Archive for August 4, 2026

SOCRadar Launches Human Identity Exposure for its Extended Threat Intelligence Platform

Posted in Commentary with tags on August 4, 2026 by itnerd

At Black Hat 2026 today, SOCRadar, a global leader in extended threat intelligence and cybersecurity, announced the launch of SOCRadar Human Identity Exposure, a new Identity & Access layer for its Extended Threat Intelligence (XTI) platform.

SOCRadar Human Identity Exposure unifies fragmented identity exposure data, including breach repositories, stealer infections, attacker telemetry, PII, data leaks, and CTI signals into a single, decision-ready record. By providing investigative analysts with a unified operational surface, it accelerates identity risk prioritization and eliminates hours of manual data correlation. Because these records are built entirely from external, attacker-held data ingested directly by the platform, there is zero integration required from HR or IAM systems. 

By tapping into the full depth and breadth of the XTI platform, SOCRadar Human Identity Exposure gives analysts an instant, comprehensive snapshot of an individual’s identity risk. Complete with automated risk scoring, critical exposure insights, and actionable pivot points, this new identity and access layer operationalizes disparate data points for swift investigation and decision-making.

Identity is now the primary path into an enterprise network, not a secondary one. Verizon’s 2025 Data Breach Investigations Report found compromised credentials were the initial vector in 22% of confirmed breaches — the leading vector for the second straight year — and The SANS Institute reported that 90% of organizations experienced at least one identity-related incident in the past year. IBM prices the average compromised-credential breach at $4.67M, with a 246-day mean time to identify and contain.

Human Identity Exposure Card

SOCRadar Human Identity Exposure includes a Human Identity Exposure Card that offers a consolidated investigative profile of an individual’s identity, inferred directly from collected breach incident data, exposed PII records, and infostealer logs, including:

  • Unified Risk Scoring: An in-platform scoring grade metric that quantifies identity risk analysis from across multiple datasets and criteria such as credential breaches and exposures, high sensitivity PII, critical data categories, PII leak records, and whether an individual’s identity shows up across various sources (e.g. leaks, breaches, infostealers).
  • Unified Personal Data Records: This widget allows analysts to see an individual’s level of public exposure by aggregating a variety of unique personal data types from across multiple PII exposure records and making them available in one central location.
  • Breach Timeline: Analysts can easily track every exposure signal, stealer hit, and external attacker telemetry record tied to an identity in a single timeline view. 
  • People Graph: This interactive visual widget provides analysts with the ‘exposure surface’ tied to an individual’s email via a graph that displays the most critical points of exposure along various attack paths.
  • Modeled Attack Scenarios: The platform automatically models potential attack scenarios (e.g. credential stuffing, stealer account takeover, sim swap, business email compromise, etc.) based on exposed data and attack telemetry with the specific attack path, confidence scoring for likelihood of attack, and defensive blocks for attack prevention.
  • Identity Location Map: Analysts can see the estimated geo-location on a map derived from breach metadata.
  • Linked Accounts: The platform surfaces all social media accounts tied to an individual’s identity record.

Additionally, analysts can leverage the platform’s Compromised Data Exposure Report, a one-click reporting feature that instantly generates identity leak incident reports for rapid sharing with stakeholders and more precise incident tracking. These reports illuminate exposed PII, password hashes, and login credentials, while providing automated risk scoring, assessments, and step-by-step remediation guidance.

Silent Push Enables Cybersecurity Companies to Build Proactive Security Products with First-Party Infrastructure Intelligence

Posted in Commentary with tags on August 4, 2026 by itnerd

Silent Push today announced expanded access to its proprietary first-party infrastructure intelligence platform, enabling cybersecurity companies to integrate the same data that powers Silent Push’s own threat detection and research capabilities directly into their products and workflows.

Unlike traditional threat intelligence that relies on indicators of compromise (IOCs) after an attack has occurred, Silent Push provides first-party infrastructure intelligence and Indicators of Future Attack® (IOFA) that identify adversary infrastructure while it is still being built, an average of 104 days before it is weaponized. This enables cybersecurity vendors to deliver earlier detection, richer context, and more proactive protection for their customers.

The offering is designed for both cybersecurity product and research teams and cyber threat intelligence (CTI) organizations seeking to enhance detection capabilities, accelerate research, and differentiate their offerings through exclusive infrastructure intelligence.

Key capabilities include:

  • First-party infrastructure intelligence unavailable through third-party data feeds or recycled threat intelligence.
  • Preemptive IOFA that identify malicious infrastructure months before attacks are launched.
  • API-first integration for enrichment, scoring, infrastructure context, bulk lookups, and automated security workflows.
  • MCP Server integration for AI-native and agentic security environments.
  • Historical DNS and WHOIS intelligence, behavioral fingerprinting, and Traffic Origin data to accelerate threat research and campaign analysis.
  • Custom intelligence feeds tailored to specific threat categories, geographies, or infrastructure patterns.

Supporting a Broad Range of Security Use Cases

Silent Push APIs enable security vendors and technology partners to build next-generation detection and investigation capabilities into their products, enrich existing threat intelligence platforms with continuously updated infrastructure data, and power published threat research with deterministic, first-party intelligence. The platform also accelerates AI-assisted security operations and threat hunting while helping organizations identify lookalike domains, malicious infrastructure, and adversary activity before attacks occur, enabling a more proactive approach to cyber defense.

Silent Push offers flexible deployment options including direct Data API access, MCP Server integration for AI workflows, full platform access for research teams, and customized intelligence feeds.  The company already provides proprietary intelligence to cybersecurity organizations that use Silent Push data to enrich their products and power customer-facing threat intelligence offerings.

For more information about Silent Push’s cybersecurity company offering, visit http://www.silentpush.com or contact sales@silentpush.com.

EU age-verification app hacked twice in three months

Posted in Commentary with tags on August 4, 2026 by itnerd

In April of this year, security researcher Paul Moore showed he could hack the European Commission’s age-verification reference app in “under 2 minutes.”

Now, three months later he notes: “Despite 3 months of security hardening and genuine improvements across the board, the fundamental issue cannot be solved.” 

Moore has demonstrated two distinct bypasses of this newer version of the app. It could be bypassed using both a modified client and an automated relay to a legitimate remote device. Moore documented the modified-client bypass and the subsequent relay demonstration on X.

Ted Miracco, CEO, Approov had this to say:

“The security industry is largely built on the assumption that the user and the app owner are on the same side and the attacker is a third party. Age verification inverts this assumption, as the user becomes the adversary. Almost none of our collective defensive playbook was designed for a world where the person you’re protecting is the person trying to get around you. Pretending otherwise is how you end up calling a relay attack unfixable instead of just predictable.

“Half of what Moore demonstrated is solvable. A cloned app with the ID checks ripped out should never have reached a verification endpoint, as this is a solved problem. The spec mandates hardware-backed keys but puts app attestation explicitly out of scope. They protected the credential but left the client unverified. The other half, relaying the QR code to an adult’s real device, is not solvable by any attestation technology, ours included.”

The EU really needs to solve this issue and look at other items just like it. Otherwise it will end badly for them.