< ciso
brief />
Tag Banner

All news with #detection engineering tag

135 articles

CISA Endorses Cyber Decoys; FortiDeceptor 6.3

🛡️ CISA published guidance on Using Cyber Decoys to Strengthen Detection and Response, urging an assume-breach posture and use of honeypots, honeytokens, breadcrumbs, and tripwires. FortiDeceptor implements these concepts with decoy VMs, centralized lure management, and integration with the Fortinet Security Fabric. Version 6.3 expands decoy coverage to GitLab, IoT printers, and cloud connectors for S3, GitHub, and SharePoint, and supports automated response workflows.
read more →

Gartner’s ISOC: A New Layer for Security Ops

🔒 Gartner introduced the Integrated Security Operations Center (ISOC) category to address the limits of traditional SIEMs by unifying detection, investigation, case management and response. ISOC emphasizes native detection and response, centralized data ownership, persistent incident case objects and cross-domain correlation to reduce latency and operational friction. The aim is streamlined workflows and lower costs for lean security teams confronting AI-accelerated threats.
read more →

AWS Continuum Raises Bar for Autonomous Code Security

🔒 AWS reports that Continuum for code vulnerabilities achieved an 89.0% end-to-end pass rate on the CyberGym-E2E benchmark, passing 819 of 920 tasks within a 90-minute limit. The multi-agent system improved on prior public results across all measured stages (discovery, validation, remediation) and reached 93.7% when allowed to run longer. The evaluation was conducted under network-isolation and submission-review rules to ensure results came from analysis rather than retrieval.
read more →

Cortex XCOR: AI-Driven Autonomous Observability

🚀 This post introduces Cortex XCOR, an AI-native observability platform from Palo Alto Networks that aims to deliver autonomous root cause analysis and remediation. The platform centers on the XCOR Operator and specialized AI agents, including an AI SRE that autonomously investigates incidents and recommends fixes. XCOR integrates full-stack telemetry with cost optimization to balance visibility and spending.
read more →

Frustrating Adversaries Through Defensive Tradecraft

🛡️ Cisco Talos outlines practical ways defenders can increase friction for attackers across the attack chain. The piece highlights techniques such as unique configurations, deception (honeypots and tarpits), behavior-based detections, RMM inventorying and allowlisting, social-engineering preparedness, and controls for AI agents. Each recommendation aims to force adversaries into slower, noisier, or less reliable methods while providing defenders more chances to detect and stop activity.
read more →

Leveraging browser telemetry for proactive defense

🔒 Modern browsers are central enterprise workspaces and require embedded security. Chrome Enterprise Premium captures high-fidelity browser telemetry to surface in-browser threats that legacy EDR and perimeter tools miss, including risks from shadow AI and autonomous agents. Streaming these signals into security operations enables proactive mitigation, automated response, and reduced investigation time, demonstrated in Mandiant case studies.
read more →

CAIRN: Metadata-First Hunting for AI Malware

🔍 Cisco Talos introduces CAIRN, a research toolkit for hunting and tracking AI-integrated malware using metadata artifacts like prompts, API endpoints, and keys. CAIRN operates without binary downloads, combining rule-based detection, semantic clustering, and relationship graphs to identify related families and infrastructure. The toolkit includes acquisition filters, a three-tier YARA ontology, and an explorer for pivoting from single samples to broader operational ecosystems.
read more →

Defender’s Window: Turning AI Parity into Security Capability

🔒 The author argues that the Cyber AI Parity Window—when defenders and attackers gain similar AI capabilities simultaneously—has narrowed into a timebound "defender's window." Organizations must rapidly convert access to AI into operational capability by automating safe workflows, measuring performance, and defining authority for machine-speed responses. The piece urges CISOs to redirect human effort toward proactive defense, detection engineering, and continuous improvement.
read more →

Detection Wins When Defenders Carry Ground Truth

🕰️ The article compares the historical longitude problem to modern cybersecurity, arguing that carrying verifiable facts — like a ship’s chronometer — beats inference-based guessing. It contrasts attackers who infer organizational details from the outside with defenders who can maintain authoritative records of approvers, owned domains and vendors. The piece emphasizes that maintaining those facts is the hard work but that doing so reduces successful fraud and provides auditable reasoning for decisions.
read more →

Amazon GuardDuty adds opt‑in detection rules

🛡️ Amazon GuardDuty now provides Custom Detection Rules, a library of 35 prebuilt, opt‑in rules for CloudTrail management events that produce 26 unique finding types mapped to 10 MITRE ATT&CK® tactics. These rules extend threat coverage without requiring additional log ingestion, normalization, or storage. Administrators can enable rules selectively where activity is unexpected and test in dry‑run mode via the GuardDuty console or API. The feature is available in all AWS commercial Regions and AWS GovCloud (US).
read more →

