threat detection

AWS wants GuardDuty to automate the first steps of threat investigations

AWS wants GuardDuty to automate the first steps of threat investigations 2026-07-21 at 12:14 By Anamarija Pogorelec Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the investigation agent is available at […]

AWS wants GuardDuty to automate the first steps of threat investigations Read More »

More alerts are making your team slower, and an outcome-based SOC fixes that

More alerts are making your team slower, and an outcome-based SOC fixes that 2026-07-20 at 08:30 By Help Net Security In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like

More alerts are making your team slower, and an outcome-based SOC fixes that Read More »

AWS retools Security Hub for AI and multicloud threats

AWS retools Security Hub for AI and multicloud threats 2026-07-15 at 11:56 By Anamarija Pogorelec AWS added AI workload protection and Microsoft Azure security monitoring to Security Hub, its centralized security platform for collecting and prioritizing security findings across cloud environments. Support for additional cloud platforms will follow. “Collecting findings was never the hard part.

AWS retools Security Hub for AI and multicloud threats Read More »

Watch on Demand: Threat Detection & Incident Response Summit – All Sessions Available

Watch on Demand: Threat Detection & Incident Response Summit – All Sessions Available 2026-05-26 at 14:02 By SecurityWeek News Register to enjoy free access and explore the tools, strategies, and frameworks needed to build a resilient security program for a world where every minute counts. The post Watch on Demand: Threat Detection & Incident Response

Watch on Demand: Threat Detection & Incident Response Summit – All Sessions Available Read More »

Virtual Event Today: Threat Detection & Incident Response Summit

Virtual Event Today: Threat Detection & Incident Response Summit 2026-05-20 at 13:02 By SecurityWeek News The speed and sophistication of cyberattacks have outpaced traditional defense methods. Please join us online today from 11AM -4PM ET for the Threat Detection & Incident Response Summit. Don’t miss this virtual event as we explore how to cut through alert

Virtual Event Today: Threat Detection & Incident Response Summit Read More »

Why Identity Security Must Move Beyond MFA

Why Identity Security Must Move Beyond MFA 2026-01-21 at 14:34 By Torsten George By integrating identity threat detection with MFA, organizations can protect sensitive data, maintain operational continuity, and reduce risk exposure. The post Why Identity Security Must Move Beyond MFA appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Why Identity Security Must Move Beyond MFA Read More »

Predator Spyware Turns Failed Attacks Into Intelligence for Future Exploits

Predator Spyware Turns Failed Attacks Into Intelligence for Future Exploits 2026-01-14 at 16:03 By Kevin Townsend The Predator spyware is more sophisticated and dangerous than previously realized. The post Predator Spyware Turns Failed Attacks Into Intelligence for Future Exploits appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Predator Spyware Turns Failed Attacks Into Intelligence for Future Exploits Read More »

Manufacturing is becoming a test bed for ransomware shifts

Manufacturing is becoming a test bed for ransomware shifts 2025-12-15 at 07:12 By Anamarija Pogorelec Manufacturing leaders may feel that ransomware risk has settled, but new data shows the threat is shifting in ways that require attention, according to a Sophos report. A global survey of 332 IT and security leaders outlines how attackers are

Manufacturing is becoming a test bed for ransomware shifts Read More »

How a noisy ransomware intrusion exposed a long-term espionage foothold

How a noisy ransomware intrusion exposed a long-term espionage foothold 2025-12-02 at 15:15 By Zeljka Zorz Getting breached by two separate and likely unconnected cyber attack groups is a nightmare scenario for any organization, but can result in an unexpected silver lining: the noisier intrusion can draw attention to a far stealthier threat that might

How a noisy ransomware intrusion exposed a long-term espionage foothold Read More »

SAP zero-day wake-up call: Why ERP systems need a unified defense

SAP zero-day wake-up call: Why ERP systems need a unified defense 2025-10-17 at 08:52 By Help Net Security In this Help Net Security video, Paul Laudanski, Director of Research at Onapsis, discusses key lessons from the SAP zero-day vulnerability. He explains why business-critical systems like ERP and CRM remain top targets for attackers, since they

SAP zero-day wake-up call: Why ERP systems need a unified defense Read More »

Building trust in AI-powered security operations

Building trust in AI-powered security operations 2025-10-15 at 08:22 By Help Net Security In this Help Net Security video, James Hodge, VP, Global Specialist Organisation at Splunk, explores the transformative role of AI in cybersecurity threat detection. He explains how AI’s ability to process vast amounts of data and detect anomalies faster than humans is

