Dragos has completed acquisitions of NetRise and runZero, a move that could tighten industrial visibility across assets, software provenance, and active threats, but only if the integrations hold up in practice.
A new roundup of eight ITDR products is a reminder that identity defense is really a question of where trust lives: in Active Directory, in cloud workloads, or across both.
New guidance highlights cyber decoys as a way to surface internal movement that can hide behind valid credentials and routine admin tools.
CISA’s guidance puts cyber decoys on the map as a practical defense layer that can help organizations detect, observe, and block suspicious activity without pretending they are a silver bullet.
Cyware’s support for NRECA research points to a harder problem than tooling alone: how distributed utilities detect threats across operational technology without disrupting the systems that keep power flowing.
The current debate around managed detection and response points to a larger truth: in a more complex threat environment, one security layer cannot carry the whole strategy.
DOE and Sandia are applying AI to electric-grid cybersecurity, but the real story is less about hype and more about whether machines can help operators find threats faster without creating new blind spots.
The shift toward Identity-First Security treats access, privilege, governance, and threat detection as one control plane, not separate IAM chores.
A newly identified Go-based payload appears to use smart contracts as a resilient fallback channel, a design that can complicate takedowns and attribution.
The latest debate in AI-driven defense is not about smarter models, but about whether the telemetry feeding them is rich enough to tell reality from noise.
AWS’s detection guidance spotlights a hard truth in cloud security: credential theft is often only the opening move, and the real story emerges when identity, storage, network, and DNS signals are read together.
The security lesson is not that multi-factor authentication fails, but that it can succeed at the wrong job if identity proofing and monitoring are treated as afterthoughts.
A defensive assessment in critical infrastructure found gaps in detection, response, and OT security, reminding operators that resilience is measured before an attacker arrives.
The appointment of Ítalo Calvano to lead Vectra AI in Latin America is a growth move, but it does not by itself signal a confirmed product shift. The security meaning lies in how vendors staff the region they want to win.
A new Android malware family has been described with a fallback exfiltration path that uses nearby infected devices, a design that pushes theft beyond ordinary internet monitoring.
OpenAI's latest warning points to a harder truth for cyber defenders: if machines can find weak spots faster, protection has to become more automated, more disciplined, and much quicker to react.
When visibility becomes a flood instead of a signal, organizations can end up staring at more evidence while understanding less of their real exposure.
An announced integration between Crytica Security, Forescout, and Vistaro points to a familiar enterprise dilemma: turning device-level alerts into something operators can actually trust and act on.
Hackers Online Club published an explainer on MITRE ATT&CK focused on threat detection and detection engineering, a reminder that security teams need a common language before they can build reliable defenses.
A data-centered model is replacing perimeter thinking, forcing defenders to protect what moves inside the organization, not just what sits outside it.