#security-operations-center — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #security-operations-center, aggregated by home.social.
-
The New Digital Battlefield: Why 2026 Demands a Hardened Security Stance
2,251 words, 12 minutes read time.
The digital landscape has fundamentally shifted, and if you are still looking at your network through the lens of yesterday’s defensive strategies, you are already behind. We have entered an era where the perimeter is not just porous; it is effectively non-existent. As we navigate 2026, the rise of agentic artificial intelligence has transformed the threat landscape from a series of isolated incidents into a continuous, automated, and relentless war of attrition. Adversaries are no longer manually probing for weaknesses during business hours; they are deploying autonomous software agents that scout, exploit, and pivot through complex multi-cloud environments without human intervention. This shift marks the end of the era where reactive patch management and static firewall rules could keep an enterprise safe. Analyzing the current trajectory of these automated threats, it is clear that the primary battlefield has moved from the network edge to the identity layer, making every single access request a potential point of compromise that requires immediate, granular verification.
The Weaponization of Intelligence and the Death of Perimeter Defense
The most significant change to the security landscape this year is the democratization of sophisticated offensive tools. Attackers have evolved beyond simple phishing schemes, utilizing generative models to craft hyper-personalized deception campaigns that are virtually indistinguishable from legitimate communications. These are not the poorly translated emails of a decade ago; these are synthesized audio, video, and text-based deepfakes that exploit human psychology by mimicking trusted colleagues or vendors. When I look at the rapid maturation of these technologies, I see a clear pattern of adversaries targeting the human element while simultaneously leveraging machine learning to identify and exploit zero-day vulnerabilities in public-facing applications. The traditional concept of a “trusted network” has been completely eroded by this reality. It is no longer enough to guard the gates; organizations must now assume that their internal environments are already compromised and operate with a mindset of constant, zero-trust verification.
Moving Beyond Prevention Toward Active Operational Resilience
Prevention remains a fundamental goal, but in 2026, it is no longer the sole pillar of a successful security posture. The smartest organizations are now shifting their focus toward operational resilience, which acknowledges the inevitability of a security incident and prioritizes the ability to withstand, contain, and recover from such events in real time. This transition requires a move away from reliance on human analysts to manually triage every alert. We are seeing a necessary pivot toward automated incident response frameworks that can detect anomalies and orchestrate remediation actions at machine speed. By integrating security orchestration, automation, and response tools into a unified platform, security teams are finally beginning to close the gap between detection and mitigation. This level of responsiveness is the only way to counter the speed of agentic AI attacks, as traditional manual processes are simply too slow to keep pace with an adversary that never sleeps and never tires.
The Silent Expansion of the Shadow AI WorkforceOne of the most insidious threats currently facing enterprises is the unchecked proliferation of shadow AI agents. In 2026, it is no longer just about employees using unapproved chatbots to summarize meeting notes; we are witnessing the deployment of autonomous agents that have been granted direct, persistent access to critical business data and internal systems. These digital coworkers operate with a level of agency that far outstrips simple automation, performing tasks like financial reporting, supply chain adjustments, and email management without constant human oversight. When an organization fails to maintain a comprehensive inventory of these agents, it effectively creates a shadow workforce that exists entirely outside the purview of traditional identity and access management systems. This identity sprawl introduces a massive, hidden attack surface where a single misconfigured agent—or one compromised through a malicious prompt injection—can initiate a cascade of unauthorized actions across the corporate network. Because these agents are designed to move data and execute processes, they essentially function as authorized insiders with elevated privileges, making the task of distinguishing between legitimate autonomous operations and malicious activity an increasingly complex needle-in-a-haystack problem.
Why Identity Has Replaced the Network as the Primary Battleground
For years, the industry obsessed over the network perimeter, pouring capital into firewalls and intrusion detection systems to keep the bad guys out. That era is definitively over. In the current threat environment, identity is the new perimeter, and it is failing under the weight of AI-powered credential abuse and deepfake deception. Attackers are no longer focused on finding a hole in a firewall; they are finding ways to walk through the front door using stolen or synthesized credentials that appear entirely authentic. When I evaluate the efficacy of modern security controls, it is obvious that static multi-factor authentication is no longer enough to stop an adversary who can perform real-time biometric spoofing or orchestrate a multi-stage social engineering attack that mimics an executive’s voice or likeness during a critical transaction. Every single access request must now be treated as a high-stakes event, validated against real-time behavioral patterns, device health telemetry, and geolocation data. We have moved into a world where trust must be continuously earned through granular verification, and any system that assumes a user or an agent is “trusted” based on a single point of entry is simply begging to be exploited.
The Rising Tide of Supply Chain and API Vulnerabilities
While the focus on agentic AI and identity is necessary, we cannot afford to ignore the systemic rot within our interconnected software ecosystems. Modern applications are built on a sprawling web of third-party APIs, open-source libraries, and cloud-native integrations that create countless back doors into an organization’s most sensitive data. Attackers have realized that they do not need to break through the fortified front door of a target company when they can instead compromise a trusted vendor, a CI/CD workflow, or an OAuth token that grants them indirect, authenticated access. The data from the past year confirms a dramatic increase in the exploitation of public-facing applications, often leveraged through these compromised trust relationships. This means that an organization’s security posture is only as strong as its weakest third-party integration. Moving forward, the only way to mitigate this risk is to treat every API and every software dependency as a potential ingress point, enforcing rigorous oversight and ensuring that security transparency extends far beyond the internal walls of the enterprise.
