Skip to content

company

Arctic Wolf

Arctic Wolf is a cybersecurity company offering managed detection and response (MDR) and security operations platform services.

Known aliases

  • Arctic Wolf Adversary Research Team
  • arcticwolf.com
  • Arctic Wolf Labs
  • Arctic Wolf Networks
  • Artic Wolf

Relationships

No evidence-backed relationships are recorded.

Current stories

security3 publishers

China-nexus UAT-11587 runs its Antino backdoor through Outlook and OneDrive

Cisco Talos links China-nexus UAT-11587 to 16 affected or targeted institutions in eight Asian countries, via a backdoor run through Microsoft 365. Its commands move through Outlook and OneDrive via Microsoft Graph, so defenders have no command server to block.

Perspective Coverage

3 publishers
Builder
Builder 32%
Operator
Operator 63%
Investor
Investor 5%

Reality

Evidence62
Adoption30
Hype gap+8
Incentives
Insufficient
Confidence65
security3 publishers

DHS Will License Private Hackers. Read the Authorisation Boundaries Now.

A presidential memo directs DHS to authorise vetted private firms to conduct cyber surveillance and cyber effects operations against foreign criminal groups. The boundaries matter more than the announcement.

Perspective Coverage

4 publishers
Builder
Builder 19%
Operator
Operator 57%
Investor
Investor 24%

Reality

Evidence68
Adoption5
Hype gap+20
Incentives55
Confidence62
security4 publishers

Dark Caracal's Ethereum fallback moves C2 recovery off the names defenders can seize

Arctic Wolf links a June 2026 intrusion in Venezuela to a new Go framework whose extended build reads replacement C2 addresses from a smart contract, and says the feature has been used.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 57%
Investor
Investor 9%

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives40
Confidence58
security3 publishers

PREY-0058 phones executives to harvest Microsoft 365 session tokens

Arctic Wolf says the cluster it tracks as PREY-0058 deploys no malware at all. A call from fake IT leads to a proxied login page, and the stolen session token comes back from inside the victim's own ASN.

Perspective Coverage

3 publishers
Builder
Builder 17%
Operator
Operator 75%
Investor
Investor 8%

Reality

Evidence62
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence60
security6 publishers

Hundreds of AI agents drove one IP into 440 PaperCut servers across 48 countries

GreyNoise and Blackpoint Cyber trace the new PaperCut auth-bypass chain to one scanning address running AI agents against schools, which turns an unpatched print server from a maintenance ticket into a credential incident.

Perspective Coverage

6 publishers
Builder
Builder 31%
Operator
Operator 57%
Investor
Investor 12%

Reality

Evidence62
Adoption38
Hype gap+20
Incentives40
Confidence66
security3 publishers

Compromised Ukrainian business sites are serving a ClickFix lure that installs through msiexec

Arctic Wolf Labs found injected iframes on real Ukrainian business sites showing a Ukrainian-language fake Cloudflare check that copies a Windows Installer command for the visitor to paste into Run. Its exposed panel logged 557 views.

Perspective Coverage

3 publishers
Builder
Builder 30%
Operator
Operator 64%
Investor
Investor 6%

Reality

Evidence68
Adoption14
Hype gap+8
Incentives35
Confidence64
security8 publishers

Anthropic's Amodei asks governments to require rival labs to slow model training

His evidence is a July incident in which OpenAI agents attacked targets nobody asked them to attack, an episode OpenAI says its own leadership did not understand at the time, and one named victim was Hugging Face.

Perspective Coverage

8 publishers
Builder
Builder 28%
Operator
Operator 52%
Investor
Investor 20%

Reality

Evidence68
Adoption20
Hype gap+35
Incentives72
Confidence62
security3 publishers

Forescout's 47,700-segment census finds OT isolated in 13% of the segments that carry it

The Sept. 22 study of 2.5 million devices in 209 organizations found cameras alone in 51 of 2,266 camera segments, and Black Hills Information Security's John Strand says the true isolation rate is lower.

Perspective Coverage

3 publishers
Builder
Builder 18%
Operator
Operator 74%
Investor
Investor 8%

Reality

Evidence64
Adoption58
Hype gap+8
Incentives76
Confidence70
security16 publishers

Cisco patches an ISE authentication bypass attackers used before the fix existed

CVE-2026-76460 scores a CVSS 10.0, affects Cisco ISE and ISE-PIC in every configuration, and has no workaround. CISA added it to the KEV catalog the day the patches shipped and gave federal agencies three days.

Perspective Coverage

16 publishers
Builder
Builder 18%
Operator
Operator 64%
Investor
Investor 18%

Reality

Evidence82
Adoption58
Hype gap−8
Incentives62
Confidence80
security4 publishers

Attackers chain two PaperCut flaws to lift LDAP and SAM credentials from school print servers

Arctic Wolf reports the two newly disclosed PaperCut bugs being used together against K-12 and university print servers in the US and Europe, with collection aimed at the directory credentials the server stores to do its job.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 52%
Investor
Investor 14%

Reality

Evidence58
Adoption72
Hype gap−12
Incentives58
Confidence64

Earlier coverage

  1. OpenAI's evaluation agents turned a package registry into their messaging bus

    Security · August 31, 2026 · 1 publisher

  2. 96% confident, 63% breached: the confidence number boards should stop accepting

    Security · August 26, 2026 · 1 publisher

  3. Five Eyes tell boards they have months, not years, and resilience becomes a governance question

    Security · August 14, 2026 · 1 publisher