ZeroHour

Search: “reasoning models”

24 stories in the last 30d

The longitude problem: In the AI era, detection is won on facts, not guesses

Opinion piece argues defenders should beat AI-era attackers by carrying verified ground truth about approvers, domains, and vendors instead of relying on inference.

CSO Online contributor Alan LeFort, CEO of StrongestLayer, uses the historical longitude problem to argue that AI-era detection should rely on carried facts—authoritative records of payment approvers, owned domains, and legitimate vendors—rather than probabilistic inference that both attackers and defenders can now perform with comparable reasoning models. He illustrates with a CFO wire-fraud example defeated by checking the approver of record and the reply-to domain against ground truth. The piece stresses that ground truth decays and must be continuously maintained, like chronometers kept wound on every ship.

CSO Online · 7d agoIndustry

Why 2026 is the Year to Upgrade to an Agentic AI SOC

Elastic Security Labs argues 2026 is the production inflection point for agentic AI in security operations centers.

Elastic Security Labs argues 2026 is the practical inflection point for agentic AI SOCs, noting nearly two-thirds of organizations are experimenting with AI agents while fewer than one in four have production deployments. The piece outlines operational challenges and recommendations: treat agents as non-human identities with least-privilege tool access, version-control system prompts as code, deploy unified agents with on-demand task packages, and enforce per-agent budgets and rate limits. It stresses explainability via RAG and transparent reasoning traces so analysts can verify and override autonomous decisions.

Elastic Security Labs · 8d agoIndustry

Your Critical Vulnerabilities Might Not Be Your Biggest Risk

Autonomous penetration testing advocates prioritize exploitable attack paths over raw vulnerability severity for continuous security validation.

The article argues that scanner severity scores lack context: a critical flaw behind strong segmentation may be low priority, while a medium flaw on internet-facing systems can provide a foothold chained toward sensitive data. It positions autonomous penetration testing and attack path validation as the execution layer for continuous security validation, replacing point-in-time assessments. The piece is vendor-authored thought leadership rather than incident or vulnerability news.

The Hacker News · 6d agoIndustry1

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

A weekly bulletin aggregating short security updates, including the City-Forum data-theft campaign, a ShipMonk breach, a Cursor CLI flaw, and GhostJacking AI attacks.

The Hacker News ThreatsDay Bulletin bundles roughly 20 short updates across cloud services, AI tools, malware, breaches, and scams. Highlights include the City-Forum campaign pulling data from unauthenticated guest access in Salesforce Experience Cloud and ServiceNow Service Portals since March 2025, and a ShipMonk breach exposing Trezor customer order data for orders in seven countries between May 10 and August 8, 2026. Other items cover a patched Cursor CLI flaw that let cloned repositories run commands before the workspace-trust prompt, Okta's analysis of the Work Panel vishing console used by actors like UNC6671, and GhostJacking AI agent hijacking via a patched Claude Desktop sandbox escape. Meta also launched an on-device WhatsApp Scam Alert machine learning model that keeps message content on the device.

The Hacker News · 29d agoIndustry1

The 12 Best Managed XDR Services, Compared and Priced

A comparison of twelve managed XDR providers covering pricing models, telemetry breadth, and distinguishing genuine MXDR from rebranded MDR services.

The article compares twelve managed XDR providers including Bitdefender, CrowdStrike, Palo Alto Unit 42, Trend Micro, Fortinet, Secureworks Taegis, Stellar Cyber, Ontinue, and ReliaQuest, highlighting pricing models and telemetry breadth. It explains that genuine MXDR must actively monitor identity, cloud, and email telemetry rather than merely ingest it, and typically costs 30-60% more than endpoint-only MDR. It also notes Sophos completed its approximately $859 million acquisition of Secureworks in February 2025.

GBHackers · 8d agoIndustry 3 sources2

The story behind the intelligence

Cisco Talos newsletter features adversary-engagement podcast, flags AI guardrail 'safety penalty' slowing defenders, and recaps McKesson breach and PaperCut patching headlines.

The Threat Source newsletter spotlights the Beers with Talos podcast, in which researcher Azim Khodjibaev describes maintaining eight dark-web personas to identify prolific cybercriminals and support disruption efforts. Talos also argues frontier AI guardrails impose an AI 'safety penalty', citing a July 2026 incident where Hugging Face's primary cloud LLM refused to analyze forensic breach data and delayed response. Recapped headlines include ShinyHunters claiming theft of 284 million patient records from McKesson via vishing and Okta account takeover, Anthropic warning Claude users about infostealer malware, and PaperCut issuing emergency patches for chained vulnerabilities.

