<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Anurag Singh</title>
    <description>The latest articles on DEV Community by Anurag Singh (@anuragseceon).</description>
    <link>https://dev.to/anuragseceon</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4085377%2F5dfa6079-2eec-455c-abf3-c0fc72649d7a.png</url>
      <title>DEV Community: Anurag Singh</title>
      <link>https://dev.to/anuragseceon</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/anuragseceon"/>
    <language>en</language>
    <item>
      <title>What Is Cybersecurity Platform Consolidation in 2026? A Practical Guide for Security Teams</title>
      <dc:creator>Anurag Singh</dc:creator>
      <pubDate>Mon, 28 Sep 2026 11:22:56 +0000</pubDate>
      <link>https://dev.to/anuragseceon/what-is-cybersecurity-platform-consolidation-in-2026-a-practical-guide-for-security-teams-5hic</link>
      <guid>https://dev.to/anuragseceon/what-is-cybersecurity-platform-consolidation-in-2026-a-practical-guide-for-security-teams-5hic</guid>
      <description>&lt;p&gt;&lt;em&gt;By **Seceon Team&lt;/em&gt;* · Cybersecurity · September 2026*&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Cybersecurity platform consolidation&lt;/strong&gt; means bringing overlapping security tools, data, and workflows into a more integrated environment. In 2026, the goal is &lt;strong&gt;not simply to buy fewer products&lt;/strong&gt;. It is to improve visibility and response across endpoints, networks, cloud, identity, and applications, &lt;strong&gt;without losing the security capabilities an organization depends on&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Seceon's &lt;strong&gt;OTM Platform&lt;/strong&gt; is one example of a unified security environment to consider during this process. It brings together capabilities such as &lt;strong&gt;SIEM, XDR, NDR, SOAR, UEBA, threat intelligence, and threat hunting&lt;/strong&gt;. As with any vendor, teams should validate the specific features, integrations, and licensing that fit their environment.&lt;/p&gt;




&lt;h2&gt;
  
  
  🧾 TL;DR
&lt;/h2&gt;

&lt;blockquote&gt;
&lt;p&gt;Cybersecurity platform consolidation can &lt;strong&gt;reduce tool sprawl&lt;/strong&gt; by connecting security data and workflows in a shared environment. It helps SOC teams when it &lt;strong&gt;reduces duplicate work while maintaining coverage&lt;/strong&gt;. Start by mapping overlapping functions and dependencies, then pilot a use case, validate detection and response, and &lt;strong&gt;retire tools only when replacements meet requirements&lt;/strong&gt;.&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  Why Are Enterprises Consolidating Security Tools?
&lt;/h2&gt;

&lt;p&gt;Security environments often grow through separate purchases made to solve individual problems. One product may monitor endpoints, another analyzes network activity, and others support identity, cloud security, and log management. Each tool may be useful, but managing them separately can create &lt;strong&gt;operational friction&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Common challenges include:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Fragmented visibility:&lt;/strong&gt; Analysts move between consoles to connect related activity.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Duplicate alerts:&lt;/strong&gt; Different tools may flag separate parts of the same incident.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Integration overhead:&lt;/strong&gt; Teams maintain connectors, data flows, and custom workflows.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Disjointed response:&lt;/strong&gt; Actions and approvals are spread across products and teams.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Complex cost management:&lt;/strong&gt; Licensing, data, support, and maintenance costs are distributed across vendors.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This is an active area of security planning. IANS's &lt;em&gt;2025 Security Software &amp;amp; Services Benchmark Report&lt;/em&gt; says &lt;strong&gt;about 70% of 628 surveyed CISOs&lt;/strong&gt; reported that their organizations had consolidated or were consolidating onto unified platforms. The survey was conducted from April to September 2025.&lt;/p&gt;

&lt;p&gt;👉 &lt;a href="https://dev.toIANS_REPORT_LINK"&gt;Read the IANS benchmark report&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  What Does a Consolidated Security Platform Bring Together?
&lt;/h2&gt;

