Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal. Detection, Dallas. Ava Okello: Report Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust Them.
RESPONSEHuntress Reconstructs Akira Ransomware Attack From Registry Artifacts After Post-Compromise EDR InstallNEW YORKNoah ParkDETECTIONCrowdStrike Shows Attackers Bypass LLM Safety Classifiers by Splitting Harmful Goals Into Benign SubtasksLONDONAva OkelloTOOLSUnit 42 Tracks ChainDrop and PolinRider Stealing Cloud Build Credentials Through Blockchain C2 Dead DropsAUSTINJames WhitfordTHREAT INTELCisco Talos Tracks UAT-11985 Phishing Taiwan Researchers With AI-Assisted Invites and Real-Time Google Login RelaysSINGAPOREPriya ShahRESPONSEHuntress Sees Active Exploitation of AhsayCBS Backup Flaws Dropping Webshells and XMRig Across Five OrganizationsNEW YORKNoah ParkDETECTIONMalware Now Embeds Instructions Meant to Steer AI Analysis Tools, Cisco Talos Finds Across 84 SamplesLONDONAva OkelloTHREAT INTELRussia-Aligned Spies Retool MATCHBOIL Malware and Widen Attacks to Ukrainian Transport, Manufacturing and Energy FirmsSINGAPOREPriya ShahRESPONSEFBI and Secret Service Warn FortiBleed Hackers Are Locking Some Fortinet Customers Out of Their Own FirewallsNEW YORKNoah ParkDETECTIONAttackers Are Testing Stolen AWS Keys for Amazon Bedrock Access, Leaving a Pattern Defenders Can SpotLONDONAva OkelloRESPONSEPoisoned Tensorlake npm Release Hid a Worm That Deletes Home Directories if Victims Revoke the Stolen TokenNEW YORKNoah ParkTHREAT INTELFBI Seizes Integrity Tech Hacking Tools as Allies Detail How China-Linked Hackers Steal Government EmailSINGAPOREPriya ShahDETECTIONMalware That Reads Its Orders From a Poem on GitHub Has Hit More Than 3,400 Exposed AI and Developer ServersLONDONAva OkelloTHREAT INTELIran-Linked Hackers Posing as Dubai Airports Recruiters Hide Malware in a Visual Studio Coding TestSINGAPOREPriya ShahTHREAT INTELFake ChatGPT and Gemini Ad Portals Use Browser-in-the-Browser Pop-Ups to Steal Logins and MFA CodesSINGAPOREPriya ShahDETECTIONMicrosoft Warns ClickFix Lures Now Hide Their Payload in the Browser CacheLONDONAva OkelloTHREAT INTELClingSTUN Backdoor Turns Unpatched IoT Devices Into Proxies Hidden in Public STUN TrafficSINGAPOREPriya ShahDETECTIONThales SConnect Flaw Opened Drive-By Code Execution on PCs Used for SWIFT 3SKey Sign-InLONDONAva OkelloRESPONSECitrix Patches NetScaler SAML Zero-Day CVE-2026-88779 After Attacks Reboot Freshly Patched AppliancesNEW YORKNoah ParkTHREAT INTELRapid7 Tracks BPFDoor and AVERAT Implants Mimicking Asian Mail GatewaysSINGAPOREPriya ShahRESPONSEMicrosoft Tracks Unauthenticated Zimbra SNMP Command Injection Exploited as CVE-2026-73570NEW YORKNoah ParkOPINIONSOC Autonomy Without Governance Recreates the Same Failure Modes AI Was Meant to FixLONDONElena VosTHREAT INTELMandiant Warns ShinyHunters Bypass WAFs to Resume PeopleSoft Mass ExploitationSINGAPOREPriya ShahDETECTIONMicrosoft Tracks EvilTokens Phishing Kit Behind Device Code Token TheftLONDONAva OkelloRESPONSECitrix Confirms Two NetScaler RCE Zero-Days Exploited in the WildNEW YORKNoah ParkDETECTIONHuntress Finds Threat Actor Compiling Silent XMR Miner Directly on EndpointLONDONAva OkelloRESPONSECISA Puts MikroTik RouterOS SSH Workflow Flaw CVE-2026-67279 on KEVWASHINGTONNoah ParkRESPONSECheck Point Patches Actively Exploited Management Server Path TraversalNEW YORKNoah ParkDETECTIONReport Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust ThemDALLASAva OkelloRESPONSEHuntress Reconstructs Akira