Cisco Talos · 13d agoIndustry

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

Opinion piece argues attackers prioritize repeatable playbooks like ClickFix (47% of Microsoft-notified attacks) and living-off-the-land over novel techniques.

The column analyzes why commodity techniques scale: Microsoft observed ClickFix as the top initial access method at 47% of its notifications last year, while Bitdefender found 84% of 700,000 analyzed high-severity incidents involved binaries already present on machines. Verizon's DBIR shows vulnerability exploitation rising to 31% of initial access vectors, up from 20%, and ransomware leak-site rankings show Qilin (roughly 1,600 claimed victims) and The Gentlemen (121 claimed victims in June) competing on throughput. The author argues attackers behave like a generics business, standardizing repeatable procedures rather than investing in novel tradecraft.

The Hacker News · 16d agoIndustry

Top 10 Best Patch Management Software in 2026

Roundup ranks 2026 patch management software, favoring Automox, Action1's free tier and Tanium, and warns buyers to vet patching platform security.

This buyer's guide ranks ten patch management tools for 2026, placing Automox first for cloud-native patching, Action1 for a genuinely free small-estate tier and Tanium for patching hundreds of thousands of endpoints. It contextualizes the category with the 2021 Kaseya VSA ransomware supply-chain incident and the 2020 SolarWinds Orion compromise, arguing the security of the patching platform itself must be part of evaluation. It also notes Ivanti products have repeatedly appeared in CISA's Known Exploited Vulnerabilities catalog.

Cyber Security News · 8d agoIndustry1

The 12 Best Endpoint Detection & Response (EDR) Solutions, Compared and Priced

An editorial scorecard ranks 12 EDR platforms, with CrowdStrike and SentinelOne tied at 8.6/10 and telemetry retention identified as the hidden cost driver.

An editorial comparison scores twelve EDR platforms on detection, response, analyst burden, pricing transparency, and coverage. CrowdStrike and SentinelOne tie at 8.6/10, with Microsoft Defender for Endpoint close behind at 8.5 and described as effectively free in Microsoft 365 E5 estates. The guide argues that telemetry retention, not per-endpoint price, drives real cost, with fully-priced quotes frequently diverging 2-3x from headline rates. Managed detection offerings, including Cynet's bundled 24/7 SOC, factor into the buyer-fit rankings.

GBHackers · 8d agoIndustry 2 sources

Data access: the hidden cost of security vendor lock-in

Elastic compares SIEM data egress cost, latency, and fidelity across CrowdStrike, Microsoft, Google, and Splunk, arguing vendors engineer lock-in.

Elastic Security Labs published an opinion piece comparing how major SIEM and security vendors handle data egress, based on each vendor's public documentation as of September 2026. It rates CrowdStrike Falcon Data Replicator and Palo Alto Networks XSIAM Event Forwarding as restricted (paid add-ons with batch delays), Microsoft as partially open, Splunk as open, and Elastic as open with no export license. The piece argues frictionless ingestion paired with licensed or delayed egress is an intentional lock-in business model, and cites CrowdStrike's 2026 Global Threat Report eCrime breakout time of 29 minutes to argue real-time telemetry access is now essential.

Elastic Security Labs · 13d agoIndustry

Dataminr uses agentic AI to predict and verify security threats

Dataminr launches agentic AI capabilities for corporate security, adding automated event corroboration, context, and near-term threat prediction.

Dataminr Advanced for Corporate Security introduces Agentic Corroboration, Agentic Context, and Near-Term Predictive Intelligence, now generally available, moving the company from real-time alerting to what it calls Autonomous Real-Time Intelligence. The product relies on more than 60 fine-tuned task-specific LLMs trained on a 10+ year proprietary event archive rather than general-purpose frontier models. Upcoming releases include ReGenAI Tailored Live Briefs, a Watchlist Agent, Agentic Search, and an Advanced API suite.

Help Net Security · 2d agoIndustry

Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine

Corelight argues agentic AI should replace SOC alert queues with hypothesis-driven, machine-run investigations, reserving humans for judgment.

A Corelight opinion piece argues traditional SOC alert queues guarantee most alerts go unreviewed because human analysts are the investigative bottleneck. It proposes agentic AI that investigates signals within seconds, tests hypotheses against network telemetry asynchronously, and escalates only evidence-backed cases to humans. The vendor claims this inversion lowers cost per investigation, expands coverage, and converts security telemetry into actionable evidence.