The Escalation of Data Poisoning and Model Integrity Risks
While much of the industry attention has been captured by the potential for AI-driven external attacks, there is an equally dangerous, albeit quieter, evolution occurring within the integrity of the data that powers these systems. We are currently facing a crisis of confidence regarding the inputs that drive corporate decision-making and autonomous workflows. In 2026, it is not enough to secure the infrastructure; we must now confront the reality of data poisoning, where adversaries inject subtle, malicious anomalies into the datasets used for training or fine-tuning enterprise machine learning models. This is not about a sudden, catastrophic system failure that triggers a loud alarm; it is about the gradual, calculated subversion of business logic. When an attacker successfully manipulates the underlying data, they can induce a model to make flawed recommendations, prioritize fraudulent transactions, or ignore malicious patterns in security logs. This turns a company’s most potent technological asset into a Trojan horse, working silently against the organization’s interests from the inside out. Securing the data pipeline has become a top-tier security imperative, requiring rigorous provenance tracking, continuous auditability of training sets, and the implementation of robust adversarial training techniques designed to identify and reject manipulated inputs before they can degrade the model’s reliability.
Addressing the Looming Talent Gap and Defensive Burnout
The rapid pace of technological change is not only taxing our technical systems; it is pushing human defenders to their absolute breaking point. We are operating in an environment where the volume, variety, and velocity of security alerts have completely outstripped the cognitive capacity of traditional security operations center teams. Expecting human analysts to keep pace with adversaries who are utilizing automated agents to conduct attacks at machine speed is a recipe for failure and inevitable burnout. This is why the integration of advanced analytics and automated triage is no longer just a luxury for the largest organizations; it is a fundamental survival requirement. The goal is to move the human element up the value chain, shifting the focus from mundane, repetitive monitoring tasks toward high-level threat hunting, architecture design, and strategic oversight. By offloading the grunt work of log aggregation, initial correlation, and basic incident containment to intelligent machines, we can preserve the sanity of our teams while simultaneously reducing the dwell time of attackers within our environments. A security strategy that fails to account for the human element of this equation is doomed to fall apart as the attrition rates in cybersecurity continue to climb in response to this relentless, high-pressure digital conflict.
Building a Future-Proof Architecture Based on Radical Transparency
Looking toward the remainder of this year and beyond, the only way for any organization to maintain a viable security stance is to embrace a philosophy of radical transparency and aggressive defensive engineering. We must abandon the secrecy that has historically defined corporate security departments and instead adopt a model of shared intelligence. This means actively participating in industry threat-sharing consortia, automating the ingestion of real-time indicators of compromise, and building systems that are designed to be observable at every layer of the stack. A closed, proprietary system is inherently more fragile in the current climate than an open, well-audited, and resilient architecture. We need to move toward a future where security controls are not just bolted onto existing infrastructure as an afterthought, but are instead natively woven into the software development lifecycle, the CI/CD pipeline, and the very identity frameworks that govern access. The threats we face today are systemic and collaborative; our defenses must be equally coordinated, pervasive, and uncompromising if we are to have any hope of maintaining control over our digital domains.
The Final Synthesis: Adapting to the Persistent Threat Paradigm
As we look toward the horizon, it becomes clear that the distinction between a peaceful digital state and an active security incident has effectively dissolved. We are no longer living in a world of binary outcomes where one is either secure or compromised. Instead, we are navigating a permanent state of high-intensity conflict where persistent, automated threats constantly probe for the slightest deviation in our operational baseline. Success in this environment is not defined by the absence of attacks, but by the ability to maintain the continuity of business operations while under fire. This requires a fundamental departure from the legacy mindset of static defenses and annual compliance audits. It demands a posture that is defined by agility, continuous monitoring, and the willingness to radically restructure how we manage identity, data, and software supply chains. The organizations that thrive will be those that accept this reality and invest heavily in the defensive infrastructure that allows them to observe, adapt, and respond faster than the adversary can evolve.
Institutionalizing Vigilance as a Core Business Function
The ultimate takeaway from the current threat landscape is that cybersecurity can no longer be sequestered into a back-office IT department. It must be elevated to a board-level priority that dictates how the company handles everything from vendor selection to product development. When leadership treats security as a checkbox, they are fundamentally misunderstanding the existential risk that these automated threats pose to their market position and operational integrity. I see this reality manifesting in the increasing frequency of leadership turnover within organizations that fail to treat security as a first-order business risk. If you are not integrating security into your organizational DNA, you are building your future on a foundation that is already actively being undermined by adversaries. Establishing a culture of vigilance means fostering a workforce that is trained to recognize the signs of deception, ensuring that security-by-design is non-negotiable for every engineering team, and maintaining a budget that reflects the severity of the threat landscape.
Securing the Path Forward in a Hostile Digital Ecosystem
In closing, the path forward is narrow and requires an uncompromising commitment to technical excellence. We cannot afford to be complacent, nor can we afford to trust in the effectiveness of legacy solutions that were never designed to operate against AI-driven adversaries. The future of security is about visibility, automation, and the ruthless elimination of unnecessary trust. It is about building a defense that is as intelligent, distributed, and persistent as the threats we are up against. This is not a short-term project that can be completed and filed away; it is a permanent change in how we operate, build, and interact in the digital world. The landscape will continue to shift, and the tools available to our adversaries will continue to improve, but by focusing on robust identity management, resilient architecture, and an unwavering commitment to data integrity, we can maintain the upper hand. The battle for the digital future is ongoing, and only those who are willing to adapt, innovate, and secure their environments with extreme prejudice will remain standing when the smoke clears.