Ransomware Attack From Registry Artifacts After Post-Compromise EDR InstallNEW YORKNoah ParkDETECTIONCrowdStrike Shows Attackers Bypass LLM Safety Classifiers by Splitting Harmful Goals Into Benign SubtasksLONDONAva OkelloTOOLSUnit 42 Tracks ChainDrop and PolinRider Stealing Cloud Build Credentials Through Blockchain C2 Dead DropsAUSTINJames WhitfordTHREAT INTELCisco Talos Tracks UAT-11985 Phishing Taiwan Researchers With AI-Assisted Invites and Real-Time Google Login RelaysSINGAPOREPriya ShahRESPONSEHuntress Sees Active Exploitation of AhsayCBS Backup Flaws Dropping Webshells and XMRig Across Five OrganizationsNEW YORKNoah ParkDETECTIONMalware Now Embeds Instructions Meant to Steer AI Analysis Tools, Cisco Talos Finds Across 84 SamplesLONDONAva OkelloTHREAT INTELRussia-Aligned Spies Retool MATCHBOIL Malware and Widen Attacks to Ukrainian Transport, Manufacturing and Energy FirmsSINGAPOREPriya ShahRESPONSEFBI and Secret Service Warn FortiBleed Hackers Are Locking Some Fortinet Customers Out of Their Own FirewallsNEW YORKNoah ParkDETECTIONAttackers Are Testing Stolen AWS Keys for Amazon Bedrock Access, Leaving a Pattern Defenders Can SpotLONDONAva OkelloRESPONSEPoisoned Tensorlake npm Release Hid a Worm That Deletes Home Directories if Victims Revoke the Stolen TokenNEW YORKNoah ParkTHREAT INTELFBI Seizes Integrity Tech Hacking Tools as Allies Detail How China-Linked Hackers Steal Government EmailSINGAPOREPriya ShahDETECTIONMalware That Reads Its Orders From a Poem on GitHub Has Hit More Than 3,400 Exposed AI and Developer ServersLONDONAva OkelloTHREAT INTELIran-Linked Hackers Posing as Dubai Airports Recruiters Hide Malware in a Visual Studio Coding TestSINGAPOREPriya ShahTHREAT INTELFake ChatGPT and Gemini Ad Portals Use Browser-in-the-Browser Pop-Ups to Steal Logins and MFA CodesSINGAPOREPriya ShahDETECTIONMicrosoft Warns ClickFix Lures Now Hide Their Payload in the Browser CacheLONDONAva OkelloTHREAT INTELClingSTUN Backdoor Turns Unpatched IoT Devices Into Proxies Hidden in Public STUN TrafficSINGAPOREPriya ShahDETECTIONThales SConnect Flaw Opened Drive-By Code Execution on PCs Used for SWIFT 3SKey Sign-InLONDONAva OkelloRESPONSECitrix Patches NetScaler SAML Zero-Day CVE-2026-88779 After Attacks Reboot Freshly Patched AppliancesNEW YORKNoah ParkTHREAT INTELRapid7 Tracks BPFDoor and AVERAT Implants Mimicking Asian Mail GatewaysSINGAPOREPriya ShahRESPONSEMicrosoft Tracks Unauthenticated Zimbra SNMP Command Injection Exploited as CVE-2026-73570NEW YORKNoah ParkOPINIONSOC Autonomy Without Governance Recreates the Same Failure Modes AI Was Meant to FixLONDONElena VosTHREAT INTELMandiant Warns ShinyHunters Bypass WAFs to Resume PeopleSoft Mass ExploitationSINGAPOREPriya ShahDETECTIONMicrosoft Tracks EvilTokens Phishing Kit Behind Device Code Token TheftLONDONAva OkelloRESPONSECitrix Confirms Two NetScaler RCE Zero-Days Exploited in the WildNEW YORKNoah ParkDETECTIONHuntress Finds Threat Actor Compiling Silent XMR Miner Directly on EndpointLONDONAva OkelloRESPONSECISA Puts MikroTik RouterOS SSH Workflow Flaw CVE-2026-67279 on KEVWASHINGTONNoah ParkRESPONSECheck Point Patches Actively Exploited Management Server Path TraversalNEW YORKNoah ParkDETECTIONReport Finds Nearly Half of Deployed Detections Need Attention Before SOCs Can Trust ThemDALLASAva Okello
Huntress shows how Shellbags, Akira logs, and PowerShell shadow-copy toolmarks reconstructed an Akira intrusion after a post-compromise agent install left only a thin EDR slice of GOST tunneling and related activity.
