Bitsight connects threat intelligence and exposure monitoring across the supply chain
Bitsight made Beacon generally available, combining supply-chain exposure monitoring with MCP support to feed threat intelligence into AI workflows.
Bitsight announced general availability of Beacon, which continuously monitors critical vendors for exposure, vulnerabilities, malicious activity, intrusion, stolen credentials and compromise. New Model Context Protocol (MCP) and agentic capabilities push Bitsight intelligence into AI-enabled workflows, with over 400 customers signing up for early access in one month. The company cites data that third parties now account for almost half of enterprise breaches, up over 60% year over year.
F5 speeds up virtual patching to counter AI-driven threats
F5 added anomaly detection and agentic threat intelligence to its AI-powered WAF, enabling virtual patch enforcement against exploits within minutes.
F5 announced enhancements to F5 WAF for Distributed Cloud, adding anomaly detection that builds per-application traffic baselines and agentic threat intelligence built on technology from the Fletch acquisition. The AI-powered WAF scores each request in real time with a neural network risk engine, and internal testing claims 98% threat detection efficacy with false positives reduced to 1%. Automated virtual patching via Distributed Cloud Web App Scanning extends to F5 WAF for BIG-IP, letting teams block actively exploited vulnerabilities at the request level in minutes; agentic features are rolling out over coming months.
Searchlight Cyber combines exposure and threat intelligence in new PTEM platform
Searchlight Cyber launched its PTEM platform, merging exposure management from Assetnote with dark web threat intelligence to prioritize likely-exploited exposures.
Searchlight Cyber launched its Preemptive Threat Exposure Management (PTEM) platform, unifying Searchlight Exposure (formerly Assetnote) with Searchlight Threat, which consolidates the Cerberus investigations platform and DarkIQ dark web monitoring. The platform pairs continuous attack surface discovery and exploitability validation with attacker intelligence from the open, deep and dark web to help teams prioritize the exposures most likely to be exploited. The launch follows the 2025 Assetnote acquisition and a new corporate identity, and cites a Gartner forecast that preemptive security will reach 50% of IT security spending by 2030.
Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritization
Recorded Future launched Automated Signature Creation in ASI, turning new CVEs into deployable detection signatures in as little as 31 minutes.
Recorded Future announced Automated Signature Creation within its Attack Surface Intelligence product, autonomously generating production-ready detection signatures for newly surfaced vulnerabilities in as little as 31 minutes. The platform correlates an organization's internet-facing assets, live threat activity (malware, ransomware, actor intent), and vulnerability intelligence to prioritize which CVEs warrant detection. The company reports a tenfold increase in in-platform signatures and maps the capability to the four prioritization criteria in CISA's June 2026 directive on risk-based vulnerability mitigation.
ANY.RUN & SentinelOne: One Workspace, Instant Context for Rapid Response
ANY.RUN integrates its interactive sandbox, IOC lookups, and STIX/TAXII threat feeds natively into SentinelOne for faster automated malware triage.
ANY.RUN and SentinelOne launched connectors that embed interactive sandbox analysis and threat intelligence into the SentinelOne console via Singularity Hyperautomation. Suspicious files and URLs from alerts are automatically submitted to the ANY.RUN sandbox, with behavioral verdicts and risk scores returned into alert notes. On-demand IOC lookups draw on sandbox history from 16,000 organizations and 700,000 analysts. A separate STIX/TAXII feed streams verified malicious IPs, domains, and URLs through the SentinelOne Marketplace TAXII Connect app.
Rubrik MCP gives AI agents controlled access to security intelligence
Rubrik launched MCP support exposing Rubrik Security Cloud APIs to enterprise AI agents with RBAC, configurable permissions, and OWASP MCP Top 10 guardrails.
Rubrik announced Rubrik MCP (Model Context Protocol), giving organizations' AI agents a secure, programmable path to Rubrik's data, identity, and application intelligence via the Rubrik Security Cloud API schema. Teams can save multi-step recovery or compliance workflows as reusable, deterministic tools, with role-based access control parity and OWASP MCP Top 10 aligned guardrails. Rubrik engineered its agent architecture with Anthropic's teams for multi-step reasoning in incident response, and says Rubrik AI is now trusted by one-third of its global customers.
