Topic: threat detection

  • Top New Infosec Products Released This Week – July 2025

    Top New Infosec Products Released This Week – July 2025

    PlexTrac's upgraded Workflow Automation Engine enhances vulnerability management by standardizing processes, automating penetration test findings, and reducing remediation time for improved operational efficiency. Bitdefender's expanded Security for Creators solution now includes Facebook and Ins...

    Read More »
  • SaaS Security Demand Surges as Data Breaches Rise

    SaaS Security Demand Surges as Data Breaches Rise

    Businesses overestimate their SaaS security, with 75% reporting incidents in the past year, a 44% increase from previous figures, highlighting a gap between confidence and actual protection. Many organizations rely too heavily on SaaS providers' security assurances instead of verifying their own p...

    Read More »
  • Stellar Cyber's AI Triage Matches Human Analysts 99.7% of the Time

    Stellar Cyber's AI Triage Matches Human Analysts 99.7% of the Time

    Stellar Cyber's Agentic Auto Triage matched human analyst accuracy 99.7% of the time in an independent study of 124 days of live customer data, covering over 138,400 security alerts. The system uses an agentic, adaptive approach that learns from alert context and historical data, unlike static ru...

    Read More »
  • Office 365 search results hijacked to steal paychecks

    Office 365 search results hijacked to steal paychecks

    A threat actor, Storm-2755, uses search engine poisoning and fake Microsoft login pages to hijack corporate email accounts, primarily targeting Canadian workers. The attack employs an adversary-in-the-middle (AiTM) technique to steal login credentials and session tokens, bypassing multi-factor au...

    Read More »
  • 3 Must-Haves to Survive a Cyberattack

    3 Must-Haves to Survive a Cyberattack

    Swift and effective response to a cyberattack depends on having clarity, control, and a reliable lifeline already in place. Clarity involves real-time detection and understanding of the incident's scope, enabling informed decisions to isolate and manage threats. Control means the ability to conta...

    Read More »
  • Gartner's 7 Questions to Evaluate AI SOC Agents

    Gartner's 7 Questions to Evaluate AI SOC Agents

    Gartner provides a seven-question framework to help security teams evaluate AI SOC agents, moving beyond marketing hype to assess real capabilities. Key evaluation areas include the agent's ability to reduce alert fatigue through concrete filtering, its investigative scope for connecting events, ...

    Read More »
  • 500 npm Packages Infected by Shai-Hulud Malware Leaking Secrets

    500 npm Packages Infected by Shai-Hulud Malware Leaking Secrets

    Over 500 npm packages, including popular tools like Zapier and Postman, have been compromised by the Shai-Hulud malware, which steals developer secrets and uploads them to rapidly multiplying GitHub repositories. The attack uses trojanized versions of legitimate packages to inject malicious scrip...

    Read More »
  • Securing Australia: How AI and Identity Redefine Cybersecurity

    Securing Australia: How AI and Identity Redefine Cybersecurity

    Australian businesses face rapidly evolving cybersecurity threats where traditional defenses are inadequate, with attackers now prioritizing immediate execution over stealth using AI to target identity systems. Cloud environments have become particularly vulnerable, with compromised credentials b...

    Read More »
  • Gurucul AI-IRM: Detect Insider Threats Faster

    Gurucul AI-IRM: Detect Insider Threats Faster

    Gurucul has launched the AI Insider Risk Management (AI-IRM) platform to enhance detection and response to insider threats through autonomous triage and bias-free risk scoring, addressing a sharp rise in such incidents. The platform integrates User and Entity Behavior Analytics (UEBA), identity a...

    Read More »
  • Neon Cyber Launches Workforce Cybersecurity Platform

    Neon Cyber Launches Workforce Cybersecurity Platform

    Neon Cyber has launched the industry's first Workforce Cybersecurity Platform (WCP), focusing on human-centric threats like phishing and credential misuse to protect users across browsers, SaaS, and enterprise systems. The platform offers AI-driven phishing protection, visibility into shadow IT, ...