Google launches Fairwind program to harden cyber defenses

🛡️ Today Google announced the Fairwind Program to provide a select group of government agencies, enterprise customers, and cybersecurity partners with access to advanced Gemini models and the CodeMender harness. The offering pairs Gemini 3.8 Flash Cyber with CodeMender to autonomously find, verify, and produce validated code fixes at scale within secure cloud environments. Participants must meet strict operational controls and the program initially prioritizes partners responsible for critical public services and infrastructure.
read more →

Exotic file formats create detection blind spots

🛡️ This article examines how threat actors increasingly use less-obvious file types to bypass defenses and deliver malware. It outlines disk image formats (ISO, IMG, VHD, VMDK) that mount natively and can evade scanning, Office-related formats like .one and .xll that hide scripts or DLLs, and SVG files that can contain JavaScript. The piece also describes polyglot files and a notable IcedID campaign that chained ZIP→ISO→CHM→mshta to deploy payloads, and stresses the need for comprehensive scanning of these formats by security tools.
read more →

State of AI in Security Operations 2026 Findings

🔍 Prophet Security's 2026 report shows AI has become mainstream in security operations: 40% of teams use AI daily and 56% are testing it. Teams face massive alert volumes, slow triage, and rising AI-driven attacks, while AI adoption is reducing investigation times and shifting analysts toward advanced roles. Privacy, explainability, and DIY project durability remain key challenges for organizations.
read more →

Detecting Multi‑Stage Attacks on AWS with Correlation

🔍 This post explains how correlating signals across AWS services and your business context reveals multi-stage attacks that single alerts miss. It outlines five attack phases and the three primary log sources—CloudTrail, VPC Flow Logs, and Route 53 Resolver logs—used to surface each phase. The guide emphasizes enabling and tuning AWS detection services such as Amazon GuardDuty, then layering custom queries that encode your environment-specific knowledge. It includes CloudWatch Logs Insights queries and operational guidance for thresholds, multi-account setups, and automating detection pipelines.
read more →

CISA red team reveals starkly different SOC outcomes

🛡️ CISA released dual red team reports showing two critical infrastructure organizations were fully domain-compromised using similar tradecraft. Organization A suffered extensive undetected access due to default machine account quotas, misconfigured AD CS templates, cleartext credentials, static cloud keys, and fragmented SOC visibility. Organization B detected and isolated initial footholds quickly, limiting spread despite similar underlying weaknesses, illustrating the decisive role of people and processes.
read more →

Using Crime Script Analysis to Explain Cyber Attacks

🔍 Crime script analysis (CSA) breaks cyber attacks into sequences of actions, decisions, and situational requirements, making complex campaigns accessible to non-technical audiences. CSA complements models like MITRE ATT&CK and the Lockheed Martin Cyber Kill Chain by offering a narrative view that highlights practical "choke points" for disruption. The post illustrates CSA with a business email compromise (BEC) example and explains how AI can both enable attackers and provide new detection opportunities. Practical mitigations include honeypot canary organizations, provider-side detection of malicious LLM use, email rate-limiting, and stricter payment verification processes.
read more →

Most organizations unprepared for agentic AI attacks

🔒 The NSA and Five Eyes agencies warn that AI lowers barriers for malicious actors while bolifying defenders, but current defenses remain asymmetric. Agentic tools can speed detection and response, yet many organizations deploy AI faster than they test it, leaving gaps in measurement and performance. Recent incidents like the OpenAI–Hugging Face breach show triage is insufficient and underscore the need for continuous validation and realistic simulations.
read more →

Perimeter Recovery Masks Weak Interior Defenses

🔍 Picus Labs' Blue Report 2026 shows perimeter defenses improved in H1 2026, with prevention rising to 69% and logging at a four-year high of 58%. However, post-compromise prevention inside networks remains weak at 37%, and quiet techniques like reconnaissance and credential theft largely evade controls. The findings highlight signature-dependent gaps and declining IOC-based prevention, urging validation of exposures and stronger detection engineering.
read more →

Four gaps slowing AI adoption in enterprise SOCs

🔍 Enterprise SOCs are investing in AI but struggle to convert tools into measurable operational gains. Many initiatives add complexity and fragmented workflows instead of reducing analyst workload. Successful deployments prioritize explainability, augment existing playbooks, and unify access to disparate security tools. Clear governance and incremental automation help turn AI pilots into repeatable operational improvements.
read more →

VirusTotal unveils URL Scanning 2.0 for analysts

🛡️ URL Scanning 2.0 expands VirusTotal's URL analysis with headless browser execution, producing full-page screenshots, DOM captures, network logs, and web-technology fingerprints. The update introduces historical pivoting so analysts can review point-in-time snapshots and track how a page's content and risk score evolved. Core telemetry is available to all users, with deeper retrospective data and infrastructure pivots reserved for Premium customers.
read more →