Noah Park, Response, New York
Read the storyFigure: CrowdStrike, Figure 4, full pipeline nine offensive security use cases, Oct 6, 2026 (fair use).
CrowdStrike says a frontier-model safety classifier blocked about 515 direct bypass attempts, but adversaries can still extract building blocks through genuinely benign subtasks and reassemble working offensive code with an unclassified local model.
Ava Okello, Detection, London
Read the storyFigure: Unit 42, Figure 1, attack flow of the ChainDrop npm worm, Oct 7, 2026 (fair use).
Unit 42 says supply chain worms are resolving command-and-control through EtherHiding, cross-chain transaction data, and NullReceiver address encoding so CI pipelines and developer hosts leak ephemeral cloud keys without hard-coded domains.
James Whitford, Tools, Austin
Read the storyGraphic: Cisco Talos, Threat Spotlight header art for the Oct 8, 2026 UAT-11985 post (fair use).
Cisco Talos says the campaign reused real public event details, likely AI-assisted invitation templates, and an adversary-in-the-middle kit that relays Google authentication including MFA challenges over HTTP and WebSocket. ClamAV and Snort coverage plus IOCs are published.
Priya Shah, Threat Intel, Singapore
Read the storyGraphic: Huntress, Rapid Response header art for the Oct 8, 2026 AhsayCBS active-exploit post (fair use).
Huntress says attackers began chaining two AhsayCBS flaws on Oct. 7 to gain SYSTEM-level remote code execution, then planted JSP webshells, an XMRig miner disguised as Microsoft Edge, and an AI-assisted PowerShell script that hides mining when Task Manager is open. Four Sigma rules and IOCs are published for defenders.
Noah Park, Response, New York
Read the storyGraphic: Cisco Talos, CAIRN header art for the Oct 8, 2026 post on AI-analysis evasion in malware (fair use).
Cisco Talos says four malware families now plant plain-language notes inside samples to influence AI triage tools, a class it calls A3. Across 84 samples the cheapest "ignore this file" comments steered model verdicts most often, while more elaborate template tricks often backfired, and defenders can hunt the same plaintext as a detection signal.
Ava Okello, Detection, London
Read the storyScreenshot: ESET Research, the fake daily planner window, titled Dairy, that late 2025 MATCHBOIL samples display when opened directly, from MATCHBOIL: New tricks, same old evil intentions, Oct 8, 2026 (fair use).
ESET says UAC-0099, a group it describes as able to act as an initial access broker for Sandworm, planted its rebuilt MATCHBOIL downloader at Ukrainian transportation, manufacturing and energy companies, adding fake planner screens, sandbox checks and a new DLL variant while leaving a trail of file paths, scheduled tasks and HTTP headers defenders can hunt.
Priya Shah, Threat Intel, Singapore
Read the storyDocument: FBI and U.S. Secret Service, cover of joint cybersecurity advisory JCSA-20261006-01, FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts, Oct 6, 2026 (fair use).
A joint FBI and Secret Service advisory says the credential theft campaign against internet-facing FortiGate firewalls is still scanning with stolen passwords, sometimes deletes or changes administrators' accounts so owners cannot log in, and has fed access to the INC/Lynx and Payload ransomware operations.
Noah Park, Response, New York
Read the storyScreenshot: Datadog Security Labs, the login page of the KMON_NOC credential harvesting platform, which asks for an access password, Oct 6, 2026 (fair use).
Datadog Security Labs says a credential harvesting platform called KMON_NOC and two Python scripts check stolen AWS keys for access to Amazon Bedrock AI models with a short, repeatable run of API calls, a sequence it has seen in 12 organizations in the past 30 days and that detection teams can hunt for.
Ava Okello, Detection, London
Read the storyGraphic: StepSecurity, summary of the tensorlake npm compromise, a self-spreading worm that holds a stolen GitHub token hostage and wipes the machine if the token is revoked, Oct 8, 2026 (fair use).
A malicious tensorlake 0.5.144, pushed to the AI sandbox company's own GitHub repository and published with valid npm provenance on October 8, steals cloud, GitHub and npm secrets, spreads through victims' packages and installs a monitor that deletes the home directory if the stolen GitHub token is revoked, so responders must remove it before rotating credentials.