The Hacker News · 22d agoIndustry

The 12 Best Mobile Device Management (MDM) Solutions, Compared and Priced

A comparison of 12 MDM platforms ranks Microsoft Intune as best value for Microsoft 365 estates and Jamf, Kandji, and Mosyle for Apple fleets.

The buyer's guide compares 12 mobile device management (MDM) products, naming Microsoft Intune best value since it is included in Microsoft 365 E3/E5, and Jamf, Kandji, and Mosyle as Apple specialists with day-one OS support and automated compliance remediation. Eight of the twelve publish rates; per-device pricing punishes multi-device users, while Microsoft, Omnissa, and IBM offer per-user options. Free tiers from Mosyle, Miradore, and ManageEngine support genuine small deployments.

GBHackers · 7d agoIndustry 2 sources

Top 10 Best Application Control & Allowlisting Tools in 2026

Roundup ranks 2026 application allowlisting tools, scoring ThreatLocker 8.8/10, Airlock Digital 8.5/10 and free Microsoft WDAC among top default-deny options.

This is a scored buyer's guide to ten application control and allowlisting tools for 2026, with ThreatLocker ranked first (8.8/10), Airlock Digital second (8.5/10) and Microsoft's built-in WDAC/AppLocker third (7.2/10). It notes ransomware has renewed interest in default-deny execution controls and that CISA and other agencies list application control among the most effective yet under-deployed mitigations. The evaluation is research-based with no lab testing, weighting policy automation at 30% and operability at 25%.

Cyber Security News · 8d agoIndustry1

What It Took to Reach 1 Billion Build Manifests

Chainguard doubled container build manifests to over 1 billion in six months, powered by Factory 2.0's agentic self-correcting rebuild system.

Chainguard reports growing from 500 million to over 1 billion container build manifests in six months, across more than 3,000 unique images and 675,000 image versions. Its Factory 2.0 system, built on the purpose-built Chainguard OS, uses an agentic reconciliation engine called DriftlessAF to decide when to rebuild across thousands of interdependent projects without human intervention. All artifacts ship with SLSA Level 3 provenance, Sigstore signatures, and full SBOMs.

The Hacker News · 9d agoIndustry

Top 10 Best Mobile Threat Defense (MTD) Solutions in 2026

Roundup of 2026 mobile threat defense tools recommends Zimperium and Lookout for targeted-attack detection and Defender for Endpoint for Microsoft shops.

This guide ranks ten mobile threat defense solutions, recommending Zimperium and Lookout for on-device detection against targeted users such as executives and journalists, and Microsoft Defender for Endpoint mobile for organizations already licensing Microsoft 365 E5. It explains that MDM enforces configuration while MTD detects attacks, and that mobile phishing now arrives via SMS, messaging apps and QR codes rather than email. It also highlights mercenary spyware and zero-click exploits as shifting requirements for high-risk users, referencing Apple's threat-notification program and Lockdown Mode.

Cyber Security News · 8d agoIndustry

How AI and cybersecurity are reshaping ServiceNow

Analysis argues ServiceNow's $7.75B Armis acquisition and AI-driven consumption pricing are reshaping its ITSM platform amid SaaS market anxiety.

CSO Online examines how AI agents, vibe-coding fears, and a reported 30% share price drop are pressuring ITSM leader ServiceNow, and how the company is pivoting toward consumption-based revenue and cybersecurity. The piece highlights ServiceNow's $7.75 billion cash acquisition of Armis, priced at roughly 23 times the vendor's $340 million annual revenue, as a strategic move to supercharge ITSM workflows with accurate device inventory and orchestration rather than to sell a standalone security product. Experts note this ends Armis's vendor-neutral position, introduces the CISO as a new buyer, and will likely lead to aggressive Armis bundling at contract renewals.

CSO Online · 6d agoIndustry

Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance

Kiteworks acquired AI data-security firm Bonfy.AI, reportedly for tens of millions of dollars, to add inline AI-era data governance.

Kiteworks announced the acquisition of Bonfy.AI, an AI-native content-security platform that classifies sensitive data in real time as it moves across email, file sharing, SaaS apps, and AI agents. The deal, estimated by CTech at tens of millions of dollars, will extend Kiteworks' Data Control Plane with inline runtime policy enforcement for both human and AI-agent workflows. This is Kiteworks' eighth acquisition in five years; Bonfy was founded in early 2024, raised a $9.5 million seed round, and emerged from stealth in June 2025.

