Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Gremlin, OtterCookie, and Vidar Surge: Credential Theft via Supply Chain and Edge Exploits
Executive Summary Live OTX pulse data from May 17, 2026, reveals a coordinated escalation in credential theft operations targeting enterpris...
TanStack 'Mini Shai-Hulud' Supply Chain Attack: IOC Analysis and macOS Hardening
Introduction OpenAI recently confirmed that two of its corporate macOS devices were compromised during the TanStack supply chain attack, dub...
Living Off the Pipeline: Detecting Poisoned Pipeline Execution in CI/CD Environments
Living Off the Pipeline: Detecting Poisoned Pipeline Execution in CI/CD Environments Introduction The concept of \"Living off the Land\" (Lo...
Cisco SD-WAN Exploit & Npm Supply Chain Attack: UAT-8616 & Chollima Campaign
Threat Intelligence Briefing: Enterprise Vulnerability & Supply Chain Assault Threat Summary Recent OTX pulse data highlights a convergence ...
SecurityScorecard Driftnet Acquisition — Leveraging Automated Reconnaissance for Supply Chain Resilience
Introduction In the modern threat landscape, your perimeter is no longer defined by your firewall, but by the security posture of every vend...
Supply Chain Attack: Malicious Node-IPC Versions (v9.1.6, v9.2.3, v12.0.1) — Detection and Remediation
Introduction A critical supply chain compromise has been identified within the widely used node-ipc npm package. Security researchers at Soc...
Perry Johnson & Associates Breach: Third-Party Supply Chain Compromise & Exfiltration Detection
Introduction Atrium Health Navicent and Interim HealthCare of Lubbock/Amarillo have begun notifying patients following a significant data br...
TroyDen, Chollima & Mr_Rot13: Multi-Front Supply Chain Assault via GitHub, npm, and cPanel CVE-2026-41940
Threat Summary Recent OTX pulse data reveals a convergence of sophisticated supply chain attacks targeting both developer ecosystems and ser...
RubyGems Supply Chain Attack: Detecting and Mitigating Malicious Package Campaigns
Introduction The RubyGems repository—the foundational infrastructure for the Ruby ecosystem—is currently under a coordinated and significant...