23 CVEs published in the last four months and 5 stories. Exploited flaws first.

A new method using Elastic Agent's Common Expression Language (CEL) has been developed to monitor the npm package manager's "min-release-age" setting. This setting helps prevent the installation of recently compromised packages by introducing a delay. The CEL integration periodically snapshots .npmrc files, allowing for the detection of when this crucial security setting is removed, a scenario that traditional log tailing methods cannot identify.

Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.

Elastic's InfoSec team has developed an automated security operations center (SOC) that significantly reduces alert triage time. By using deterministic queries and specialized AI agents, the system handles most alert investigations before human analysts are involved, cutting down a 30-minute process to under three minutes. This approach leverages Elastic's own technology stack and focuses on efficient, cost-effective automation to manage increasing alert volumes.

Elastic's InfoSec Product Security Team has developed an AI agent capable of generating comprehensive CVE security advisories. This agent utilizes generative AI and Retrieval-Augmented Generation (RAG) against MITRE's CWE and CAPEC databases, ensuring accurate classification and scoring. The process automates the drafting of advisories from raw vulnerability reports, significantly speeding up the disclosure phase.

Elastic Security now integrates with Google Threat Intelligence (GTI) to automatically ingest and analyze threat data. This integration allows for real-time detection of malicious indicators like IPs, domains, and file hashes within user telemetry. The system also supports on-demand enrichment of alerts using AI-driven workflows that query external sources like VirusTotal.