Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How to Use Aurora Security Assistant for Deeper Security Expertise and Context

In this demo, we will look at different use cases for the Aurora Security Assistant including the data explorer queries, organizational risk and vulnerability information, and quick answers around self-service and product documentation.

How the Arctic Wolf Agentic SOC Delivers Faster, More Accurate Security Outcomes

Learn how Arctic Wolf Superintelligence Platform and the Swarm of Experts work together to deliver faster, more accurate outcomes for customers by leveraging unmatched telemetry, deterministic models, our golden data set and human expertise.

Critical Citrix NetScaler ADC and Citrix NetScaler Gateway Vulnerabilities

On September 27th 2026, Citrix disclosed multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway. Arctic Wolf tracking indicates that CVE-2026-88771 and CVE-2026-88772 have been exploited in attacks against NetScaler devices as zero-days. Additional CVEs are also disclosed in the Citrix Security Bulletin. CVE-2026-88771 is an unauthenticated remote code execution vulnerability caused by improper input validation that can allow arbitrary command execution.

How the Aurora Agentic SOC Is Building the Next Generation of SOC Analysts

AI is changing how security operations work. It can process more data, reduce repetitive work, and move investigations forward faster than human teams could on their own. But speed and scale are not the only factors security leaders should be considering. The more important question is what happens to human expertise when machines take on more of the investigative workload. Across the industry, there is growing concern that AI will narrow the path into technical careers.

Your Security Team Is Stretched Thin. Can AI Return the Hours?

The Arctic Wolf 2026 AI & Cybersecurity Trends Report asked security leaders how much time their teams spend each week on nine separate security tasks, and the answer came back between 13 and 15 hours for each one. That’s a workload that adds up to roughly three full-time people before anything unplanned arrives. Leaders are already acting on the problem.

Engineered for Trust: How We Built the AI Trust Engine

The rapid advancement of frontier AI models has fundamentally changed how security products are built. Capabilities that once took months to develop can now be delivered at machine speed, and the market is filling up with agentic security operations centers (SOCs). Numerous vendors now promise AI agents that can investigate alerts, correlate evidence, reason over complex signals, and even close incidents on their own. The technology appears capable, but what often gets left out is a reason to believe it.

UPDATE: Active Exploitation CVE-2026-32996 of Veeam Agent

On September 14, 2026, public technical details and proof-of-concept (PoC) exploit code were released for CVE-2026-32996, increasing the likelihood of exploitation attempts against affected Veeam Agent for Microsoft Windows deployments. CVE-2026-32996 is a local privilege escalation vulnerability in Veeam Agent for Microsoft Windows version 13.0.1.2067 and affects all earlier version 13 builds.

We Need to Pace AI Development. We Can't Pace AI Defense

Anthropic CEO Dario Amodei published an essay this month called “We Must Pace the Frontier.” His argument is straightforward, calling out the reality that AI capabilities are advancing faster than the industry’s ability to align and safeguard them, and frontier labs need to slow the rate of capability growth long enough for safety work, alignment, and interpretability to catch up. He points to two developments behind his concern.

CVE-2026-76461: Active Exploitation of Cisco Secure Email Gateway Critical Zero-Day Vulnerability Immediate Mitigation Required

CVE-2026-76461 is a pre-authentication SQL injection vulnerability in the email parsing logic of Cisco Secure Email Gateway (AsyncOS). This vulnerability enables unauthenticated remote threat actors to execute arbitrary code as root by sending crafted, malicious emails. This grants threat actors full control over the operating system, allowing data exfiltration, email surveillance, persistent access, and potential network pivoting, all without user interaction or credentials.

CVE-2026-84869: ConnectWise ScreenConnect Client Vulnerability Critical Remote Session File Transfer Exploitation Risk

A critical security weakness (CVE-2026-84869) has been identified in the ConnectWise ScreenConnect client (prior to version 26.6.5), where missing authorization controls and improper privilege management allow file transfers and execution through active remote sessions without host confirmation.

Astra Just Raised the Bar for AI-Enabled Attacks. Here's What That Means for Defenders

OpenAI published its assessment of its newest GPT model, Astra, and found it to be the first of their models to reach a critical level of cybersecurity capability, meaning that given the right tools and access, it could autonomously exploit previously unknown vulnerabilities. As a result, OpenAI has restricted Astra’s most advanced cybersecurity capabilities to trusted partners before a public rollout.

The Howler Podcast: Three Year Anniversary

The Howler Podcast is 3! Join Chelsea and Mary as they reflect on the past three years and chat with special guest, Brian NeSmith, Co-founder & Executive Chairman! Interested in running with the pack? Explore careers at Arctic Wolf—one of the fastest-growing and exciting cybersecurity companies in the world, to learn about how you can join our Pack, create impact, and influence what’s next in security operations.

CVE-2026-86218: Active Exploitation of N-able N-central: Critical Pre-Auth Remote Code Execution (RCE) Vulnerability

A maximum-severity (CVSS 10.0) vulnerability CVE-2026-86218 has been discovered in N-able N-central prior to build 2026.3.1.14. This flaw allows unauthenticated attackers to execute arbitrary code on the N-central server before authentication enabling remote takeover of the platform. The vulnerability is classified as static code injection (consistent with CWE-96) in a public-facing application endpoint.

CrowdStrike Falcon Sensor Local Privilege Escalation Zero-Day (FalconFlank)

On September 3, 2026, a security researcher known as Nightmare Eclipse/Chaotic Eclipse publicly disclosed a zero-day dubbed ‘FalconFlank’ which abuses the Office malicious macro remediation workflow in CrowdStrike Falcon Sensor. The attack leverages a time-of-check to time-of-use (TOCTOU) race condition, allowing an attacker with code execution on a vulnerable system to hijack the Falcon macro remediation routine. This results in DLL side-loading and execution as NT AUTHORITY\SYSTEM.

The IT Asset Inventory Problem: Do You Know What's Actually on Your Network?

Ask a room of security leaders whether they have a complete, current inventory of everything on their network, and watch how long it takes anyone to say yes. Effort is rarely the issue. Modern environments change faster than any single record can keep up with. A configuration management database (CMDB) shows what was documented. An endpoint tool shows where its agent is installed. A scanner shows what it was told to scan.

A Practical Guide to Attack Surface Management

Attack surface management (ASM) is the discipline of continuously discovering, inventorying, assessing, and prioritizing every asset, control, and exposure across your environment. It gives you an always-on picture of what you actually have, rather than a point-in-time scan. Done right, it answers the three questions every security leader is really asking: What do I have? Where am I exposed? What do I fix first?