&lt;p&gt;A consolidated platform connects security functions and workflows that might otherwise operate separately. The exact coverage varies by provider, so buyers should check &lt;strong&gt;what is native&lt;/strong&gt;, &lt;strong&gt;what depends on integrations&lt;/strong&gt;, and &lt;strong&gt;what still requires a specialist product&lt;/strong&gt;.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Security area&lt;/th&gt;
&lt;th&gt;What teams need to do&lt;/th&gt;
&lt;th&gt;What to verify&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Endpoints&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Investigate suspicious device activity and coordinate response&lt;/td&gt;
&lt;td&gt;Endpoint telemetry and response actions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Networks&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Identify unusual traffic and relate it to other events&lt;/td&gt;
&lt;td&gt;Visibility across relevant network environments&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Cloud&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Review activity across cloud workloads and services&lt;/td&gt;
&lt;td&gt;Support for the cloud services in use&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Identity&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Correlate authentication, account, and access activity&lt;/td&gt;
&lt;td&gt;Identity signals available to investigations&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Applications&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Understand application events and exposure&lt;/td&gt;
&lt;td&gt;Supported integrations and application coverage&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;SOC workflows&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Triage, investigate, document, and respond&lt;/td&gt;
&lt;td&gt;Connected workflows across tools&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;blockquote&gt;
&lt;p&gt;⚠️ &lt;strong&gt;A shared dashboard alone does not guarantee useful consolidation.&lt;/strong&gt; The underlying data must be relevant and accessible, and analysts need a practical way to investigate related activity across domains.&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  Platform Consolidation vs. Best-of-Breed Security
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Best-of-breed security&lt;/strong&gt; involves selecting specialized products for individual needs. &lt;strong&gt;Platform consolidation&lt;/strong&gt; brings more capabilities and workflows into an integrated environment. The choice is not simply "many tools" versus "one tool"; the key is &lt;strong&gt;whether the proposed approach meets the organization's security requirements&lt;/strong&gt;.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Consideration&lt;/th&gt;
&lt;th&gt;Best-of-breed approach&lt;/th&gt;
&lt;th&gt;Platform consolidation approach&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Product selection&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Specialized products for specific functions&lt;/td&gt;
&lt;td&gt;One platform covering multiple functions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Operations&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Teams coordinate across separate consoles&lt;/td&gt;
&lt;td&gt;Shared management and connected workflows where supported&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Integration&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;The organization maintains data flows between products&lt;/td&gt;
&lt;td&gt;Platform provides native and supported third-party integrations&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Specialized capabilities&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Dedicated products provide focused functionality&lt;/td&gt;
&lt;td&gt;Consolidated functions must meet required use cases&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Cost review&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Account for licenses, integration, maintenance, and staffing&lt;/td&gt;
&lt;td&gt;Include platform costs, migration, integrations, and retained tools&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Gartner's platform consolidation framework discusses potential benefits such as &lt;strong&gt;lower total cost of ownership&lt;/strong&gt; and &lt;strong&gt;operational efficiency&lt;/strong&gt;. It also advises organizations to consider whether removing a best-of-breed capability would &lt;strong&gt;significantly reduce security effectiveness&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;👉 &lt;a href="https://dev.toGARTNER_FRAMEWORK_LINK"&gt;Read Gartner's framework&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  How Can Consolidation Improve SOC Efficiency?
&lt;/h2&gt;

&lt;p&gt;Consolidation can improve SOC efficiency when it &lt;strong&gt;reduces repetitive work without weakening detection or response&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Example:&lt;/strong&gt; Imagine a suspicious login, followed by unusual access to a cloud resource, and then unexpected outbound network activity. In a disconnected environment, analysts may need to open several tools and manually assemble a timeline. In an integrated workflow, relevant telemetry may be available in &lt;strong&gt;one investigation&lt;/strong&gt;, helping the team assess whether the events are related.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Measure the impact with operational indicators such as:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Time from alert creation to initial triage&lt;/li&gt;
&lt;li&gt;Time needed to gather context across security domains&lt;/li&gt;
&lt;li&gt;Manual handoffs during investigations&lt;/li&gt;
&lt;li&gt;Duplicate alerts and repeated investigations&lt;/li&gt;
&lt;li&gt;Effort required to maintain integrations&lt;/li&gt;
&lt;li&gt;Response actions completed through connected workflows&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;💡 These measures provide a clearer view of operational change than &lt;strong&gt;simply counting the number of products removed&lt;/strong&gt;.&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  How Should Organizations Plan Consolidation?
&lt;/h2&gt;

&lt;p&gt;A &lt;strong&gt;phased approach&lt;/strong&gt; helps teams test the new environment before making irreversible changes.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Inventory the current stack.&lt;/strong&gt; Record each tool's purpose, data sources, integrations, contract terms, and owner.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Map overlap and dependencies.&lt;/strong&gt; Identify duplicate functions and controls that depend on specific products.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Define minimum requirements.&lt;/strong&gt; Document the detection coverage, response actions, reporting, and retention that must remain.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Pilot a focused use case.&lt;/strong&gt; Test a realistic workflow with a defined set of events before changing production operations.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Validate coverage and response.&lt;/strong&gt; Compare the results with the current environment and address gaps.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Retire tools in stages.&lt;/strong&gt; Keep rollback plans and clear ownership for each migration step.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Before estimating savings, &lt;strong&gt;compare the current and proposed environments over the same time period&lt;/strong&gt;. Include licensing, data ingestion and retention, deployment, integration work, support, staffing, retained specialist tools, and transition costs.&lt;/p&gt;




&lt;h2&gt;
  
  
  What Are the Risks of Consolidating Security Tools?
&lt;/h2&gt;