SUPPORTSUBSCRIBECONTACT MED. Bryan King
Sources
- CISA Cybersecurity Advisories
- NIST Cybersecurity Framework
- ENISA Threat Landscape Reports
- SANS Institute Security Blog
- Gartner Cybersecurity Research
- CrowdStrike Global Threat Report
- Mandiant M-Trends Report
- Palo Alto Networks Cyberpedia
- Google Security Blog
- Microsoft Security Blog
- IBM Cost of a Data Breach Report
- CIS Critical Security Controls
- Cybereason Defense Blog
- Dark Reading
- The Hacker News
- Recorded Future Intelligence
- Rapid7 Security Blog
- Unit 42 Threat Intelligence
- FireEye Threat Research
- Tenable Research Blog
- AlienVault Security Essentials
- Varonis Data Security Blog
- Proofpoint Security Blog
- Trend Micro Security News
- Check Point Research
- Recorded Future Threat Intelligence
- Kaspersky Daily
- FortiGuard Labs
- Cisco Security Reports
- Splunk Security Blog
- CrowdStrike Blog
- CyberScoop
- SC Media
- ZDNet Security
- BleepingComputer
Disclaimer:
The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.
Related Posts
Rate this:
#agenticAIThreats #AIDrivenThreats #APIVulnerabilities #automatedDefense #automatedIncidentResponse #automatedSecurityTools #autonomousCyberAttacks #behavioralAnalytics #biometricSpoofing #cloudSecurity #credentialAbuse #cyberHygiene #cyberResilience #cyberRiskManagement #cyberWarfare #cybersecurityBestPractices #cybersecurityFuture #cybersecurityLeadership #cybersecurityPosture #cybersecurityStrategy #cybersecurityTrends2026 #dataPoisoning #deepfakeDetection #digitalInfrastructure #enterpriseProtection #enterpriseRisk #enterpriseSecurity #identityCentricSecurity #incidentManagement #informationSecurity #modelIntegrity #networkDefense #operationalResilience #riskManagement #securityAutomation #securityOperationsCenter #securityByDesign #shadowAI #softwareSupplyChain #supplyChainSecurity #threatHunting #threatIntelligence #threatLandscape #threatMitigation #ZeroTrustArchitecture -
AI Transforms SOCs, But Human Analysts Remain Vital
AI is revolutionizing Security Operations Centers, but not by replacing human analysts - instead, it's freeing them from tedious tasks to focus on high-stakes decision-making. By automating routine work, AI is augmenting human capabilities, not replacing them.
#ArtificialIntelligence #SecurityOperationsCenter #Soc #Automation #CyberDefense
-
Threat Response Times Hinge on Smart SOC Design
When a breach occurs, the clock is ticking - and the cost of delayed response can be crippling, with every hour of inaction threatening data exfiltration, service disruption, regulatory exposure, and brand damage. A smart SOC design can be the difference between a swift response and a devastating fallout.
#SecurityOperationsCenter #SmartSocDesign #Mttr #ThreatResponse #IncidentResponse
-
Kaspersky Uncovers Horabot Campaign Targeting Mexico
Kaspersky's Security Operations Center has uncovered a complex Horabot campaign targeting Mexico, and is now sharing crucial insights on how it works and how to detect it. This critical threat intelligence will help defenders in Mexico and beyond prioritize their resources and stay one step ahead of the threat.
https://osintsights.com/kaspersky-uncovers-horabot-campaign-targeting-mexico
#Horabot #Mexico #Kaspersky #SecurityOperationsCenter #EmergingThreats
-
This Punchbowl Phish Is Bypassing 90% Of Email Filters Right Now
997 words, 5 minutes read time.
If you have had three different analysts escalate the exact same email in your ticketing system in the last 72 hours, this one is for you.
This is not a Nigerian prince scam. This is not a fake Amazon order. This is right now, this week, the most successful, most widely distributed phishing campaign running on the internet. And almost nobody is talking about just how good it is.
What this scam actually is
You get an email. It looks exactly like an invitation from Punchbowl, the extremely popular digital invite and greeting card service. There’s no misspelled logo. There’s no broken grammar. There is absolutely nothing that jumps out as fake.
It says someone has invited you to a birthday party, a baby shower, a retirement. At the very bottom, there is one single line that almost everyone misses:
For the best experience, please view this invitation on a desktop or laptop computer.
If you click the link, you do not get an invitation. You get malware. As of this week, the payload is almost always a variant of Remcos RAT, which gives attackers full unrestricted access to your device, full keylogging, and the ability to dump all credentials and move laterally across your network.
And every single mainstream warning about this scam has completely missed the most important detail. That line about the desktop? That is not a throwaway line. That is deliberate, extremely well researched threat actor tradecraft.
Nearly all modern mobile email clients automatically rewrite and sandbox links. Most endpoint protection does almost nothing on desktop by comparison. The attackers know this. They are actively telling you to defeat your own security for them. And it works.
Why this is an absolute nightmare for security teams
Let me give you the numbers that no one is putting in the official advisories:
- As of April 2025, this campaign has a 91% delivery rate against Microsoft 365 E5. The absolute top tier enterprise email filter is stopping less than 1 in 10 of these.
- Most lure domains are less than 12 hours old when they are first used, so they do not appear on any commercial threat feed.
- This is not just targeting consumers. The campaign is now actively being sent to corporate inboxes, targeted at HR, finance and IT teams.
- Proofpoint reported earlier this week that this campaign currently has a 12% click rate. For context, the average phish has a click rate of 0.8%.
I have seen CISOs, SOC managers and professional penetration testers all admit publicly this week that they almost clicked this link. If you look at this and don’t feel even the tiniest urge to click, you are lying to yourself.
This is what good phishing looks like. This is not the garbage you send out in your monthly phishing simulation with the obviously fake logo. This is the stuff that actually works.
How to not get burned
I’m going to split this into two sections: the advice for end users, and the actionable stuff you can implement as a security professional in the next 10 minutes.
