The Latest Threat Research and Intelligence

Get the Latest Cybersecurity Research, Threat 
Intelligence, and AI Security Insights from SentinelLABS.

TraderTraitor_APIs_ftr

Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties

North Korean operators built a foothold on a DevOps engineer's Mac in a campaign whose job interview lures deliver malware via Terraform lock files.

Read More
hf-agents_ftr

Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face

Two Hugging Face accounts reveal that OpenAI's agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline.

Read More
model_is_malware_ftr

The Model Is the Malware | What Four Agentic Intrusions Tell Defenders

OpenAI, Anthropic and Meta disclosed agents reaching external systems. The tools didn't matter, and that changes the playbook for investigating intrusions.

Read More
Mythos_sol_ftr

Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?

A real-world benchmark tests whether powerful AI models can keep an investigation trustworthy when new evidence invalidates their conclusions.

Read More

All SentinelLABS Posts

  • HelloKitty Ransomware Lacks Stealth, But Still Strikes Home

    HelloKitty Ransomware Lacks Stealth, But Still Strikes Home

  • A Guide to Ghidra Scripting Development for Malware Researchers

    A Guide to Ghidra Scripting Development for Malware Researchers

  • 20 Common Tools & Techniques Used by macOS Threat Actors & Malware

    20 Common Tools & Techniques Used by macOS Threat Actors & Malware

  • CVE-2021-24092: 12 Years in Hiding – A Privilege Escalation Vulnerability in Windows Defender

    CVE-2021-24092: 12 Years in Hiding – A Privilege Escalation Vulnerability in Windows Defender

  • Zeoticus 2.0 | Ransomware With No C2 Required

    Zeoticus 2.0 | Ransomware With No C2 Required

  • FADE DEAD | Adventures in Reversing Malicious Run-Only AppleScripts

    FADE DEAD | Adventures in Reversing Malicious Run-Only AppleScripts

  • Greyware’s Anatomy: The “Potentially Unwanted” are Upping Their Game

    Greyware’s Anatomy: The “Potentially Unwanted” are Upping Their Game

  • Building a Custom Malware Analysis Lab Environment

    Building a Custom Malware Analysis Lab Environment

  • SolarWinds | Understanding & Detecting the SUPERNOVA Webshell Trojan

    SolarWinds | Understanding & Detecting the SUPERNOVA Webshell Trojan

  • SolarWinds SUNBURST Backdoor: Inside the APT Campaign

    SolarWinds SUNBURST Backdoor: Inside the APT Campaign

  • Introducing SentinelOne’s Ghidra Plugin for VirusTotal

    Introducing SentinelOne’s Ghidra Plugin for VirusTotal

  • APT32 Multi-stage macOS Trojan Innovates on Crimeware Scripting Technique

    APT32 Multi-stage macOS Trojan Innovates on Crimeware Scripting Technique