Skip to content

Topic

Detection Engineering

Security discipline of writing, tuning, and maintaining detection rules and alerts that turn system telemetry into signals of malicious activity.

Current stories

leadership1 publisher

Triage and tuning decided which SOC caught CISA's red team

CISA's red team breached two critical-sector organisations, and only the water-sector one contained it, isolating machines in up to 20 minutes. The gap traces to alert tuning and triage, so the first fix most SOCs need is analyst time.

Publishers:itpro.com

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives55
Confidence45
build1 publisher

An autonomous AI agent narrated its own post-exploitation moves into DIVD's logs

DIVD says the autonomous AI agent behind its first security incident in seven years wrote its own reasoning into the system logs. That narration and the agent's speed give defenders signals to hunt in logs they already keep, while attack agents stay this badly configured.

Publishers:dev.to

Reality

Evidence35
Adoption
Insufficient
Hype gap+25
Incentives
Insufficient
Confidence35
security4 publishers

Phishing crews adopt the AI red team's invisible Unicode trick to break keyword filters

A hunting signature Microsoft built to catch prompt injection in email started firing on ordinary phishing instead, where invisible tag characters were splitting lure words like "funding" so filters never parsed them.

Perspective Coverage

4 publishers
Builder
Builder 31%
Operator
Operator 60%
Investor
Investor 9%

Reality

Evidence64
Adoption72
Hype gap+16
Incentives74
Confidence66

Earlier coverage

  1. GiveWP rebuilds an anonymous visitor's serialized object into command execution

    Build · August 28, 2026 · 1 publisher

  2. TA4922 parks Donut Loader in the same folder as a signed executable

    Build · August 28, 2026 · 1 publisher

  3. Fresh domains and post-delivery redirects walk past filters reporting a healthy block rate

    Security · August 27, 2026 · 1 publisher

  4. An exposed LiteLLM gateway hands over every key in PID 1's environment

    Build · August 27, 2026 · 1 publisher

  5. Honeypots logged a SharePoint JWT bypass hunting for a Business Data Catalog sink

    Build · August 27, 2026 · 1 publisher

  6. Agent Tesla v4 hides in emoji and never hits disk: an email-rule problem, not a new-malware one

    Security · August 21, 2026 · 2 publishers

  7. MLflow's webhook tester is now a credential-theft tool, and it is on CISA's KEV list

    Build · August 20, 2026 · 1 publisher

  8. Zimbra's SNMP notifier turns a crafted SMTP message into command execution as the zimbra user

    Build · August 20, 2026 · 1 publisher

  9. Forminator trusts a forged upload: a dropdown flaw exposes 600,000 WordPress sites to RCE

    Build · August 18, 2026 · 1 publisher

  10. Clop's Windchill implant borrows the app's own keystore, so app logs are the only witness

    Build · August 18, 2026 · 1 publisher

  11. GitLab bundles a zero-click GraphQL flaw with a CSRF bug, and only one needs a victim

    Build · August 18, 2026 · 1 publisher

  12. The AI security line item to fund first is log coverage, not another agent

    Security · August 18, 2026 · 2 publishers

  13. "Work PC" beats DESKTOP-XXXXXXXX: Entra device-join detection needs a new anchor

    Security · August 18, 2026 · 1 publisher

  14. C2Looper puts its C2 inside GitHub, and domain-reputation stacks will not care

    Security · August 18, 2026 · 1 publisher

  15. Microsoft is generating its detection test logs, and admitting what they do not prove

    Build · August 17, 2026 · 1 publisher

  16. ShieldBreak: a Defender-to-SYSTEM PoC that your last patch cycle did not stop

    Build · August 17, 2026 · 1 publisher