REPORTS
Fresh threat intelligence we ingest from public vendor and research feeds — each report linked to its original source. Search, filter by source, and open the reference.
Reports
Newest first. Search, filter by source, open the original.
11 reports · page 1 of 1

sentinelone · tlp:amber · 7/9/2026, 12:55:00 PM
One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement China and India ran separate espionage operations against the same Pakistani police force, each drawn by different stakes in Pakistan's internal security. Executive Summary SentinelLABS has been tracking sustained cyberespionage activity against several Pakistani law enforcement organizations, taking place from February 2024 to April 2026. All these actors converged on Balochistan Police ov…
Read original ↗https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcementsentinelone · tlp:amber · 7/2/2026, 1:00:02 PM
Context Engineering | Compaction & Agent Memory for Automated Malware Analysis Compaction cut input tokens 86% across long-running agent evals with no quality loss. Context discipline matters as much as model selection. Executive Summary Compaction is a context-management pattern used across agent systems to compress prior context into a denser working state for long-running tasks. SentinelLABS evaluated OpenAI’s native Responses API implementation against our automated mal…
sentinelone · tlp:amber · 6/23/2026, 9:59:42 PM
macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox DPRK-linked implant embeds 38 fabricated system messages that spoof an LLM triage harness, hiding a credential stealer and Telegram C2 underneath. Executive Summary SentinelLABS has analyzed a Rust macOS implant that embeds a 3.5 KB prompt-injection payload of 38 fabricated “system” messages, built to steer an LLM-assisted triage pipeline into aborting or refusing its analysis. Command-and…
Read original ↗https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandboxsentinelone · tlp:amber · 6/11/2026, 1:00:59 PM
LABScon25 Replay | Keynote: Steps to an Ecology of Cyber Decades of piling complexity onto non-standardized stacks have left security unsteerable. Juan Andrés Guerrero-Saade makes the case for a new approach. In this final video in our LABScon Replay series from LABScon 25, we present the keynote from SentinelLABS’ own Juan Andrés Guerrero-Saade (JAGS), VP, Intelligence & Security Research and Senior Technical Fellow. In this engaging talk, Juan argues that cybersecurit…
Read original ↗https://www.sentinelone.com/labs/labscon25-replay-keynote-steps-to-an-ecology-of-cybersentinelone · tlp:amber · 6/2/2026, 1:00:58 PM
LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine ESET researchers show how Gamaredon facilitated Turla access to Ukrainian targets, revealing rare cooperation between FSB-linked espionage groups. In this LABScon 25 presentation, ESET researchers Matthieu Faou and Zoltán Rusnák present the first technical evidence that Gamaredon actively facilitated Turla’s access to high-value Ukrainian targets in Ukraine. Across incidents observed…
Read original ↗https://www.sentinelone.com/labs/labscon25-replay-gamaredon-x-turla-unveiling-a-2025-espionage-alliance-targeting-ukrainesentinelone · tlp:amber · 5/14/2026, 1:00:44 PM
LABScon25 Replay | Breach Alpha: Trading on Cyber Fallout Mick Baccio and Scott Roberts examine whether public breach signals and market timing models can turn cyber incidents into actionable trading opportunities. When a company suffers a cyber breach, its stock price often takes a hit, but the timing, depth, and duration of that reaction are far less predictable. In this LABScon25 presentation, Mick Baccio and Scott Roberts explore whether public indicators of breach acti…
Read original ↗https://www.sentinelone.com/labs/labscon25-replay-breach-alpha-trading-on-cyber-falloutsentinelone · tlp:amber · 5/7/2026, 10:00:17 AM
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale Cloud attack framework skips cryptomining, harvests financial, messaging, and enterprise credentials for fraud, spam, and potential extortion. Executive Summary SentinelLABS has identified PCPJack, a credential theft framework that worms across exposed cloud infrastructure and removes artifacts associated with TeamPCP, a threat actor persona who claimed several high-profile supply chain intrusions throughou…
Read original ↗https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scalesentinelone · tlp:amber · 5/6/2026, 1:00:29 PM
LABScon25 Replay | Please Connect to the Foreign Entity to Enhance Your User Experience Joe FitzPatrick reveals how consumer imports of networked devices pose a real security risk to small businesses and critical infrastructure alike. In this LABScon 25 presentation, Joe FitzPatrick explores how networked devices manufactured overseas have quietly become indispensable to everything from small-business prototyping labs to roadside infrastructure. He argues that the safeguard…
Read original ↗https://www.sentinelone.com/labs/labscon25-replay-please-connect-to-the-foreign-entity-to-enhance-your-user-experiencesentinelone · tlp:amber · 4/23/2026, 10:00:45 PM
fast16 | Mystery Shadow Brokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet A previously unknown 2005 cyber sabotage framework patches high-precision calculation software in memory to silently corrupt results. Update | 07 May 2026 Executive Summary SentinelLABS has uncovered a previously undocumented cyber sabotage framework whose core components date back to 2005, tracked as fast16. fast16.sys selectively targets high-precision calculation sof…
Read original ↗https://www.sentinelone.com/labs/fast16-mystery-shadowbrokers-reference-reveals-high-precision-software-sabotage-5-years-before-stuxnetsentinelone · tlp:amber · 4/22/2026, 10:00:15 PM
LABScon25 Replay | Are Your Chinese Cameras Spying For You Or On You? Marc Rogers and Silas Cutler expose how cheap smart home devices conceal a shadow supply chain of shell companies, firmware flaws, and foreign data routing. In this LABScon 25 presentation, Marc Rogers and Silas Cutler explore the complex, “shadow” supply chain of ultra-cheap Chinese smart home devices, specifically focusing on video doorbells and security cameras widely sold on mainstream onl…
Read original ↗https://www.sentinelone.com/labs/labscon25-replay-are-your-chinese-cameras-spying-for-you-or-on-yousentinelone · tlp:amber · 3/19/2026, 10:00:07 AM
Building an Adversarial Consensus Engine | Multi-Agent LLMs for Automated Malware Analysis Single-tool LLM analysis produces reports that look authoritative but aren't. A serial consensus pipeline catches artifacts and hallucinations at source. Executive Summary Large Language Models can perform static malware analysis, but individual tool runs produce unreliable results contaminated by decompiler artifacts, dead code, and hallucinated capabilities. We built a multi-agent a…
Read original ↗https://www.sentinelone.com/labs/building-an-adversarial-consensus-engine-multi-agent-llms-for-automated-malware-analysis