<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[CyberSOC Labs]]></title><description><![CDATA[CyberSOC Labs]]></description><link>https://www.cybersoclabs.com/blog</link><generator>RSS for Node</generator><lastBuildDate>Thu, 27 Aug 2026 17:57:26 GMT</lastBuildDate><atom:link href="https://www.cybersoclabs.com/blog-feed.xml" rel="self" type="application/rss+xml"/><item><title><![CDATA[India’s DPDP Act: What Organizations Need to Know in 2026]]></title><description><![CDATA[India’s Digital Personal Data Protection Act (DPDP Act), enacted in August 2023, is now moving from paperwork into active enforcement. With the implementing Rules notified in late 2025, 2026 is the year organizations processing Indian users’ data need to move from “we’re aware of this law” to “we’re actually compliant.” Here’s where things stand. Where the law is right now The DPDP framework is rolling out in three phases, and it’s important to know which one applies to you: Phase 1 —...]]></description><link>https://www.cybersoclabs.com/post/india-s-dpdp-act-what-organizations-need-to-know-in-2026</link><guid isPermaLink="false">6a7df836cae5bb2ffa102aed</guid><pubDate>Thu, 13 Aug 2026 17:06:16 GMT</pubDate><dc:creator>Syed Adnaan</dc:creator></item><item><title><![CDATA[Two Attackers, One Cancer Diagnostics Business: The Abbott Breach Explained]]></title><description><![CDATA[On July 16, 2026, healthcare giant Abbott Laboratories confirmed it was investigating unauthorized access to legacy systems belonging to Exact Sciences — the cancer-diagnostics company behind Cologuard, which Abbott acquired for $20.6 billion in March 2026, just twelve weeks before the intrusion began. How attackers got in Abbott traced the breach to a vishing (voice phishing) attack against Abbott and Exact Sciences employees in mid-June 2026. In a now-familiar pattern, ShinyHunters gang...]]></description><link>https://www.cybersoclabs.com/post/two-attackers-one-cancer-diagnostics-business-the-abbott-breach-explained</link><guid isPermaLink="false">6a7df1f7aaa4bd07042492ec</guid><pubDate>Thu, 13 Aug 2026 16:36:11 GMT</pubDate><dc:creator>Syed Adnaan</dc:creator></item><item><title><![CDATA[A Phone Call, an Analytics Platform, and 10 Million Dating App Records]]></title><description><![CDATA[On January 27–28, 2026, the extortion group ShinyHunters posted a claim to its dark web leak site: over 10 million records stolen from Match Group, the company behind Hinge, OkCupid, and Match.com — along with a 1.7GB sample archive to back it up. The attack chain Public reporting reconstructs the intrusion as follows: A vishing call targeted a Match Group employee with Okta single sign-on access. The employee’s credentials and MFA approval were compromised. The attacker authenticated into...]]></description><link>https://www.cybersoclabs.com/post/a-phone-call-an-analytics-platform-and-10-million-dating-app-records</link><guid isPermaLink="false">6a7df111aaa4bd0704249124</guid><pubDate>Thu, 13 Aug 2026 16:32:33 GMT</pubDate><dc:creator>Syed Adnaan</dc:creator></item><item><title><![CDATA[When the Identity Protection Company Gets Breached: The Aura Vishing Incident]]></title><description><![CDATA[There’s a particular irony reserved for security companies that become the breach headline. In March 2026, Aura, a Burlington, Massachusetts-based identity theft protection and credit monitoring company, confirmed that an attacker had accessed approximately 900,000 records — and the entry point wasn’t malware or a software flaw. It was a phone call. How the attack worked An Aura employee received a targeted voice phishing (vishing) call. The attacker impersonated a trusted party convincingly...]]