Tag: threat detection
184 articles

Securing Enterprise AI Requires Lifecycle Approach
The AI revolution is here, with nearly a third of organizations already leveraging AI for threat detection and incident response, and 63% expecting full integration by 2027 - but a staggering 73% of IT security leaders admit their organization wouldn't be ready for a major cyberattack. As AI adoption accelerates, the gap between usage and security readiness is growing alarmingly.

Security Leaders Warn of Evolving Insider Threats
Insiders pose a uniquely potent threat because they already have the keys to the kingdom - and traditional defenses often miss the mark by relying on alerts that don't account for the devastating impact of trusted accounts gone rogue. To stay ahead, defenders must validate their readiness against insider threats by asking tough questions about access, escalation, and lateral movement.

CISA Red Team Tests Expose Organizational Vulnerabilities
CISA's red team tests revealed some eye-opening vulnerabilities, with the team slipping past security operations centers undetected, gaining access to workstations, escalating privileges, and moving freely between systems. This simulated cyber attack exposed weaknesses in critical infrastructure organizations, highlighting areas for improvement in detecting and responding to threats.

AI-Powered SOCs Disrupt Traditional Alert Queue Model
The traditional Security Operations Center (SOC) model is broken, relying on an outdated alert queue that leaves most threats uninvestigated. AI-powered SOCs are changing the game with a new architecture that uses software agents to transform the queue into a continuous investigation engine.

AI Platforms Shine in SOCs with Clear Roles
Discover how AI platforms are revolutionizing Security Operations Centers (SOCs) by taking on high-level roles and freeing teams to focus on critical threats. By integrating with existing security tools, these platforms enable teams to efficiently sift through millions of alerts and catch potential threats that might otherwise fly under the radar.

Kaspersky's Network Anomaly Detection Exposes Stealthy Attacks
Stay one step ahead of sneaky attackers with Network Anomaly Detection, a powerful tool that uncovers stealthy threats like Kerberoasting and DNS tunneling that often evade signature-based security tools. By spotting unusual network activity, you can shut down hidden attacks before they cause damage.

Okta Bolsters Identity Security with Permiso Acquisition
Okta is taking identity security to the next level with its acquisition of Permiso Security, bringing together cutting-edge threat detection and response capabilities with its existing identity stack to provide unparalleled protection. This game-changing move will enable Okta to spot and respond to risks that emerge after users, machines, or AI-driven agents have authenticated.

SIEM Gaps Expose 40% of Attacks
A whopping 40% of attacks slip through undetected due to glaring gaps in Security Information and Event Management (SIEM) systems, leaving organizations alarmingly exposed.

Microsoft Unveils AI-Powered Security Tools to Counter Emerging Threats
Microsoft is fighting back against emerging threats with AI-powered security tools, leveraging the power of agentic AI to help defenders stay one step ahead. By deploying specialized "red, blue, and green" agents, the company's new Project Perception system continuously identifies, evaluates, and reduces security risks.

Microsoft Unveils AI-Powered Cybersecurity Tools in Heated Market
Microsoft just launched Project Perception, an AI-powered security platform that supercharges cyber defense by merging multiple components into a continuously learning system that can reason, prioritize, and act at lightning-fast machine speed. This game-changing tech combines human oversight with powerful automation to revolutionize the way we fight cyber threats.

NVIDIA Launches Open Secure AI Alliance to Share Threat-Detecting Tech
Join the Open Secure AI Alliance, a groundbreaking coalition of 37 industry leaders, as they revolutionize AI security by sharing cutting-edge threat-detecting technologies and collaborative defense strategies. Together, they're breaking down silos to safeguard the future of AI and software development.

Microsoft Unveils AI-Powered Security Model to Outperform Rivals
Microsoft just unveiled a game-changing AI-powered security model that has achieved a remarkable 95.95 percent success rate in identifying vulnerabilities, leaving the competition in the dust. This innovative model, combined with the MDASH harness, is poised to revolutionize bug hunting and cybersecurity.

