threat detection

Microsoft Named Leader in Enterprise MDR/MXDR Report
Microsoft has been recognized as a leader in the 2026 IDC MarketScape report for Managed Detection and Response (MDR) and Managed Extended Detection and Response (MXDR) services for enterprises. The report highlights the increasing complexity of cyber threats, including AI-driven attacks, and the need for expert-led services to defend against them. Microsoft's offering, Defender Experts MDR, is described as a round-the-clock service that leverages the Microsoft Defender platform and human expertise to detect, investigate, and respond to security incidents.

AI Coding Tools Trigger Endpoint Security Rules
Researchers have observed that AI coding assistants are inadvertently triggering endpoint security software designed to detect malicious activity. These tools, including Cursor, Claude Code, and OpenAI Codex, are setting off behavioral detection rules due to actions like credential harvesting and system reconnaissance, which mimic attacker behavior. The AI agents themselves are not malicious, but their operations resemble those of human intruders.

Operationalizing Day Minus Seven: The Cloud-Native ROC
The article introduces the concept of a Risk Operations Center (ROC) as a necessary evolution for cybersecurity teams facing AI-driven threats. It argues that traditional risk management models are insufficient due to the speed at which AI can discover and exploit vulnerabilities, especially in cloud environments. A ROC, powered by platforms like Qualys Enterprise TruRisk Management (ETM), aims to unify disparate security findings, hyper-prioritize risks based on exploitability and business impact, and enable autonomous remediation to keep pace with attackers.

Blackpoint AI SOC Agent autonomously contains identity-based attacks
Blackpoint Cyber has released an AI-powered security agent designed to automatically detect and neutralize identity-based cyberattacks. This agent focuses on threats targeting cloud-based productivity suites like Microsoft 365 and Google Workspace. By leveraging a combination of artificial intelligence and human oversight, the system aims to significantly reduce the time it takes to contain compromised accounts and prevent further damage.

Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects
Kaspersky's 2025 compromise assessments revealed that many organizations struggle with undetected threats, with a significant portion of high-severity incidents remaining hidden for months or even years. A substantial percentage of these missed threats were only identified through proactive assessments, highlighting gaps in existing security tools' alerting capabilities. The analysis also noted that attackers frequently utilize remote management tools and living-off-the-land binaries, and that malicious files can persist even in backups.

5 Myths About AI in the SOC Security Teams Need to Rethink
Security operations teams are increasingly adopting AI, but common assumptions about its role need reevaluation. Experts suggest AI should augment, not replace, human analysts by handling repetitive tasks and data processing. While automation is beneficial for enrichment and triage, critical actions still require human oversight. Transparency and explainability are crucial for building trust and ensuring analysts can confidently use AI outputs.

Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap
Microsoft has made Azure AD Graph Activity Logs available for ingestion into Elastic, enabling threat detection within SIEM/XDR solutions. Previously, this critical telemetry was largely inaccessible to customers, leaving a significant visibility gap for defenders. This development allows for the monitoring of adversary activities that leverage the legacy graph.windows.net surface, which remained unlogged until recently.