></description><link>https://www.cybersoclabs.com/post/when-the-identity-protection-company-gets-breached-the-aura-vishing-incident</link><guid isPermaLink="false">6a7df03daaa4bd0704248f5b</guid><pubDate>Thu, 13 Aug 2026 16:29:09 GMT</pubDate><dc:creator>Syed Adnaan</dc:creator></item><item><title><![CDATA[Foxconn Hit Again: Inside the Nitrogen Ransomware Attack That Touched Apple, Nvidia, and Intel]]></title><description><![CDATA[On May 11, 2026, a ransomware group called Nitrogen posted an entry on its dark web leak site, NitroBlog, naming a familiar target: Foxconn, the world’s largest contract electronics manufacturer. The group claimed to have stolen 8 terabytes of data across more than 11 million files. Foxconn confirmed the intrusion the next day. What was hit The attack disrupted several of Foxconn’s North American facilities, including sites in Mount Pleasant, Wisconsin and Houston, Texas. Workers were told to...]]></description><link>https://www.cybersoclabs.com/post/foxconn-hit-again-inside-the-nitrogen-ransomware-attack-that-touched-apple-nvidia-and-intel</link><guid isPermaLink="false">6a7deeb3cae5bb2ffa10171b</guid><pubDate>Thu, 13 Aug 2026 16:23:47 GMT</pubDate><dc:creator>Syed Adnaan</dc:creator></item><item><title><![CDATA[The Canvas Breach: How 275 Million Records Went Up for Ransom in Two Weeks]]></title><description><![CDATA[In late April 2026, students and teachers logging into Canvas — the learning management system used by roughly 41% of U.S. higher education institutions and around 30 million active users worldwide had no idea they were about to become part of the largest education-sector breach on record. What happened Canvas is operated by Instructure, a private edtech company whose software runs coursework, grading, and messaging for over 8,000 schools, universities, and ministries of education globally....]]></description><link>https://www.cybersoclabs.com/post/the-canvas-breach-how-275-million-records-went-up-for-ransom-in-two-weeks</link><guid isPermaLink="false">6a7ded451edc2c80bd34844c</guid><pubDate>Thu, 13 Aug 2026 16:18:22 GMT</pubDate><dc:creator>Syed Adnaan</dc:creator></item><item><title><![CDATA[Cybersecurity Best Practices: Vendor Risk, Technical Hygiene, and Resilience]]></title><description><![CDATA[A practical guide to the “four open doors” behind almost every major 2026 breach: unpatched systems, trusted vendors, exposed databases, and weak recovery planning Why this focus Security researchers reviewing 2026’s breach reports found a consistent story: not one major incident required a nation-state-grade zero-day. Attackers walked through doors that were already open — an unpatched flaw, a compromised vendor, an exposed database, or a ransomware payment that didn’t even guarantee...]]></description><link>https://www.cybersoclabs.com/post/cybersecurity-best-practices-vendor-risk-technical-hygiene-and-resilience</link><guid isPermaLink="false">6a7deb9f2d04e90cb22838d2</guid><pubDate>Thu, 13 Aug 2026 16:10:30 GMT</pubDate><dc:creator>Syed Adnaan</dc:creator></item><item><title><![CDATA[Cybersecurity Best Practices: Defending Identity, Access, and People]]></title><description><![CDATA[A practical guide for reducing the risk of the attack pattern behind most 2026 breaches Why this focus Looking across this year’s major breaches — Aura, Match Group, Abbott/Exact Sciences, Canvas — a single pattern shows up again and again: attackers didn’t need a zero-day exploit. They needed one employee, one phone call, and one set of single sign-on (SSO) credentials. This document covers the practices that directly address that pattern. 1. Move beyond phishable MFA Adopt...]]></description><link>https://www.cybersoclabs.com/post/cybersecurity-best-practices-defending-identity-access-and-people</link><guid isPermaLink="false">6a7de6d89eafd9eb8e5a02db</guid><pubDate>Thu, 13 Aug 2026 15:54:22 GMT</pubDate><dc:creator>Syed Adnaan</dc:creator></item></channel></rss>