SentinelOne / SentinelLabs
sentinellabs · B · active
https://www.sentinelone.com/labs/
SentinelLabs CTI/research arm, APT, ransomware, and cloud-native attack research (added 2026-05-08). 2026-05-08 audit: WebFetch returned 5 dated articles latest 2026-05-07 (PCPJack cloud worm, LABScon25 Replay sessions, Multi-Agent LLM malware analysis). RSS at https://www.sentinelone.com/labs/feed/ also works. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.sentinelone.com/labs/ (listing) then webfetch per-article URL; RSS at https://www.sentinelone.com/labs/feed/. AVOID: No issues; WebFetch works on listing and detail. Note recent feed is heavy on LABScon25 conference replays (still substantive technical writeups).. | 2026-07-05 admiralty audit: B, vendor threat-research lab, original malware/APT research; live and drillable. Status stays active.
Cited in 6 entries
Citation cadence
Citation days per ISO week (20 weeks of coverage span, total 6).
- TraderTraitor (Jade Sleet) compromises a non-cryptocurrency IT-services firm via a weaponized Terraform provider lockfile, resolving C2 through a Nostr-relay dead drop2026-09-21
- CVE-2025-25249, Fortinet FortiOS/FortiSwitchManager: unauthenticated CAPWAP heap overflow added to CISA KEV, actively exploited since July via the PivotC2 RAT2026-09-10
- Hugging Face: a fully autonomous AI agent breached production, ran 17,000+ actions before detection2026-07-21
- Espionage actors weaponise a citizen-facing e-government complaint portal as a watering hole, serving a fake 'portal update' that reflectively loads a RAT2026-07-10
- macOS.Gaslight, a DPRK-aligned Rust backdoor that targets the LLM-assisted analyst2026-06-26
- SentinelOne: "Living Off the Pipeline", CI/CD subversion taxonomy with three real intrusion cases (TeamCity, GitLab service-account pivot, Contagious Interview)2026-05-16