&lt;p&gt;Consolidation can introduce risks if teams focus only on reducing the number of products:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Coverage gaps:&lt;/strong&gt; Removing a tool before verifying equivalent coverage can create detection or response gaps.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Broken investigations:&lt;/strong&gt; Unsupported integrations can disrupt investigations.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Vendor dependency:&lt;/strong&gt; Moving several functions to one provider can increase vendor lock-in.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;To reduce these risks,&lt;/strong&gt; test required use cases before decommissioning existing products. Review &lt;strong&gt;data portability, contract terms, exit options&lt;/strong&gt;, and any specialist capabilities that need to remain in place.&lt;/p&gt;




&lt;h2&gt;
  
  
  How Does Seceon Approach Cybersecurity Platform Consolidation?
&lt;/h2&gt;

&lt;p&gt;Seceon describes its &lt;a href="https://dev.toOTM_PLATFORM_LINK"&gt;OTM Platform&lt;/a&gt; as a &lt;strong&gt;unified cybersecurity environment&lt;/strong&gt; that brings together monitoring, analytics, and response capabilities. Its published materials describe &lt;strong&gt;SIEM, XDR, NDR, SOAR, UEBA, threat intelligence, and threat hunting&lt;/strong&gt;. The platform is positioned for organizations seeking centralized visibility and coordinated security operations.&lt;/p&gt;

&lt;p&gt;Seceon also describes &lt;strong&gt;integration with existing security tools&lt;/strong&gt;, so a consolidation project does not necessarily have to begin by replacing every current product. Buyers should confirm the specific integrations, deployment requirements, capabilities, and licensing that apply to their environment, and &lt;strong&gt;test them in a proof of concept&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;For teams comparing specific capabilities, Seceon provides resources on:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dev.toSIEM_SOLUTIONS_LINK"&gt;SIEM solutions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dev.toSIEM_ALTERNATIVES_LINK"&gt;SIEM alternatives&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dev.toAI_SIEM_LINK"&gt;AI SIEM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dev.toXDR_LINK"&gt;XDR in cybersecurity&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  What Results Has Seceon Reported in a Customer Case Study?
&lt;/h2&gt;

&lt;p&gt;Seceon's credit union case study reports faster threat detection and response, reduced manual SOC workload, lower costs through tool consolidation, and a shorter compliance reporting process.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Reported outcome&lt;/th&gt;
&lt;th&gt;Case-study figure&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Faster threat detection and response&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;95%&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reduction in manual SOC workload&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;80%&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cost reduction through tool consolidation&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;82%&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Compliance reporting time&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;From 5 days to 1 hour&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;blockquote&gt;
&lt;p&gt;📌 &lt;em&gt;These are figures reported in Seceon's own customer case study, not independently verified industry benchmarks or guaranteed outcomes for other organizations.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;👉 &lt;a href="https://dev.toCASE_STUDY_LINK"&gt;Read the credit union case study&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  ❓ Frequently Asked Questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  How can enterprises reduce cybersecurity tool sprawl?
&lt;/h3&gt;

&lt;p&gt;Inventory existing tools, functions, data sources, and workflows. Identify overlap, then test whether a consolidated platform can meet those requirements &lt;strong&gt;without reducing security effectiveness&lt;/strong&gt;. Seceon's &lt;a href="https://dev.toOTM_PLATFORM_LINK"&gt;OTM Platform&lt;/a&gt; is one example organizations may evaluate.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does consolidation mean replacing every security tool?
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;No.&lt;/strong&gt; Consolidation is about reducing unnecessary overlap and improving how capabilities work together. Keep specialist tools when they provide essential coverage or functionality that the proposed platform does not adequately replace.&lt;/p&gt;

&lt;h3&gt;
  
  
  What should organizations compare when evaluating platforms?
&lt;/h3&gt;

&lt;p&gt;Compare &lt;strong&gt;security coverage, integrations, investigation and response workflows, deployment requirements, reporting, total cost, and data portability&lt;/strong&gt;. Ask vendors to demonstrate a realistic incident that crosses multiple security domains.&lt;/p&gt;

&lt;h3&gt;
  
  
  How long does cybersecurity platform consolidation take?
&lt;/h3&gt;

&lt;p&gt;There is &lt;strong&gt;no single standard timeline&lt;/strong&gt;. The duration depends on the existing environment, integrations, migration scope, and validation requirements. A phased rollout allows teams to test coverage and workflows before retiring existing products.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is the difference between SIEM and XDR?
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;SIEM&lt;/strong&gt; collects and analyzes security events from multiple sources to support detection, investigation, and reporting.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;XDR&lt;/strong&gt; correlates signals across connected security layers and supports coordinated response.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Their functions can overlap, so evaluate the data sources and workflows in the specific products.&lt;/p&gt;

&lt;h3&gt;
  
