Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.

SOCtember

Always First. Fast SOC News.

Detection

Detection engineering, alert operations, and the work of deciding whether a signal is useful enough to reach a responder.

CrowdStrike diagram summarizing nine MITRE ATT&CK-aligned offensive categories where the decompose-recompose pipeline produced working exploit code.
Figure: CrowdStrike, Figure 4, full pipeline nine offensive security use cases, Oct 6, 2026 (fair use).

DETECTION · LONDON

CrowdStrike Shows Attackers Bypass LLM Safety Classifiers by Splitting Harmful Goals Into Benign Subtasks

CrowdStrike says a frontier-model safety classifier blocked about 515 direct bypass attempts, but adversaries can still extract building blocks through genuinely benign subtasks and reassemble working offensive code with an unclassified local model.

Ava Okello, Detection, London

Read the story
Abstract Cisco Talos CAIRN research header graphic for a technical blog on malware that embeds instructions aimed at AI analysis tools.
Graphic: Cisco Talos, CAIRN header art for the Oct 8, 2026 post on AI-analysis evasion in malware (fair use).

DETECTION · LONDON

Malware Now Embeds Instructions Meant to Steer AI Analysis Tools, Cisco Talos Finds Across 84 Samples

Cisco Talos says four malware families now plant plain-language notes inside samples to influence AI triage tools, a class it calls A3. Across 84 samples the cheapest "ignore this file" comments steered model verdicts most often, while more elaborate template tricks often backfired, and defenders can hunt the same plaintext as a detection signal.

Ava Okello, Detection, London

Read the story
Dark login page with a shield icon and the name KMON_NOC above a single password field and a log-in button, with Russian-language labels for access password and log in and a line noting that authorization is required for all endpoints.
Screenshot: Datadog Security Labs, the login page of the KMON_NOC credential harvesting platform, which asks for an access password, Oct 6, 2026 (fair use).

DETECTION · LONDON

Attackers Are Testing Stolen AWS Keys for Amazon Bedrock Access, Leaving a Pattern Defenders Can Spot

Datadog Security Labs says a credential harvesting platform called KMON_NOC and two Python scripts check stolen AWS keys for access to Amazon Bedrock AI models with a short, repeatable run of API calls, a sequence it has seen in 12 organizations in the past 30 days and that detection teams can hunt for.

Ava Okello, Detection, London

Read the story
Black Lotus Labs diagram titled The Canto Incognito Campaign, April to Sept 2026: an actor server in Italy, an infected router serving malware on port 81 and C2 on port 9999, a PoeLLM botnet of LiteLLM, Ollama, Gotenberg and Gitea servers that find the C2 from a poem on GitHub, and arrows to a Kryptex mining pool, scanning and brute force.
Graphic: Black Lotus Labs (Lumen Technologies), overview of the Canto Incognito campaign, in which PoeLLM-infected LiteLLM, Ollama, Gotenberg and Gitea servers find their command server from a poem on GitHub, mine cryptocurrency and scan for new victims, Oct 7, 2026 (fair use).

DETECTION · LONDON

Malware That Reads Its Orders From a Poem on GitHub Has Hit More Than 3,400 Exposed AI and Developer Servers

Lumen's Black Lotus Labs said on October 7 that PoeLLM, a cryptomining botnet it ties to an Italian-speaking actor, breaks into exposed LiteLLM, Ollama, Gotenberg and Gitea servers and finds its command server by decoding four words in a poem the operator edits on GitHub.

Ava Okello, Detection, London

Read the story
Fake Cloudflare verification box with Win+R, Ctrl+V and Enter steps above a Windows Run dialog, with the cmd for /r command that searches the Firefox profile for f_ files of 33433 bytes.
Screenshot: Microsoft Threat Intelligence, a fake Cloudflare check telling the visitor to paste a command into Windows Run that copies a cached file to t.vbs and runs it, Oct 3, 2026 (fair use).

DETECTION · LONDON

Microsoft Warns ClickFix Lures Now Hide Their Payload in the Browser Cache

Microsoft Threat Intelligence said on October 3 that compromised websites are pre-fetching a VBScript payload into visitors' browser caches disguised as a PNG file, so the ClickFix command a victim pastes into Windows Run only has to find and launch it. Huntress, separately, described killing ClickFix chains on the endpoint before its SOC saw the alert.

Ava Okello, Detection, London

Read the story
Sequence diagram of forged signatures leading SConnect's native host to load an unsigned DLL.
Figure: Bay Area Labs / Am I Being Pwned?, SConnect drive-by RCE attack flow, Oct 2, 2026 (fair use).

DETECTION · LONDON

Thales SConnect Flaw Opened Drive-By Code Execution on PCs Used for SWIFT 3SKey Sign-In

Bay Area Labs disclosed on October 2, 2026, how a hand-rolled RSA check in Thales SConnect, the browser middleware long used with SWIFT 3SKey tokens, let a malicious web page or iframe load an unsigned DLL in about six to 10 seconds. Thales published the flaw as CVE-2026-18397, rated 9.4 critical, on October 1.

Ava Okello, Detection, London

Read the story
Microsoft Security Blog featured image for Unmasking EvilTokens, an operations room with a video wall.
Photo: Microsoft. Official Security Blog featured image for Unmasking EvilTokens.

DETECTION · LONDON

Microsoft Tracks EvilTokens Phishing Kit Behind Device Code Token Theft

Microsoft Threat Intelligence says EvilTokens, sold as phishing-as-a-service and tracked to Storm-2992, abused device code authentication to steal tokens and fuel BEC campaigns that compromised more than 12,000 inboxes worldwide.

Ava Okello, Detection, London

Read the story

DETECTION · LONDON

AI Tool Adoption Floods SOCs With Alert Noise, Not Agent Takeovers

LONDON - Enterprise adoption of coding agents and consumer AI assistants is generating a fast-growing class of security alerts that are overwhelmingly benign, according to a September 2026 analysis of SOC telemetry published by Intezer researchers and summarized by The Hacker News and the Cloud Security Alliance.

Ava Okello, Detection, London

Read the story

Did You Know

DETECTION · LONDON

Untuned Alerts Can Hide Active Intrusions From the SOC

LONDON - Organization B had an established baseline and a finer-tuned alert system. After medium-severity payload alerts, defenders isolated compromised workstations within minutes (within 10, 2, and 20 minutes across three hosts), cutting command and control and forcing the red team into an assume-breach model. CISA's lesson for operations teams: establish and continuously maintain baselines, refine alerting so routine administrative activity is filtered, and treat untuned detection stacks as a direct cause of missed intrusions.

Ava Okello, Detection, London

Read the explainer