Sign in

SentinelOne

@sentinelone.com
950 followers 13 following 485 posts

The world’s most advanced, autonomous AI-powered cybersecurity platform. We empower the world to run securely, with leading organizations trusting us to Secure Tomorrow™. Secure your enterprise: sentinelone.com/request-demo

PostsRepliesMedia
SentinelOne @sentinelone.com · 11/08/2026
How do you start an autonomous SOC? Listen to this breakdown of approachable steps overheard at #BHUSA: ⚙️ Refine your data 👥 Grant agents small amounts of access 🔁 Start with reversible actions (quarantine files, don't isolate hosts) 🤝 Widen scope as trust is earned Crawl, walk, run.
010
SentinelOne @sentinelone.com · 08/07/2026
Long-running AI agents face a memory problem, but compaction fixes it. SentinelLABS tested OpenAI’s compaction on a reverse-engineering harness: input tokens fell 86% and output fell 31%, with no loss in accuracy. Working memory stays in context; evidence goes to storage. s1.ai/CE-Compact
000
Reposted by SentinelOne
The Vertex Project @vertexproject.bsky.social · 02/06/2026
New Signals & Stories episode with @hegel.bsky.social from @sentinelone.com & @invisig0th.bsky.social We discuss: 🔹DPRK IT workers posing as job applicants 🔹Cross-functional intelligence sharing 🔹AI in CTI 🔹And more! #CyberSecurity #CTI #ThreatIntelligence www.youtube.com/watch?v=uQ1_...
1146
SentinelOne @sentinelone.com · 18/05/2026
Full research from @philofishal.bsky.social: s1.ai/shub-reaper
s1.ai
SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
SHub Reaper bypasses Apple's Terminal mitigation, steals credentials and documents, and plants a persistent backdoor for continued access after infection.
011
SentinelOne @sentinelone.com · 18/05/2026
The lesson for defenders isn't "watch for Reaper." It's that brand recognition is not a signal of safety — it signals the attack. Unexpected AppleScript activity, outbound traffic after Script Editor runs, LaunchAgents in trusted-vendor namespaces — that's where to look.
100
SentinelOne @sentinelone.com · 18/05/2026
Microsoft, Apple, Google — in that order, in one chain. The victim never sees a single unfamiliar name.
100
SentinelOne @sentinelone.com · 18/05/2026
- The lure: a fake WeChat or Miro installer - The delivery: a typo-squatted domain, mlcrosoft[.]co[.]com - The execution: dressed up as an Apple XProtectRemediator security update - The persistence: a fake Google Software Update directory, beaconing every 60 seconds
100
SentinelOne @sentinelone.com · 18/05/2026
A new macOS stealer called Reaper — a SHub variant tracked by @sentinellabs.bsky.social — runs an infection chain where each stage hides behind a different trusted brand.
121
SentinelOne @sentinelone.com · 13/05/2026
Today’s attacks are credentials nobody rotated and a model left isolated. 📄 The 2026 AI & Cloud Verified Exploit Paths & Secrets Scanning Report: s1.ai/AISecrets 🔗 The Accompanying Blog: s1.ai/AISecr-Bl
s1.ai
AI & Cloud Exploit Paths and Secrets Report 2026 | SentinelOne
AI & Cloud Exploit Paths and Secrets Report 2026: Uncovers LLM keys, cloud credentials and attack chains from 11K+ environments. Reduce risk and scale.
010
SentinelOne @sentinelone.com · 13/05/2026
This is what a realistic AI-era attack chain looks like. Drawn from 11,000+ anonymized cloud environments in our 2026 report. No zero-day. No prompt injection research paper. No novel technique. What we see instead is a misconfigured bucket, one hardcoded key, and a model connected to a CRM.
120
SentinelOne @sentinelone.com · 07/05/2026
“At SentinelOne, the real value of AI is how quickly it helps us turn signals into an actionable advantage for defenders. GPT-5.5 helps analysts connect telemetry, focus on what matters, and strengthen how organizations investigate, detect, and respond to emerging threats.”
000
SentinelOne @sentinelone.com · 07/05/2026
Frontier AI isn't being built in isolation. Neither is the frontier of cyber defense. That’s why we’re proud to be a partner in OpenAI’s Trusted Access for Cyber (TAC) Program. Read more: s1.ai/GPT5-5Cyb
100
SentinelOne @sentinelone.com · 07/05/2026
The cloud attack ecosystem is developing competitive dynamics as it evolves. Full analysis by @sentinellabs.bsky.social researcher @alex.leetnoob.com: s1.ai/pcpjack
s1.ai
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
Cloud attack framework skips cryptomining, harvests financial, messaging, and enterprise credentials for fraud, spam, and potential extortion.
020
SentinelOne @sentinelone.com · 07/05/2026
💀 Deploys Sliver C2 beacons via a second toolset, compiled with garble obfuscation to defeat signature detection 🚫 Zero cryptomining. None. In a world where every cloud worm drops XMRig eventually, this one doesn't. It's going straight for credential monetization, extortion, and fraud.
