Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal.

SOCtember

Always First. Fast SOC News.

Microsoft graphic with a gear, a network, and a signal on a blue and yellow field.

Microsoft Security Blog

TOOLS · REDMOND

Microsoft folds SIEM and threat protection into Defender as ISOC enters preview

REDMOND - Microsoft on September 23, 2026, announced Integrated Security Operations Center, or ISOC, in Microsoft Defender, a preview foundation that puts security information and event management and native threat protection on one shared platform so analysts and agents can investigate and act without stitching separate stacks.

September 23, 2026

Ava Okello, Detection, London

Latest

Full desk

RESPONSE · WASHINGTON

CISA Flags TeamCity Flaw CVE-2026-63077 as Used in Ransomware Campaigns

WASHINGTON - The Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities catalog so that CVE-2026-63077, a critical JetBrains TeamCity On-Premises flaw, is now marked with known ransomware campaign use. Trade press reported the KEV change on Wednesday, September 23, 2026. CISA first added the vulnerability to the catalog on August 5, 2026, after evidence of active exploitation. The live KEV feed lists knownRansomwareCampaignUse as Known for this CVE.

Noah Park, Response, New York

Read the story

Text desk note. No incident photograph.

Did You Know

RESPONSE · WASHINGTON

Did You Know: Patching a KEV Host Before Collecting Evidence Can Erase the Intrusion Trail

WASHINGTON - When CISA adds a vulnerability to the Known Exploited Vulnerabilities catalog and flags forensic triage, the agency's Binding Operational Directive 26-04 implementation guidance tells responders to collect evidence before they patch. Patching first can destroy the artifacts that show whether an adversary already used the hole.

September 25, 2026

Noah Park, Response, New York

Read the story

Text desk note. No incident photograph.

THREAT INTEL · SINGAPORE

Arista Confirms Actively Exploited VeloCloud Orchestrator Flaw

SINGAPORE - Arista Advisory 0183, published September 22, 2026 and revised to 1.1 on September 23, 2026, covers CVE-2026-93952 in the on-premises VeloCloud Orchestrator. The flaw was discovered externally and is actively exploited.

Priya Shah, Threat Intel, Singapore

Read the story
A technician at monitors in a data-center monitoring room. Not a photograph of an Arista or VeloCloud incident.
Photo: Derrick Coetzee

THREAT INTEL · SAN JOSE

Talos Documents CLOSEDQUORUM, Windows Implant That Lets AI Models Vote on C2 Moves

SAN JOSE - Cisco Talos researchers have documented CLOSEDQUORUM, which they describe as the first publicly reported Windows implant in their knowledge that uses a panel of commercial large language models as tactical command and control after deployment. The finding appears in a Talos blog by Ryan Fetterman dated Tuesday, September 22, 2026, and was uncovered with CAIRN, Talos' new open-source toolkit for tracking AI-integrated malware. Talos has not confirmed in-the-wild deployment.

Priya Shah, Threat Intel, Singapore

Read the story

Text desk note. No incident photograph.

TOOLS · REDMOND

Microsoft folds SIEM and threat protection into Defender as ISOC enters preview

REDMOND - Microsoft on September 23, 2026, announced Integrated Security Operations Center, or ISOC, in Microsoft Defender, a preview foundation that puts security information and event management and native threat protection on one shared platform so analysts and agents can investigate and act without stitching separate stacks.

Ava Okello, Detection, London

Read the story

Text desk note. No incident photograph.

TOOLS · WASHINGTON

CISA Scales Free SIEM-as-a-Service to Shorten Federal Response Windows

WASHINGTON - The Cybersecurity and Infrastructure Security Agency is expanding its security information and event management as a service offering for federal civilian agencies, aiming to give agency and CISA hunters shared SIEM telemetry at no cost to participating departments while cutting the time needed to start an investigation.

September 25, 2026

James Whitford, Tools, Austin

Read the story

Text desk note. No incident photograph.

TOOLS · MOUNTAIN VIEW

SentinelOne Extends Wayfinder Threat Hunting to AWS, Azure, and Google Cloud

MOUNTAIN VIEW - SentinelOne on September 24, 2026, said it has expanded Wayfinder Threat Hunting to AWS, Azure, and Google Cloud. In a Business Wire announcement that day, the company said the service pairs Singularity Platform telemetry with human-led hunting, and that it uses threat intelligence and intrusion findings from SentinelOne and Google Threat Intelligence in one workflow. SentinelOne said the cloud step follows earlier Wayfinder coverage of endpoints and of identity hunting for Okta and Microsoft Entra ID.

September 25, 2026

James Whitford, Tools, Austin

Read the story

Photo: SentinelOne

OPINION · LONDON

Alert Fatigue Is a Detection Pipeline Failure, Not an Analyst Character Flaw

LONDON - SOCs still treat missed alerts as a people problem. Detection engineering evidence says most alert fatigue is manufactured upstream in the detection pipeline. Future of SecOps (Aug 2026, Marta K.) described a review that blamed an analyst after a shift queue of more than 800 alerts, including EDR and identity duplicates of one medium-severity credential anomaly. Alert fatigue is volume, noise, duplication, and weak prioritization exceeding review capacity. Intezer (THN Sep 12, 2026): ~16.9M SOC alerts Feb-Jun 2026; ~73k AI-related (0.43%), up 685%; of AI-related, 94.1% benign tool use, 5.8% unsafe/policy, 0.02% confirmed attacks; no confirmed org-agent takeovers. ISACA 2025 via FoS: 55% understaffed; 38% need 3-6 months to fill entry-level. Fix: measure FP/duplicate/backlog/TTA by rule; tune defaults; correlate; severity contracts; rule owners; triage feedback. AI triage helps enrichment but cannot retire orphan rules.

Elena Vos, Opinion, London

Read the story

Text desk note. No incident photograph.

Did You Know

DETECTION · LONDON

Untuned Alerts Can Hide Active Intrusions From the SOC

LONDON - Organization B had an established baseline and a finer-tuned alert system. After medium-severity payload alerts, defenders isolated compromised workstations within minutes (within 10, 2, and 20 minutes across three hosts), cutting command and control and forcing the red team into an assume-breach model. CISA's lesson for operations teams: establish and continuously maintain baselines, refine alerting so routine administrative activity is filtered, and treat untuned detection stacks as a direct cause of missed intrusions.

Ava Okello, Detection, London

Read the explainer

Text desk note. No incident photograph.

A technician at monitors in a data-center monitoring room. Layout photograph, not live news.
Photo: Derrick Coetzee

Section

Detection

Sourced item filed.

Read the story