Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Mirage Kitten Campaign: NightLedger Backdoor & ArcBridge Toolset Analysis
Threat Summary A new wave of espionage activity has been detected attributed to the advanced persistent threat (APT) group Mirage Kitten (al...
CastleLoader, NeedleStealer & AI MCP Exploits: Multi-Vector Credential Theft — OTX Pulse Analysis
Threat Summary Recent OTX pulses indicate a convergence of sophisticated infostealer campaigns and emerging exploit vectors targeting AI inf...
SAFEPAY Ransomware: DACH Region Blitz — Retail & Education Sectors Under Siege via Critical VPN Flaws
Threat Actor Profile — SAFEPAY Aliases & Attribution: SAFEPAY is a relatively new but aggressive Ransomware-as-a-Service (RaaS) operation th...
CISA KEV Flash: 8 Critical CVEs Under Active Attack — Fortinet, Check Point & Microsoft Targeted
Active Exploitation Intelligence CISA has added 8 vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog between July 21 and J...
BabaDeda Loader + ClickFix Social Engineering: OTX Pulse Analysis — Enterprise Detection Pack
Threat Summary Based on the OTX pulse data, the BabaDeda loader family represents an evolving malware framework discovered in April 2026 tha...
GENESIS Ransomware Gang: 6 New Victims Posted — Critical Infrastructure & Manufacturing Targeted via Firewall Exploits
Threat Actor Profile — GENESIS Aliases: No significant aliases confirmed; operates strictly under the GENESIS moniker. Operational Model: GE...
Fake Corepack Supply Chain Attack: OpenShield & Apprunner Distribution
Fake Corepack Supply Chain Attack: OpenShield & Apprunner Distribution Excerpt: Fake Corepack site targeting developers with OpenShield info...
CRPXO Ransomware: Cross-Sector Surge & Firewall Exploitation — Detection Engineering Brief
Threat Actor Profile — CRPXO Identity & Operations CRPXO operates as a Ransomware-as-a-Service (RaaS) entity with a high operational tempo. ...
SECTION9 Ransomware: Surge in LATAM & Global Attacks — Check Point & ScreenConnect Exploitation
Executive Summary Security Arsenal Threat Intelligence Team has detected a significant spike in activity by the SECTION9 ransomware group. A...