Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
ShinyHunters Breaches: Identity and SaaS Security Hardening Guide
The recent wave of ShinyHunters breaches has sent a clear message to the cybersecurity community: the days of relying solely on vulnerabilit...
Cordial Spider & Snarky Spider: SaaS Extortion via Vishing and SSO Abuse — Detection & Response Guide
Introduction Security Arsenal is tracking active campaigns involving two distinct threat clusters—Cordial Spider (tracked as UNC6671, O-UNC-...
Shadow IT and AI Agents: Defending the Stack Beyond Glasswing
Shadow IT and AI Agents: Defending the Stack Beyond Glasswing The recent news regarding Glasswing serves as a stark reminder for the securit...
Zendesk Support Breach at Hims & Hers: Third-Party Supply Chain Defense
Introduction Telehealth giant Hims & Hers Health recently disclosed a significant data breach stemming from a compromise of its third-party ...
LeakyLooker Exploits: Defending Google Looker Studio Against Cross-Tenant SQL Attacks
In the modern SaaS ecosystem, the boundaries between "trusted" business intelligence tools and critical infrastructure are often blurred. We...