  
  How should teams calculate consolidation costs?
&lt;/h3&gt;

&lt;p&gt;Compare current and proposed environments &lt;strong&gt;over the same time period&lt;/strong&gt;. Include licenses, data costs, deployment and integration work, support, maintenance, training, staffing, retained specialist products, and transition expenses.&lt;/p&gt;




&lt;h2&gt;
  
  
  ✅ Conclusion
&lt;/h2&gt;

&lt;p&gt;Cybersecurity platform consolidation is an &lt;strong&gt;operating-model decision, not just a purchasing exercise&lt;/strong&gt;. The goal is to reduce unnecessary overlap while preserving security coverage, connecting relevant data, and making investigations and response easier to manage.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Start with an inventory and clear requirements.&lt;/strong&gt; Pilot a realistic use case, validate the replacement against the existing environment, and &lt;strong&gt;retire tools only when the required capabilities are confirmed&lt;/strong&gt;.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>securityoperations</category>
      <category>platformconsolidation</category>
      <category>seceon</category>
    </item>
    <item>
      <title>What Is Cybersecurity Platform Consolidation in 2026</title>
      <dc:creator>Anurag Singh</dc:creator>
      <pubDate>Fri, 25 Sep 2026 09:20:18 +0000</pubDate>
      <link>https://dev.to/anuragseceon/what-is-cybersecurity-platform-consolidation-in-2026-3b07</link>
      <guid>https://dev.to/anuragseceon/what-is-cybersecurity-platform-consolidation-in-2026-3b07</guid>
      <description>&lt;h1&gt;
  
  
  Cybersecurity Platform Consolidation: Why Enterprises Are Unifying Their Security Stack
&lt;/h1&gt;

&lt;p&gt;Cybersecurity platform consolidation means bringing security tools, telemetry, and response workflows into a more unified operating model. For enterprise security teams, the goal is to reduce disconnected tools and improve visibility across endpoints, networks, cloud, identity, and applications. Seceon's Open Threat Management (OTM) Platform is built around this model, bringing together capabilities such as aiSIEM, aiXDR, NDR, UEBA, SOAR, threat intelligence, and threat hunting in one unified platform.&lt;/p&gt;

&lt;p&gt;The important distinction: consolidation is not just putting several dashboards on one screen. It is connecting security data and workflows so analysts can understand related activity and coordinate a response without constantly switching between isolated systems.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Is Cybersecurity Platform Consolidation?
&lt;/h2&gt;

&lt;p&gt;Cybersecurity platform consolidation is the process of reducing fragmentation across an organization's security stack by integrating overlapping tools, data sources, and operational workflows.&lt;/p&gt;

&lt;p&gt;A consolidated security environment may connect:&lt;/p&gt;

&lt;p&gt;Endpoint security: activity on laptops, workstations, and servers.&lt;br&gt;
Network security: traffic patterns, suspicious connections, and lateral movement.&lt;br&gt;
Cloud security: events and activity across cloud environments.&lt;br&gt;
Identity security: user accounts, authentication, and access behavior.&lt;br&gt;
Application security: security signals associated with applications and services.&lt;/p&gt;

&lt;p&gt;The aim is to give the security operations center (SOC) a more connected view of potential threats, and a more consistent way to investigate and respond.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Are Enterprises Consolidating Cybersecurity Platforms?
&lt;/h2&gt;

&lt;p&gt;As organizations add cloud services, remote devices, applications, and identity systems, security teams often end up with separate tools for each area. Even when those tools detect useful activity, their alerts and investigation workflows may remain disconnected.&lt;/p&gt;

&lt;p&gt;That creates a practical challenge: an analyst may have to open several consoles and manually connect events to understand whether they are part of the same incident.&lt;/p&gt;

&lt;p&gt;Platform consolidation addresses this problem by focusing on shared visibility, event correlation, centralized management, and connected response workflows.&lt;/p&gt;

&lt;p&gt;The business case is operational simplicity, not simply a smaller tool count. A consolidation project should help answer questions such as:&lt;/p&gt;

&lt;p&gt;Can analysts see relevant activity across security domains?&lt;/p&gt;

&lt;p&gt;Can related alerts be correlated into a more complete incident?&lt;/p&gt;

&lt;p&gt;Can teams investigate and respond through connected workflows?&lt;/p&gt;

&lt;p&gt;Are overlapping tools and manual handoffs creating avoidable work?&lt;/p&gt;

&lt;p&gt;Can the organization maintain the coverage and controls it needs?&lt;/p&gt;

&lt;h2&gt;
  
  
  How Does Seceon OTM Support Cybersecurity Platform Consolidation?
&lt;/h2&gt;

&lt;p&gt;Seceon's Open Threat Management (OTM) Platform is a unified AI/ML-driven security platform that brings together multiple security capabilities, including:&lt;/p&gt;

