Arcseer Blog

Insights on offensive security and risk.

Research, threat intelligence, compliance guidance, and perspectives from practitioners who have been on both sides of the attack.

Research 10 min read

AI Penetration Testing: From Vulnerabilities to Attack Paths

Why autonomous AI penetration testing doesn't just find more weaknesses — it reasons about how an attacker would chain them into genuine business risk, and reports validated attack paths, not isolated findings.

Arcseer Research Team 22 July 2026
Threat Intelligence 8 min read

From left-pad to Mini Shai-Hulud: A Decade of NPM Supply Chain Attacks

Ten years and seven major incidents took npm supply chain attacks from a single unpublished package to a self-propagating worm with valid cryptographic provenance. Here is how we got from left-pad to Mini Shai-Hulud.

Arcseer Research Team 15 June 2026
Threat Intelligence 15 min read

We're Bracing for an AI-Driven Wave of Attacks - But What Will They Actually Look Like?

Anthropic has spent a year tracking how threat actors are weaponising AI. The findings challenge some of our most comfortable assumptions about where the danger really lies.

Arcseer Research Team 5 June 2026
Compliance 9 min read

The Expiring Security Snapshot

A fifth of cyber insurance claims now fail, most of them over a gap between what was attested and what was true.

Arcseer Research Team 27 May 2026
Threat Intelligence 8 min read

The Soft Underbelly: Why Shipbroking Is the Structural Blind Spot in Maritime Cyber Risk

Maritime cyber regulation points at the ship. The money moves through broker inboxes, email payment threads and unsigned instructions - and that is where attackers have learned to focus.

Arcseer Research Team 14 May 2026
Research 14 min read

Is It Negligent Not to Use AI in Your Security Assessment Programme?

Reid Hoffman argued doctors not using AI as a second opinion are bordering on malpractice. The same argument is beginning to apply to cyber security assessment.

Arcseer Research Team 28 April 2026
Research 11 min read

Ctrl+Alt+Delete: Is AI Finally Making Manual Pen Testers Obsolete?

The industry has spent two years asking whether AI can match a human pen tester. It is time to ask a more honest question: for how much of the work the industry actually delivers, has it already surpassed them?

Arcseer Research Team 22 February 2026
Threat Intelligence 6 min read

When Attackers Use AI, Defence Must Scale Too

State-sponsored groups, criminal enterprises, and lone actors are now using AI to conduct operations that previously required entire specialist teams. The turning point is not approaching. It has arrived.

Arcseer Research Team 18 December 2025