Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Flying Eagle RAT, Shai-Hulud NPM Worm & ClickFix: Cross-Vector Credential Theft Campaigns — Detection Pack
Threat Summary Recent OTX pulses reveal a coordinated surge in credential theft operations spanning mobile ecosystems, software supply chain...
SleeperGem & AgentBaiting: Defending Against Supply Chain and AI Ecosystem Compromise
Introduction The July 2026 threat landscape has shifted decisively toward the poisoning of the development and AI ecosystems. The latest Sec...
openSUSE Trivy v0.72.0 Update: Critical Security Fix for Vulnerability Scanner
openSUSE Trivy v0.72.0 Update: Critical Security Fix for Vulnerability Scanner Introduction Security Arsenal is tracking the release of open...
Fake Corepack Supply Chain Attack: OpenShield & Apprunner Distribution
Fake Corepack Supply Chain Attack: OpenShield & Apprunner Distribution Excerpt: Fake Corepack site targeting developers with OpenShield info...
GitHub Dependabot Cooldown: Defending Against Supply Chain Poisoning
Introduction In the relentless arms race of 2026, supply chain attacks remain the most potent vector for initial access. Attackers have incr...
AI Supply Chain Compromise: Defending Against Rogue Autonomous Agents
The paradigm of software vulnerability has shifted. We are no longer simply patching buffer overflows; we are now grappling with autonomous ...
Supply Chain Hardening: GitHub and PyPI Time-Based Defenses
Supply Chain Hardening: GitHub and PyPI Time-Based Defenses Introduction GitHub and the Python Package Index (PyPI) have announced a signifi...
Defending Against HalluSquatting and Slopsquatting: Securing AI Pipelines from Late-Binding Attacks
Defending Against HalluSquatting and Slopsquatting: Securing AI Pipelines from Late-Binding Attacks Introduction The integration of AI codin...
GitHub Actions Abuse & Supply Chain OAuth Theft: cPanel Exploit & CRM Data Breach
Threat Summary Recent OTX pulses indicate a surge in supply chain attacks targeting both infrastructure and SaaS platforms. An unknown threa...