Skip to main content

Tag: threat detection

184 articles

Corporate meeting room with conference table, chairs, and a partially filled diagram on the wall.

Securing Enterprise AI Requires Lifecycle Approach

The AI revolution is here, with nearly a third of organizations already leveraging AI for threat detection and incident response, and 63% expecting full integration by 2027 - but a staggering 73% of IT security leaders admit their organization wouldn't be ready for a major cyberattack. As AI adoption accelerates, the gap between usage and security readiness is growing alarmingly.

Analyst 207
Empty office corridor with cubicles and private offices, laptop screen blurred in foreground.

Security Leaders Warn of Evolving Insider Threats

Insiders pose a uniquely potent threat because they already have the keys to the kingdom - and traditional defenses often miss the mark by relying on alerts that don't account for the devastating impact of trusted accounts gone rogue. To stay ahead, defenders must validate their readiness against insider threats by asking tough questions about access, escalation, and lateral movement.

Analyst 207
Security analysts work amidst multiple computer screens in a monitoring room with subtle signs of disarray.

CISA Red Team Tests Expose Organizational Vulnerabilities

CISA's red team tests revealed some eye-opening vulnerabilities, with the team slipping past security operations centers undetected, gaining access to workstations, escalating privileges, and moving freely between systems. This simulated cyber attack exposed weaknesses in critical infrastructure organizations, highlighting areas for improvement in detecting and responding to threats.

Analyst 207
Security analysts work at computer stations in a high-tech operations center with multiple screens displaying data…

AI-Powered SOCs Disrupt Traditional Alert Queue Model

The traditional Security Operations Center (SOC) model is broken, relying on an outdated alert queue that leaves most threats uninvestigated. AI-powered SOCs are changing the game with a new architecture that uses software agents to transform the queue into a continuous investigation engine.

Analyst 207
Security analysts work at a large workstation in a brightly-lit operations center with multiple screens and a city view.

AI Platforms Shine in SOCs with Clear Roles

Discover how AI platforms are revolutionizing Security Operations Centers (SOCs) by taking on high-level roles and freeing teams to focus on critical threats. By integrating with existing security tools, these platforms enable teams to efficiently sift through millions of alerts and catch potential threats that might otherwise fly under the radar.

Analyst 207
A dimly lit server room with rows of computer servers and network equipment on racks, surrounded by neatly organized cables…

Kaspersky's Network Anomaly Detection Exposes Stealthy Attacks

Stay one step ahead of sneaky attackers with Network Anomaly Detection, a powerful tool that uncovers stealthy threats like Kerberoasting and DNS tunneling that often evade signature-based security tools. By spotting unusual network activity, you can shut down hidden attacks before they cause damage.

Analyst 207
Modern tech facility with a laptop on a neutral surface, surrounded by blurred screens and devices, conveying innovation…

Okta Bolsters Identity Security with Permiso Acquisition

Okta is taking identity security to the next level with its acquisition of Permiso Security, bringing together cutting-edge threat detection and response capabilities with its existing identity stack to provide unparalleled protection. This game-changing move will enable Okta to spot and respond to risks that emerge after users, machines, or AI-driven agents have authenticated.

Analyst 207
Security analysts work at computer stations in a brightly-lit operations center surrounded by multiple screens displaying…

SIEM Gaps Expose 40% of Attacks

A whopping 40% of attacks slip through undetected due to glaring gaps in Security Information and Event Management (SIEM) systems, leaving organizations alarmingly exposed.

Analyst 207
Futuristic security operations center with large screen and devices on a modern table.

Microsoft Unveils AI-Powered Security Tools to Counter Emerging Threats

Microsoft is fighting back against emerging threats with AI-powered security tools, leveraging the power of agentic AI to help defenders stay one step ahead. By deploying specialized "red, blue, and green" agents, the company's new Project Perception system continuously identifies, evaluates, and reduces security risks.

Analyst 207
Futuristic cybersecurity system with transparent glass-like structure surrounded by subtle ambient lights.

Microsoft Unveils AI-Powered Cybersecurity Tools in Heated Market

Microsoft just launched Project Perception, an AI-powered security platform that supercharges cyber defense by merging multiple components into a continuously learning system that can reason, prioritize, and act at lightning-fast machine speed. This game-changing tech combines human oversight with powerful automation to revolutionize the way we fight cyber threats.

Analyst 207
Diverse professionals gather around a large table in a bright, neutral room, engaged in discussion and reviewing technology.

NVIDIA Launches Open Secure AI Alliance to Share Threat-Detecting Tech

Join the Open Secure AI Alliance, a groundbreaking coalition of 37 industry leaders, as they revolutionize AI security by sharing cutting-edge threat-detecting technologies and collaborative defense strategies. Together, they're breaking down silos to safeguard the future of AI and software development.

Analyst 207
Sleek computer terminal with futuristic security props on minimalist background.

Microsoft Unveils AI-Powered Security Model to Outperform Rivals

Microsoft just unveiled a game-changing AI-powered security model that has achieved a remarkable 95.95 percent success rate in identifying vulnerabilities, leaving the competition in the dust. This innovative model, combined with the MDASH harness, is poised to revolutionize bug hunting and cybersecurity.

Analyst 207
Security operations center analyst working at a workstation with multiple monitors and equipment.