Noah Park, Response, New York
Read the storyScreenshot: FBI, via joint Cybersecurity Advisory AA26-281A, a MicroScan account dashboard showing detected vulnerabilities, recovered in FBI investigations of Integrity Technology Group, Oct 8, 2026 (fair use).
The FBI and nine partner agencies said on October 8 that hackers tied to Integrity Technology Group, a China-based company with links to the Chinese government, stole email from government, law enforcement, healthcare and religious organizations in Southeast Asia, as the Justice Department seized domains behind the company's Microscan scanner and FishHub phishing tool.
Priya Shah, Threat Intel, Singapore
Read the storyGraphic: Black Lotus Labs (Lumen Technologies), overview of the Canto Incognito campaign, in which PoeLLM-infected LiteLLM, Ollama, Gotenberg and Gitea servers find their command server from a poem on GitHub, mine cryptocurrency and scan for new victims, Oct 7, 2026 (fair use).
Lumen's Black Lotus Labs said on October 7 that PoeLLM, a cryptomining botnet it ties to an Italian-speaking actor, breaks into exposed LiteLLM, Ollama, Gotenberg and Gitea servers and finds its command server by decoding four words in a poem the operator edits on GitHub.
Ava Okello, Detection, London
Read the storyScreenshot: Unit 42 (Palo Alto Networks), the fake Dubai Airports careers portal the attackers had the target install before sending a trojanized coding test, Oct 6, 2026 (fair use).
Unit 42 researchers said on October 6 that an Iranian state-aligned group it tracks as CL-STA-1178 sent an Iraq-based engineer a fake coding assessment that ran malware as soon as Visual Studio opened the project, then took its orders through GitHub repositories and issue comments.
Priya Shah, Threat Intel, Singapore
Read the storyScreenshot: Island, clicking Connect on a spoofed Gemini Ads page opens a fake Google sign-in window drawn inside the page while the real address bar still shows gemini-beta-invites.com, Oct 6, 2026 (fair use).
Island researchers said on October 6 that a human-operated phishing platform posing as AI advertising products for Gemini, ChatGPT, Claude, Perplexity and a fake Muse Ads draws a counterfeit Google sign-in window inside the page, then lets a live operator choose which MFA prompt the victim sees next.
Priya Shah, Threat Intel, Singapore
Read the storyScreenshot: Microsoft Threat Intelligence, a fake Cloudflare check telling the visitor to paste a command into Windows Run that copies a cached file to t.vbs and runs it, Oct 3, 2026 (fair use).
Microsoft Threat Intelligence said on October 3 that compromised websites are pre-fetching a VBScript payload into visitors' browser caches disguised as a PNG file, so the ClickFix command a victim pastes into Windows Run only has to find and launch it. Huntress, separately, described killing ClickFix chains on the endpoint before its SOC saw the alert.
Ava Okello, Detection, London
Read the storyScreenshot: Nozomi Networks Labs packet capture of a spoofed STUN reply carrying a flood command in its transaction ID, Oct 1, 2026 (fair use).
FortiGuard Labs said on October 5 that ClingSTUN, a Linux backdoor spread through 24 known flaws in routers, cameras and other edge devices, uses legitimate public STUN servers so its traffic blends with VoIP and WebRTC. Nozomi Networks, tracking the same malware as Cling, found operator commands hidden in STUN transaction IDs.
Priya Shah, Threat Intel, Singapore
Read the storyFigure: Bay Area Labs / Am I Being Pwned?, SConnect drive-by RCE attack flow, Oct 2, 2026 (fair use).
Bay Area Labs disclosed on October 2, 2026, how a hand-rolled RSA check in Thales SConnect, the browser middleware long used with SWIFT 3SKey tokens, let a malicious web page or iframe load an unsigned DLL in about six to 10 seconds. Thales published the flaw as CVE-2026-18397, rated 9.4 critical, on October 1.
Ava Okello, Detection, London
Read the storyPhoto/figure: Rapid7 Labs research art, Sleeper Cells in the Telecom Backbone hero (fair use).
Rapid7 Intelligence published its first research drop on October 2, 2026, documenting Linux implants that impersonate South Korean SpamSniper and Taiwanese ShareTech mail-security appliances, with BPFDoor, Rekoobe, and a modular tool Rapid7 tracks as AVERAT blending command-and-control into SMTP traffic on the network edge.
