Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Agentic SOC Isn't Coming for Analysts' Jobs. It's Coming for Their Tabs.

An agentic SOC uses AI-powered investigation, analysis, and automation to gather data, connect activity, and handle repetitive investigative work. Analysts remain in control and focus on judgment, prioritization, and response. This addresses the need for machine-speed security operations as AI agents gain autonomy and Tier 1 access to systems. Spend five minutes watching a security analyst at work and the “AI will replace analysts” headline starts to sound out of touch.

What's New in LogRhythm SIEM for October 2026

The October 2026 LogRhythm SIEM release modernizes self-hosted security operations with an in-place migration from Elasticsearch to OpenSearch, a next-generation self-service reporting engine, generative AI collectors, and a community Model Context Protocol (MCP) server. The release also includes backend and API updates that improve event drilldown, rule administration, network routing, and telemetry quality while helping organizations maintain control of sensitive security data.

AI Security in DevOps: Best Practices to Follow

SUMMARY Attacking a CI/CD pipeline used to require a specialist who understood Git internals, cloud identity, and the way build runners handle secrets. That is no longer true. The barrier to entry for an advanced attack has dropped to the level of writing prompts in English. Automation itself is not new to DevOps, but AI has raised its ceiling on both sides of the fence.

Block malicious packages across your organization with Supply Chain Firewall and Datadog Code Security

Campaigns such as Shai-Hulud 2.0 have demonstrated how quickly package malware can propagate through npm and then harvest credentials. Traditional dependency scanning can identify known risks in code once a package is added to the code, but security teams also need a check before installation.

AI Threats Are Evolving Fast. Your Employees Are Still the Last Line of Defense.

New training on using AI safely and spotting AI-powered threats arrives this Cybersecurity Awareness Month Attackers are moving faster than ever, weaponizing newly discovered vulnerabilities before defenders can patch them and building new types of malware that signature-based defenses can’t catch.

When a Security Guardrail Detects the Attack and Still Can't Stop It

Salt Labs recently showed that a single email could hijack the AI agent platform Manus and reach a victim’s connected accounts. The full technical breakdown, with complete evidence, payloads, and screenshots, is in our research team’s write-up, and Dark Reading first reported the finding in an exclusive. This post is the shorter version: what the finding means and what it tells every organization now deploying AI agents. For the full technical detail, read the Salt Labs research blog.

How We Hijacked an AI Agent With a Single Email

Salt Labs found that the agentic AI platform Manus could be hijacked with a single email. By hiding malicious instructions inside an ordinary message, researchers got Manus to execute malicious code and, from there, reach the email, cloud storage, and code repository accounts a user had connected to it. The full attack required nothing from the victim beyond asking Manus to check their inbox. No stolen password, no clicked link.

OpenShift Console: A Practical Guide

Your first login to a Red Hat OpenShift cluster can feel like sitting in an unfamiliar cockpit: dozens of menus, two perspectives, and dashboards full of metrics you haven’t learned to read yet. The OpenShift Console pulls all of it into one browser-based interface, so you can see what’s running, fix what’s broken, and deploy what’s next without memorizing a single oc flag command.

Building a bot takes five minutes. What it stands on took eight years. Introducing LimaCharlie Bots.

Co-founder and CCO We shipped bots in the LimaCharlie AI Terminal. You can create one in a few minutes: give it a role, pick a profile if you want one, and open a chat. I said this during our September Build Log demo and I'll repeat it here, because everything else in this post follows from it. The bot is the easy part.

PoSA v1.11: Turning Fragmented Attack Signals Into Actionable Risk

With PoSA v1.11, we focused on a practical problem: detecting more attack activity does not necessarily help fraud and security teams make better decisions. PoSA already identifies activity across digital impersonation, credential theft, attacker devices and account access. The challenge is making the connections between that activity easier to understand, identifying which users and devices require attention, and making that intelligence available to the systems and teams responsible for responding.