Tag: detection
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…
-
BSidesCharm 2026 Finding Badness With The Threat Detection And Response Lifecycle
Presenter: Shawn Thomas Our thanks to BSidesCharm for publishing their Creators, Authors and Presenter’s outstanding BSidesCharm 2026 content on the Organizations’ YouTube Channel. Permalink First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/bsidescharm-2026-finding-badness-with-the-threat-detection-and-response-lifecycle/
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
AI Agent Threat Response: Why Pre-Runtime Controls Matter More Than Runtime Detection
AI agent threat response starts before runtime. See why pre-runtime credential controls stop agent misuse that runtime detection can only observe. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/ai-agent-threat-response-why-pre-runtime-controls-matter-more-than-runtime-detection/
-
How Threat Research and MDR Help SMBs Build a Defensive Edge
Threat research gives security teams insight into how attackers operate, while MDR turns that intelligence into faster detection and response. ESET explains how combining threat intelligence, continuous monitoring, and human expertise can help SMBs strengthen their defenses. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-threat-research-and-mdr-help-smbs-build-a-defensive-edge/
-
AWS Security Teams Can Correlate CloudTrail, VPC and Route 53 Logs to Detect Attacks
AWS security teams can improve detection of multi-stage intrusions by correlating API activity in CloudTrail with network metadata in VPC Flow Logs and DNS activity in Route 53 Resolver query logs. The approach turns isolated alerts into an attack narrative spanning credential abuse, reconnaissance, privilege escalation, lateral movement and data exfiltration. A suspicious GetCallerIdentity request…
-
Stop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)
In Part 1 of this series, we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series, we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you are essentially building a robotic…
-
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
The SOC we’ve always known was built around a model that guarantees most of the alert queue will never receive analyst review. There’s never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity score. The issue then waits for a human to decide…
-
False Positive Elimination: How Runtime Context Saves Developer Time
<div cla TL;DR Traditional application security tools generate false-positive vulnerability findings because they analyze code patterns without execution context, flagging vulnerabilities in code that never runs with untrusted data. Runtime instrumentation solves this by observing actual production behavior, revealing that only a small percentage of flagged vulnerabilities are truly exploitable. Reducing application security false positives…
-
How ‘Subtractive’ Security Erases Attack Paths
Chris Frenz, Rectangle Health CISO, on Reducing Risk From Attackers in Healthcare. Healthcare security teams can reduce cyber risk by removing attacker options before an incident occurs rather than relying primarily on detection and response, said Chris Frenz, CISO at Rectangle Health, describing a new subtractive-hardening architecture standard he developed for OWSAP. First seen on…
-
Foul Language: WordlistLoader Disguises Malware as Ordinary Text
ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer. First seen on darkreading.com Jump to article: www.darkreading.com/data-privacy/wordlistloader-disguises-malware-ordinary-text
-
What the latest UAE cyber attacks reveal about threats to critical sectors
ThreatLocker CEO Danny Jenkins explains why aviation, energy and education organisations remain attractive targets, and why prevention should take precedence over detection First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649634/What-the-latest-UAE-cyber-attacks-reveal-about-threats-to-critical-sectors
-
The Network Access Debt AI Is Making Harder to Ignore
Tags: access, ai, cloud, cybersecurity, detection, endpoint, identity, network, threat, vulnerability, vulnerability-managementFor the last decade, cybersecurity has responded to an evolving threat landscape by adding new layers of defense. Organizations invested in endpoint security, identity, cloud security, vulnerability management, detection and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-network-access-debt-ai-is-making-harder-to-ignore/
-
Understanding detection coverage and blind spots for UK SMEs
For many UK SMEs, the real question is not whether you have security tools in place, but whether those tools would actually spot a problem in time. A business can spend money on antivirus, logging, and monitoring, yet still miss the events that matter most. That gap is what we mean by detection coverage and……
-
New Agent Tesla malware version uses emoji obfuscation to evade detection
First seen on scworld.com Jump to article: www.scworld.com/brief/new-agent-tesla-malware-version-uses-emoji-obfuscation-to-evade-detection
-
New Agent Tesla malware version uses emoji obfuscation to evade detection
First seen on scworld.com Jump to article: www.scworld.com/brief/new-agent-tesla-malware-version-uses-emoji-obfuscation-to-evade-detection
-
Rethinking Threat Intelligence: New Tactics for the Age of AI
Joe Hladik, head of Rubrik Zero Labs, sat down with the CEO and founder of the Techstrong Group, Alan Shimel, at Black Hat 2026 to talk about how Zero Labs is taking novel approaches to threat intelligence. One emerging source of threat intelligence, Hladik said, has historically been overlooked in threat detection: backup data. “When..…
-
New Agent Tesla Malware Variant Boosts Evasion Capabilities
An Agent Tesla v4 malware campaign used novel emoji-based code obfuscation to evade detection, KnowBe4 has revealed First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/agent-tesla-malware-evasion/
-
Black Hat 2026: What should you be allowed to talk to AI about? FireTail Blog
Tags: ai, attack, business, conference, control, cybersecurity, data, detection, edr, framework, LLM, strategy, technology, tool, vulnerability, vulnerability-managementAug 21, 2026 – Jeremy Snyder – If you were at RSA Conference last year, you probably remember the goats. Or the puppies. Or the miniature petting zoos. It was a year of “over-the-top” spectacle. A bit of a circus, if I’m being honest.Coming into RSAC 2026, the vibe shifted. The show floor was noticeably…
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman. One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making bets with his colleagues about various wartime events in Europe.…
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman. One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making bets with his colleagues about various wartime events in Europe.…
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman. One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making bets with his colleagues about various wartime events in Europe.…
-
The Trust Gap Filigran Found at Black Hat
Tags: detectionWalk the floor at Black Hat long enough, and the pitches start to blur. Everyone is touting better visibility, faster detection, and sharper prioritization. But a few feet away from the booths, the conversations become more interesting. Practitioners and senior decision-makers from the same organizations describe their exposure management programs in different terms, and the..…