100
SentinelOne @sentinelone.com · 07/05/2026
🔑 Steals cloud credentials across AWS, Kubernetes, Docker, Slack, GitHub, Stripe, and 30+ other services 🌐 Propagates externally using Common Crawl parquet data — a legitimate web archive nonprofit — as its target list
100
SentinelOne @sentinelone.com · 07/05/2026
What PCPJack does after it wins the turf war:
100
SentinelOne @sentinelone.com · 07/05/2026
This isn’t a theory—it’s in the code. PCPJack specifically kills TeamPCP processes and even reports a "PCP replaced" metric back to its C2.
100
SentinelOne @sentinelone.com · 07/05/2026
Threat actors are in a turf war for ownership of your infrastructure. @sentinellabs.bsky.social has uncovered PCPJack, a predatory cloud credential worm that hunts its own kind. Its first move? A scorched-earth eviction of rival group TeamPCP.
110
SentinelOne @sentinelone.com · 06/05/2026
🗞️ WIRED's full story: s1.ai/WIRED-F16 📄 Full SentinelLABS’s report: s1.ai/fast16
s1.ai
Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet
Researchers have finally cracked Fast16, mysterious code capable of silently tampering with calculation and simulation software. It was created in 2005—and likely deployed by the US or an ally.
020
SentinelOne @sentinelone.com · 06/05/2026
In this @wired.com video about fast16, @agreenberg.bsky.social walks through the whole arc: A 2005 malware that sat in plain sight, the NSA leak that named it, and what @sentinellabs.bsky.social's Vitaly Kamluk and @jags.bsky.social finally figured out it was doing.
3319
SentinelOne @sentinelone.com · 30/04/2026
In the era of frontier AI models, the question isn't what vulnerabilities exist. It's what an adversary can actually chain together to exploit today. The answer lives not in the model or the SOC, but in the loop between them. And that loop is what we're unveiling. 🔗 Learn more: s1.ai/Claude-WF
s1.ai
Wayfinder Frontier AI Services: Expose Risks | SentinelOne
Wayfinder Frontier AI Services from SentinelOne deliver exposure intelligence to identify high-priority risks, reduce the attack surface, and stop attacks fast.
000
SentinelOne @sentinelone.com · 30/04/2026
Continuous discovery using the most advanced frontier models. Real exploitability, not paper risk. Mitigations that break attack chains before adversaries finish them.
100
SentinelOne @sentinelone.com · 30/04/2026
Introducing Wayfinder Frontier AI Services, powered by @anthropic.com's Claude Security, delivered by SentinelOne’s elite cybersecurity pros.
s1.ai
Wayfinder Frontier AI Services: Expose Risks | SentinelOne
Wayfinder Frontier AI Services from SentinelOne deliver exposure intelligence to identify high-priority risks, reduce the attack surface, and stop attacks fast.
100
SentinelOne @sentinelone.com · 30/04/2026
Frontier model. Frontier operators. Real threats, stopped before they become attacks.
100
SentinelOne @sentinelone.com · 29/04/2026
Hosted by @sentinellabs.bsky.social. A program committee with reviewers from Google, Netflix, Dartmouth, Johns Hopkins, and SentinelLABS. Malware, exploits, APTs, cybercrime — any platform. Original work only. No vendor theater. Bring the paper. Deadline June 19.
010
SentinelOne @sentinelone.com · 29/04/2026
LABScon 2026 Call for Papers is open. Sept 16–19, Scottsdale. Invite-only. Fifth year.
labscon.io
LABScon - Security Research in Real Time | LABScon
Join us September 16-19th for LABScon, an intimate, invite-only event for the top cybersecurity minds to gather, share cutting-edge research.
111
SentinelOne @sentinelone.com · 23/04/2026
The implications reach into advanced physics, cryptographic research, and nuclear programs.
wired.com
Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet
Researchers have finally cracked Fast16, mysterious code capable of silently tampering with calculation and simulation software. It was created in 2005—and likely deployed by the US or an ally.
000
SentinelOne @sentinelone.com · 23/04/2026
Meet fast16 — compiled in 2005, five years before Stuxnet. It isn't espionage. It's not ransomware. It's a precision instrument designed to make scientists trust math that's been quietly broken. Silently. Precisely. Across an entire network.
100
SentinelOne @sentinelone.com · 23/04/2026
The history of cyberwar just got rewritten with a new @sentinellabs.bsky.social discovery by Vitaly Kamluk and @jags.bsky.social. Stuxnet wasn't the beginning of nation-state sabotage through software. It was just the first one we caught. Read the full @wired.com story by @agreenberg.bsky.social 👇
166
SentinelOne @sentinelone.com · 01/04/2026
The critical question isn’t how hard AI is to implement today. It’s what your organization looks like once it isn’t. Read the full analysis: s1.ai/BlindSpot
s1.ai
The Implementation Blind Spot | Why Organizations Are Confusing Temporary Friction with Permanent Safety
Our new blog post explores the ‘cognitive rust belt’ — how AI friction masks skill loss and why organizations must act now.
