Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Brown Health Medical Group Data Breach: Defending Against Large-Scale PHI Exposure
Brown Health Medical Group Data Breach: Defending Against Large-Scale PHI Exposure The recent confirmation of a data breach at Lifespan Phys...
The Frontier AI Vulnerability Burst: Industrializing Autonomous Open-Source Discovery
The Frontier AI Vulnerability Burst: Industrializing Autonomous Open-Source Discovery Introduction We have long operated under the assumptio...
Keyv npm Worm: Detection & Remediation for Supply Chain IDE Hooks
Introduction On August 4, 2026, the JavaScript ecosystem faced a significant supply chain disruption involving a malicious worm linked to th...
ChainDrop npm Supply-Chain Attack: Detection, IOCs, and Remediation Strategies
Introduction The npm ecosystem is currently facing a significant security event with the emergence of 'ChainDrop,' a self-propagating malwar...
Supply Chain Attack: Detecting and Mitigating Hijacked keyv and cacheable npm Packages
Introduction Wiz Research is actively investigating a critical software supply chain attack affecting multiple packages within the keyv and ...
Phorpiex, Mozi, Mirai: Direct-to-IP C2 Tactics — OTX Pulse Analysis
Phorpiex, Mozi, Mirai: Direct-to-IP C2 Tactics — OTX Pulse Analysis Threat Summary Recent intelligence from AlienVault OTX highlights a sign...
Larva-24009 (HeptaX) Phishing Campaign: QuasarRAT & UltraVNC Deployment — Healthcare Sector Threat Analysis
Larva-24009 (HeptaX) Phishing Campaign: QuasarRAT & UltraVNC Deployment — Healthcare Sector Threat Analysis Threat Summary The Larva-24009 t...
Larva-24009 (HeptaX) Phishing: QuasarRAT & UltraVNC via LNK — OTX Pulse Analysis
Threat Summary The Larva-24009 threat actor (also known as HeptaX) is conducting an active phishing campaign targeting the healthcare sector...
Active GHOSTBLADE Campaign: Detecting Leaked DarkSword Kit Exploitation on iOS
Active GHOSTBLADE Campaign: Detecting Leaked DarkSword Kit Exploitation on iOS Introduction Security Arsenal is tracking an active and conce...