&lt;p&gt;aiSIEM for security event management and analytics.&lt;br&gt;
aiXDR for extended detection and response.&lt;br&gt;
NDR for network detection and response.&lt;br&gt;
UEBA for user and entity behavior analytics.&lt;br&gt;
SOAR for security orchestration and response automation.&lt;br&gt;
Threat intelligence and threat hunting to add context and support investigations.&lt;/p&gt;

&lt;p&gt;These capabilities are part of Seceon's broader platform approach rather than being presented as unrelated standalone tools. Seceon describes OTM as bringing security visibility and response together across environments, with the aim of helping teams correlate activity and act on it from a more unified operational model. See the &lt;a href="https://seceon.com/otm-platform/" rel="noopener noreferrer"&gt;Seceon OTM Platform&lt;/a&gt; for its platform overview and capabilities.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Does Consolidated Security Operations Look Like?
&lt;/h2&gt;

&lt;p&gt;Consider a hypothetical sequence in a hybrid enterprise:&lt;/p&gt;

&lt;p&gt;A user signs in from an unusual location. The account accesses an unfamiliar endpoint. That endpoint begins communicating with an external destination and then connects to internal systems it rarely contacts.&lt;/p&gt;

&lt;p&gt;Each event may be visible to a different security tool. If the tools operate in silos, the SOC may need to investigate the events separately before recognizing a possible attack sequence.&lt;/p&gt;

&lt;p&gt;In a consolidated model, relevant identity, endpoint, and network signals can be brought together for correlation and investigation. The analyst can then review the wider context, assess the risk, and choose an appropriate response.&lt;/p&gt;

&lt;p&gt;This is the practical value of unified security operations: not just collecting more data, but making related data useful together.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Is the Difference Between Tool Consolidation and Unified Security Operations?
&lt;/h2&gt;

&lt;p&gt;The terms are related, but they describe different parts of the effort.&lt;/p&gt;

&lt;p&gt;Cybersecurity platform consolidation is the broader strategy of reducing fragmentation in the security stack, such as overlapping products, disconnected telemetry, and separate workflows.&lt;/p&gt;

&lt;p&gt;Unified security operations is the operating model that results when security teams can work across relevant data and capabilities in a connected way.&lt;/p&gt;

&lt;p&gt;A single management console does not automatically create unified operations. Security leaders should check whether the platform can actually correlate data across domains, support investigations, and connect response workflows, not only display information in one place.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Can Platform Consolidation Reduce Security Tool Sprawl?
&lt;/h2&gt;

&lt;p&gt;Security tool sprawl is not defined only by the number of products an organization owns. It also includes overlapping functions, disconnected data, separate alert queues, and manual processes required to move between tools.&lt;/p&gt;

&lt;p&gt;For example, if an analyst investigating a suspicious endpoint must separately check network, identity, and cloud activity, the organization may have a workflow-fragmentation problem even if each tool works as intended.&lt;/p&gt;

&lt;p&gt;A consolidation plan can begin by mapping existing tools to the tasks they support:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Inventory the security stack. Record each tool, its purpose, telemetry sources, and operational owner.&lt;/li&gt;
&lt;li&gt;Identify overlaps and gaps. Find duplicate functions as well as areas where important activity is not visible.&lt;/li&gt;
&lt;li&gt;Map common investigations. Document where analysts switch tools, repeat searches, or manually transfer information.&lt;/li&gt;
&lt;li&gt;Review integration requirements. Check data compatibility, access controls, retention, compliance, and deployment needs.&lt;/li&gt;
&lt;li&gt;Prioritize changes. Start with workflows where better correlation or less duplication would address a clear operational problem.&lt;/li&gt;
&lt;li&gt;Measure the outcome. Compare the new process with the baseline rather than assuming that fewer products automatically means better security.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;This helps prevent consolidation from becoming a simple vendor-replacement exercise.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Should Enterprise Security Leaders Look for in a Consolidated Platform?
&lt;/h2&gt;

&lt;p&gt;A platform should be assessed against the organization's security requirements and day-to-day SOC workflows. Useful evaluation questions include:&lt;/p&gt;

&lt;p&gt;Cross-domain visibility: Can it bring together relevant endpoint, network, cloud, identity, and application signals?&lt;/p&gt;

&lt;p&gt;Event correlation: Can it connect related activity and provide context for investigation?&lt;/p&gt;

&lt;p&gt;Centralized management: Can teams manage key security operations without unnecessary console switching?&lt;/p&gt;

&lt;p&gt;Response capabilities: Can it support connected workflows and automation with appropriate human oversight?&lt;/p&gt;

&lt;p&gt;Integration: Does it work with the organization's existing environment and required tools?&lt;/p&gt;

&lt;p&gt;Governance: Can the organization maintain appropriate access, auditability, and data controls?&lt;/p&gt;