Building trust in AI-powered security operations Read More »

The unseen side of malware and how to find it

The unseen side of malware and how to find it 2025-09-19 at 08:31 By Anamarija Pogorelec Security teams rely on threat reports to understand what’s out there and to keep their organizations safe. But a new report shows that these reports might only reveal part of the story. Hidden malware variants are quietly slipping past

The unseen side of malware and how to find it Read More »

The top CTEM platforms you should know in 2025

The top CTEM platforms you should know in 2025 2025-08-14 at 08:02 By Help Net Security Continuous Threat Exposure Management (CTEM) is a modern cybersecurity strategy originally coined by Gartner analysts, which focuses on identifying, prioritizing, validating, and mobilizing teams to reduce threat exposure across an organization’s full attack surface. It’s in a category of

The top CTEM platforms you should know in 2025 Read More »

Why 90% of cyber leaders are feeling the heat

Why 90% of cyber leaders are feeling the heat 2025-08-06 at 08:02 By Anamarija Pogorelec 90% of cyber leaders find managing cyber risks harder today than five years ago, mainly due to the explosion of AI and expanding attack surfaces, according to BitSight. These threats are also fueling high rates of burnout, with 47% of

Why 90% of cyber leaders are feeling the heat Read More »

Tired of gaps in your security? These open-source tools can help

Tired of gaps in your security? These open-source tools can help 2025-07-17 at 07:42 By Anamarija Pogorelec When it comes to spotting threats, security teams need tools that can pull data from all over and make it easier to analyze. In this article, we’ll take a look at some popular open-source tools that help with

Tired of gaps in your security? These open-source tools can help Read More »

Industrial security is on shaky ground and leaders need to pay attention

Industrial security is on shaky ground and leaders need to pay attention 2025-07-03 at 07:07 By Help Net Security 44% of industrial organizations claim to have strong real-time cyber visibility, but nearly 60% have low to no confidence in their OT and IoT threat detection capabilities, according to Forescout. How confident are you in your

Industrial security is on shaky ground and leaders need to pay attention Read More »

Enterprise SIEMs miss 79% of known MITRE ATT&CK techniques

Enterprise SIEMs miss 79% of known MITRE ATT&CK techniques 2025-06-09 at 07:32 By Help Net Security Using the MITRE ATT&CK framework as a baseline, organizations are generally improving year-over-year in understanding security information and event management (SIEM) detection coverage and quality, but plenty of room for improvement remains, according to CardinalOps. MITRE ATT&CK enhances SOC

Enterprise SIEMs miss 79% of known MITRE ATT&CK techniques Read More »

Virtual Event Today: Threat Detection & Incident Response (TDIR) Summit

Virtual Event Today: Threat Detection & Incident Response (TDIR) Summit 2025-05-21 at 12:49 By SecurityWeek News SecurityWeek’s 2025 Threat Detection & Incident Response (TDIR) Summit takes place as a virtual summit on Wednesday, May 21st. The post Virtual Event Today: Threat Detection & Incident Response (TDIR) Summit appeared first on SecurityWeek. This article is an

Virtual Event Today: Threat Detection & Incident Response (TDIR) Summit Read More »

Event Preview: 2025 Threat Detection & Incident Response (Virtual) Summit

Event Preview: 2025 Threat Detection & Incident Response (Virtual) Summit 2025-05-20 at 15:39 By SecurityWeek News SecurityWeek’s 2025 Threat Detection & Incident Response (TDIR) Summit takes place as a virtual summit on Wednesday, May 21st. The post Event Preview: 2025 Threat Detection & Incident Response (Virtual) Summit appeared first on SecurityWeek. This article is an

Event Preview: 2025 Threat Detection & Incident Response (Virtual) Summit Read More »

PRevent: Open-source tool to detect malicious code in pull requests

PRevent: Open-source tool to detect malicious code in pull requests 2025-02-20 at 16:52 By Zeljka Zorz Apiiro security researchers have released open source tools that can help organizations detect malicious code as part of their software development lifecycle: PRevent (a scanner for pull requests), and a malicious code detection ruleset for Semgrep and Opengrep static

PRevent: Open-source tool to detect malicious code in pull requests Read More »

Scroll to Top