Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

CISA's Logging Reference Architecture for OMB M-26-14: What federal agencies should do next

On August 20, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) published its Logging Reference Architecture (LRA), the implementation guidance federal civilian executive branch (FCEB) agencies have been waiting for since the Office of Management and Budget's Memorandum M-26-14 reset the requirements for enterprise logging.

The only perfect Endpoint Prevention and Response (EPR) score in 2026 belongs to Elastic

Elastic sits at the very top of this year’s AV-Comparatives' CyberRisk Quadrant within the 2026 Endpoint Prevention and Response (EPR) test with the only protection scores at 100%, combined with both the lowest modelled operational footprint of any tested product and zero false alerts.

The security attack that hid inside your observability data

How teams are leaving value on the table and what it costs when they do It's 3:00 a.m. Your on-call engineer gets paged that the central processing unit (CPU) is at 97% on payment-processor-01. They open their observability platform, look at the metric spike, reboot the host, and close the ticket.

Defending against AI-fueled social engineering

Social engineering has always been the softest edge of enterprise defense, and AI is sharpening adversaries’ attacks. Phishing, business email compromise, and impersonation still dominate the initial-access playbook, but AI has stripped out the cost, time, and skill barriers that once forced attackers to choose between reach and precision.

Machine vs. machine: The new reality of cybersecurity in ANZ

Frontier AI has handed attackers something they have never had before: the ability to move at machine speed. Attacks that once took days to craft now take minutes. Threats have not just evolved to be automated, adaptive, and operational around the clock. They have also changed category. We surveyed more than 850 IT and cybersecurity professionals across Australia and New Zealand to understand how organisations are keeping up. What the data reveals is not a capability problem. It is a pace problem.

How SLED can win the cybersecurity race with agentic AI

Adversaries are using AI to launch cyber attacks in record time, forcing security teams to measure responses in minutes instead of months. Phishing campaigns built with large language models (LLMs) achieve click-through rates 4.5 times higher than traditional methods,1 and the average time between initial compromise and lateral movement has fallen to just 29 minutes.2 This is a 65% increase from the prior year.2 State and local governments and higher education institutions are at an inflection point.

From tool procurement to platform architecture: Rethinking the SOC for machine-speed threats

The gap between attacker speed and defender readiness is widening. Attackers can now move from initial access to full domain control in less than a minute using AI.1 Large language model-generated phishing campaigns are achieving click-through rates 4.5 times higher than traditional methods.2 Most enterprise SOCs weren't built for this tempo and fidelity.

Making Waves: Elastic named a Strong Performer in The Forrester Wave: Extended Detection And Response Platforms, Q2 2026

Elastic has been named a Strong Performer in The Forrester Wave: Extended Detection And Response Platforms, Q2 2026 report. The report recognized our SIEM-replacement capabilities, open data architecture, AI innovation, and endpoint protection. Here's what Forrester found and why we believe it reflects what we've been building.

Monitor Claude activity in Elastic Security

The agentic security operations platform As more people across an organization start using Claude, security and compliance teams end up asking the same questions they ask about any other system: Who’s using it? How are they signing in? Who’s changing the configuration? Claude’s Compliance API answers all of that. It tracks more than 300 event types across Claude Enterprise, Claude Team, and Claude Platform, and every event arrives with the actor, a timestamp, and where it came from.