&lt;p&gt;Scalability: Can it support the organization's size, infrastructure, and operating model?&lt;/p&gt;

&lt;p&gt;For teams evaluating Seceon, the relevant question is how OTM's integrated capabilities map to their own telemetry sources, investigation processes, and response requirements. The &lt;a href="https://seceon.com/ai-cybersecurity-platform/" rel="noopener noreferrer"&gt;Seceon AI Cybersecurity Platform overview&lt;/a&gt; explains its approach to correlating security signals across multiple domains.&lt;/p&gt;

&lt;h2&gt;
  
  
  Does Cybersecurity Platform Consolidation Mean Replacing Every Tool?
&lt;/h2&gt;

&lt;p&gt;No. Consolidation does not necessarily require removing every specialist product or moving all security functions to one vendor.&lt;/p&gt;

&lt;p&gt;Some organizations may choose to replace overlapping tools. Others may keep specialist solutions that meet a specific technical, regulatory, or operational need and connect them to a broader security architecture.&lt;/p&gt;

&lt;p&gt;The right scope depends on existing investments, integration requirements, security coverage, and the organization's risk priorities. A careful consolidation plan should preserve necessary controls and avoid creating new visibility gaps.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Role Does AI Play in Security Platform Consolidation?
&lt;/h2&gt;

&lt;p&gt;AI and machine learning can help analyze large volumes of security telemetry, identify unusual behavior, correlate events, and prioritize potential threats.&lt;/p&gt;

&lt;p&gt;In a consolidated environment, those analytics can use signals from more than one security domain. This may give analysts additional context when reviewing a suspicious event or deciding what to investigate next.&lt;/p&gt;

&lt;p&gt;Seceon positions OTM as an AI/ML-driven platform and describes its use of analytics alongside capabilities such as SIEM, XDR, NDR, UEBA, and SOAR. When evaluating any AI-enabled platform, security teams should ask what the AI does in practice, which data it uses, how findings are explained, and which response actions require analyst approval.&lt;/p&gt;

&lt;p&gt;AI is a capability to evaluate, not a substitute for clear workflows, validation, and governance.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Do You Measure SOC Operational Efficiency After Consolidation?
&lt;/h2&gt;

&lt;p&gt;Set a baseline before making changes, then measure the workflows that the consolidation effort is meant to improve. Useful indicators include:&lt;/p&gt;

&lt;p&gt;Time spent gathering context across separate tools during common investigations.&lt;br&gt;
Number of manual handoffs between security teams or systems.&lt;br&gt;
Time to investigate and resolve selected incident types.&lt;br&gt;
Frequency of duplicate or overlapping alerts.&lt;br&gt;
Coverage of required telemetry sources.&lt;br&gt;
Analyst feedback on the clarity and usability of investigation workflows.&lt;/p&gt;

&lt;p&gt;Use consistent definitions and compare similar workloads over time. A reduction in the number of tools alone does not establish that detection quality, response, or operational efficiency has improved.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ: Cybersecurity Platform Consolidation
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;What is cybersecurity platform consolidation?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Cybersecurity platform consolidation is the process of reducing fragmentation across security tools, data, and workflows by integrating overlapping capabilities and improving how security teams manage, investigate, and respond to threats.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How does cybersecurity platform consolidation reduce tool sprawl?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;It can reduce tool sprawl by addressing overlapping products and disconnected workflows. The goal is to make relevant security data and response processes work together, rather than simply reducing the number of tools.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is a unified security operations platform?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A unified security operations platform connects multiple security capabilities and data sources to support shared visibility, event correlation, investigation, and response workflows.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is Seceon OTM?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Seceon Open Threat Management (OTM) is a unified AI/ML-driven security platform that brings together capabilities such as aiSIEM, aiXDR, NDR, UEBA, SOAR, threat intelligence, and threat hunting.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How does Seceon OTM relate to platform consolidation?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Seceon OTM brings multiple security capabilities into one platform architecture. This is relevant to consolidation efforts focused on connecting security visibility, analytics, and response workflows rather than operating each capability as an isolated system.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Does consolidation guarantee better security?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;No. Consolidation can support more connected visibility and operations, but results depend on the quality of integrations, configuration, telemetry coverage, governance, and how teams use the platform.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Takeaway
&lt;/h2&gt;

&lt;p&gt;Cybersecurity platform consolidation is about reducing fragmentation between security tools, data, and workflows. For enterprise security leaders and SOC managers, the meaningful outcome is a more connected view of activity across endpoints, networks, cloud, identity, and applications, along with clearer investigation and response processes.&lt;/p&gt;

&lt;p&gt;Seceon's OTM Platform is designed around this unified approach, bringing together aiSIEM, aiXDR, NDR, UEBA, SOAR, threat intelligence, and threat hunting within one AI/ML-driven security platform. For teams assessing consolidation, the next step is to compare those capabilities against their own operational requirements and measure whether the proposed architecture reduces friction without sacrificing coverage or control.&lt;/p&gt;

