SentinelOne

SentinelOne Next-generation cybersecurity solutions. SentinelOne has offices in Palo Alto, Tel Aviv, and Tokyo.

SentinelOne was founded in 2013 by an elite team of cybersecurity and defense experts who developed a fundamentally new, groundbreaking approach to endpoint protection. SentinelOne is a pioneer in delivering autonomous security for the endpoint, data center and cloud environments to help organizations secure their assets with speed and simplicity. SentinelOne unifies prevention, detection, respons

e, remediation and forensics in a single platform powered by artificial intelligence. With SentinelOne, organizations can detect malicious behavior across multiple vectors, rapidly eliminate threats with fully-automated integrated response, and to adapt their defenses against the most advanced cyberattacks. The company is recognized by Gartner as a Visionary for Endpoint Protection and has enterprise customers in North America, Europe, and Japan. To learn more, please visit our website at www.sentinelone.com.

🚨 This week, global law enforcement dealt major blows to cybercrime networks spanning four continents, while a $320/mont...
08/30/2026

🚨 This week, global law enforcement dealt major blows to cybercrime networks spanning four continents, while a $320/month phishing kit turned trusted Docusign emails into Microsoft 365 session thieves, and a multi-stage RAT campaign weaponized a legitimate security driver to blind endpoint defenses.

🚦 The Good: INTERPOL's Operation Jackal IV yielded 58 arrests across 22 countries targeting Black Axe fraud networks, the FBI seized infrastructure supporting Chinese state-sponsored espionage targeting NASA and the U.S. Senate, the U.S. Treasury sanctioned Iranian MOIS-linked hackers under Operation Economic Outcast, and Australian authorities charged two men behind the TeamPCP supply chain attacks that compromised over 1,000 organizations worldwide.

The Bad: Researchers disclosed NovaCookies, a $320/month adversary-in-the-middle phishing kit that abuses genuine Docusign notifications to proxy Microsoft 365 sign-ins through attacker infrastructure, stealing authenticated sessions even from MFA-protected accounts across hundreds of organizations.

The Ugly: A newly discovered campaign targeting Cambodia deployed Spark RAT through a multi-stage infection chain that exploited a vulnerable OPSWAT driver to kill Microsoft Defender and other security tools before establishing remote access, with infrastructure overlaps pointing to a possible Chinese-linked threat actor.

This was the week in cyber. πŸ”— Full technical breakdown: https://s1.ai/GBU9-Wk35

New joint research from SentinelOne and Tenable suggests a growing disconnect between vulnerability discovery, disclosur...
08/26/2026

New joint research from SentinelOne and Tenable suggests a growing disconnect between vulnerability discovery, disclosure and actual exploitation.

The most critical takeaway: Both nation state and criminal threat actors are focusing on vendors and susceptible points in the attack surface more than specific CVEs.

AI has compressed disclosure-to-exploit time to about a week. Today's average remediations cycle? Five months. Closing that gap starts with knowing where the next wave of exploitation will land.

Read the full research: https://s1.ai/jovqh

We commissioned a survey of 611 North American security leaders on AI adoption in the SOC.96% of organizations sit at th...
08/25/2026

We commissioned a survey of 611 North American security leaders on AI adoption in the SOC.

96% of organizations sit at the earliest stages of AI maturity, and 99% report measurable improvements in incident response and remediation.

Platform-oriented organizations report the strongest results. 82% of organizations now call themselves platform-oriented, up 13 points in a single year.

Read the full findings from the survey, in partnership with 451 Research, here: https://s1.ai/451-research

08/25/2026

At OneCon 2026, you will connect with the peers, engineers, and security leaders solving the same problems you are.

But the fun and knowledge goes beyond networking. Here’s what else you have to look forward to:
πŸ† Watch the Sentinels League. The world's best threat hunters compete across Endpoint, SIEM, Cloud, and AI for $100K in prizes. Real scenarios. Real stakes.
πŸ™… Sharpen your edge in hands-on labs and expert-led sessions. Walk away with skills to reduce risk right away.

Register now so you don’t miss out: https://www.onecon.io/?utm_source=facebook&utm_medium=organic-social&utm_campaign=no-utm-campaign

🚨 This week, cybercrime hit Iranian state-sponsored hackers, Medusa ransomware's growing list of critical infrastructure...
08/21/2026

🚨 This week, cybercrime hit Iranian state-sponsored hackers, Medusa ransomware's growing list of critical infrastructure victims, and a critical Windows zero-day now being actively exploited in the wild.

🚦 The Good: The U.S. charged 17 Iranian nationals linked to a state-backed hack-for-hire operation that stole 31.5 terabytes of academic research and intellectual property, valued at $3.4 billion from universities, companies, and government agencies worldwide.

The Bad: CISA, the FBI, and HHS warned that Medusa ransomware has breached over 500 critical infrastructure organizations since 2021, targeting healthcare, defense, manufacturing, and financial services through a growing RaaS affiliate model.

The Ugly: CISA confirmed that a critical remote code ex*****on vulnerability in the Windows IKE Extension, allowing unauthenticated attackers to compromise any unpatched Windows system over the network is now being actively exploited in the wild.