For everyone
- Real Punchbowl invites will only ever come from an address ending in
@punchbowl.com. There are no exceptions. If it comes from anywhere else, delete it immediately. - Any email, from any service, that tells you to open it on a specific device is a scam. Full stop. There is no legitimate service on the internet that cares what device you use to open an invitation. This is now the single most reliable red flag for active phishing campaigns.
- Do not go to Punchbowl’s website to “check if the invite is real”. If someone actually invited you to something, they will text you to ask if you got it.
For SOC Analysts and Security Teams
These are the steps you can go and implement right now before you finish reading this post:
- Add an email detection rule for the exact string
for the best experience please view this on a desktop or laptop. At time of writing this rule has a 0% false positive rate. - Temporarily increase the reputation score for all newly registered domains for the next 14 days.
- Add this exact lure to your phishing simulation program immediately. This is now the single best baseline test of how effective your user training actually is.
- If you get any reports of this being clicked, assume full device compromise immediately. Do not waste time triaging. Isolate the host.
Closing Thought
The worst part about this scam is how predictable it is. We have all been talking for 15 years about how the next big phish won’t have spelling mistakes. We all said it will look perfect. It will be something you actually expect. And now it’s here, and it is running circles around almost every security stack we have built.
If you see this email, report it. If you are on shift right now, go push that detection rule. And for the love of god, stop laughing at people who almost clicked it.
Call to Action
If this breakdown helped you think a little clearer about the threats out there, don’t just click away. Subscribe for more no-nonsense security insights, drop a comment with your thoughts or questions, or reach out if there’s a topic you want me to tackle next. Stay sharp out there.
D. Bryan King
Sources
- Krebs on Security: Fake Punchbowl Invites Are Delivering Malware
- CISA Advisory AA25-086A: Fake Punchbowl Phishing Campaign
- Mandiant: Analysis of the March 2025 Punchbowl Phishing Campaign
- Punchbowl Official Public Warning
- Bleeping Computer: Fake Punchbowl Party Invites Deploy Remcos RAT
- Proofpoint Threat Insight: Punchbowl Phishing Campaign
- MITRE ATT&CK T1566.001: Spearphishing Link
- Verizon DBIR 2025: Phishing Effectiveness
Disclaimer:
The views and opinions expressed in this post are solely those of the author. The information provided is based on personal research, experience, and understanding of the subject matter at the time of writing. Readers should consult relevant experts or authorities for specific guidance related to their unique situations.
Related Posts
Rate this:
#attackVector #boardroomRisk #breachPrevention #CISAAlert #CISO #credentialTheft #cyberResilience #cyberattack #cybercrime #cybersecurityAwareness #defenseInDepth #desktopOnlyPhishing #detectionRule #DKIM #DMARC #emailFilterBypass #emailGateway #emailHygiene #emailSecurity #emailSecurityGateway #endpointProtection #incidentResponse #indicatorsOfCompromise #initialAccess #IoCs #lateralMovement #linkSafety #logAnalysis #maliciousLink #malware #MITREATTCK #mobileEmailRisk #phishingCampaign #phishingDetection #phishingScam #phishingSimulation #phishingStatistics #PunchbowlPhishing #ransomwarePrecursor #RemcosRAT #sandboxEvasion #securityAlert #SecurityAwarenessTraining #securityBestPractices #securityLeadership #securityMonitoring #securityOperationsCenter #securityStack #SOCAnalyst #socialEngineering #spearPhishing #SPF #suspiciousEmail #T1566001 #threatActor #threatHunting #threatIntelligence #userTraining #zeroTrust -
How data science can boost your detection engineering maintenance and keep you from herding sheep: https://medium.com/falconforce/how-data-science-can-boost-your-detection-engineering-maintenance-and-keep-you-from-herding-sheep-8713b7220776
#datascience #securityoperationsCenter #detectionengineering
-
How data science can boost your detection engineering maintenance and keep you from herding sheep: https://medium.com/falconforce/how-data-science-can-boost-your-detection-engineering-maintenance-and-keep-you-from-herding-sheep-8713b7220776
#datascience #securityoperationsCenter #detectionengineering
-
Why SOC efficiency is the most valuable currency in cybersecurity https://www.csoonline.com/article/4086904/why-soc-efficiency-is-the-most-valuable-currency-in-cybersecurity.html #SecurityOperationsCenter
-
Why SOC efficiency is the most valuable currency in cybersecurity https://www.csoonline.com/article/4086904/why-soc-efficiency-is-the-most-valuable-currency-in-cybersecurity.html #SecurityOperationsCenter
-
Zobacz jak polować na włamywaczy i na czym polega obsługa incydentów w SOC
W piątek 17 września, o godzinie 19:00 robimy lajwa pt. “Jak naprawdę wygląda praca w SOC“. Zapisać może się każdy, wystarczy kliknąć na poniższy przycisk:
Zapisz się, nawet jeśli ten termin Ci nie pasuje, bo każdy kto się zapisze, otrzyma od nas wieczysty dostęp do nagrania po zakończeniu transmisji. Możesz też otrzymać certyfikat potwierdzający udział.
Threat hunting, w ramach którego poluje się na cyberprzestępców, to bardzo ciekawa praca. Właśnie tym zajmują się pracownicy tzw. SOC-ów (ang. Security Operations Center). Na lajwie pokażemy z jakich narzędzi korzystają, aby wykrywać zagrożenia i obsługiwać incydenty w małych i dużych firmach. Część z tej wiedzy przyda Ci się nie tylko w firmie — możesz ją wykorzystać do ochrony domowej sieci. A jeśli przeszło Ci przez myśl, żeby zmienić pracę i dołączyć do zespołu SOC w jakiejś firmie (albo dopiero zaczynasz swoją karierę w IT), to już w ogóle nasz piątkowy LIVE będzie dla Ciebie idealnym drogowskazem, jak to zrobić i na co uważać.
