LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host

threat detection

mdr

Microsoft Named Leader in Enterprise MDR/MXDR Report

Microsoft has been recognized as a leader in the 2026 IDC MarketScape report for Managed Detection and Response (MDR) and Managed Extended Detection and Response (MXDR) services for enterprises. The report highlights the increasing complexity of cyber threats, including AI-driven attacks, and the need for expert-led services to defend against them. Microsoft's offering, Defender Experts MDR, is described as a round-the-clock service that leverages the Microsoft Defender platform and human expertise to detect, investigate, and respond to security incidents.

ai

AI Coding Tools Trigger Endpoint Security Rules

Researchers have observed that AI coding assistants are inadvertently triggering endpoint security software designed to detect malicious activity. These tools, including Cursor, Claude Code, and OpenAI Codex, are setting off behavioral detection rules due to actions like credential harvesting and system reconnaissance, which mimic attacker behavior. The AI agents themselves are not malicious, but their operations resemble those of human intruders.

aihigh

Operationalizing Day Minus Seven: The Cloud-Native ROC

The article introduces the concept of a Risk Operations Center (ROC) as a necessary evolution for cybersecurity teams facing AI-driven threats. It argues that traditional risk management models are insufficient due to the speed at which AI can discover and exploit vulnerabilities, especially in cloud environments. A ROC, powered by platforms like Qualys Enterprise TruRisk Management (ETM), aims to unify disparate security findings, hyper-prioritize risks based on exploitability and business impact, and enable autonomous remediation to keep pace with attackers.

aihigh

Blackpoint AI SOC Agent autonomously contains identity-based attacks

Blackpoint Cyber has released an AI-powered security agent designed to automatically detect and neutralize identity-based cyberattacks. This agent focuses on threats targeting cloud-based productivity suites like Microsoft 365 and Google Workspace. By leveraging a combination of artificial intelligence and human oversight, the system aims to significantly reduce the time it takes to contain compromised accounts and prevent further damage.

compromise assessmenthigh

Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects

Kaspersky's 2025 compromise assessments revealed that many organizations struggle with undetected threats, with a significant portion of high-severity incidents remaining hidden for months or even years. A substantial percentage of these missed threats were only identified through proactive assessments, highlighting gaps in existing security tools' alerting capabilities. The analysis also noted that attackers frequently utilize remote management tools and living-off-the-land binaries, and that malicious files can persist even in backups.

ai

5 Myths About AI in the SOC Security Teams Need to Rethink

Security operations teams are increasingly adopting AI, but common assumptions about its role need reevaluation. Experts suggest AI should augment, not replace, human analysts by handling repetitive tasks and data processing. While automation is beneficial for enrichment and triage, critical actions still require human oversight. Transparency and explainability are crucial for building trust and ensuring analysts can confidently use AI outputs.

azurehigh

Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

Microsoft has made Azure AD Graph Activity Logs available for ingestion into Elastic, enabling threat detection within SIEM/XDR solutions. Previously, this critical telemetry was largely inaccessible to customers, leaving a significant visibility gap for defenders. This development allows for the monitoring of adversary activities that leverage the legacy graph.windows.net surface, which remained unlogged until recently.