allegations, and the incident highlights ongoing tensions over cyber activities between China and the U.S. #NSA #NTSC #ChineseCyberOps #CyberEspionage…

Read More
China Alleges NSA Cyberattack on National Time Service Center

China claims to have undeniable evidence that the NSA conducted a two-year cyberattack against China’s NTSC, involving sophisticated weapons and exploiting SMS vulnerabilities. The MSS also accuses the U.S. of extensive cyber espionage targeting multiple regions and dismisses American allegations of Chinese cyber threats. #NSA #NTSC #Cyberattack #TimeService #U.S.Embassy…

Read More
Microsoft: Russia, China Increasingly Using AI to Escalate Cyberattacks on the US

Foreign nations including Russia, China, Iran, and North Korea are ramping up their use of artificial intelligence to carry out cyberattacks and create deceptive content targeting the United States. Microsoft’s recent report highlights over 200 instances of AI-driven disinformation and cyber espionage by adversaries in just one month, demonstrating a significant…

Read More
Flax Typhoon Exploiting ArcGIS Server

A China-backed APT group, assessed as likely Flax Typhoon, maintained year-long access to a self-hosted ArcGIS server by converting a legitimate Java Server Object Extension (SOE) into a gated web shell and embedding it in backups to survive recovery. The attackers also deployed a renamed SoftEther VPN executable as a persistent service to create a VPN bridge for lateral movement and C2, enabling credential harvesting and internal scanning. #FlaxTyphoon #ArcGIS #SoftEtherVPN

Read More
China-Backed Flax Typhoon APT Maintained Year-Long Access by Turning ArcGIS SOE into Web Shell Backdoor

A recent report from ReliaQuest details how the China-backed APT group “Flax Typhoon” exploited legitimate enterprise software, specifically ArcGIS, to maintain covert long-term access. This sophisticated attack involved repurposing trusted software components into backdoors, evading detection and complicating defense efforts. #FlaxTyphoon #ArcGIS #SupplyChainAttack…

Read More
CISA warns of ‘significant’ threat to federal networks after nation-state hackers stole F5 source code, undisclosed bug info

The U.S. federal government has issued an emergency directive for all agencies to update F5 products following a sophisticated nation-state cyberattack that compromised source code and vulnerabilities. This incident highlights the ongoing threat of nation-state actors exploiting vulnerabilities in critical infrastructure components like F5 BIG-IP devices. #F5 #BIGIPAttack…

Read More
An Insider Look At The IRGC-linked APT35 Operations: Ep3 – Malware Arsenal & Tooling

APT35 (Charming Kitten) maintained a professional malware development pipeline producing two RAT families (Saqeb System and RAT-2AC2), custom webshells (m0s.asp variants), support tools, and QA/testing materials used to target 300+ entities across the Middle East from 2022–2025. The collection shows advanced anti-detection, modular architectures, multi-hop C2 (including TOR), and explicit operational playbooks for persistence, credential theft, VNC access, and ransomware staging. #Saqeb_System #RAT-2AC2

Read More