Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Head Mare PhantomCore via TrueConf Supply-Chain Compromise + STARDUST CHOLLIMA Rust Crate Backdoor: OTX Pulse Analysis — Enterprise Detection Pack
Head Mare PhantomCore + STARDUST CHOLLIMA Rust Supply-Chain Backdoor: Enterprise Detection Pack Two fresh AlienVault OTX pulses (modified 20...
SynkLoader, BRIDGEHEAD & N4D Mesh: Cross-Platform Credential Theft Wave — OTX Pulse Analysis & Enterprise Detection Pack
SynkLoader, BRIDGEHEAD & N4D Mesh: Cross-Platform Credential Theft Wave — OTX Pulse Analysis & Enterprise Detection Pack Threat Summary Five...
Offside Wallet Theft Factory: 40 Malicious Firefox Extensions Stealing Crypto Wallet Seeds — Detection and Removal Guide
Executive Summary The Socket Threat Research team has exposed a coordinated browser-extension malware campaign dubbed Offside Wallet Theft F...
arrayref Rust Crate Poisoned to Deliver Infostealer: Supply Chain Detection and Remediation Guide
Introduction A maintainer account behind the widely used arrayref Rust crate was compromised, and attackers used that access to publish pois...
Rust Crates.io Supply Chain Attack: Malicious arrayref, internment & append-only-vec Builds Execute Remote Payloads — Detection and Remediation Guide
Rust Crates.io Supply Chain Attack: Malicious arrayref, internment & append-only-vec Builds Execute Remote Payloads — Detection and Remediat...
HelloNet APT Campaign: ViPNet Supply Chain Compromise Deploys HelloInjector/HelloBackdoor Against Russian Critical Infrastructure — OTX Detection Pack
Threat Summary AlienVault OTX pulse data confirms an active, previously undocumented APT campaign — tracked as HelloNet — that has been expl...
GoSerpent RAT + HelloNet ViPNet Supply-Chain Campaign: OTX Pulse Analysis — State-Sponsored Intrusion Detection Pack
GoSerpent RAT + HelloNet ViPNet Supply-Chain Campaign: OTX Pulse Analysis Threat Summary Two concurrent OTX pulses published 2026-08-15 reve...
Trivy Supply-Chain Compromise: How a Poisoned GitHub Action Exposed 2,500 Organizations — Detection and Remediation Guide
The Real Patient Zero: Trivy, Not LiteLLM When the LiteLLM supply-chain attack broke, the initial narrative pointed at poisoned PyPI package...
PATCHCORD, SHEETCORD & Evooo1Bot: Google Sheets C2 Espionage + Linux Botnet Credential Theft — OTX Detection Pack
Threat Summary This week's AlienVault OTX feed surfaces four distinct but operationally converging threat streams, all orbiting a common obj...