SOC Threat Radar - August 2026
Barracuda Networks, Wednesday, August 26th, 2026
Barracuda's SOC reports GlobalProtect scanning, credential harvesting, firewall misconfigurations and abuse of remote access tools.
Barracuda Research summarizes findings from incidents its Managed XDR service mitigated over the past month.
A recurring theme is attackers exploiting trusted and legitimate software rather than deploying obvious malware, which keeps activity below the threshold of tools looking for known-bad binaries. Specific observations include scanning for vulnerable GlobalProtect deployments, credential harvesting campaigns, and risk arising from misconfigured firewalls that expose more than intended.
The report also covers abuse of trusted remote access software, where attackers use legitimate administration tooling already permitted in the environment to move and persist.