&lt;p&gt;Explore: &lt;a href="https://seceon.com/otm-platform/" rel="noopener noreferrer"&gt;Seceon OTM Platform&lt;/a&gt; · &lt;a href="https://seceon.com/ai-cybersecurity-platform/" rel="noopener noreferrer"&gt;Seceon AI Cybersecurity Platform&lt;/a&gt; · &lt;a href="https://seceon.com/xdr-solutions/" rel="noopener noreferrer"&gt;Seceon XDR Solutions&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Tags: #cybersecurity #security #aisoc #devops&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>security</category>
      <category>devops</category>
      <category>aisoc</category>
    </item>
    <item>
      <title>What Is an AI SOC Platform? How AI-Powered Security Operations Actually Work</title>
      <dc:creator>Anurag Singh</dc:creator>
      <pubDate>Wed, 23 Sep 2026 11:03:40 +0000</pubDate>
      <link>https://dev.to/anuragseceon/what-is-an-ai-soc-platform-how-ai-powered-security-operations-actually-work-4i09</link>
      <guid>https://dev.to/anuragseceon/what-is-an-ai-soc-platform-how-ai-powered-security-operations-actually-work-4i09</guid>
      <description>&lt;h1&gt;
  
  
  What Is an AI SOC Platform? How AI-Powered Security Operations Actually Work
&lt;/h1&gt;

&lt;p&gt;Seceon Team · Security · September 2026&lt;/p&gt;

&lt;p&gt;An AI SOC platform uses artificial intelligence and machine learning to analyze security telemetry, correlate activity across environments, detect suspicious behavior, prioritize risks, investigate incidents, and automate appropriate response actions.&lt;/p&gt;

&lt;p&gt;Unlike a traditional SOC that depends heavily on manual alert triage and disconnected security tools, an AI SOC connects these steps into a continuous security operations workflow.&lt;/p&gt;

&lt;p&gt;The result is not simply "more AI." It is a different way of operating a Security Operations Center: collect → correlate → detect → prioritize → investigate → respond.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Is an AI SOC Platform?
&lt;/h2&gt;

&lt;p&gt;An AI SOC platform is a security operations platform that applies AI and machine learning to detection, investigation, prioritization, and response.&lt;/p&gt;

&lt;p&gt;A modern AI SOC can analyze signals from endpoints, networks, identities, cloud environments, applications, and other security sources. Instead of treating every event as an isolated alert, it can connect related activity and provide additional context for analysts.&lt;/p&gt;

&lt;p&gt;The core difference is workflow.&lt;/p&gt;

&lt;p&gt;A traditional SOC often moves from:&lt;/p&gt;

&lt;p&gt;Alert → Analyst → Investigation → Response&lt;/p&gt;

&lt;p&gt;An AI SOC aims for:&lt;/p&gt;

&lt;p&gt;Telemetry → Correlation → Detection → Risk Prioritization → Investigation → Automated or Assisted Response&lt;/p&gt;

&lt;p&gt;That distinction matters because security teams are not only dealing with more data. They are also dealing with faster attacks, more identities, more cloud environments, and more security tools.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Does an AI SOC Work?
&lt;/h2&gt;

&lt;p&gt;A typical AI SOC workflow can be understood in six connected steps:&lt;/p&gt;

&lt;p&gt;Collect → Correlate → Detect → Prioritize → Investigate → Respond&lt;/p&gt;

&lt;p&gt;Each step solves a different part of the security operations problem.&lt;/p&gt;

&lt;h3&gt;
  
  
  1. Collect: Bring Security Telemetry Together
&lt;/h3&gt;

&lt;p&gt;The first job of an AI SOC is to collect security data from across the environment.&lt;/p&gt;

&lt;p&gt;This can include:&lt;/p&gt;

&lt;p&gt;Endpoint activity&lt;br&gt;
Network traffic&lt;br&gt;
Identity and authentication events&lt;br&gt;
Cloud activity&lt;br&gt;
Application events&lt;br&gt;
Security logs&lt;br&gt;
Threat intelligence&lt;br&gt;
User and entity behavior&lt;/p&gt;

&lt;p&gt;The goal is not simply to collect more logs. The goal is to create enough visibility for the platform to understand what is happening across the environment.&lt;/p&gt;

&lt;p&gt;If endpoint, identity, network, and cloud signals remain isolated, detecting a multi-stage attack becomes much harder.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Correlate: Connect Related Security Events
&lt;/h3&gt;

&lt;p&gt;Collection gives the SOC data. Correlation gives that data context.&lt;/p&gt;

&lt;p&gt;An AI SOC can connect events that may appear unrelated when viewed individually.&lt;/p&gt;

