Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]

Intel Chat with Matt Bromiley and Chris Luft. Matt and Chris break down four stories from the week in threat intel: Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat. Stories covered: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.

Find and stop vulnerable code at runtime - Secure App in Splunk Observability Cloud

Secure App brings runtime application security into Splunk Observability Cloud using the same OpenTelemetry instrumentation as your APM traces to surface the vulnerabilities actually running in production, prioritize them by real-world exploit risk, and catch live attacks. TOC.

How to have an epic lunch break (UpGuard edition)

Chris O'Brien, Head of Sales Engineering at UpGuard, spent his lunch break at his local fair — carnival games, rides, and all. When we say work-life balance matters to us, we mean it. Sometimes that looks like stepping away from back-to-back meetings to grab a corn dog and a life-size plushie. UpGuard helps organizations manage third-party risk and monitor their attack surface — but great security work starts with a team that's supported enough to log off, recharge, and show up sharp.

Sumo Logic's SOC Analyst Agent: Automated triage for every tier one alert

Sumo Logic's SOC Analyst Agent automatically triages every insight within the SIEM, replacing the manual work that used to fall to a tier-one analyst. Using Sumo Logic's own SOC as customer zero, we found that 100% of tier-one alerts are triaged end-to-end by the agent, resulting in a 89% reduction in median time to triage, from 28 minutes to 3 minutes. In this demo, you’ll see.

Mobot: Sumo Logic's natural language AI for SOC investigations

Mobot is Sumo Logic's conversational interface designed to streamline investigations for SOC analysts and observability users. Ask a question in plain English and get a full SOC analyst-style investigation without writing a query. Inside an Insight, Mobot pulls context like the C2IP, ransomware hash, host, and exfiltration data automatically. A six-word question, "anyone else hit by the campaign?", triggers a full investigation across every mailbox and endpoint tied to that attack, with a link to the raw query behind every answer.

The 14-Hour Recovery: Rethinking Healthcare Cyber Resilience

Ransomware recovery for healthcare IT depends on isolated recovery environments (IRE) and the ability to find clean data for patient safety. Jeremy Cathey shares insights on building cyber resilience by moving away from traditional disaster recovery toward a model that handles systemic cyberattacks. He details the three essential zones of an IRE: the clean room for forensics, the staging zone for validation, and the standby production environment where clinicians resume work.