Tag: detection
-
What Is Agentic MDR? Three Architectures Hide Behind One Label
Agentic MDR is managed detection and response delivered by AI agents that investigate and act on security alerts autonomously, under human-defined governance, in place of analysts working a queue. The service provider still owns the outcome. The work itself shifts… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/what-is-agentic-mdr-three-architectures-hide-behind-one-label/
-
Stopping Rogue AI Agents in Real Time
Capsule Security CEO Naor Paz joins Alan Shimel to explain why rogue AI agent detection is a runtime problem, not a posture one, and how inspecting intent drift can stop a dangerous tool call before it runs. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/stopping-rogue-ai-agents-in-real-time/
-
Black Duck Joins Project Glasswing to Strengthen AI-Era Software Security
Black Duck, a provider of AI-powered application security solutions, has announced its participation in Project Glasswing, Anthropic’s industry-wide initiative aimed at protecting critical software infrastructure through the defensive use of advanced AI. Through its involvement, Black Duck will integrate Mythos throughout its application security offerings, pairing AI-driven, deterministic vulnerability detection with established remediation processes, risk-based…
-
Mars Security Launches Real-Time Intel-to-Detection Engine That Turns Live Threat Intelligence Into Backtested Detections in Minutes
New York, NY, United States, 8th September 2026, CyberNewswire First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mars-security-launches-real-time-intel-to-detection-engine-that-turns-live-threat-intelligence-into-backtested-detections-in-minutes/
-
Mars Security Launches Real-Time Intel-to-Detection Engine That Turns Live Threat Intelligence Into Backtested Detections in Minutes
New York, NY, United States, 8th September 2026, CyberNewswire First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mars-security-launches-real-time-intel-to-detection-engine-that-turns-live-threat-intelligence-into-backtested-detections-in-minutes/
-
The 12 Best Antivirus (Endpoint Protection) Software for Business, Compared and Priced
Best value overall: Microsoft Defender for Endpoint, if you hold Microsoft 365 E5, you already own competitive enterprise endpoint protection and the marginal cost is zero. Best published pricing: Bitdefender and ESET, both of which let you budget without a sales call. Best detection: CrowdStrike. Best cleanup tool: Malwarebytes. One vendor on the standard […]…
-
The 12 Best Managed Firewall Services, Compared and Priced
Best value overall: Fortinet. Delivered directly and through the largest partner network in security, at price points the premium providers can’t approach provided you vet the actual delivery partner. Best detection quality: Secureworks. Best global reach: NTT Data. Best if you want to stop owning firewalls: Cato Networks. Best for SMB: Barracuda MSP. Managed firewall…
-
The 12 Best Network Security Policy Management Tools, Compared and Priced
Best value overall: Opinnate. It targets the gap the enterprise vendors leave open policy automation at a price mid-market organizations can actually approve and it’s the most accessible commercial model in this list. Best capability: AlgoSec and Tufin. Best for change detection: FireMon. Cheapest credible entry: ManageEngine, which is the only vendor here with genuinely…
-
The 12 Best Network Security Policy Management Tools, Compared and Priced
Best value overall: Opinnate. It targets the gap the enterprise vendors leave open policy automation at a price mid-market organizations can actually approve and it’s the most accessible commercial model in this list. Best capability: AlgoSec and Tufin. Best for change detection: FireMon. Cheapest credible entry: ManageEngine, which is the only vendor here with genuinely…
-
New $7 SweepLED Gadget Detects Hidden Cameras With 94% Accuracy in 5 Seconds
Researchers have developed SweepLED, a smartphone-based hidden-camera detection system that uses a low-cost LED accessory and computer vision to identify concealed lenses in under five seconds. The system is detailed in the research paper titled >>Hide-and-Sweep: Detecting Concealed Cameras via LED Illumination Sweeps.<< It is designed to help users identify covert cameras hidden in common…
-
Organizations Struggle to Detect, Contain OutScope AI Agents
Enterprises are confident in AI agent security, but weak least-privilege controls and slow detection reveal a growing governance gap. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/organizations-struggle-to-detect-contain-out-of-scope-ai-agents/
-
Ransomware protection for MSPs: A 6-point checklist for faster recovery
Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ransomware-protection-for-msps-a-6-point-checklist-for-faster-recovery/
-
Singularity Rootkit Bypasses Elastic Defend eBPF Module Load Detection
Security researcher has disclosed a technique used by the Singularity Linux rootkit to evade Elastic Defend by suppressing module-load telemetry to avoid detection across multiple layers. This research highlights how trusted-process exclusions in endpoint eBPF monitoring can become significant targets for advanced kernel-level threats. According to the report, Elastic Defend has monitored Linux kernel module…
-
How to Evaluate API Security and Abuse Detection Platforms
First seen on scworld.com Jump to article: www.scworld.com/buyers-guide/how-to-evaluate-api-security-and-abuse-detection-platforms
-
The HuntDetection Gap: Choosing an AI Threat Hunting Solution in 2026
If you’re in the market for an AI threat hunting solution, chances are you’re evaluating based on investigation quality. That’s an understandable and reasonable metric to go on investigation quality is important, and most vendors focus their marketing on it. It’s not, however, the most important metric. Pretty much every vendor has decent investigation The…
-
Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes
Failed SSH logins pile up in an auth log, and a scanner walks a website looking for exposed admin paths. CrowdSec reads log sources and HTTP requests, works out which … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/01/crowdsec-1-8-0-bot-detection/
-
ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool
ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something much more ordinary: an application that looks like adware and appears to…
-
Measuring detection coverage against MITRE ATTCK using DeTTCT
For many UK SMEs, the hardest part of detection engineering is not writing alerts. It is knowing whether the alerts you already have actually cover the techniques that matter. A SIEM or XDR platform can produce a lot of noise, but without a structured way to measure coverage you can end up with false confidence….…
-
Could a Pattern on Your Clothing Fool Facial Recognition? Interview with Bill Swearingen
Can a pattern on your clothing change what a camera thinks it sees? Tom talks with Black Hat USA 2026 speaker Bill Swearingen about adversarial clothing research, why person detection and facial recognition are different problems, and what model limitations mean for biometric surveillance, privacy, and accountability. ** Links mentioned on the show ** Black……
-
How to Detect Anomalous User Behavior in Your SaaS App with Node.js and Audit Logs
Build a lightweight behavioral anomaly detection layer on top of existing audit logs to catch suspicious logins, rapid exports, privilege changes and dormant-account abuse in real time. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-to-detect-anomalous-user-behavior-in-your-saas-app-with-node-js-and-audit-logs/
-
Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit
A newly analyzed phishing operation is using server-side polymorphism to generate a distinct credential-harvesting page for virtually every request, undermining detection approaches built around file hashes, fixed HTML identifiers, and static JavaScript signatures. The campaign came to light after a phishing message submitted to the SANS Internet Storm Center (ISC) pointed recipients to a URL…
-
Building a detection-as-code pipeline with Sigma and CI/CD
Detection engineering has matured beyond writing one-off SIEM rules by hand. For many UK SMEs, the practical next step is to treat detections as code: version them, review them, test them, promote them through environments, and measure whether they still do what you expect. That is where a detection-as-code pipeline with Sigma and CI/CD becomes……
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…