    Read More »
  • Why IT and OT convergence complicates railway cybersecurity

    Why IT and OT convergence complicates railway cybersecurity

    The convergence of legacy operational technology (OT) with modern IT systems in railways has expanded attack surfaces, requiring active management of the IT-OT interface rather than treating it as a boundary. When vulnerabilities arise in critical components like signalling, decisions involve ris...

    Read More »
  • Open-Source CI/CD Tool Detects Stolen Credential Attacks

    Open-Source CI/CD Tool Detects Stolen Credential Attacks

    CI/CD Abuse Detector is an open-source security tool that uses a large language model (LLM) to detect suspicious modifications in CI/CD pipelines, particularly attacks involving stolen credentials, and offers drop-in templates for GitHub Actions. The tool addresses credential theft vulnerabilitie...

    Read More »
  • Broadcom XDR Aids Understaffed SOC Teams

    Broadcom XDR Aids Understaffed SOC Teams

    Broadcom has launched Symantec CBX, a unified cloud platform that merges Symantec and Carbon Black technologies into an extended detection and response (XDR) offering for resource-constrained security teams. The platform specifically targets mid-sized organizations facing enterprise-grade threats...

    Read More »
  • Top Cybersecurity Jobs Hiring in March 2026

    Top Cybersecurity Jobs Hiring in March 2026

    The global demand for specialized cybersecurity talent is exceptionally high, offering diverse career paths from technical roles to strategic leadership positions across various organizations. Key specialized roles highlighted include leadership positions like CISO and Associate Director of Appli...

    Read More »
  • WorldLeaks Ransomware Unleashes New 'RustyRocket' Malware

    WorldLeaks Ransomware Unleashes New 'RustyRocket' Malware

    A new malware called **'RustyRocket'**, used by the extortion group World Leaks, is designed for stealthy data theft and persistent network access, evading traditional security. The malware, written in Rust, acts as a data exfiltration and proxy tool, targeting Windows and Linux by hiding its tra...

    Read More »
  • Vega Secures $120M to Revolutionize Enterprise Cyber Threat Detection

    Vega Secures $120M to Revolutionize Enterprise Cyber Threat Detection

    Traditional centralized security analysis is too slow and expensive for modern, distributed cloud data, creating a critical industry challenge. Vega Security, with new $120M funding, uses a distributed model to analyze data where it resides, avoiding costly data movement and centralization. The s...

    Read More »
  • 6 Overlooked Okta Security Settings You Must Check Now

    6 Overlooked Okta Security Settings You Must Check Now

    Securing identity providers like Okta is critical as they act as central gatekeepers for digital access, with risks arising from misconfigurations and evolving threats. The article outlines six essential Okta security practices, including robust password policies, phishing-resistant MFA, and feat...

    Read More »
  • Why Ransomware Attacks Spike on Weekends

    Why Ransomware Attacks Spike on Weekends

    Threat actors deliberately target organizations on weekends and holidays when security staffing is minimal, exploiting slower detection to infiltrate systems more deeply. Business transitions like mergers and acquisitions create vulnerabilities, with 60% of incidents occurring after such shifts d...

    Read More »
  • Avast's Free AI Scam Protection Now Available Worldwide

    Avast's Free AI Scam Protection Now Available Worldwide

    Avast has globally launched its free AI scam protection tool, Scam Guardian, via its Free Antivirus platform to make advanced scam defense accessible to all, addressing the rise in AI-enhanced, personalized scams. The tool uses proprietary AI to analyze communication context and language, identif...

    Read More »
  • Sophos Intelix Boosts Microsoft Security & Copilot

    Sophos Intelix Boosts Microsoft Security & Copilot

    Sophos Intelix threat intelligence is now integrated with Microsoft Security Copilot and Microsoft 365 Copilot, providing real-time access to Sophos' data within Microsoft's AI environments to enhance security and accelerate threat response. The integration enriches Microsoft Security Copilot wit...

    Read More »