Co dokładnie pokażemy?
W trakcie spotkania zobaczysz 2 demonstracje: Jak wyglada analiza przykładowego incydentu?
Jak wygląda przykładowy Threat HuntingA oprócz tego pokażemy też:
narzędzia używane w profesjonalnych SOC-ach wraz ze szczerym omówieniem wad i zalet (Splunk, Wazuh, Elastic, MITRE, OpenCTI, MISP),
różne stanowiska w SOC-ach oraz to, co powinieneś umieć, aby rozpocząć na nich pracę,
jak zbudować domowy SOC,
gdzie w SOC-ach jest miejsce dla AI i agentów,Będzie też sekcja Q&A z Michałem Garcarzem, który ma 30 lat doświadczenia w obszarze cyberbezpieczeństwa, a od ponad 10 lat buduje i nadzoruje różne SOC. [...]
#Elastic #MichałGarcarz #MISP #MITRE #OpenCTI #Praca #SecurityOperationsCenter #SOC #Splunk #Wazuh
-
Zobacz jak polować na włamywaczy i na czym polega obsługa incydentów w SOC
W piątek 17 września, o godzinie 19:00 robimy lajwa pt. “Jak naprawdę wygląda praca w SOC“. Zapisać może się każdy, wystarczy kliknąć na poniższy przycisk:
Zapisz się, nawet jeśli ten termin Ci nie pasuje, bo każdy kto się zapisze, otrzyma od nas wieczysty dostęp do nagrania po zakończeniu transmisji. Możesz też otrzymać certyfikat potwierdzający udział.
Threat hunting, w ramach którego poluje się na cyberprzestępców, to bardzo ciekawa praca. Właśnie tym zajmują się pracownicy tzw. SOC-ów (ang. Security Operations Center). Na lajwie pokażemy z jakich narzędzi korzystają, aby wykrywać zagrożenia i obsługiwać incydenty w małych i dużych firmach. Część z tej wiedzy przyda Ci się nie tylko w firmie — możesz ją wykorzystać do ochrony domowej sieci. A jeśli przeszło Ci przez myśl, żeby zmienić pracę i dołączyć do zespołu SOC w jakiejś firmie (albo dopiero zaczynasz swoją karierę w IT), to już w ogóle nasz piątkowy LIVE będzie dla Ciebie idealnym drogowskazem, jak to zrobić i na co uważać.
Co dokładnie pokażemy?
W trakcie spotkania zobaczysz 2 demonstracje: Jak wyglada analiza przykładowego incydentu?
Jak wygląda przykładowy Threat HuntingA oprócz tego pokażemy też:
narzędzia używane w profesjonalnych SOC-ach wraz ze szczerym omówieniem wad i zalet (Splunk, Wazuh, Elastic, MITRE, OpenCTI, MISP),
różne stanowiska w SOC-ach oraz to, co powinieneś umieć, aby rozpocząć na nich pracę,
jak zbudować domowy SOC,
gdzie w SOC-ach jest miejsce dla AI i agentów,Będzie też sekcja Q&A z Michałem Garcarzem, który ma 30 lat doświadczenia w obszarze cyberbezpieczeństwa, a od ponad 10 lat buduje i nadzoruje różne SOC. [...]
#Elastic #MichałGarcarz #MISP #MITRE #OpenCTI #Praca #SecurityOperationsCenter #SOC #Splunk #Wazuh
-
AI is altering entry-level cyber hiring — and the nature of the skills gap https://www.csoonline.com/article/4058190/ai-is-altering-entry-level-cyber-hiring-and-the-nature-of-the-skills-gap.html #SecurityOperationsCenter #ArtificialIntelligence #ITSkills #Careers #Hiring
-
AI is altering entry-level cyber hiring — and the nature of the skills gap https://www.csoonline.com/article/4058190/ai-is-altering-entry-level-cyber-hiring-and-the-nature-of-the-skills-gap.html #SecurityOperationsCenter #ArtificialIntelligence #ITSkills #Careers #Hiring
-
CrowdStrike bets big on agentic AI with new offerings after $290M Onum buy https://www.csoonline.com/article/4057472/crowdstrike-bets-big-on-agentic-ai-with-new-offerings-after-290m-onum-buy.html #SecurityOperationsCenter #ArtificialIntelligence #TechnologyIndustry
-
CrowdStrike bets big on agentic AI with new offerings after $290M Onum buy https://www.csoonline.com/article/4057472/crowdstrike-bets-big-on-agentic-ai-with-new-offerings-after-290m-onum-buy.html #SecurityOperationsCenter #ArtificialIntelligence #TechnologyIndustry
-
CISOs grapple with the realities of applying AI to security functions https://www.csoonline.com/article/4054301/cisos-grapple-with-the-realities-of-applying-ai-to-security-functions.html #SecurityOperationsCenter #ArtificialIntelligence #SecurityPractices
-
CISOs grapple with the realities of applying AI to security functions https://www.csoonline.com/article/4054301/cisos-grapple-with-the-realities-of-applying-ai-to-security-functions.html #SecurityOperationsCenter #ArtificialIntelligence #SecurityPractices
-
5 trends reshaping IT security strategies today https://www.csoonline.com/article/4054295/5-trends-reshaping-it-security-strategies-today.html #SecurityOperationsCenter #ArtificialIntelligence #SecurityPractices #RiskManagement #ITLeadership #ITStrategy #Budgeting
-
5 trends reshaping IT security strategies today https://www.csoonline.com/article/4054295/5-trends-reshaping-it-security-strategies-today.html #SecurityOperationsCenter #ArtificialIntelligence #SecurityPractices #RiskManagement #ITLeadership #ITStrategy #Budgeting
-
DXC i 7AI wprowadzają autonomicznych agentów AI do cyberbezpieczeństwa. Koniec z ręczną analizą alertów?
