Cybersecurity intelligence for defenders

Practical cyber defense for modern security teams.

CyberOpsHub is a professional cybersecurity knowledge hub focused on SOC operations, SIEM engineering, threat intelligence, vulnerability management, incident response, and practical security guidance.

Built for hands-on defenders.

Clear operational content for people who secure networks, investigate alerts, manage cyber risk, and build detection capabilities.

πŸ›‘οΈ

SOC & Incident Response

Alert triage, investigation workflows, phishing response, endpoint analysis, and incident handling procedures.

πŸ“‘

SIEM & Detection Engineering

Practical guides for Wazuh, log parsing, custom rules, dashboards, detection logic, and security monitoring.

🧬

Threat Intelligence

IOC handling, MISP workflows, enrichment, feed validation, and how to turn intelligence into actionable defense.

Latest articles.

Newest cyber news, technical explainers, and practical how-to guides.

Threat Intelligence

FBI Warns Kali365 PhaaS Platform Bypasses Microsoft 365 MFA Through OAuth Token Theft

According to the FBI advisory, Kali365 enables threat actors to bypass multi-factor authentication (MFA) protections without directly stealing user passwords. Instead, attackers abuse legitimate Microsoft authentication workflows to trick victims into authorizing attacker-controlled sessions.

Read Full Article
Threat Intelligence

Iranian Hackers Deploy MiniFast and MiniJunk V2 in Expanding Espionage Campaigns Using AI and SEO Poisoning

An Iranian state-sponsored cyber espionage group known as Nimbus Manticore has been linked to a new wave of highly targeted intrusion campaigns leveraging AI-assisted malware development, SEO poisoning, phishing operations, and trojanized enterprise software installers.

Read Full Article
Vulnerability Management

Ghost CMS SQL Injection Flaw Exploited in Large-Scale ClickFix Campaign

The vulnerability, tracked as CVE-2026-26980, affects Ghost CMS versions 3.24.0 through 6.19.0 and enables unauthenticated attackers to extract sensitive database content, including administrative API keys.

Read Full Article
Cyber News

Remote Sunrise Helper for Windows 2026.14 - Remote Code Execution

Remote Sunrise Helper for Windows 2026.14 - Remote Code Execution.. local exploit for Windows platform

Read Full Article
Vulnerability Management

Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions

Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be met. The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of 8.8. It has been assigned an important severity.

Read Full Article
Cyber News

Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service

Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service. CVE-2026-23918 . webapps exploit for Multiple platform

Read Full Article
View All Articles β†’

Resources.

Downloadable checklists, templates, scripts, and technical guides.

βœ…

SOC Checklists

Phishing investigation, brute-force analysis, malware alert triage, and suspicious login review.

Open Resource

βš™οΈ

Security Scripts

PowerShell, Python, Bash, and API examples for common security operations tasks.

Open Resource

πŸ“„

Policy Templates

Vendor security, acceptable use, access management, AI usage, and incident response documents.

Open Resource

πŸ”’

Ransomware Incident Response Playbook

A complete phase-by-phase response playbook for ransomware incidents β€” from detection and containment through recovery and post-incident review.

Open Resource

🎣

Phishing Incident Response Playbook

Step-by-step response for phishing reports β€” triage, containment, investigation, and recovery including credential compromise handling.

Open Resource

⚠️

Data Breach Incident Response Playbook

Structured response for confirmed or suspected data breaches, including legal and regulatory notification guidance for GDPR, HIPAA, and CCPA.

Open Resource

πŸ”

SOC Alert Triage Playbook

The standard SOC process for triaging security alerts β€” 5-step methodology, disposition framework, severity scoring, and SLA targets for L1/L2 analysts.

Open Resource

🎯

Threat Hunting Playbook β€” SOC Edition

A practical threat hunting playbook covering hypothesis building, data sources, SIEM query examples, MITRE ATT&CK hunt hypotheses, and documentation templates.

Open Resource

βœ…

Endpoint Analysis & Incident Handling Procedures for IOC IP Connection Detection

This playbook provides operational guidance for detecting, triaging, investigating, containing, and remediating endpoint communications involving known malicious or suspicious IP addresses (Indicators of Compromise β€” IOC IPs).

Open Resource

Make CyberOpsHub your cyber knowledge platform.

Publish practical cybersecurity articles, create downloadable resources, and build trust with readers looking for clear, professional security guidance.

Contact CyberOpsHub