Priya Shah, Threat Intel, Singapore
Read the storyImage: The Hacker News, NetScaler SAML service-unavailable illustration (fair use).
Citrix shipped its second emergency NetScaler update in a week after attackers crashed SAML-enabled gateways that had already been patched for the PitScaler flaws, and incident responders say the forced reboots are being used to fire earlier log-injection payloads on appliances that missed the first fix.
Noah Park, Response, New York
Read the storyPhoto/figure: Microsoft Security Research / Microsoft Security Blog, Sep 30, 2026. Figure 1. CVE-2026-73570 attack chain (fair use).
Microsoft Security Research published findings on September 30, 2026, tracking unauthenticated OS command injection in the Zimbra Collaboration Suite SNMP notification path as CVE-2026-73570, with post-exploitation webshells, privilege escalation, credential theft, and mailbox staging observed on internet-facing mail servers.
Noah Park, Response, New York
Read the storyPhoto: Splunk. Enterprise Security 8.7 product UI showing the AI SOC Analyst moving from investigation context to a governed response action with Approve or Decline.
Splunk Enterprise Security 8.7 frames the Agentic SOC as a move from AI-assisted investigation to governed autonomous response, where permitted actions, approval gates, evidence, policy, and auditability matter more than buying a stronger model.
Elena Vos, Opinion, London
Read the storyLeak-site notice and data listing. Identifiers redacted.
Mandiant and Google Threat Intelligence Group say UNC6240, tracked as ShinyHunters, is again exploiting PeopleSoft CVE-2026-35273 by requesting a URL-encoded PSEMHUB path that literal WAF rules miss.
Priya Shah, Threat Intel, Singapore
Read the storyPhoto: Microsoft. Official Security Blog featured image for Unmasking EvilTokens.
Microsoft Threat Intelligence says EvilTokens, sold as phishing-as-a-service and tracked to Storm-2992, abused device code authentication to steal tokens and fuel BEC campaigns that compromised more than 12,000 inboxes worldwide.
Citrix says exploits of CVE-2026-88771 and CVE-2026-88772 have been observed on unmitigated NetScaler ADC and Gateway deployments, and CISA added both flaws to the KEV catalog on September 27, 2026.
Noah Park, Response, New York
Read the storyHuntress. AnyDesk download attempt under tomcat9.exe.
Huntress says a threat actor exploited Samsung MagicINFO, installed AnyDesk, and compiled a SilentXMRMiner build on the endpoint, producing noisy compiler telemetry before the miner reached C3Pool.
Ava Okello, Detection, London
Read the storyPhoto: Deavmi. MikroTik RB951Ui-2HnD. CC BY-SA 3.0 Wikimedia.
Federal agencies have until September 28 to remediate internet-exposed RouterOS devices after CISA confirmed active exploitation of the SSH state-machine bug used in the MikroTrick takeover chain.
NEW YORK - For security operations teams, this is a VPN and remote-access control-plane incident, not only a gateway patch ticket, and it is distinct from the management-plane path traversal CVE-2026-93616 that Check Point disclosed in the same advisory wave. Priority work is inventory of gateways and Spark hosts still on vulnerable trains with certificate-based Site-to-Site or Remote Access VPN; installation of LivePatch Take 26 or the matching Jumbo or Spark build; and log review for anomalous certificate-based Mobile Access logins since September 12, without limiting the hunt to the three published subjects. Check Point also advises looking for second-stage internal port and service scanning from suspicious Mobile Access users. If patching is delayed, the vendor recommends disabling VPN implied rules and restricting Site-to-Site UDP/500 and UDP/4500 to peer IP addresses (and for Remote Access, the required UDP and TCP services), noting that those temporary mitigations do not apply to locally managed Spark firewalls. Confirmed or suspected compromise should trigger forensic triage before operators treat residual risk as closed on patch status alone.
NEW YORK - F5 Networks has confirmed a critical heap-based buffer overflow in BIG-IP Access Policy Manager is under active exploitation, and CISA added it to the Known Exploited Vulnerabilities catalog.
WASHINGTON - The Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities catalog so that CVE-2026-63077, a critical JetBrains TeamCity On-Premises flaw, is now marked with known ransomware campaign use. Trade press reported the KEV change on Wednesday, September 23, 2026. CISA first added the vulnerability to the catalog on August 5, 2026, after evidence of active exploitation. The live KEV feed lists knownRansomwareCampaignUse as Known for this CVE.