DXC Technology, globalny dostawca usług IT, oraz firma 7AI, specjalizująca się w tzw. agentach AI, ogłosiły strategiczne partnerstwo.
Jego owocem jest nowa usługa DXC Agentic Security Operations Center (SOC), która wykorzystuje autonomiczne, inteligentne boty do wykrywania, analizy i neutralizowania cyberzagrożeń. Rozwiązanie ma skrócić czas reakcji, obniżyć koszty i zwiększyć skalę ochrony firm.
Nowo utworzone centrum bezpieczeństwa odchodzi od tradycyjnego modelu, w którym analitycy ręcznie przetwarzają alerty. Zamiast tego, zadania te przejmują inteligentni agenci AI, którzy samodzielnie analizują potencjalne zagrożenia i reagują na incydenty. Jak zapowiada Maciej Tomczyk, dyrektor zarządzający DXC Technology Poland, usługa będzie dostępna dla klientów na całym świecie, w tym również w Polsce, oferując „większą szybkość działania, sprawniejsze wykrywanie i reagowanie na incydenty bezpieczeństwa”.
Kluczem do działania platformy jest innowacyjna technologia „Dynamic Reasoning” opracowana przez 7AI. Pozwala ona autonomicznym agentom ustalać w czasie rzeczywistym, jak badać nowe, nawet wcześniej nieznane zagrożenia, bez potrzeby korzystania z gotowych scenariuszy. Dzięki temu DXC Agentic SOC eliminuje opóźnienia związane z ręczną obsługą, skracając czas potrzebny na zbadanie zagrożenia – który dotychczas wynosił od 30 minut do 2,5 godziny – i redukując liczbę fałszywych alarmów.
Partnerstwo opiera się na synergii obu firm. DXC wnosi swoją globalną skalę działania, w tym obsługę setek klientów i przetwarzanie 4,5 miliona zagrożeń dziennie, co tworzy ogromne środowisko danych do trenowania AI. 7AI dostarcza natomiast swoją przełomową platformę. Według danych 7AI, jej technologia pomogła już zaoszczędzić klientom ponad 224 000 godzin pracy analityków, co przekłada się na ponad 11,2 mln dolarów odzyskanej produktywności. Prognozy na rok 2025 zakładają oszczędności przekraczające 100 milionów dolarów.
Cisco udostępnia otwarty model AI dla cyberbezpieczeństwa. Ma być skuteczniejszy niż ChatGPT
#7AI #agenciAI #AI #automatyzacja #cyberbezpieczeństwo #DXCTechnology #news #ochronaDanych #SecurityOperationsCenter #SoC #sztucznaInteligencja
-
DXC i 7AI wprowadzają autonomicznych agentów AI do cyberbezpieczeństwa. Koniec z ręczną analizą alertów?
DXC Technology, globalny dostawca usług IT, oraz firma 7AI, specjalizująca się w tzw. agentach AI, ogłosiły strategiczne partnerstwo.
Jego owocem jest nowa usługa DXC Agentic Security Operations Center (SOC), która wykorzystuje autonomiczne, inteligentne boty do wykrywania, analizy i neutralizowania cyberzagrożeń. Rozwiązanie ma skrócić czas reakcji, obniżyć koszty i zwiększyć skalę ochrony firm.
Nowo utworzone centrum bezpieczeństwa odchodzi od tradycyjnego modelu, w którym analitycy ręcznie przetwarzają alerty. Zamiast tego, zadania te przejmują inteligentni agenci AI, którzy samodzielnie analizują potencjalne zagrożenia i reagują na incydenty. Jak zapowiada Maciej Tomczyk, dyrektor zarządzający DXC Technology Poland, usługa będzie dostępna dla klientów na całym świecie, w tym również w Polsce, oferując „większą szybkość działania, sprawniejsze wykrywanie i reagowanie na incydenty bezpieczeństwa”.
Kluczem do działania platformy jest innowacyjna technologia „Dynamic Reasoning” opracowana przez 7AI. Pozwala ona autonomicznym agentom ustalać w czasie rzeczywistym, jak badać nowe, nawet wcześniej nieznane zagrożenia, bez potrzeby korzystania z gotowych scenariuszy. Dzięki temu DXC Agentic SOC eliminuje opóźnienia związane z ręczną obsługą, skracając czas potrzebny na zbadanie zagrożenia – który dotychczas wynosił od 30 minut do 2,5 godziny – i redukując liczbę fałszywych alarmów.
Partnerstwo opiera się na synergii obu firm. DXC wnosi swoją globalną skalę działania, w tym obsługę setek klientów i przetwarzanie 4,5 miliona zagrożeń dziennie, co tworzy ogromne środowisko danych do trenowania AI. 7AI dostarcza natomiast swoją przełomową platformę. Według danych 7AI, jej technologia pomogła już zaoszczędzić klientom ponad 224 000 godzin pracy analityków, co przekłada się na ponad 11,2 mln dolarów odzyskanej produktywności. Prognozy na rok 2025 zakładają oszczędności przekraczające 100 milionów dolarów.