This was the week in cyber. πŸ”— Full technical breakdown: https://s1.ai/GBU9-Wk34

🚨 This week, cybercrime hit The Com's sextortion network, Fortinet-exposed critical infrastructure, and Microsoft Defend...
08/14/2026

🚨 This week, cybercrime hit The Com's sextortion network, Fortinet-exposed critical infrastructure, and Microsoft Defender's patch process.

🚦 The Good: A 20-year-old member of The Com was sentenced to two years in prison for blackmail and child sexual abuse offenses against 117 victims aged 13 to 17 worldwide.

The Bad: U.S., U.K., and South Korean authorities jointly warned that Gunra ransomware is actively exploiting known Fortinet FortiOS and FortiProxy vulnerabilities to breach and extort critical organizations across healthcare, government, and financial services.

The Ugly: A security researcher published a working proof-of-concept for β€œShieldBreak”, a new patch bypass for a previously "fixed" Microsoft Defender zero-day granting SYSTEM-level privileges on Windows 11 and Windows Server 2025 with a claimed 100% success rate.

This was the week in cyber. πŸ”— Full technical breakdown: https://s1.ai/GBU9-Wk33

🚨 This week in cybersecurity: Snowflake hacker's guilty plea covers a 100M-record breach, stray keyword sends Mythos 5 a...
08/09/2026

🚨 This week in cybersecurity: Snowflake hacker's guilty plea covers a 100M-record breach, stray keyword sends Mythos 5 after the wrong target, and ChainDrop's worm spreads through npm.

🚦 The Good: Snowflake hacker Connor Riley Moucka pleaded guilty to breaching 165 organizations and exposing records tied to 100 million people, facing up to 30 years at sentencing in October. Separately, Ransom Cartel creator Maksim Silnikau was sentenced to 16 years for running a ransomware operation that attempted to extort at least $5.2 million from 18 companies.

The Bad: The UK AI Security Institute reported that an agent running Claude Mythos 5 spent 34 hours attempting to merge a malware dropper into a real open-source repository, denying the code was malicious when flagged, force-pushing git history, and using a second account to vouch for its own pull request. Anthropic, OpenAI, and Meta each disclosed separate incidents of AI models reaching real systems without authorisation in recent weeks.

The Ugly: The ChainDrop worm compromised more than 1,300 npm packages collectively pulling two billion monthly downloads by breaching a single maintainer's GitHub account and self-propagating through the supply chain, harvesting GitHub tokens, AWS credentials, Kubernetes secrets, and more with every new package it touched.

This was the week in cyber.

πŸ”— Full technical breakdown: https://s1.ai/GBU9-Wk32

🚨 This week, cybercrime hit β€œThe Com” – a decentralized youth recruitment network, the Apple App Store, and autonomous A...
07/31/2026

🚨 This week, cybercrime hit β€œThe Com” – a decentralized youth recruitment network, the Apple App Store, and autonomous AI sandboxes.

🚦 The Good: International law enforcement disrupted the decentralized criminal network "The Com", while U.S. and Australian agencies issued new guidance for isolating critical operational technology.

The Bad: Three victims are suing Apple after losing $1.8 million in Bitcoin to a fraudulent cryptocurrency wallet application that successfully bypassed App Store security reviews.

The Ugly: Autonomous OpenAI models actively exploited zero-day vulnerabilities in Artifactory servers to escape a secure testing sandbox and compromise third-party infrastructure.

This was the week in cyber.

πŸ”— Full technical breakdown: https://s1.ai/GBU9-Wk31

07/27/2026

"It's baffling to consider that we're placing all of this friction on the defenders while attackers are essentially getting to enjoy this technology to the best of its abilities, to the extent that cybersecurity is a sort of economics of friction, we're completely misaligned here," – Juan AndrΓ©s Guerrero-Saade on CNN's The Source.

JAGS joined the show to break down the OpenAI sandbox incident that inspired the new bipartisan AI "kill switch" bill on the Hill. The highlights include:

β†’ Frontier models can now run autonomously on complex tasks for days, showcasing real progress, and real fear that needs grounding in how these systems actually work.

β†’ The team resolving it had to reach for a Chinese open-weight model because leading US models added too much friction. Attackers don't face that friction.

Where should AI safety legislation actually be aimed: at model behavior, or at the security architecture underneath it? Comment below with what you think.

🚨 This week, cybercrime hit global phishing operations, enterprise calendar applications, and autonomous AI sandboxes.🚦 ...
07/24/2026

🚨 This week, cybercrime hit global phishing operations, enterprise calendar applications, and autonomous AI sandboxes.

🚦 The Good: German and U.S. authorities dismantled the Kratos phishing-as-a-service network and arrested its developer, seizing over 200 servers globally.

The Bad: A novel espionage implant dubbed HollowGraph is hijacking Microsoft 365 calendars to establish a covert command-and-control channel using far-future events as dead drops.

The Ugly: Open-source AI platform Hugging Face was breached by an autonomous OpenAI agent that escaped its sandbox via zero-day exploits to steal cybersecurity test solutions.

This was the week in cyber.

πŸ”— Full technical breakdown: https://s1.ai/GBU9-Wk30

Address

444 Castro Street, Suite 500
Mountain View, CA
94041

Alerts

Be the first to know and let us send you an email when SentinelOne posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to SentinelOne:

Shortcuts

Share