Evaluating AI in Security Operations Requires New Framework
When evaluating AI in security operations, it's crucial to determine if it can deliver accurate verdicts across various scenarios and attack surfaces - and surprisingly, verdict quality only improves dramatically once a certain threshold of relevant data, such as identity and context, is reached. Below that threshold, no amount of fine-tuning can compensate.

SANS Warns of AI Governance Gap as Security Teams' Confidence Eroding
Despite a significant surge in AI adoption, with 78% of organizations now using AI in their cybersecurity strategy, a growing number are facing a harsh reality: 63% report major gaps in threat detection and response. This alarming trend highlights a pressing need for better AI governance to bridge the confidence gap.

Microsoft Ramps Up Vulnerability Detection with AI-Driven Scanning Tools
Microsoft is supercharging its vulnerability detection capabilities with AI-driven scanning tools, which will soon lead to a surge in Windows updates as more zero-day vulnerabilities are uncovered. Get ready for a higher volume of security updates, as AI helps defenders identify and address issues faster than ever before.

AI SOC Platforms Face Test of Predictive Power
Meet Mike Shannon, Guardant Health's Director of Security Engineering, who's ditched manual queries for Exabot - a game-changing AI solution that's revolutionizing the way security teams operate. By harnessing the power of AI SOC platforms, organizations can now automate core security tasks, freeing up teams to focus on high-stakes threats.

Kaspersky Compromise Assessments Reveal Persistent Detection Gaps
Kaspersky's 2025 Compromise Assessment analysis reveals a shocking truth: 60% of incidents go undetected due to a lack of reliable alerts from existing tools, while manual detection accounts for only 20% of discovered threats. This blind spot allows threats to hide for alarmingly long periods, with 30.8% of incidents having a dwell time of over three months.

Cybersecurity Gaps Exposed in Non-Email Threat Detection
As cybercriminals shift their focus from email to other trusted channels, a glaring gap in non-email threat detection has emerged, leaving organizations vulnerable to attacks on messaging and social platforms. A recent survey of cybersecurity pros reveals that while 60% of attacks now target non-email channels, half of respondents admit their organizations lack confidence in detecting these threats.

Managed Detection and Response Hits Limits in AI-Powered Attack Era
The traditional Managed Detection and Response model is struggling to keep up with the evolving threat landscape, leaving nearly 1% of real threats hidden in low-severity alerts that often go unreviewed. This means that in a typical enterprise generating 450,000 alerts annually, hundreds of potential security incidents may be slipping through the cracks.

Browser-Based Phishing Attacks Evade Detection by Cybersecurity Software
Most cybersecurity tools are doing their job - but that's exactly the problem, as they're not designed to catch attacks that occur at the browser session layer, where attackers are now hiding. One in five phishing attacks on enterprise browsers slip through undetected, according to Menlo Security's latest report.

EDR Adoption Falls Short on Cyber Resilience
Many organizations have invested in advanced endpoint detection and response (EDR) platforms, but struggle to turn that visibility into real-world protection, leaving them vulnerable to cyber threats. The harsh reality is that EDR is only as effective as the team's ability to act on its alerts.

SIEM Helps MSPs Filter Out Noise, Accelerate Threat Detection
MSPs are drowning in a sea of security alerts, but the real challenge is cutting through the noise to identify genuine threats. When endpoint, identity, cloud, and network sensors operate in isolation, duplicate alerts and blind spots create an incomplete picture, making it tough to prioritize and respond to potential threats.

SOCs Shut Down Incident Risks with Proactive Threat Detection
Stay ahead of incident risks with proactive threat detection from ANY.RUN's Threat Intelligence Feeds, which deliver a continuous stream of high-confidence threat data from a vast network of organizations and SOC professionals. By shrinking the time between detection and understanding, modern Security Operations Centers (SOCs) can effectively shut down threats before they cause harm.

Phishing Attacks Expose Gaps in Early Detection
In just 40 seconds, ANY.RUN's interactive sandbox exposed the full attack chain of a phishing attack, revealing redirects, fake pages, and signs of possible remote access. This game-changing tool helps teams detect phishing threats early, providing concrete evidence of business exposure before it's too late.