Read, think, share Security is everyone’s responsibility

security operations news

EDR, cloud security, email security, identity, and SIEM platforms ship with built-in detection logic that pushes MTTD close to zero for known techniques. Anthropic restricted its Mythos Preview model last week after it autonomously found and exploited zero-day vulnerabilities in every major operating system and browser. A single click can turn into identity exposure, remote access, data access, or a wider investigation before the team has a clear picture. They’re the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. Organizations are rushing to implement AI without fully grasping where its legal protections begin and end.

For the 2026 Security 100, CRN is recognizing 20 security operations, risk and threat intelligence vendors that have stood out over the past year through delivering a combination of technical advancements and expanded opportunities for solution and service provider partners. He started his career analyzing IT and professional services markets and GTM strategies, now helping translate complex technology benefits into stories that connect innovation, business, and people. The future of SOC operations lies not in processing more alerts faster, but in preventing the conditions that generate unnecessary alerts while developing laser-focused capabilities against the threats that matter most. With continuous exposure management integrated into the SecOps workflow, each incident becomes a learning opportunity that strengthens future detection and response capabilities. Continuous exposure management transforms this by providing real-time context about the systems, configurations, and vulnerabilities involved in each alert. Traditional detection tools generate alerts based on signatures and behavioral patterns, but lack environmental context.

security operations news

The multi-layered approach is designed to improve perimeter protection, early threat detection, fire risk identification, situational awareness and operational resilience across critical infrastructure and commercial environments. ThreatConnect will bring its cyber threat intelligence and risk prioritization offering to Dataminr’s AI platform, which focuses on providing rapid threat intel and risk detection, according to Dataminr. From vendors that https://scivast.com/articles/mastering-information-risk-management/ provide agentic SOC tools to those offering advanced threat feeds, here’s a look at 20 key companies in security operations, risk and threat intelligence. FortiSOC supports log ingestion, normalization, correlation, automation, case management, behavioral analytics, and identity-focused investigations through a single console and a unified data model, integrating telemetry from Fortinet and third-party environments.

  • Recent moves by Dataminr included the acquisition of ThreatConnect in a move aimed at boosting its capabilities around AI-powered threat intelligence.
  • Fast-growing Cribl said the acquisition adds detection engineering capabilities to its technology portfolio that will help customers improve security threat coverage, lower data costs and bolster their security operations centers (SOCs).
  • ThreatConnect will bring its cyber threat intelligence and risk prioritization offering to Dataminr’s AI platform, which focuses on providing rapid threat intel and risk detection, according to Dataminr.
  • Every morning, SOC analysts log into an environment where visibility feels fragmented, spending hours pivoting between disconnected telemetry feeds and managing noisy alerts that require constant manual tuning….
  • Security teams plagued by technological inefficiencies while external threats increase When SOC workflows aren’t operating at their peak, it creates major barriers to effective threat detection and response.

Announcing the Public Preview of Cortex Data Security: Unified Data Protect…

Other major moves to bolster the Splunk SecOps platform include enabling Splunk customers to ingest security data from Cisco firewall systems at no charge. The offering connects Splunk Enterprise Security 8.2 with SOAR, UEBA and the Splunk AI Assistant to provide accelerated threat response as well as simplification in the SOC, according to the vendor. The expansion helps with the currently available offerings in security operations, such as AI SIEM (security information and event management), while also helping to set the stage for a bigger shift into an agentic SOC going forward, according to the company. Key moves include the integration of technology from recently acquired Observo AI, which can optimize data pipelines for autonomous threat detection and response. SentinelOne is enabling the shift to a truly agentic SOC with recent enhancements to its Singularity AI SIEM platform—with the ultimate goal of being able to provide a stunning level of autonomy in security operations, according to SentinelOne co-founder and CEO Tomer Weingarten.

