Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
New XCSSET macOS Variant: Defending Against Compromised Xcode Projects
Introduction Security Arsenal is actively tracking a significant resurgence of the XCSSET malware, specifically engineered to target macOS d...
Keyv npm Worm: Detection & Remediation for Supply Chain IDE Hooks
Introduction On August 4, 2026, the JavaScript ecosystem faced a significant supply chain disruption involving a malicious worm linked to th...
ChainDrop npm Supply-Chain Attack: Detection, IOCs, and Remediation Strategies
Introduction The npm ecosystem is currently facing a significant security event with the emergence of 'ChainDrop,' a self-propagating malwar...
Atomic MacOS (AMOS) Stealer: Detection and Incident Response Playbook
Atomic MacOS (AMOS) Stealer: Detection and Incident Response Playbook Introduction The SANS Internet Storm Center (ISC) has raised the flag ...
Arch Linux AUR Malicious Package Campaign: Supply Chain Defense
Introduction The Arch Linux team has taken the emergency step of temporarily disabling the "adoption" feature within the Arch User Repositor...
AI-Assisted Social Engineering: Detecting WebDAV Delivery and Infostealer Campaigns
AI-Assisted Social Engineering: Detecting WebDAV Delivery and Infostealer Campaigns Introduction The discovery of an exposed command-and-con...
GoSerpent Malware: Detection and Defense Strategies for Southeast Asian Diplomacy
Introduction In February 2026, Kaspersky researchers uncovered a sophisticated espionage campaign targeting government and diplomatic entiti...
AsyncAPI npm Supply Chain Attack: Detection and Remediation for Credential-Stealing RAT
AsyncAPI npm Supply Chain Attack: Detection and Remediation for Credential-Stealing RAT Introduction A critical supply-chain compromise has ...
AsyncAPI npm Supply Chain Attack: Multi-Stage Loader Detection and Removal
AsyncAPI npm Supply Chain Attack: Multi-Stage Loader Detection and Removal Introduction In July 2026, the JavaScript ecosystem faced a signi...