Network Security

Decrypting SentinelOne Detection | The Behavioral AI Engine in Real-Time CWPP

In October, the first blog post in this series discussed the Static AI Engine. In this, the second installment of the Detection Engine blog series, we examine the SentinelOne Behavioral AI Engine. Although AI, especially GenAI, are very hot topics right now, SentinelOne has been using AI as a keystone of our technology since our […]

Decrypting SentinelOne Detection | The Behavioral AI Engine in Real-Time CWPP Read More »

Mallox Resurrected | Ransomware Attacks Exploiting MS-SQL Continue to Burden Enterprises

The ransomware landscape is characterized by a heavy churn in both actor groups and malware families, with only a few players exhibiting relative longevity. Once feared threats such as REvil and Conti have either been dismantled or dissolved, while others – ALPHV, Black Basta and LockBit, for example – continue to extort businesses with impunity.

Mallox Resurrected | Ransomware Attacks Exploiting MS-SQL Continue to Burden Enterprises Read More »

The Good, the Bad and the Ugly in Cybersecurity – Week 49

The Good | Co-Founder of Criminal Crypto Exchange Pleads Guilty to Money-Laundering Schemes Anatoly Legkodymov (aka “Gandalf” or “Tolik”), co-founder of the Bitzlato cryptocurrency exchange, has pleaded guilty to his role in aiding ransomware gangs and other cybercriminals in laundering over $700 million. Legkodymov has agreed to disband Bitzlato and forfeit his claim to approximately

The Good, the Bad and the Ugly in Cybersecurity – Week 49 Read More »

AWS re:Invent 2023 Highlights | Showcasing the Latest Advances in Cloud Security and Innovation

Last week’s AWS re:Invent 2023, held in Las Vegas, was a milestone event showcasing the latest innovations in cloud security. This year, the focus was on the transformative role of Generative AI in cloud computing, a theme that resonated throughout the conference’s keynotes, breakout sessions, and hands-on labs. In this post, we unpack the essential

AWS re:Invent 2023 Highlights | Showcasing the Latest Advances in Cloud Security and Innovation Read More »

Iran-Backed Cyber Av3ngers Escalates Campaigns Against U.S. Critical Infrastructure

Earlier this week, CISA released an advisory warning of active exploitation of Programmable Logic Controllers (PLCs) used in Water and Wastewater treatment plants following intrusions into two U.S. critical infrastructure installations. The advisory and attacks come in the wake of increased public threats made by the Iran-backed Cyber Av3ngers “hacktivist” group to target industries using

Iran-Backed Cyber Av3ngers Escalates Campaigns Against U.S. Critical Infrastructure Read More »

DPRK Crypto Theft | macOS RustBucket Droppers Pivot to Deliver KandyKorn Payloads

North Korean-aligned threat actors targeting macOS have had a busy 2023, with two major campaigns noted so far: RustBucket and KandyKorn. The initial RustBucket campaign used a second-stage malware, dubbed ‘SwiftLoader’, which functioned externally as a PDF Viewer for a lure document sent to targets. While victims viewed the lure, SwiftLoader retrieved and executed a

DPRK Crypto Theft | macOS RustBucket Droppers Pivot to Deliver KandyKorn Payloads Read More »