Evaluating AI in Security Operations Requires New Framework

When evaluating AI in security operations, it's crucial to determine if it can deliver accurate verdicts across various scenarios and attack surfaces - and surprisingly, verdict quality only improves dramatically once a certain threshold of relevant data, such as identity and context, is reached. Below that threshold, no amount of fine-tuning can compensate.

Analyst 207
Cybersecurity pro stands by whiteboard, surrounded by laptop and notes, looking concerned.

SANS Warns of AI Governance Gap as Security Teams' Confidence Eroding

Despite a significant surge in AI adoption, with 78% of organizations now using AI in their cybersecurity strategy, a growing number are facing a harsh reality: 63% report major gaps in threat detection and response. This alarming trend highlights a pressing need for better AI governance to bridge the confidence gap.

Analyst 207
Modern office workspace with laptop, papers, and blurred computer screen.

Microsoft Ramps Up Vulnerability Detection with AI-Driven Scanning Tools

Microsoft is supercharging its vulnerability detection capabilities with AI-driven scanning tools, which will soon lead to a surge in Windows updates as more zero-day vulnerabilities are uncovered. Get ready for a higher volume of security updates, as AI helps defenders identify and address issues faster than ever before.

Analyst 207
Security analysts work in a SOC with a large screen displaying a network graph and various security metrics on a console…

AI SOC Platforms Face Test of Predictive Power

Meet Mike Shannon, Guardant Health's Director of Security Engineering, who's ditched manual queries for Exabot - a game-changing AI solution that's revolutionizing the way security teams operate. By harnessing the power of AI SOC platforms, organizations can now automate core security tasks, freeing up teams to focus on high-stakes threats.

Analyst 207
Empty corporate IT room with server racks and workstations, one out-of-focus laptop screen visible.

Kaspersky Compromise Assessments Reveal Persistent Detection Gaps

Kaspersky's 2025 Compromise Assessment analysis reveals a shocking truth: 60% of incidents go undetected due to a lack of reliable alerts from existing tools, while manual detection accounts for only 20% of discovered threats. This blind spot allows threats to hide for alarmingly long periods, with 30.8% of incidents having a dwell time of over three months.

Analyst 207
Person at desk with laptop and smartphone looks concerned amidst papers and notes.

Cybersecurity Gaps Exposed in Non-Email Threat Detection

As cybercriminals shift their focus from email to other trusted channels, a glaring gap in non-email threat detection has emerged, leaving organizations vulnerable to attacks on messaging and social platforms. A recent survey of cybersecurity pros reveals that while 60% of attacks now target non-email channels, half of respondents admit their organizations lack confidence in detecting these threats.

Analyst 207
Security analysts work at computer stations in a bright, daytime operations center surrounded by multiple screens…

Managed Detection and Response Hits Limits in AI-Powered Attack Era

The traditional Managed Detection and Response model is struggling to keep up with the evolving threat landscape, leaving nearly 1% of real threats hidden in low-severity alerts that often go unreviewed. This means that in a typical enterprise generating 450,000 alerts annually, hundreds of potential security incidents may be slipping through the cracks.

Analyst 207
Office worker sits at desk with laptop, surrounded by papers, with a concerned expression.

Browser-Based Phishing Attacks Evade Detection by Cybersecurity Software

Most cybersecurity tools are doing their job - but that's exactly the problem, as they're not designed to catch attacks that occur at the browser session layer, where attackers are now hiding. One in five phishing attacks on enterprise browsers slip through undetected, according to Menlo Security's latest report.

Analyst 207
Security team working in office with computer screens and natural daylight pouring in through a large window.

EDR Adoption Falls Short on Cyber Resilience

Many organizations have invested in advanced endpoint detection and response (EDR) platforms, but struggle to turn that visibility into real-world protection, leaving them vulnerable to cyber threats. The harsh reality is that EDR is only as effective as the team's ability to act on its alerts.

Analyst 207
Security analysts work together in a brightly-lit operations center surrounded by multiple data screens and monitors.

SIEM Helps MSPs Filter Out Noise, Accelerate Threat Detection

MSPs are drowning in a sea of security alerts, but the real challenge is cutting through the noise to identify genuine threats. When endpoint, identity, cloud, and network sensors operate in isolation, duplicate alerts and blind spots create an incomplete picture, making it tough to prioritize and respond to potential threats.

Analyst 207
Security professionals monitor threat detection interface in a brightly-lit operations center.

SOCs Shut Down Incident Risks with Proactive Threat Detection

Stay ahead of incident risks with proactive threat detection from ANY.RUN's Threat Intelligence Feeds, which deliver a continuous stream of high-confidence threat data from a vast network of organizations and SOC professionals. By shrinking the time between detection and understanding, modern Security Operations Centers (SOCs) can effectively shut down threats before they cause harm.

Analyst 207
Security analyst working at a workstation surrounded by screens in a bright operations center.

Phishing Attacks Expose Gaps in Early Detection

In just 40 seconds, ANY.RUN's interactive sandbox exposed the full attack chain of a phishing attack, revealing redirects, fake pages, and signs of possible remote access. This game-changing tool helps teams detect phishing threats early, providing concrete evidence of business exposure before it's too late.

Analyst 207