Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Cordyceps CI/CD Flaws: Detecting GitHub Workflow Hijacking and Supply-Chain Attacks
Introduction Security Arsenal is tracking a critical class of vulnerabilities codenamed "Cordyceps," recently disclosed by Novee Security. T...
Lazarus Supply Chain & Cloud Atlas APT: OTX Pulse Analysis — Multi-Vector Malware Detection Pack
Threat Summary Recent OTX Pulse intelligence indicates a surge in sophisticated, multi-vector threat activity spanning state-sponsored opera...
Okendo Supply Chain & SocGholish Fake Updates: OTX Pulse Analysis — Enterprise Detection Pack
Threat Summary Recent OTX pulses highlight a convergence of supply chain compromises and persistent credential-harvesting operations. The Sm...
GitHub Actions Pwn Request Attack: Detecting and Blocking Malicious pull_request_target Exploitation
GitHub Actions Pwn Request Attack: Detecting and Blocking Malicious pullrequesttarget Exploitation Introduction GitHub has released a critic...
Supply Chain Attack: Detecting Klue OAuth Token Abuse and Salesforce Compromise
Introduction A significant supply chain attack has surfaced involving Klue, a business intelligence platform, which was breached to leverage...
AI Agent Supply Chain Compromise: Detection Strategies for Malicious Skills
AI Agent Supply Chain Compromise: Detection Strategies for Malicious Skills Introduction In a stark demonstration of the fragility of the bu...
Miasma Campaign: Detecting npm Supply Chain Attacks Bypassing SLSA Level 3
Introduction The Miasma campaign marks a disturbing evolution in open-source supply chain warfare. By leveraging a stolen session cookie tha...
SocGholish Disruption & Okendo Supply Chain: C2 Network Analysis — Enterprise Detection Pack
Threat Summary The latest OTX pulse data reveals a concerning convergence of supply chain compromises and web infrastructure exploitation. W...
Operation Endgame & SmartApeSG: SocGholish Takedown, Okendo Supply Chain Attack, and FortiBleed Credential Harvesting — Intel Brief
Threat Summary This briefing synthesizes five OTX pulses highlighting a turbulent week for credential theft infrastructure. While "Operation...