LIVE · cybersecurity feed
Live wire
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emergeOracle Critical Patch Update, August 2026 Security Update ReviewCVE-2026-65400 · Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active ExploitationOver 500 Critical Infrastructure Organizations Hit by Medusa RansomwareMedusa ransomware gang has hit over 500 organizations, CISA warns
intezer

Intezer Introduces Native Automation for Security Response Workflows

Intezer has launched Workflows, a new feature allowing security teams to build and customize automated response actions directly within its platform. This integration aims to streamline incident response by eliminating the need for a separate SOAR system, enabling faster post-investigation actions where alerts are already being triaged and analyzed.

zeroday.news ·

Intezer has introduced Workflows, a new native automation and response builder integrated directly into its platform, aiming to streamline security operations by eliminating the need for separate Security Orchestration, Automation, and Response (SOAR) systems. The company announced the feature on August 19, 2026, positioning it as a way for security teams to create and customize response workflows within the same environment where alerts are triaged and investigated.

The new capability allows organizations to automate post-investigation actions, such as closing alerts, notifying analysts, isolating hosts, or updating tickets, directly within the Intezer AI SOC. This integration is designed to bridge the gap between alert investigation and remediation, which often relies on standalone SOAR platforms, custom integrations, or manual processes. Intezer emphasizes that Workflows enables actions to run immediately, leveraging the full context of the investigation.

According to Intezer CEO Itai Tevet, the integration of forensic-depth investigation with custom, automated response is crucial for security teams to operate at "machine scale" in response to AI-driven attacker tactics. The company's 2026 AI SOC Report highlighted that nearly 1% of real incidents originated from alerts initially classified at the lowest severity levels. For an enterprise generating 450,000 alerts annually, this translates to approximately 54 real threats per year that could potentially go uninvestigated if relying on partial alert coverage.

Intezer Workflows provides security teams with control over actions taken once an investigation yields a verdict. Key features include the ability to build response logic directly within the Intezer platform, eliminating the need for a separate SOAR. These workflows can trigger actions across the security stack, such as host isolation or ticket updates, based on investigation outcomes, without requiring additional API integrations or polling.

Users can create workflows using natural language descriptions through Intezer's MCP, which then generates the workflow for review, refinement, testing, and activation. The system ensures that all evidence, data, and organizational context gathered during the investigation are carried into the response phase. Each workflow run is logged within the relevant alert or case, providing an audit trail for troubleshooting. For Managed Security Service Providers (MSSPs), Intezer Workflows also offers automation for customer communications and per-tenant routing, processes that typically demand manual effort.

intezerautomationsecurity responsesoar
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

OpenAI confirms ChatGPT is down as logins and signups fail

ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]

ai

Smashing Security podcast #481: Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold stat

aicritical

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

ransomware

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]

cloud

Sakura Internet hack exposes data of up to 1.36 million accounts

Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]

breach

Healthtech firm CareCloud data breach impacts 3.7 million patients

U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]