Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Howler Episode 33 - Matt Setzer, SVP, Chief Architect

This month, we sit down with Matt Setzer, Senior Vice President, Chief Architect, to learn more about a day in the life of an architect, his philosophy on meaningful innovation, and so much more! Matt Setzer is SVP & Chief Architect at Arctic Wolf, where he partners with product and engineering leadership to set the technical strategy for the Arctic Wolf products and platform. Matt has spent the last twenty years in senior engineering and architect roles in the security space at Microsoft and Sophos. Prior to that he spent number of years working in the game industry.

Microsoft Defender Patch Bypass: High Severity Zero-Day Privilege Escalation (CVE-2026-50656/RoguePlanet, ShieldBreak)

A critical zero-day vulnerability (CVE-2026-50656/“RoguePlanet”) in Microsoft Defender’s Malware Protection Engine (mpengine.dll) enables local users, including standard, low-privilege accounts, to escalate privileges to NT AUTHORITY\SYSTEM using a race condition and improper link resolution. Microsoft initially issued a patch (Engine v1.1.26060.3008) in July 2026.

Reflections from Black Hat: Speed Is Table Stakes. Resilience Is the Win.

Black Hat 2026 came just weeks after the Five Eyes cybersecurity agencies — CISA, the UK’s NCSC, Australia’s ACSC, Canada’s CCCS, and New Zealand’s NCSC-NZ — issued a joint statement to boards and executives with the blunt message that AI is rewriting the rules of cyber risk, the window between vulnerability and exploitation is shrinking, and organizations have a matter of months to adapt.

Arctic Wolf Cocktail Chats - Nick Schneider, President & CEO | Black Hat 2026

Arctic Wolf President & CEO Nick Schneider sits down with Ilina Cashiola, SVP of Corporate Marketing, for a cocktail chat at Black Hat USA 2026 to break down three major announcements shaping the next chapter of AI-led security operations.

Arctic Wolf Cocktail Chats - Dan Schiappa, President, Technology & Services | Black Hat 2026

Arctic Wolf President of Technology & Services Dan Schiappa sits down for a cocktail chat with Arctic Wolf SVP of Corporate Marketing Ilina Cashiola at Black Hat USA 2026 to break down the momentum behind the Aurora Agentic SOC and what's next for AI-led security operations.

Payroll Pirates: Strange New Tides in Business Email Compromise

Arctic Wolf is tracking an ongoing Microsoft 365 phishing campaign affecting healthcare, education, manufacturing, government, professional services, and other sectors across the United States, Canada, and Europe. In July 2026, we observed hundreds of organizations being targeted by email, with successful intrusions identified across a broad range of environments.

SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299

On July 30th, 2026, SolarWinds released fixes for a critical Authentication-Bypass vulnerability in Web Help Desk (WHD) tracked as CVE-2026-28323, and a related high-severity Denial-of-Service vulnerability, tracked as CVE-2026-28299. Although no active exploitation has been observed yet, WHD is commonly internet-facing and the authentication bypass requires no credentials, making it a likely target once exploit code becomes available.

Active Supply Chain Attack on npm Packages (keyv, cacheable): Immediate Mitigation Required

A sophisticated supply chain attack has actively compromised multiple npm packages, including keyv, cacheable, cacheable-request, flat-cache, file-entry-cache, and possible related adapters. Attackers took control of a popular maintainer’s npm account on or before August 4, 2026, and began publishing trojanized package versions containing a preinstall hook (setup.mjs) as a loader.

Defense at Machine Speed: How Arctic Wolf Built the Aurora Agentic SOC on AWS

Avni Wala, Principal Developer – Arctic Wolf Laura Ellis, SVP Artificial Intelligence – Arctic Wolf Merin Eralil, Security Partner Solutions Architect – AWS Tim Sitze, Solutions Architect – AWS AI didn’t just make defenders faster. It made attackers faster too. The moment both sides got access to the same speed, speed stopped being the advantage. With speed no longer separating attackers from defenders, the deciding factor moved somewhere else.

Introducing the Cyber AI Readiness Accelerator: Outpace Your Adversary with Exposure Management

AI has overwhelmingly changed how organizations build and grow. It’s also changed how attackers find and exploit exposures and weaknesses. The window between “exposure exists” and “exposure is exploited” is shrinking, and most security teams already feel it.