Cybersecurity intelligence for defenders

Practical cyber defense for modern security teams.

CyberOpsHub is a professional cybersecurity knowledge hub focused on SOC operations, SIEM engineering, threat intelligence, vulnerability management, incident response, and practical security guidance.

Built for hands-on defenders.

Clear operational content for people who secure networks, investigate alerts, manage cyber risk, and build detection capabilities.

πŸ›‘οΈ

SOC & Incident Response

Alert triage, investigation workflows, phishing response, endpoint analysis, and incident handling procedures.

πŸ“‘

SIEM & Detection Engineering

Practical guides for Wazuh, log parsing, custom rules, dashboards, detection logic, and security monitoring.

🧬

Threat Intelligence

IOC handling, MISP workflows, enrichment, feed validation, and how to turn intelligence into actionable defense.

Latest articles.

Newest cyber news, technical explainers, and practical how-to guides.

Cyber News

New DOUBLECUP ClickFix service hides malware in browser cache images

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. [...]

Read Full Article
Cyber News

Fake Roblox Xeno script launcher pushes infostealer, RAT malware

Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...]

Read Full Article
Cyber News

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package

Read Full Article
Cyber News

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Malware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim's screen. Unit 42 detailed three attack paths against Chrome's Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets the master key

Read Full Article
Cyber News

⚑ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from

Read Full Article
Cyber News

Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)

Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 1) appeared first on SecurityWeek.

Read Full Article
Cyber News

Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion

The payments giant says BioCatch’s behavioral and device intelligence will help financial institutions combat account takeovers, scams and other forms of digital fraud. The post Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion appeared first on SecurityWeek.

Read Full Article
Cyber News

Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm

Researchers from Jesta intercepted and investigated the model, which was attempting to compromise more than 1,200 hosts for proxyjacking and to launch further attacks

Read Full Article
Cyber News

CVE-2026-13072: MongoDB Compute Mode DoS Vulnerability

CVE-2026-13072 is a denial of service vulnerability in MongoDB compute mode. Learn about its impact, affected versions, and mitigation methods.

Read Full Article
Cyber News

VMware fixes three critical flaws allowing auth bypass, VM escapes

Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. [...]

Read Full Article
Cyber News

Google says AI helped Chrome fix 1,072 security bugs in two releases

Google says artificial intelligence is dramatically increasing the number of security vulnerabilities it can find and fix in Chrome, with more than 1,000 security bugs patched across the browser's two most recent releases as it expands its use of AI. [...]

Read Full Article
Cyber News

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...]

Read Full Article
View All Articles β†’

Resources.

Downloadable checklists, templates, scripts, and technical guides.

βœ…

SOC Checklists

Phishing investigation, brute-force analysis, malware alert triage, and suspicious login review.

Open Resource

βš™οΈ

Security Scripts

PowerShell, Python, Bash, and API examples for common security operations tasks.

Open Resource

πŸ“„

Policy Templates

Vendor security, acceptable use, access management, AI usage, and incident response documents.

Open Resource

πŸ”’

Ransomware Incident Response Playbook

A complete phase-by-phase response playbook for ransomware incidents β€” from detection and containment through recovery and post-incident review.

Open Resource

🎣

Phishing Incident Response Playbook

Step-by-step response for phishing reports β€” triage, containment, investigation, and recovery including credential compromise handling.

Open Resource

⚠️

Data Breach Incident Response Playbook

Structured response for confirmed or suspected data breaches, including legal and regulatory notification guidance for GDPR, HIPAA, and CCPA.

Open Resource

πŸ”

SOC Alert Triage Playbook

The standard SOC process for triaging security alerts β€” 5-step methodology, disposition framework, severity scoring, and SLA targets for L1/L2 analysts.

Open Resource

🎯

Threat Hunting Playbook β€” SOC Edition

A practical threat hunting playbook covering hypothesis building, data sources, SIEM query examples, MITRE ATT&CK hunt hypotheses, and documentation templates.

Open Resource

βœ…

Endpoint Analysis & Incident Handling Procedures for IOC IP Connection Detection

This playbook provides operational guidance for detecting, triaging, investigating, containing, and remediating endpoint communications involving known malicious or suspicious IP addresses (Indicators of Compromise β€” IOC IPs).

Open Resource

Make CyberOpsHub your cyber knowledge platform.

Publish practical cybersecurity articles, create downloadable resources, and build trust with readers looking for clear, professional security guidance.

Contact CyberOpsHub