[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fElXKv3rtpDqxZwBdT23waixZYN60zIS60b2l_qgkPy0":3},{"article":4,"iocs":40,"watch_terms":41},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":20,"category":21,"article_tags":24},"d95f74d1-913a-4430-86ae-85fca6b6e864","🔒 Firmware persistence is real\n\nCampaigns like ArcaneDoor deploy bootkits that live below the OS...","firmware-persistence-is-real-campaigns-like-arcanedoor-deploy-bootkits-that-live-5d5878","🔒 Firmware persistence is real\n\nCampaigns like ArcaneDoor deploy bootkits that live below the OS.\n\nThey survive reboots.\nThey suppress logs.\nThey stay invisible.","The ArcaneDoor campaign leverages firmware-level bootkits to achieve persistence that survives reboots and evades detection by operating below the operating system. These bootkits suppress logging and maintain invisibility, making them difficult to detect and remove through conventional security measures. This represents a significant escalation in adversary sophistication and capability.","ArcaneDoor campaign deploys firmware bootkits for persistent below-OS access.",null,"https:\u002F\u002Fx.com\u002FSentinelOne\u002Fstatus\u002F2042288867227914372","2026-04-09T17:09:44+00:00","2026-04-09T18:00:13.818825+00:00",9,[17],{"name":18,"type":19},"ArcaneDoor","campaign","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":20,"icon":11,"name":22,"slug":23},"Malware","malware",[25,30,35],{"category":26},{"id":27,"icon":11,"name":28,"slug":29},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":31},{"id":32,"icon":11,"name":33,"slug":34},"d6f63bb8-0801-486a-be7f-171400700454","IoT\u002FOT","iot-ot",{"category":36},{"id":37,"icon":11,"name":38,"slug":39},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[],[]]