Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

We Need to Pace AI Development. We Can't Pace AI Defense

Anthropic CEO Dario Amodei published an essay this month called “We Must Pace the Frontier.” His argument is straightforward, calling out the reality that AI capabilities are advancing faster than the industry’s ability to align and safeguard them, and frontier labs need to slow the rate of capability growth long enough for safety work, alignment, and interpretability to catch up. He points to two developments behind his concern.

Astra Just Raised the Bar for AI-Enabled Attacks. Here's What That Means for Defenders

OpenAI published its assessment of its newest GPT model, Astra, and found it to be the first of their models to reach a critical level of cybersecurity capability, meaning that given the right tools and access, it could autonomously exploit previously unknown vulnerabilities. As a result, OpenAI has restricted Astra’s most advanced cybersecurity capabilities to trusted partners before a public rollout.

The Howler Podcast: Three Year Anniversary

The Howler Podcast is 3! Join Chelsea and Mary as they reflect on the past three years and chat with special guest, Brian NeSmith, Co-founder & Executive Chairman! Interested in running with the pack? Explore careers at Arctic Wolf—one of the fastest-growing and exciting cybersecurity companies in the world, to learn about how you can join our Pack, create impact, and influence what’s next in security operations.

CVE-2026-86218: Active Exploitation of N-able N-central: Critical Pre-Auth Remote Code Execution (RCE) Vulnerability

A maximum-severity (CVSS 10.0) vulnerability CVE-2026-86218 has been discovered in N-able N-central prior to build 2026.3.1.14. This flaw allows unauthenticated attackers to execute arbitrary code on the N-central server before authentication enabling remote takeover of the platform. The vulnerability is classified as static code injection (consistent with CWE-96) in a public-facing application endpoint.

CrowdStrike Falcon Sensor Local Privilege Escalation Zero-Day (FalconFlank)

On September 3, 2026, a security researcher known as Nightmare Eclipse/Chaotic Eclipse publicly disclosed a zero-day dubbed ‘FalconFlank’ which abuses the Office malicious macro remediation workflow in CrowdStrike Falcon Sensor. The attack leverages a time-of-check to time-of-use (TOCTOU) race condition, allowing an attacker with code execution on a vulnerable system to hijack the Falcon macro remediation routine. This results in DLL side-loading and execution as NT AUTHORITY\SYSTEM.

The IT Asset Inventory Problem: Do You Know What's Actually on Your Network?

Ask a room of security leaders whether they have a complete, current inventory of everything on their network, and watch how long it takes anyone to say yes. Effort is rarely the issue. Modern environments change faster than any single record can keep up with. A configuration management database (CMDB) shows what was documented. An endpoint tool shows where its agent is installed. A scanner shows what it was told to scan.

A Practical Guide to Attack Surface Management

Attack surface management (ASM) is the discipline of continuously discovering, inventorying, assessing, and prioritizing every asset, control, and exposure across your environment. It gives you an always-on picture of what you actually have, rather than a point-in-time scan. Done right, it answers the three questions every security leader is really asking: What do I have? Where am I exposed? What do I fix first?