Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Try Sumo Logic in minutes: see SIEM and Dojo AI agents in action

You already know the feeling. An alert fires, and you’re the one digging through logs to figure out if it matters. A query takes three tries to get right. A tool demo looked great, but you still cannot picture it running against your own environment. Before dedicating too much of your over-committed schedule to a proof of concept, you want to know one thing: does this actually work the way they say it does?

Sumo Logic MCP server: bringing SIEM and log data into Claude and other AI clients

More security and operations work now happens inside an AI client instead of a dedicated console. That shift creates a gap for any platform that isn’t part of the conversation. Every time an analyst needs to triage an insight or check a log, they have to leave the AI client and go open a different tool. Sumo Logic closes that gap with a Model Context Protocol (MCP) server.

How the SOC Analyst Agent cuts investigation time from four hours to fourteen minutes

MFA fatigue campaigns work on a simple bet: eventually, someone taps “approve” just to make the notifications stop. It paid off. The attacker was in. The first move was quiet — deactivate SMS authentication, a small settings change easy to miss on a busy queue, and exactly the kind of thing that buys room to work without tripping an alarm. Then came the real work: AWS credentials pulled from one system, SSH keys from another, and a slow and methodical pull of internal source code.

Navigating cybersecurity in the airline industry: Balancing legacy systems and innovation

Commercial airlines run some of the world’s most complex technology environments. Every day, they balance decades-old aircraft systems with modern cloud platforms, connected devices, global payment networks, and strict regulatory requirements, all while ensuring flights depart safely and on time. For security teams, that means protecting an enormous attack surface without disrupting operations.

Dojo AI: Agentic security and cloud operations powered by AI-ready telemetry

You’re collecting more telemetry than ever, but chances are it hasn’t made your job easier. Fragmented data, disconnected tools, and manual investigations mean more noise, slower response times, and higher operational costs. The promise of AI is that it will solve it, but in most cases, you just end up trading noise for expensive hallucinations. Point an LLM at raw, unorganized log storage, and you get an assistant that burns through credits to produce generic, unreliable answers.

Everything you need to know for a career in cybersecurity

So, you want to be a cybersecurity analyst. With the rise in high-profile data breaches, privacy concerns and rapid technological advancements, there’s a greater demand for cybersecurity analysts now. And the demand for cybersecurity analysts is only expected to grow. But before you get too far into pursuing this job, let’s look into the basics of this profession. Below, we answer the most frequently asked questions about becoming a cybersecurity analyst.

AI across the security lifecycle

For nearly a decade, the security industry has used machine learning to solve detection. By feeding it enough logs and determining abnormal behaviors, it found the threats that rules-based systems miss. This delivered sharper anomaly detection, fewer false positives, and UEBA is now essential. In fact, threat detection and analytics account for close to 44% of total SIEM spend, the single largest use case by far. Using machine learning for detection was only the start.

How digital banking is redefining fraud prevention

The banking industry stands at a critical intersection of technology, security, and customer experience. As financial institutions navigate massive data volumes and increasingly sophisticated threats, they’re also trying to survive the digital transformation that’s made customer expectations higher than ever and trust more fragile than before.

Before you replace your SIEM: AI-driven security requires operational context, not just centralized data

Artificial intelligence is rapidly reshaping how security operations centers (SOCs) function. Many organizations are now evaluating AI-native architectures to reduce workload and accelerate investigations. A new architectural narrative is emerging. A growing set of AI-native security vendors are proposing centralizing telemetry in a warehouse and deploying AI agents to replace the operational role of the SIEM. They want to centralize telemetry, apply AI, and automate the SOC.