Cisco udostępnia otwarty model AI dla cyberbezpieczeństwa. Ma być skuteczniejszy niż ChatGPT
#7AI #agenciAI #AI #automatyzacja #cyberbezpieczeństwo #DXCTechnology #news #ochronaDanych #SecurityOperationsCenter #SoC #sztucznaInteligencja
-
📬 Cybercrime schläft nie – wie das SOC Bedrohungen stoppt, bevor Sie davon erfahren
#Advertorial #ITSicherheit #FalsePositive #LEITWERKAG #SecurityOperationsCenter #SIEMSystem #SOARTechnologie #SoC https://sc.tarnkappe.info/a32925 -
📬 Cybercrime schläft nie – wie das SOC Bedrohungen stoppt, bevor Sie davon erfahren
#Advertorial #ITSicherheit #FalsePositive #LEITWERKAG #SecurityOperationsCenter #SIEMSystem #SOARTechnologie #SoC https://sc.tarnkappe.info/a32925 -
Warum das SOC in der Krise steckt – und wie Sie das ändern https://www.csoonline.com/article/4043049/warum-das-soc-in-der-krise-steckt-und-wie-sie-das-andern.html #SecurityOperationsCenter
-
Warum das SOC in der Krise steckt – und wie Sie das ändern https://www.csoonline.com/article/4043049/warum-das-soc-in-der-krise-steckt-und-wie-sie-das-andern.html #SecurityOperationsCenter
-
How AI is reshaping cybersecurity operations – Source: www.csoonline.com https://ciso2ciso.com/how-ai-is-reshaping-cybersecurity-operations-source-www-csoonline-com/ #rssfeedpostgeneratorecho #SecurityOperationsCenter #ArtificialIntelligence #CyberSecurityNews #SecurityPractices #ITStrategy #CSOonline #CSOOnline #itskills
-
How AI is reshaping cybersecurity operations – Source: www.csoonline.com https://ciso2ciso.com/how-ai-is-reshaping-cybersecurity-operations-source-www-csoonline-com/ #rssfeedpostgeneratorecho #SecurityOperationsCenter #ArtificialIntelligence #CyberSecurityNews #SecurityPractices #ITStrategy #CSOonline #CSOOnline #itskills
-
How AI is reshaping cybersecurity operations https://www.csoonline.com/article/4042494/how-ai-is-reshaping-cybersecurity-operations.html #SecurityOperationsCenter #ArtificialIntelligence #SecurityPractices #ITStrategy #ITSkills
-
How AI is reshaping cybersecurity operations https://www.csoonline.com/article/4042494/how-ai-is-reshaping-cybersecurity-operations.html #SecurityOperationsCenter #ArtificialIntelligence #SecurityPractices #ITStrategy #ITSkills
-
Agentic AI promises a cybersecurity revolution — with asterisks – Source: www.csoonline.com https://ciso2ciso.com/agentic-ai-promises-a-cybersecurity-revolution-with-asterisks-source-www-csoonline-com/ #rssfeedpostgeneratorecho #SecurityOperationsCenter #ArtificialIntelligence #TechnologyIndustry #CyberSecurityNews #SecurityPractices #CSOonline #CSOOnline
-
Agentic AI promises a cybersecurity revolution — with asterisks – Source: www.csoonline.com https://ciso2ciso.com/agentic-ai-promises-a-cybersecurity-revolution-with-asterisks-source-www-csoonline-com/ #rssfeedpostgeneratorecho #SecurityOperationsCenter #ArtificialIntelligence #TechnologyIndustry #CyberSecurityNews #SecurityPractices #CSOonline #CSOOnline
-
Agentic AI promises a cybersecurity revolution — with asterisks https://www.csoonline.com/article/4040145/agentic-ai-promises-a-cybersecurity-revolution-with-asterisks.html #SecurityOperationsCenter #ArtificialIntelligence #TechnologyIndustry #SecurityPractices
-
Agentic AI promises a cybersecurity revolution — with asterisks https://www.csoonline.com/article/4040145/agentic-ai-promises-a-cybersecurity-revolution-with-asterisks.html #SecurityOperationsCenter #ArtificialIntelligence #TechnologyIndustry #SecurityPractices
-
7 reasons the SOC is in crisis — and 5 steps to fix it – Source: www.csoonline.com https://ciso2ciso.com/7-reasons-the-soc-is-in-crisis-and-5-steps-to-fix-it-source-www-csoonline-com/ #IdentityandAccessManagement #rssfeedpostgeneratorecho #SecurityOperationsCenter #PenetrationTesting #CyberSecurityNews #CSOonline #CSOOnline
-
7 reasons the SOC is in crisis — and 5 steps to fix it – Source: www.csoonline.com https://ciso2ciso.com/7-reasons-the-soc-is-in-crisis-and-5-steps-to-fix-it-source-www-csoonline-com/ #IdentityandAccessManagement #rssfeedpostgeneratorecho #SecurityOperationsCenter #PenetrationTesting #CyberSecurityNews #CSOonline #CSOOnline
-
Skills gaps send CISOs in search of managed security providers – Source: www.csoonline.com https://ciso2ciso.com/skills-gaps-send-cisos-in-search-of-managed-security-providers-source-www-csoonline-com/ #rssfeedpostgeneratorecho #SecurityOperationsCenter #ManagedServiceProviders #CyberSecurityNews #SecurityPractices #riskmanagement #outsourcing #CSOonline #CSOOnline #itskills #budget
-
Skills gaps send CISOs in search of managed security providers – Source: www.csoonline.com https://ciso2ciso.com/skills-gaps-send-cisos-in-search-of-managed-security-providers-source-www-csoonline-com/ #rssfeedpostgeneratorecho #SecurityOperationsCenter #ManagedServiceProviders #CyberSecurityNews #SecurityPractices #riskmanagement #outsourcing #CSOonline #CSOOnline #itskills #budget