010
SentinelOne @sentinelone.com · 01/04/2026
By automating the "grunt work" of junior analysts, organizations aren't increasing efficiency. They are removing the very gym that builds the mental muscles for high-level judgment. 🧠💪
100
SentinelOne @sentinelone.com · 01/04/2026
In this blog, Chris St.Myers argues that organizations feel "safe" today because AI is still hard to use. They are busy debugging prompts and fixing hallucinations. But this technical friction is masking a long-term problem.
100
SentinelOne @sentinelone.com · 01/04/2026
3️⃣ Which "wasteful" manual skills are you currently eliminating that are actually the essential training data for your future leaders?
100
SentinelOne @sentinelone.com · 01/04/2026
2️⃣ Are you building workflows that require active human trade-offs, or "verification loops" where a human just clicks "approve"?
210
SentinelOne @sentinelone.com · 01/04/2026
1️⃣ If your senior staff retired tomorrow, could your juniors replicate their "smell test" decisions using only the AI tools provided?
100
SentinelOne @sentinelone.com · 01/04/2026
These questions aren’t being asked by most organizations not because they're careless, but because the cost doesn't show up until you need it and discover you can't rebuild it on demand. This is the Cognitive Rust Belt.
100
SentinelOne @sentinelone.com · 01/04/2026
The biggest risk in your AI strategy? What quietly disappears when AI handles the work that builds expertise. Here are three questions to pressure-test your exposure👇
100
SentinelOne @sentinelone.com · 24/03/2026
🔗 Download the Defender's Guide: s1.ai/Thrt-Rprt
s1.ai
Annual Threat Hunting Report 2026
Discover key cyber threats in SentinelOne’s 2026 Threat Hunting Report, including identity abuse, MFA bypass, and automation-driven attack tactics.
000
SentinelOne @sentinelone.com · 24/03/2026
Living Off the Pipeline: Compromise software pipelines enable code injection and secret theft. The Machine Multiplier: Automation—not just AI—is compressing response windows to seconds, not days.
100
SentinelOne @sentinelone.com · 24/03/2026
The Modern Defender's Battlefield: The Identity Paradox: Adversaries look like your most productive employees. Edge Decay: Unmanaged, legacy infrastructure is being weaponized at industrial scale.
100
SentinelOne @sentinelone.com · 24/03/2026
This defender’s guide isn't a collection of stats or "actor branding"—it’s a deep dive into the mechanics of how adversaries exploit organizational blind spots.
100
SentinelOne @sentinelone.com · 24/03/2026
The SentinelOne Annual Threat Report reveals a fundamental shift: adversaries are no longer just "hacking in". They are using authorized credentials, automation, and legacy systems to break human-centered defense.
100
SentinelOne @sentinelone.com · 24/03/2026
Adversaries are now industrializing the breach. SentinelOne’s new Annual Threat Report is officially out, and this is one of the key takeaways. Targeting core systems like identity, infrastructure, and automation is not new—but executing these tactics at an industrial scale is.
100
SentinelOne @sentinelone.com · 19/03/2026
Reliability in AI Security comes from the pipeline structure, not just the model. Read the full technical breakdown by @philofishal.bsky.social: s1.ai/advers-llm
010
SentinelOne @sentinelone.com · 19/03/2026
↪️ Deterministic Integrity: We chose custom bridge scripts over MCP to ensure 100% data extraction and lower latency. ↪️ High-Fidelity Results: Reports are cross-validated and every capability is anchored to a specific virtual address.
100
SentinelOne @sentinelone.com · 19/03/2026
↪️ The Serial Pipeline: r2, Ghidra, Binary Ninja, and IDA Pro act as independent analysts, verifying or rejecting each other’s findings in a chain. ↪️ The Gauntlet: Reliability is enforced through an "Active Rejection Mandate," forcing agents to act as highly skeptical peers.
100
SentinelOne @sentinelone.com · 19/03/2026
Here’s how our Adversarial Consensus Engine for reversing macOS malware works 👇
100
SentinelOne @sentinelone.com · 19/03/2026
Individual LLM tools often fail at malware reversing because they amplify “noise.” They produce confident but unreliable results contaminated by decompiler artifacts, dead code, and hallucinated capabilities.
100
SentinelOne @sentinelone.com · 19/03/2026
Want an AI malware analyst you can actually trust? @sentinellabs.bsky.social just built a multi-agent architecture that brings the rigor of human peer review to automated malware analysis. This Adversarial Consensus Engine doesn’t just “think,” but doubts. 🤔 🧵
120
SentinelOne @sentinelone.com · 17/03/2026
The irony? Every transaction is public and permanent on blockchains. While threat intel analysts face a race against time, the ledger never lies—if you know how to track the movement. Watch the full LABScon 2025 video: s1.ai/LC25-AM
s1.ai
LABScon25 Replay | Your Apps May Be Gone, But the Hackers Made $9 Billion and They’re Still Here
Andrew MacPherson exposes how crypto thieves exploit DeFi architecture, from the $1.5 billion Bybit heist to drainers-as-a-service and fund laundering.
000