Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

A double-edged bleeding edge: Classifying AI threats

Sophos X-Ops presents a working taxonomy for attacks using, and targeting, AI Conversations about ‘AI threats’ typically collapse into one of two extremes. On the one hand, hype: unverified claims that don’t hold up to scrutiny and invite significant criticism. On the other, dismissal: it’s just old tradecraft with new branding.

AI Powered Threat Detection: CISO's Guide

The market is giving CISOs a blunt signal. AI-powered threat detection and response was valued at USD 5.59 billion in 2024 and is projected to reach USD 23.52 billion by 2032, at a 20.00% CAGR according to Kings Research on the AI-powered threat detection and response market. That kind of growth doesn't happen because security teams like new tooling. It happens because modern environments generate more telemetry than analysts can realistically review, and attackers move faster than rule updates.

Strengthening modern detection with Open NDR and integrated threat intelligence

Adversaries are evolving faster than defenders can respond, and they're weaponizing AI to accelerate their attacks. We’ve seen “living-off-the-land”, lateral movement, and the abuse of legitimate administrator tools enable hackers to hide in plain sight, diluting the effectiveness of traditional detection methods. Meanwhile, defenders are nervously trying to keep up with the accelerating pace of AI-empowered threats hitting them at machine speed.

The Cybersecurity Poverty Line: Why it exists and why Sophos exists to erase it

The Cybersecurity Poverty Line: Why it exists and why Sophos exists to erase it Erase is an ambitious word. We chose it because the agentic era of AI creates a genuine opportunity to change the equation. There are roughly 359 million businesses in the world. Fewer than 35,000 of them employ a CISO. Every framework, product taxonomy, analyst report, compliance regime, and piece of cybersecurity marketing in circulation assumes a senior security leader on the other end.

Episode 17 - Home Labs and Tinted Windows: Why Network Visibility Starts at Your Front Door

In this episode, host Richard Bejtlich and guest Ricky Lin explore the practical—and often personal—side of network defense: monitoring the home network. Ricky shares how he uses Corelight and Zeek to track everything from his children's YouTube habits to the constant chatter of IoT devices like Tesla vehicles and smart appliances. They delve into the "tinted windows" analogy to explain why visibility into encrypted traffic is still possible through network metadata, even when the contents are hidden.

Threat Detection and Response Solutions: A Complete Guide

For those evaluating threat detection and response solutions, the underlying issues are often a persistent reality: The firewall says one thing, the endpoint tool says another, cloud alerts pile up in a separate console, and the compliance team still asks for evidence that no one can assemble quickly. Analysts waste time pivoting between tools when they should be deciding whether an incident is real and what to contain first.

Corelight Sensor v29.1 release highlights: Network evidence powers network operations

Corelight Sensor v29.1 and Fleet Manager v29.1.1 fundamentally expand what a Corelight Sensor delivers. The release turns existing network evidence into a shared source of truth for SecOps, NetOps, triage, and forensic investigation. Network performance monitoring and asset classification unlock new value from traffic you're already collecting.

Extending the value of network evidence: Introducing Performance and Asset Visibility

Every packet flowing through a Corelight sensor contains both security-relevant data and performance-relevant data. Until now, Corelight has focused exclusively on extracting security value from network traffic: connection logs, protocol analysis, and threat detections. But the same traffic that reveals lateral movement also reveals TCP latency. The same DNS queries that surface potential C2 channels also reveal resolution timing.

Performance and Asset Visibility Walkthrough

Network security depends on clear visibility across every digital asset. This detailed walkthrough covers Corelight's new Network Performance and Asset Classification logs. You will learn about these two logs, how to configure them, and how to use them during cyber investigations. Network Performance and Asset Visibility logs are available as part of the Sensor v29.1 general availability release to customers with Sensor and Investigator Bundle licenses.