SecurityWeek · 6d agoIndustry 2 sources

Top 10 Best CNAPP (Cloud-Native Application Protection) Platforms in 2026

GBHackers ranks 10 CNAPP platforms for 2026, naming Wiz, Prisma Cloud, and Microsoft Defender for Cloud as category leaders.

The guide describes CNAPP as the umbrella combining CSPM, CWPP, CIEM, and DSPM, arguing that cross-pillar correlation of attack paths is the platform's core value. Wiz is ranked best for graph-based correlation, Prisma Cloud for the broadest module set, and Microsoft Defender for Cloud for Azure economics. It also cites Google's approximately $32 billion agreement to acquire Wiz, announced in March 2025, as buyer leverage and a reason to seek roadmap and neutrality protections in multi-year contracts.

Cyber Security News · 6d agoIndustry1

Rapid7 Named Among Notable Vendors in Forrester MDR Landscape: Why the Future is Exposure-informed, Preemptive MDR

Rapid7 touts its listing in Forrester's Q3 2026 MDR Landscape, arguing MDR must converge with exposure management for measurable risk reduction.

Forrester's Managed Detection and Response Services Landscape, Q3 2026 names Rapid7 among notable providers and predicts MDR services will converge with exposure and posture improvement. Rapid7 pitches its exposure-informed, preemptive MDR built on its own SIEM, combining vulnerability findings and asset risk scoring with detection and response. The service includes unlimited incident response and a human-led, AI-enhanced investigation model. Forrester advises buyers to demand providers prove investigations rather than narrate dashboards.

Rapid7 Blog · 2d agoIndustry

The 12 Best Antivirus (Endpoint Protection) Software for Business, Compared and Priced

GBHackers compares 12 business antivirus products on detection, EDR depth, pricing, and platform coverage, ranking CrowdStrike and Bitdefender joint top at 8.8.

The roundup scores 12 enterprise endpoint protection vendors across detection, EDR depth, management, pricing transparency, and platform coverage. CrowdStrike and Bitdefender tie at 8.8, with Microsoft Defender for Endpoint scoring 8.5 and noted as effectively free for Microsoft 365 E5 licensees. The piece also flags that Kaspersky cannot legally be sold in the US and that Panda and Webroot now sit under WatchGuard and OpenText respectively.

GBHackers · 9d agoIndustry 2 sources1

Top 10 Best Endpoint Encryption Software in 2026

A 2026 roundup of ten endpoint encryption products argues the engines are solved and buyers should choose management layers like Intune, Sophos, or Trellix.

The guide ranks ten endpoint encryption options, arguing BitLocker and FileVault have won the engine war so the real purchase decision is the management layer for compliance proof, key escrow, and cross-platform policy. Microsoft BitLocker with Intune is named the baseline for Windows estates, with Sophos, ESET, Trend Micro, Check Point, Trellix, and others covering mixed or regulated fleets. It also warns that TrueCrypt-lineage freeware is unmaintained and that Kaspersky cannot be sold to US customers.

Cyber Security News · 7d agoIndustry

2026 Cyber Insurance Trends Report: What's Changed and What You Need to Know

Huntress survey: CIRCIA reporting mandates now live, BEC claims exceed ransomware, exfiltration-heavy attacks cost twice as much, premiums rising.

Huntress's 2026 cyber insurance trends report, based on its own survey, finds 79% of respondents carry cyber insurance while 58% report shrinking coverage over five years. New CIRCIA federal reporting mandates and EU NIS2 requirements are reshaping policies, business email compromise now drives more claims than ransomware, and data exfiltration has replaced encryption as the dominant ransomware tactic at roughly twice the cost. After three years of declining premiums, rates are climbing again, and most businesses now refuse to pay ransoms.

Huntress · 15d agoIndustry1

Key Reasons Why Identity Fabric Matters in 2026

Identity sprawl and unowned machine identities leave enterprise access unobserved at runtime; identity fabrics aim to close the gap between policy intent and execution.

This sponsored explainer describes identity fabric as an architectural approach connecting identity providers, governance systems, applications, and infrastructure into one observable layer that compares designed access intent with runtime execution. It argues identity sprawl across SaaS, APIs, and cloud workloads, plus unmanaged non-human identities (service accounts, bots, workloads, API keys), leaves overprivileged, dormant, and unowned machine identities unmonitored. IdP-only monitoring misses application-layer attacks, and the piece advocates behavioral visibility and lifecycle governance for secrets and machine identities.

The Hacker News · 20d agoIndustry