  • Many of these traditional tools are very accurate, but their fatal flaw is a lack of context and a narrow focus – missing the forest for the trees.
  • Most organizations report 2–10 people staffing their SOC, a finding that has remained the most common answer since the SANS SOC Survey began in 2017.
  • At Accelerate 2026, Fortinet is previewing FortiSOC, a cloud-delivered offering that brings together the core capabilities of FortiAnalyzer, FortiSIEM, FortiSOAR, and FortiTIP into a single integrated service, while expanding FortiAI to introduce new agentic workflows across security operations.
  • When SOC workflows aren’t operating at their peak, it creates major barriers to effective threat detection and response.
  • The vendor-neutral platform supports hybrid deployments and integrates with the broader 3xLOGIC ecosystem, providing a cost-effective path to AI-powered surveillance modernization.
  • Not only are GSOCs managing an increased threat volume—protecting people, assets, supply chains, and operations—but they have also become a critical asset for employees and executives when problems arise.
  • Even more troubling, 61% of security teams admitted to ignoring alerts that later proved to be critical security incidents.
  • Capabilities that are being leveraged for the Optiv service include Wiz Cloud and Wiz Code, as well as Wiz Defend cloud detection and response.
  • Optiv Agentic Security Operations brings together Google Security Operations technology, which had already been central to the former Optiv MDR offering, with deeply integrated cloud and AI security capabilities from Google-owned Wiz as well as with Google Threat Intelligence.
  • Cortex XDR excelled in the 2026 AV-Comparatives EDR Test, consolidating 68 alerts into 3 incidents for efficient investigation.
  • It is delivered as SaaS and is designed so businesses small, medium, and large can select and customize products from the suite that specially fit their unique situations.

At SOF Week 2026, Pro-Shot Defense discusses the maintenance technologies and weapon support tools designed to keep special operations forces mission ready in the world’s harshest environments. When it comes to agentic security operations, Zscaler is delivering a highly disruptive offering built upon the acquisitions of security data fabric provider Avalor and managed detection and response trailblazer Red Canary, according to Zscaler founder and CEO Jay Chaudhry. ZeroEyes has announced executive leadership changes to support its continued growth as the company evolves into a comprehensive multi-analytics threat intelligence platform.

Fortinet announced unified endpoint security enhancements though FortiEndpoint to consolidate multiple endpoint products, reduce agent sprawl, simplify licensing and management, and strengthen protection against emerging threats, including AI application misuse. Enhancements include a dedicated agent that automates alert triage, investigation, threat hunting, and Model Context Protocol (MCP) support to maintain shared context and execution continuity across detection, investigation, and response workflows. The Fortinet Security Operations Platform unifies telemetry, analytics, threat intelligence, and response across the kill chain, reducing complexity and accelerating investigations without forcing operational rebuilds. The cyber threats and risks are too high not to be proactive in advancing the capabilities of security operations centers. The adage is that people, processes, and technologies are essential for holistic cybersecurity. CompTIA is another certification organization that offers excellent training for potential SOC analysts.

security operations news

Introducing native support for leading frontier AI models, including Claude Sonnet 4.6, Claude Opus 4.8 and Gemini 3.5 https://integratingpulse.com/articles/worldview-3-satellite-imagery-insights/ Flash across the Cortex platform. Discover how Palo Alto Networks Cortex XSIAM integrates with NVIDIA DOCA Argus to deliver deep visibility and secure the AI Factory with zero performa… AWS Systems Manager extends its capabilities to on-premises environments through Hybrid Activations, allowing physical servers and local virtual machi…

security operations news

“Too many security teams have good data, powerful tools and endless alerts, but no real confidence that they are actually protected,” Mumcuoglu said in the news release. The combination of Cribl’s AI Platform for Telemetry and CardinalOps’ agentic detection software provides an alternative for legacy SIEM architectures, helping clients improve threat coverage and strengthen SOCs, according to the companies. In iconic venues around the world, Cisco Wi-Fi, AI, and security support the most bandwidth-hungry, future-facing fan interactions.