Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection

Arctic Wolf Labs has been tracking a cluster of campaigns built around CastleLoader, a multi-stage shellcode loader that has served as the backbone of a number of related intrusion sets over the past year. Previous reporting from Huntress documented the.NET-based CastleStealer (net40), and LevelBlue documented the PythonRAT observed in related campaigns. Both reports noted NetSupport RAT as a common final payload.

Lessons from the OpenAI and Hugging Face Incident: When Safety Filters Disarm the Defender

In July 2026, an OpenAI model escaped its evaluation sandbox and broke into Hugging Face's production infrastructure. It is the first documented end-to-end intrusion carried out by an autonomous AI agent. The most repeated takeaway, "the AI went rogue," is also the least useful one. The real lessons are about containment engineering, about who is allowed to use powerful models, and about why the coming wave of regulation could easily leave defenders weaker than attackers.

Public mTLS client-auth certificates stop renewing in October

Chrome’s root program decides what certificates will be trusted by Chrome, and what they are allowed to do. Recently, Google decided that client authentication isn’t on the list. Under Chrome Root Program Policy v1.8, every certificate issued on or after March 15, 2027 can assert only one Extended Key Usage (EKU): server authentication. Let’s Encrypt moved early.

What Is AI Pentesting and How Does It Works?

AI pentesting (AI penetration testing) is the use of reasoning-capable AI models to autonomously find, exploit, and validate security vulnerabilities in running applications — especially the context-dependent flaws, such as broken authorization and business-logic abuse, that traditional scanners cannot detect.

Optimized CyberVault Integration with CohesityOS 7.4

Nearly nine months after launching Cyber Vault for Cohesity, 11:11 Systems continues to advance a cost- and performance-optimized solution for moving a copy of Cohesity backups offsite into immutable AWS S3 object storage. With the recent release of CohesityOS 7.4, the solution has taken its next step. 11:11 Systems is now a named External Target repository type, making it even easier to implement the best practices our data protection experts have built into the Cyber Vault solution.

Manage Your Secrets With Keeper Security's Universal Secrets Sync

Developers, how are you managing your secrets? Keeper Security’s Universal Secrets Sync automatically distributes credentials and secrets stored in Keeper to external secrets managers and cloud platforms, including AWS Secrets Manager, Azure Key Vault and Google Cloud Secret Manager.

The Hidden Cost of "Free": When Platform Incentives Become Lock-In

In enterprise software, “free” is rarely free. A free year can be a smart commercial incentive. It can also become a financial trap if the real cost, payment terms, and renewal baseline are unclear. When a platform deal looks almost too good to question, CFOs should question it first. Large multi-year incentives can look like a procurement win. They lower the apparent cost of entry, support a consolidation story, and create the impression of immediate savings.

Normalize security logs to Google SecOps UDM with Observability Pipelines

Google Security Operations (SecOps) is Google Cloud’s security operations platform for detecting, investigating, and responding to threats across large volumes of security telemetry. To make that telemetry useful across sources, Google SecOps uses the Unified Data Model (UDM), a common event schema that provides a consistent structure for security logs. But logs from firewalls, endpoints, identity providers, and other sources all describe and format security events differently.

From tool procurement to platform architecture: Rethinking the SOC for machine-speed threats

The gap between attacker speed and defender readiness is widening. Attackers can now move from initial access to full domain control in less than a minute using AI.1 Large language model-generated phishing campaigns are achieving click-through rates 4.5 times higher than traditional methods.2 Most enterprise SOCs weren't built for this tempo and fidelity.