Threat Research Archives - Arctic Wolf /resources/tag/threat-research/ The Leaders in Security Operations Thu, 06 Aug 2026 23:15:55 +0000 en-US hourly 1 https://wordpress.org/?v=7.1 /wp-content/uploads/2019/11/aw-favicon-rebrand-150x150.png Threat Research Archives - Arctic Wolf /resources/tag/threat-research/ 32 32 Payroll Pirates: Strange New Tides in Business Email Compromise /resources/blog/payroll-pirates-strange-new-tides-in-business-email-compromise/ Thu, 06 Aug 2026 23:15:55 +0000 /?p=135381 ... Payroll Pirates: Strange New Tides in Business Email Compromise]]> Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection /resources/blog/castleloader-new-campaigns-new-tooling-and-the-needlestealer-connection/ Mon, 27 Jul 2026 22:36:18 +0000 /?p=134383 ... Expanding the Castle: New Campaigns, New Tooling, and the NeedleStealer Connection]]> Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware /resources/blog/exploitation-of-cve-2026-0257-leads-to-qilin-ransomware/ Mon, 20 Jul 2026 22:10:55 +0000 /?p=134072 ... Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware]]> Malicious GitHub Campaign: Fake “Arctic Wolf” and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer /resources/blog/fake-github-repositories-deliver-boryptgrab-lineage-infostealer/ Mon, 13 Jul 2026 22:46:04 +0000 /?p=133919 ... Malicious GitHub Campaign: Fake “Arctic Wolf” and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer]]> From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks /resources/blog/citrixbleed-2-to-cloudflared-the-tools-and-techniques-behind-anubis-ransomware-attacks/ Wed, 01 Jul 2026 02:28:44 +0000 /?p=133342 ... From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks]]> Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory /resources/blog/inside-fortibleed-reverse-engineering-the-cyberstrike-harvester-behind-a-global-fortigate-credential-factory/ Wed, 24 Jun 2026 00:27:52 +0000 /?p=132985 ... Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory]]> Arctic Wolf Observes an Increase in Palo Alto Networks GlobalProtect Authentication Bypass Exploitation via CVE-2026-0257 /resources/blog/arctic-wolf-observes-increase-in-palo-alto-networks-globalprotect-authentication-bypass-exploitation-via-cve-2026-0257/ Thu, 11 Jun 2026 14:34:17 +0000 /?p=132270 ... Arctic Wolf Observes an Increase in Palo Alto Networks GlobalProtect Authentication Bypass Exploitation via CVE-2026-0257]]> Home-Field Disadvantage: AiTM, QR-Code Phishing, and Infostealers at the 2026 FIFA World Cup /resources/blog/aitm-qr-code-phishing-and-infostealers-at-the-2026-fifa-world-cup/ Tue, 09 Jun 2026 12:59:17 +0000 /?p=132145 ... Home-Field Disadvantage: AiTM, QR-Code Phishing, and Infostealers at the 2026 FIFA World Cup]]> From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services /resources/blog/kali365-expands-into-aws-microsoft-okta-xerox-max-messenger/ Tue, 02 Jun 2026 12:59:05 +0000 /?p=131993 ... From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services]]> FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch /resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/ Wed, 27 May 2026 18:23:19 +0000 /?p=131875 ... FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch]]>