CISA Red Team Compromises Two Critical Infrastructure Orgs; One SOC Detected Nothing
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released advisory AA26-237A, titled "A Tale of Two SOCs," on August 25, 2026, detailing…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released advisory AA26-237A, titled "A Tale of Two SOCs," on August 25, 2026, detailing…
The traditional Security Operations Center (SOC) model is fundamentally constrained by the alert queue, where the sheer volume of telemetry ensures most…
Artificial Intelligence (AI) is transforming Security Operations Centers (SOCs) by automating repetitive tasks, uncovering patterns in large datasets, and accelerating decision-making. Modern…
German incident response company QUIRSO analyzed the exploitation of CVE-2026-59310 and attributed it with moderate confidence to a Chinese-speaking threat actor. Their…
OpenAI has launched GPT-5.6-Cyber, a specialized cybersecurity model designed for vulnerability research, penetration testing, and incident response. Built on the GPT-5.6 Sol…
Kali365, a device code phishing kit, is actively targeting US organizations by abusing Microsoft's legitimate authentication flow. According to ANY.RUN telemetry, the…
The rapid evolution of AI is creating pressure on security leaders to adopt AI tools, but not all AI is suited for…
N-able has disclosed that attackers exploited an authentication bypass vulnerability in its N-central remote monitoring and management (RMM) platform, gaining remote administrative…
Attackers compromised a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses.…
Adform is an advertising technology company that detected and responded to a supply-chain compromise of its JavaScript file trackpoint-async.js, which was used…