Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Modernizing Medicine $3M Breach Settlement: Defensive Lessons for Healthcare EHR and SaaS Security
Introduction Modernizing Medicine (ModMed), a Boca Raton, Florida-based provider of cloud-hosted, AI-powered electronic health record (EHR) ...
ShinyHunters Breach at AdaptHealth Exposes 4.1 Million Patients — Detection and Hardening Guide for Healthcare Defenders
Another 4.1 Million Patients Just Became Extortion Leverage AdaptHealth, a major U.S. provider of home medical equipment and healthcare-at-h...
McKesson Data Theft Extortion Attack: Defending Healthcare SaaS and Cloud Data Against ShinyHunters-Style Extortion
McKesson Data Theft Extortion: What Healthcare Defenders Need to Know McKesson, one of the largest healthcare distribution and services vend...
OAuth Token Theft in Google Workspace: Detecting and Breaking the Modern Attack Chain
Introduction The defensive playbook most organizations run against Google Workspace compromise is built around a single assumption: the atta...
Beacon CRM Breach: 1,500 Charities' Data Exfiltrated — Third-Party Detection and Response Playbook
A Vendor Breach With Your Name on the Breach Notification Beacon, a CRM platform serving the non-profit sector, has notified approximately 1...
ShinyHunters Breaches: Identity and SaaS Security Hardening Guide
The recent wave of ShinyHunters breaches has sent a clear message to the cybersecurity community: the days of relying solely on vulnerabilit...
Cordial Spider & Snarky Spider: SaaS Extortion via Vishing and SSO Abuse — Detection & Response Guide
Introduction Security Arsenal is tracking active campaigns involving two distinct threat clusters—Cordial Spider (tracked as UNC6671, O-UNC-...
Shadow IT and AI Agents: Defending the Stack Beyond Glasswing
Shadow IT and AI Agents: Defending the Stack Beyond Glasswing The recent news regarding Glasswing serves as a stark reminder for the securit...
Zendesk Support Breach at Hims & Hers: Third-Party Supply Chain Defense
Introduction Telehealth giant Hims & Hers Health recently disclosed a significant data breach stemming from a compromise of its third-party ...