Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The latest News and Information on Security Incident and Event Management.

What's New in LogRhythm SIEM for October 2026

The October 2026 LogRhythm SIEM release modernizes self-hosted security operations with an in-place migration from Elasticsearch to OpenSearch, a next-generation self-service reporting engine, generative AI collectors, and a community Model Context Protocol (MCP) server. The release also includes backend and API updates that improve event drilldown, rule administration, network routing, and telemetry quality while helping organizations maintain control of sensitive security data.

The Agentic SOC Isn't Coming for Analysts' Jobs. It's Coming for Their Tabs.

An agentic SOC uses AI-powered investigation, analysis, and automation to gather data, connect activity, and handle repetitive investigative work. Analysts remain in control and focus on judgment, prioritization, and response. This addresses the need for machine-speed security operations as AI agents gain autonomy and Tier 1 access to systems. Spend five minutes watching a security analyst at work and the “AI will replace analysts” headline starts to sound out of touch.

CASB vs SIEM for SaaS Security

Today’s businesses spend more money on SaaS tools than on laptops. According to Gartner, the average organization now uses over 125 different SaaS applications. With the multitude of cloud apps businesses use on a daily basis, securing that expanding environment requires visibility and control across users, applications, data, and infrastructure.

Ranking the top 10 SIEM platforms in 2026

Security information and event management, or SIEM, remains one of the foundational technologies in the security operations center. Gartner defines SIEM as a configurable system of record that collects, aggregates, and analyzes security event data from on-premises and cloud environments to support threat detection, investigation, and response, along with compliance requirements.

The New CISO Ep. 151 - Sean Murphy | Complacency Kills: Why More Discomfort Might Fix Your Burnout

Sean Murphy spent more than twenty years in the CISO chair and walked away from it while things were going well. In this episode of The New CISO, he returns to talk with Steve Moore about trading the operational seat for a field CISO role at F5 — and why getting too good at the job was the warning sign.

Extend Investigations with Falcon Next-Gen SIEM Federated Search and Snowflake

See how CrowdStrike Falcon Next-Gen SIEM Federated Search extends investigations to security data stored in Snowflake without requiring the entire dataset to be ingested into the SIEM. In this demo, an analyst pivots from suspicious endpoint activity in Falcon to Corelight network telemetry retained in Snowflake. Using remoteTable(), the analyst searches the remote data directly from Advanced Event Search, retrieving only the context needed to investigate the affected host and understand the broader scope of the incident.