Patchstack and other defenders report pearcmd-based file writes against unpatched WordPress after CVE-2026-87902 disclosure, turning a template-resolution path traversal into a SOC containment problem.
CISA added a critical WSO2 API Manager JWT authentication bypass to KEV on September 24, giving federal agencies until September 27 and pushing SOCs to treat exposed gateways as an auth-plane incident.
CISA put an unauthenticated Adobe Commerce and Magento incorrect-authorization flaw on KEV on September 24, giving agencies until September 27 and pushing SOCs to treat exposed storefronts as session-hijack cases.
WASHINGTON - When CISA adds a vulnerability to the Known Exploited Vulnerabilities catalog and flags forensic triage, the agency's Binding Operational Directive 26-04 implementation guidance tells responders to collect evidence before they patch. Patching first can destroy the artifacts that show whether an adversary already used the hole.
SINGAPORE - Arista Advisory 0183, published September 22, 2026 and revised to 1.1 on September 23, 2026, covers CVE-2026-93952 in the on-premises VeloCloud Orchestrator. The flaw was discovered externally and is actively exploited.
SAN JOSE - Cisco Talos researchers have documented CLOSEDQUORUM, which they describe as the first publicly reported Windows implant in their knowledge that uses a panel of commercial large language models as tactical command and control after deployment. The finding appears in a Talos blog by Ryan Fetterman dated Tuesday, September 22, 2026, and was uncovered with CAIRN, Talos' new open-source toolkit for tracking AI-integrated malware. Talos has not confirmed in-the-wild deployment.
LONDON - Enterprise adoption of coding agents and consumer AI assistants is generating a fast-growing class of security alerts that are overwhelmingly benign, according to a September 2026 analysis of SOC telemetry published by Intezer researchers and summarized by The Hacker News and the Cloud Security Alliance.
Conifers published The Detection Blind Spot on September 24, based on 14,652 detections in live enterprise environments, and said deployed detection counts are a weak proxy for real coverage.
LONDON - Organization B had an established baseline and a finer-tuned alert system. After medium-severity payload alerts, defenders isolated compromised workstations within minutes (within 10, 2, and 20 minutes across three hosts), cutting command and control and forcing the red team into an assume-breach model. CISA's lesson for operations teams: establish and continuously maintain baselines, refine alerting so routine administrative activity is filtered, and treat untuned detection stacks as a direct cause of missed intrusions.
REDMOND - Microsoft on September 23, 2026, announced Integrated Security Operations Center, or ISOC, in Microsoft Defender, a preview foundation that puts security information and event management and native threat protection on one shared platform so analysts and agents can investigate and act without stitching separate stacks.
WASHINGTON - The Cybersecurity and Infrastructure Security Agency is expanding its security information and event management as a service offering for federal civilian agencies, aiming to give agency and CISA hunters shared SIEM telemetry at no cost to participating departments while cutting the time needed to start an investigation.
MOUNTAIN VIEW - SentinelOne on September 24, 2026, said it has expanded Wayfinder Threat Hunting to AWS, Azure, and Google Cloud. In a Business Wire announcement that day, the company said the service pairs Singularity Platform telemetry with human-led hunting, and that it uses threat intelligence and intrusion findings from SentinelOne and Google Threat Intelligence in one workflow. SentinelOne said the cloud step follows earlier Wayfinder coverage of endpoints and of identity hunting for Okta and Microsoft Entra ID.
LONDON - SOCs still treat missed alerts as a people problem. Detection engineering evidence says most alert fatigue is manufactured upstream in the detection pipeline. Future of SecOps (Aug 2026, Marta K.) described a review that blamed an analyst after a shift queue of more than 800 alerts, including EDR and identity duplicates of one medium-severity credential anomaly. Alert fatigue is volume, noise, duplication, and weak prioritization exceeding review capacity. Intezer (THN Sep 12, 2026): ~16.9M SOC alerts Feb-Jun 2026; ~73k AI-related (0.43%), up 685%; of AI-related, 94.1% benign tool use, 5.8% unsafe/policy, 0.02% confirmed attacks; no confirmed org-agent takeovers. ISACA 2025 via FoS: 55% understaffed; 38% need 3-6 months to fill entry-level. Fix: measure FP/duplicate/backlog/TTA by rule; tune defaults; correlate; severity contracts; rule owners; triage feedback. AI triage helps enrichment but cannot retire orphan rules.