< ciso
brief />
Tag Banner

All news with #threat hunting tag

85 articles

Hunting MacSync Stealer via behavioral pivots

🔍 Microsoft Defender Experts expanded earlier reporting on MacSync Stealer, a macOS information stealer that rotates infrastructure rapidly. The investigation correlated recurring command-line, request, and upload traits to link over 30 domains and show active staged collection and chunked HTTP PUT exfiltration. The write-up maps payload retrieval, C2 check-in, collection, staging, and cleanup to durable hunting pivots.
read more →

Perimeter Recovery Masks Weak Interior Defenses

🔍 Picus Labs' Blue Report 2026 shows perimeter defenses improved in H1 2026, with prevention rising to 69% and logging at a four-year high of 58%. However, post-compromise prevention inside networks remains weak at 37%, and quiet techniques like reconnaissance and credential theft largely evade controls. The findings highlight signature-dependent gaps and declining IOC-based prevention, urging validation of exposures and stronger detection engineering.
read more →

Identity-Driven Attacks and SOC Response Trends

🔐 Unit 42 finds identity compromises underpin most modern incidents, with the 2026 Global Incident Response Report showing identity weaknesses in nearly 90% of investigations and 65% of initial access events. Attackers increasingly use phishing, social engineering, MFA manipulation and third-party account misuse to gain entry, then move laterally, escalate privileges and blend into administrative behavior. Unit 42 recommends correlating identity, endpoint, cloud and network telemetry, applying AI-driven correlation and centralized investigations, and investing in continuous threat hunting and SOC engineering to detect and contain identity-driven intrusions earlier.
read more →

Five priorities for your Black Hat agenda

🔒 Black Hat remains a vital forum for practitioners despite commercialization; attendees should avoid flashy distractions and focus on substantive technical content. Key topics to prioritize this year include agentic AI exploitation, modern APT infrastructure, AI-powered vulnerability discovery, threat hunting in the AI era, and real-world adversary AI use. Seek sessions and case studies that emphasize operational controls, behavioral detection, and collaboration across security, IT, and development teams.
read more →

Microsoft unveils multi-model agentic cyber stack

🔐 Microsoft announced Project Perception, an AI-driven service entering public preview on Aug. 3 that uses multiple AI agents to continuously evaluate and update enterprise security posture. The multi-model harness selects the best model for each task to balance quality and cost, and Microsoft also introduced MAI-Cyber-1-Flash, a specialist model trained to find vulnerabilities. Integrated agents perform red-, blue- and green-team playbooks to detect, triage, and remediate threats automatically.
read more →

Rethinking Security for the Age of AI

🛡️ Microsoft introduces Project Perception, an agentic security system designed for AI-era threats. It combines signals, context, models and specialized agents to continuously perceive, reason and act at machine speed while keeping humans in control. The system uses a multi-model architecture to optimize for quality and cost, beginning with software vulnerability management using MAI-Cyber-1-Flash in MDASH. Project Perception enters public preview on August 3.
read more →

Shadow Token via Remote Debug: OAuth mailbox hijack

🔒 Kaspersky researchers describe a covert technique named Shadow Token via Remote Debug (STRD) used by the ToddyCat APT to gain persistent access to Google Workspace mailboxes without user interaction. The attackers deploy malware (Umbrij) that duplicates a browser profile, launches a headless debugging browser, and programmatically authorizes a third-party OAuth app to obtain an access token. This approach can survive password resets and evades endpoint detection when properly executed.
read more →

Cloud CISO Perspectives: AI and deep context defense

🛡️ Francis deSouza outlines how deep context gives defenders an AI-driven advantage by unifying enterprise telemetry, vulnerability management, and agentic automation. The post introduces Google AI Threat Defense, combining Gemini, Wiz, CodeMender, and Mandiant into a prepare–scan–remediate–monitor lifecycle. It emphasizes human oversight, Zero Trust for AI, and real-world impact such as Morgan Stanley’s rapid detection improvements.
read more →

AI Helps Find Bugs but Humans Must Prove Them

🛡️ AI is accelerating offensive security by producing many potential findings quickly, but generated reports are not the same as validated evidence. AI tools can read code, generate payloads, and suggest attack paths, yet validation still requires human knowledge of systems, reachability, and exploitability. Low-quality AI submissions are already increasing triage burden, so teams must separate leads from proven findings and apply rigorous validation before driving engineering action.
read more →

The Hunter’s Paradox: Rethinking AI in Threat Hunting

🔍 This post examines whether AI should lead threat hunting, arguing the choice is not binary. The author reframes hunting as a reasoning-driven process rather than a human-only activity and explains why scale, velocity, and capacity force us toward automation. Practical guidance includes scoped hunts, strict access controls, and graduated autonomy while keeping humans responsible for strategy and novel analysis.
read more →