Corero brings cloud-based AI threat analysis to SmartWall ONE
Corero adds cloud-delivered AI analysis to SmartWall ONE for faster DDoS attack identification and automated protection policy generation.
Corero Network Security announced AI-Augmented Cloud-Assist for SmartWall ONE, a cloud-delivered AI layer that analyzes DDoS telemetry, identifies emerging attack behaviors, and recommends protection policies that can be applied manually or automatically within seconds. It creates a continuous intelligence loop between Corero's cloud and on-premises SmartWall ONE deployments, with security experts providing oversight. The feature targets AI data centers, NeoCloud providers, service providers, and digital enterprises requiring low-latency edge mitigation.
Can AI make threat intelligence easier? One platform thinks so
Feedly positions its AI-driven Threat Intelligence platform to cut CTI collection time, scanning 10,000+ sources with 1,000 AI models and reporting 70% time savings.
A profile of Feedly Threat Intelligence describes how CTI teams such as RH-ISAC reduced threat data collection from 10 hours weekly to 2-3 hours after adoption. The platform scans over 10,000 open web sources using 1,000 AI models to extract TTPs, CVEs and IoCs into a real-time Threat Graph queryable via an Ask AI LLM with source citations. Customers including GreyNoise, Sopra Steria, gematik and GISA reported measurable gains such as 20 hours saved daily and earlier vulnerability flagging than CISA 65% of the time. The product integrates with Anomali ThreatStream, Cortex XSOAR, Microsoft Sentinel and OpenCTI, plus a REST API and GitHub scripts.
Product showcase: ScamNet looks for warning signs in suspicious calls and shady links
Synaptrex's ScamNet app filters scam calls, messages and websites on Apple devices using on-device AI and reputation checks.
ScamNet: Anti-Scam Suite from Synaptrex Technologies is a free consumer app (with ScamNet+ subscription) for iPhone, iPad and Mac that blocks robocalls and spam via iOS Call Blocking & Identification, filters unknown senders with an offline detection engine, and provides a Safari extension that analyzes and blocks suspicious websites. A Check/Report tool accepts phone numbers, websites, crypto addresses, text, images and audio, and a Device Shield verifies passcode, OS updates and screen-recording status.
Wazuh and AI For Enhanced SOC Workflows
Wazuh details AI-powered SOC workflows via its AI Analyst, self-hosted Llama 3 via Ollama, and Claude 3.5 Haiku integrations.
Wazuh outlines how AI can augment SOC analysts handling high alert volumes. The Wazuh AI Analyst on Wazuh Cloud uses Amazon Bedrock and Anthropic Claude to generate scheduled security posture reports. Self-hosted options include Llama 3 with Ollama, FAISS, and LangChain for privacy-sensitive threat hunting, plus an OpenSearch Assistant integration with Claude 3.5 Haiku. This is a vendor-contributed piece describing product capabilities rather than an incident or vulnerability.
New infosec products of the month: August 2026
August 2026 roundup of security product releases from ServiceNow, Tanium, Snyk, F5, A10, Searchlight Cyber, Intezer, NETSCOUT, Tufin, and Abnormal AI.
Help Net Security's monthly product roundup covers roughly a dozen vendors. Highlights include Snyk's general availability of Evo Continuous Offensive Security with AI-powered pentesting and AI agent red teaming, Searchlight Cyber's PTEM platform combining exposure visibility with attacker intelligence, and A10 and F5 AI gateways to govern enterprise LLM and agent usage. Other updates include Abnormal AI email DLP and phishing training, NETSCOUT outbound DDoS mitigation for service providers, Intezer's native Workflows automation, and Tufin's AI-powered Segmentation Intelligence.
Security Data Isn’t the Problem. Security Context Is.
Horizon3 blog argues security context, not data volume, is the SOC bottleneck, promoting its NodeZero integration with CrowdStrike Falcon Next-Gen SIEM.
Horizon3.ai published a vendor blog explaining how its NodeZero Proactive Security Platform integration with CrowdStrike Falcon Next-Gen SIEM brings validated exposure findings into existing security operations workflows. The post argues SOCs are now limited by confidence rather than visibility, needing context to decide which issues matter. It cites a global chemical manufacturer that validated exploitable exposures with NodeZero before completing a $2 billion merger.