Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Watch what happens when your AI agent actually knows how to investigate

A SOC analyst spots suspicious activity from an internal IP. They need to understand what is happening. They open their SIEM's built-in AI assistant and type: "Tell me about 192.168.0.10." The assistant checks the entity store. Nothing. The analyst rephrases: "This is in our environment. Can you please check the logs and walk me through what's going on with this device?" A moment later, the assistant returns a summary. The host is involved in Windows file sharing and remote administration.

Hunting Citrix NetScaler Zero-Days with Corelight

Citrix’s security bulletin CTX697096, the NetScaler security blog, and WatchTowr’s vulnerability FAQ describe an urgent situation for organizations using NetScaler ADC and NetScaler Gateway. Two vulnerabilities (CVE-2026-88771 and CVE-2026-88772) are known to be exploited. CISA confirms active exploitation globally and has added both to its Known Exploited Vulnerabilities catalog.

Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitation

On September 27, 2026, Citrix disclosed eight vulnerabilities affecting NetScaler Application Delivery Controller (ADC) and NetScaler Gateway. Two of these vulnerabilities are critical (CVSS score of 9.5) and can allow an unauthenticated remote attacker to execute code: Citrix has observed exploitation against unmitigated NetScaler deployments, and the U.S.

Kiteworks recommends server shutdown pending possible attack

On September 25, 2026, reports emerged that Kiteworks (formerly Acellion) emailed customers that law enforcement alerted them about an “imminent” cyberattack on Kiteworks systems, possibly caused by exploitation of a zero-day vulnerability. Kiteworks reportedly advised customers to shut down servers between 02:00 and 08:00 UTC on September 26, if not sooner, as a “precautionary” measure.

Canada Raises the Bar for Critical Infrastructure Cybersecurity. Is Your Network Ready?

Canada has taken a significant step toward strengthening national cyber resilience. With Royal Assent now granted to Bill C-8, the Government of Canada is establishing a new framework for protecting critical cyber systems and securing the country's most essential services.

Investigate your network in plain English: introducing Natural Language Query

Every SOC analyst has been there. An alert fires. You know what you need to find. Maybe it's all outbound connections from a specific host that spiked overnight. Maybe it's every DNS query over 100 characters from a subnet you're watching. You know the question. What you don't know is the exact query syntax you need to ask it. So you open the documentation. You search for field names. You try a query, get it wrong, adjust, and try again. Minutes pass.

Post-Quantum Cryptography: The upgrade nobody asked for (but everyone's getting)

Post-Quantum Cryptography (PQC) is the security equivalent of showing up at the airport and discovering TSA changed the rules overnight again: Laptops out, laptops in, shoes off, shoes on, and declare your shampoo like it’s contraband uranium. You can argue with the signage, but the plane is still leaving, and compliance is not optional. The good news is you don’t need a physics degree, a quantum computer, or a wellness crystal to deal with it.

The water system attacks were simple. Securing OT isn't.

Recent cyberattacks against U.S. water and wastewater systems have put some familiar operational technology (OT) security problems back in the headlines. Federal agencies have warned about malicious actors targeting internet-facing programmable logic controllers (PLCs), changing device configurations, and disrupting operations at utilities across multiple states.