Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Payroll Pirates: Strange New Tides in Business Email Compromise

Arctic Wolf is tracking an ongoing Microsoft 365 phishing campaign affecting healthcare, education, manufacturing, government, professional services, and other sectors across the United States, Canada, and Europe. In July 2026, we observed hundreds of organizations being targeted by email, with successful intrusions identified across a broad range of environments.

SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299

On July 30th, 2026, SolarWinds released fixes for a critical Authentication-Bypass vulnerability in Web Help Desk (WHD) tracked as CVE-2026-28323, and a related high-severity Denial-of-Service vulnerability, tracked as CVE-2026-28299. Although no active exploitation has been observed yet, WHD is commonly internet-facing and the authentication bypass requires no credentials, making it a likely target once exploit code becomes available.

Defense at Machine Speed: How Arctic Wolf Built the Aurora Agentic SOC on AWS

Avni Wala, Principal Developer – Arctic Wolf Laura Ellis, SVP Artificial Intelligence – Arctic Wolf Merin Eralil, Security Partner Solutions Architect – AWS Tim Sitze, Solutions Architect – AWS AI didn’t just make defenders faster. It made attackers faster too. The moment both sides got access to the same speed, speed stopped being the advantage. With speed no longer separating attackers from defenders, the deciding factor moved somewhere else.

Introducing the Cyber AI Readiness Accelerator: Outpace Your Adversary with Exposure Management

AI has overwhelmingly changed how organizations build and grow. It’s also changed how attackers find and exploit exposures and weaknesses. The window between “exposure exists” and “exposure is exploited” is shrinking, and most security teams already feel it.

Scale, Trust, and Value: How the Aurora Agentic SOC Delivers for Customers

AI didn’t just make defenders faster. It made attackers faster too. The moment both sides got access to the same speed, speed stopped being the advantage. With speed no longer separating attackers from defenders, the deciding factor moved somewhere else. Ask a CISO what’s actually kept agentic security out of reach, and it comes down to this: they can’t afford to build it, and even if they could, they’d struggle to trust it. Neither half of that problem outweighs the other.

You Can't Buy Your Way Out of Downtime

A ransomware note doesn’t take down a business. The weeks of downtime after it does. That’s the distinction I hear missed most in boardroom conversations about cyber risk. Leaders ask what it costs to stop an attack. The harder question, and the one that actually decides whether a business comes out the other side, is what it takes to keep operating while you recover from one.

CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching

Threat actors are actively exploiting two high-severity authentication bypass vulnerabilities, CVE-2026-18556 and CVE-2026-18577, in N-able N-Central, a widely deployed remote monitoring and management (RMM) platform used by MSPs and enterprise IT teams. N-able began investigating anomalous activity on July 31 and released an emergency hotfix (2026.3.1.7) on August 2, 2026, to remediate both vulnerabilities.

Arctic Wolf Named a Leader in the 2026 IDC MarketScape for Worldwide Managed Detection and Response Service for Midmarket

Midmarket security teams face the same adversaries as the largest enterprises, often with a fraction of the staff and budget. Alert volumes keep climbing, AI-driven threats are accelerating, and lean teams are expected to do more with fewer resources. What these organizations need is world-class AI-led security operations that are actually within reach.

Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection

Arctic Wolf Labs has been tracking a cluster of campaigns built around CastleLoader, a multi-stage shellcode loader that has served as the backbone of a number of related intrusion sets over the past year. Previous reporting from Huntress documented the.NET-based CastleStealer (net40), and LevelBlue documented the PythonRAT observed in related campaigns. Both reports noted NetSupport RAT as a common final payload.

What the OpenAI-Hugging Face Incident Really Tells Us

For years, the conversation about AI in cybersecurity has been mostly hypothetical. What happens when a model can plan and execute an attack on its own? How far away is that, really? This week, OpenAI gave us a concrete answer, and it arrived earlier than many expected. The incident is a genuine milestone, and it deserves the attention it is getting. But the most useful response is disciplined execution on the fundamentals, at a pace that matches the moment.