UK unveils AI-driven national Cyber Shield

🔒 The UK’s NCSC and DSIT unveiled a blueprint called Cyber Shield to deploy autonomous AI agents that detect and neutralize cyberattacks at machine speed. The plan uses cooperating “red” and “blue” agents to identify weaknesses, detect threats and progressively automate remediation while operating under organizational control. The initiative emphasizes explainable and federated AI, industry partnerships, and a staged rollout beginning with government and critical sectors.
read more →

Five new SOC roles emerging from AI evolution

🔒 The rise of AI-driven SOCs is reshaping security operations and creating new specialist roles rather than simply replacing people. Today's AI-SOC automates Tier 1 triage and is moving into Tier 2 investigation and remediation, prompting demand for skills in data engineering, agent orchestration, model training, threat hunting, and AI-savvy red teaming. Organizations will need professionals who can integrate diverse telemetry, manage agent swarms, fine-tune models, hunt adversary intent, and test AI-specific weaknesses.
read more →

Challenges and Practical Paths for Autonomous SOCs

🔒 The promise of a fully autonomous SOC—where collection, analysis, investigation, and response happen without human intervention—attracts organizations facing talent shortages and a growing threat landscape. Vendors show value in alert enrichment and noise reduction, but autonomous decision-making and response have delivered limited ROI. Real-world obstacles include poor source data quality, tool integration gaps, analyst distrust, context deficits, AI hallucinations, compliance issues, and the need for human control.
read more →

Google Security Operations: Autonomous threat containment

🛡️ Google details how Google Security Operations pairs with Google AI Threat Defense to detect, investigate, and contain AI-accelerated attacks across cloud and enterprise environments. The post explains three specialized agents — Detection Engineering, Triage and Investigation, and Threat Hunting — that translate threat intelligence into custom detections, autonomously investigate alerts, and proactively hunt stealthy compromises. These agents use diverse telemetry, simulated events, and AI-driven automation to reduce time-to-detection and speed remediation, addressing gaps where patching is impossible or delayed.
read more →

15 Tough Cybersecurity Questions Every CISO Must Answer

🔍 Security leaders outline 15 critical questions CISOs should ask to ensure security programs adapt to evolving threats and business needs. These prompts focus on demonstrating ROI, aligning defenses with critical business processes, measuring detection and response speed, and addressing AI-driven risks like nonhuman identities and automated attacks. The guidance also stresses vendor risk, shadow AI, application security for widespread coding, and preparing security for future business growth.
read more →

Most SOCs See Limited Value from First‑Wave AI

🔎 The SOC-CMM 2026 report shows rapid AI adoption across SOCs but limited perceived value: only about 10% report excellent value while 71% report some or no value. The dominant deployment pattern is the taker model—off‑the‑shelf AI bolted into existing tools—creating fragmented workflows and weak handoffs. The report argues the next wave must be architectural: AI that operates across detection, hunting, investigation, remediation, and threat intel with built‑in governance and institutional knowledge.
read more →

Cisco Live report: AI, networking, and wellbeing

🐶 At Cisco Live U.S. in Las Vegas, the author describes the conference pace, the value of quiet spaces and noise-canceling gear, and the welcome presence of therapy dogs sponsored by Splunk. Discussions at the event centered on AI from an infrastructure and security lens, including the daunting scale of data and associated defense challenges. Cisco Talos highlights expansion of its Threat Hunting program using AI-driven telemetry plus expert validation to find advanced intrusions like a recent KongTuke C2 discovery.
read more →

Balancing Cyber Product Leadership and Endurance

🔥 Tony Giandomenico of Cisco Talos discusses how endurance from Ironman training informs his approach to leading major cybersecurity product launches. He highlights rapid advances in frontier AI models, the evolving threat landscape, and the need to apply similar AI-driven speed to defensive tools. Tony explains Cisco Talos Threat Hunting, its focus on endpoint telemetry and expansion into firewalls and identity, and stresses communication, influence, and purpose as keys to sustaining focus across long careers.
read more →

Hypothesis-Driven Threat Hunting at Cisco Talos

🔍 Cisco Talos Threat Hunting adopts a hypothesis-first approach: rather than waiting for alert thresholds, analysts formulate theories about adversary behavior and search telemetry to validate them. Using AI for scale and human expertise for context, continuous hunts run across global telemetry to surface candidates that automated detection misses. Confirmed findings are reported with remediation guidance and feed back into detection tuning and product improvements.
read more →

PraisonAI Authentication Bypass Scanned by Internet

🔍 Sysdig reported that a newly disclosed authentication bypass in the open-source orchestration framework PraisonAI was probed by internet scanners about 3 hours and 44 minutes after a GitHub advisory published on May 11. The flaw stems from a legacy Flask API server that ships with authentication disabled by default, affecting versions 2.5.6 through 4.6.33 and fixed in 4.6.34. Researchers urge immediate upgrades and monitoring for the “CVE-Detector/1.0” user-agent and suspicious /api/agents and related paths.
read more →