QKS Group announced today that it has named SOCRadar as a leader in theSPARK Matrix™: Digital Threat Intelligence Management, 2026.
QKS Group defines Digital Threat Intelligence Management as technology that offers unified insight into external threats to organizational digital-facing assets. The technology aggregates and processes threat intelligence from multiple sources and provides comprehensive information about threat actors to enable improved investigation, threat hunting, and cyber defense.
SOCRadar differentiates itself within the DTIM landscape through a comprehensive, intelligence-driven platform that unifies digital risk protection, threat intelligence, and external attack surface management under a single operational framework. Its ability to correlate threat actor activity, brand exposure, dark web intelligence, and asset-level vulnerabilities provides organizations with enriched, contextual visibility beyond traditional threat monitoring. By integrating automation, analyst-ready insights, and continuous monitoring across deep and dark web, social media, and open sources, the platform enables faster threat prioritization and response. Supported by a globally scalable delivery model and localized intelligence coverage, SOCRadar allows enterprises to proactively mitigate external threats, strengthen digital resilience, and streamline security operations without increasing tool sprawl or operational complexity.
The QKS Group SPARK Matrix™ includes a detailed analysis of the global market dynamics, major trends, vendor landscape, and competitive positioning. The study also provides a competitive analysis and ranking of the Digital Threat Intelligence Management, 2025 providers in the form of the SPARK Matrix™. The study also provides strategic information for users to evaluate different vendor capabilities, competitive differentiation, and market positions.
Additional Resources:
- For more information about SOCRadar, visit Here.
- SPARK Matrix™ Digital Threat Intelligence Management, 2026
FortiGate Post-Exploitation RAT, PivotC2 Spotted by SOCRadar
Posted in Commentary with tags SOC Radar on September 8, 2026 by itnerdThe SOCRadar Threat Research Unit (STRU) identified, with high confidence, exploitation of CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager cw_acd daemon. Successful exploitation delivers PivotC2, a Node.js RAT designed specifically as a FortiGate post-exploitation tool. PivotC2 supports features such as interactive shells, tunneling, network scanning, and configuration harvesting.
Based on the observed inline comments and usage guidance, the actors highly likely leveraged AI to develop the RAT. Active exploitation has been observed since at least July 2026 and is still ongoing. The threat actors targeted more than 30,000 IP addresses, leading to the exploitation and infection of 178 devices with PivotC2.
For full details, the analysis of this post-exploitation RAT can be read here: https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/
Leave a comment »