-
Skills gaps send CISOs in search of managed security providers https://www.csoonline.com/article/4016339/skills-gaps-send-cisos-in-search-of-managed-security-providers.html #SecurityOperationsCenter #ManagedServiceProviders #SecurityPractices #RiskManagement #Outsourcing #ITSkills #Budget
-
Skills gaps send CISOs in search of managed security providers https://www.csoonline.com/article/4016339/skills-gaps-send-cisos-in-search-of-managed-security-providers.html #SecurityOperationsCenter #ManagedServiceProviders #SecurityPractices #RiskManagement #Outsourcing #ITSkills #Budget
-
Pressure is mounting to cut jobs in favor of AI. Here’s why you shouldn’t. – Source: www.csoonline.com https://ciso2ciso.com/pressure-is-mounting-to-cut-jobs-in-favor-of-ai-heres-why-you-shouldnt-source-www-csoonline-com/ #rssfeedpostgeneratorecho #SecurityOperationsCenter #ArtificialIntelligence #TechnologyIndustry #CyberSecurityNews #StaffManagement #CSOonline #CSOOnline #ITJobs
-
Pressure is mounting to cut jobs in favor of AI. Here’s why you shouldn’t. – Source: www.csoonline.com https://ciso2ciso.com/pressure-is-mounting-to-cut-jobs-in-favor-of-ai-heres-why-you-shouldnt-source-www-csoonline-com/ #rssfeedpostgeneratorecho #SecurityOperationsCenter #ArtificialIntelligence #TechnologyIndustry #CyberSecurityNews #StaffManagement #CSOonline #CSOOnline #ITJobs
-
CrowdStrike is cutting jobs in favor of AI. Here’s why you shouldn’t. https://www.csoonline.com/article/4012831/crowdstrike-is-cutting-jobs-in-favor-of-ai-heres-why-you-shouldnt.html #SecurityOperationsCenter #ArtificialIntelligence #TechnologyIndustry #StaffManagement #ITJobs
-
CrowdStrike is cutting jobs in favor of AI. Here’s why you shouldn’t. https://www.csoonline.com/article/4012831/crowdstrike-is-cutting-jobs-in-favor-of-ai-heres-why-you-shouldnt.html #SecurityOperationsCenter #ArtificialIntelligence #TechnologyIndustry #StaffManagement #ITJobs
-
How Contrast ADR Speeds up SOC Incident Response Time| SOC Challenges From Alert Fatigue to Application-Layer Visibility | Contrast Security – Source: securityboulevard.com https://ciso2ciso.com/how-contrast-adr-speeds-up-soc-incident-response-time-soc-challenges-from-alert-fatigue-to-application-layer-visibility-contrast-security-source-securityboulevard-com/ #ApplicationDetectionandResponse(ADR) #SecurityOperationsCenter(SOC) #applicationvulnerabilities #ApplicationLayerSecurity #APIsecurity
-
How Contrast ADR Speeds up SOC Incident Response Time| SOC Challenges From Alert Fatigue to Application-Layer Visibility | Contrast Security – Source: securityboulevard.com https://ciso2ciso.com/how-contrast-adr-speeds-up-soc-incident-response-time-soc-challenges-from-alert-fatigue-to-application-layer-visibility-contrast-security-source-securityboulevard-com/ #ApplicationDetectionandResponse(ADR) #SecurityOperationsCenter(SOC) #applicationvulnerabilities #ApplicationLayerSecurity #APIsecurity
-
Security operations centers are fundamental to cybersecurity — here’s how to build one – Source: www.csoonline.com https://ciso2ciso.com/security-operations-centers-are-fundamental-to-cybersecurity-heres-how-to-build-one-source-www-csoonline-com/ #rssfeedpostgeneratorecho #SecurityOperationsCenter #CyberSecurityNews #SecurityPractices #CSOandCISO #CSOonline #CSOOnline #Security
-
Security operations centers are fundamental to cybersecurity — here’s how to build one – Source: www.csoonline.com https://ciso2ciso.com/security-operations-centers-are-fundamental-to-cybersecurity-heres-how-to-build-one-source-www-csoonline-com/ #rssfeedpostgeneratorecho #SecurityOperationsCenter #CyberSecurityNews #SecurityPractices #CSOandCISO #CSOonline #CSOOnline #Security
-
What Cybersecurity Can Teach Us About the Human Body https://thecyberexpress.com/cybersecurity-about-the-human-body/ #CybersecurityInfographic #IntrusionDetectionSystem #SecurityOperationsCenter #TheCyberExpressNews #CyberEssentials #TheCyberExpress #DataEncryption #FirewallDaily #HumanBody #firewall
-
39% of IT leaders fear major incident due to excessive workloads https://www.csoonline.com/article/3814828/39-of-it-leaders-fear-major-incident-due-to-excessive-workloads.html #SecurityOperationsCenter #IncidentResponse #RiskManagement #ITLeadership #ITTraining #ITSkills
-
From reactive to proactive: Redefining incident response with unified, cloud-native XDR – Source: www.csoonline.com https://ciso2ciso.com/from-reactive-to-proactive-redefining-incident-response-with-unified-cloud-native-xdr-source-www-csoonline-com/ #rssfeedpostgeneratorecho #SecurityOperationsCenter #CyberSecurityNews #CSOonline #CSOOnline #Security
-
From reactive to proactive: Redefining incident response with unified, cloud-native XDR https://www.csoonline.com/article/3628571/from-reactive-to-proactive-redefining-incident-response-with-unified-cloud-native-xdr.html #SecurityOperationsCenter #Security