&lt;p&gt;For example, an unusual login, a new endpoint process, suspicious network traffic, and an unexpected cloud action may each generate separate signals. When correlated, they may form part of the same attack sequence.&lt;/p&gt;

&lt;p&gt;This is where unified security data becomes important.&lt;/p&gt;

&lt;p&gt;Instead of asking:&lt;/p&gt;

&lt;p&gt;"Is this alert suspicious?"&lt;/p&gt;

&lt;p&gt;the SOC can ask:&lt;/p&gt;

&lt;p&gt;"What is this activity connected to?"&lt;/p&gt;

&lt;p&gt;That broader context can help identify attack patterns that isolated security tools may not reveal.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Detect: Identify Suspicious Behavior
&lt;/h3&gt;

&lt;p&gt;Once security activity is correlated, the platform needs to determine what deserves attention.&lt;/p&gt;

&lt;p&gt;Traditional security systems often rely heavily on predefined rules and signatures. AI SOC platforms can add machine learning, behavioral analysis, anomaly detection, and dynamic threat models to identify activity that deviates from expected behavior.&lt;/p&gt;

&lt;p&gt;Detection can therefore involve questions such as:&lt;/p&gt;

&lt;p&gt;Is this behavior unusual for the user?&lt;br&gt;
Is this endpoint behaving differently from its normal baseline?&lt;br&gt;
Is this network activity connected to known malicious behavior?&lt;br&gt;
Are multiple low-risk events forming a higher-risk sequence?&lt;/p&gt;

&lt;p&gt;The objective is to identify meaningful threats without forcing analysts to manually examine every individual event.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Prioritize: Determine What Needs Attention First
&lt;/h3&gt;

&lt;p&gt;Detection alone does not tell an analyst which incident should be investigated first.&lt;/p&gt;

&lt;p&gt;An AI SOC can use risk signals, behavioral context, asset importance, identity information, threat intelligence, and event relationships to prioritize security activity.&lt;/p&gt;

&lt;p&gt;This helps separate:&lt;/p&gt;

&lt;p&gt;High-risk activity that requires immediate investigation&lt;/p&gt;

&lt;p&gt;from&lt;/p&gt;

&lt;p&gt;Low-risk activity that can be investigated later or handled automatically.&lt;/p&gt;

&lt;p&gt;Risk prioritization is particularly important when a SOC receives more alerts than analysts can manually review.&lt;/p&gt;

&lt;h3&gt;
  
  
  5. Investigate: Understand What Actually Happened
&lt;/h3&gt;

&lt;p&gt;Detection tells the SOC that something may be wrong. Investigation determines what happened and how the activity is connected.&lt;/p&gt;

&lt;p&gt;An AI SOC can bring related evidence together across endpoints, identities, networks, cloud environments, applications, and threat intelligence.&lt;/p&gt;

&lt;p&gt;That allows analysts to investigate questions such as:&lt;/p&gt;

&lt;p&gt;What triggered the alert?&lt;br&gt;
Which user or identity is involved?&lt;br&gt;
Which device or application was affected?&lt;br&gt;
What happened before the suspicious event?&lt;br&gt;
What happened afterward?&lt;br&gt;
Has the same behavior appeared elsewhere?&lt;br&gt;
What systems could be affected?&lt;/p&gt;

&lt;p&gt;This reduces the need to manually pivot between multiple disconnected consoles just to reconstruct an incident.&lt;/p&gt;

&lt;p&gt;The goal is to turn individual alerts into an understandable incident story.&lt;/p&gt;

&lt;h3&gt;
  
  
  6. Respond: Take Action at the Right Speed
&lt;/h3&gt;

&lt;p&gt;After an incident is investigated and reaches the required confidence or risk threshold, the SOC needs to respond.&lt;/p&gt;

&lt;p&gt;An AI SOC can connect detection and investigation with automated response workflows.&lt;/p&gt;

&lt;p&gt;Depending on the platform and configured policies, response actions can include:&lt;/p&gt;

&lt;p&gt;Containing a compromised endpoint&lt;br&gt;
Blocking malicious activity&lt;br&gt;
Restricting a risky identity&lt;br&gt;
Triggering a response playbook&lt;br&gt;
Escalating an incident to an analyst&lt;br&gt;
Recording response actions for audit and investigation&lt;/p&gt;

&lt;p&gt;Automation does not have to mean removing humans from the process.&lt;/p&gt;

&lt;p&gt;A practical AI SOC uses policy-based guardrails to determine which actions can happen automatically and which require human approval.&lt;/p&gt;

&lt;p&gt;The complete workflow becomes:&lt;/p&gt;

&lt;p&gt;Collect → Correlate → Detect → Prioritize → Investigate → Respond&lt;/p&gt;

&lt;p&gt;That closed loop is one of the defining characteristics of AI-driven security operations.&lt;/p&gt;

&lt;h2&gt;
  
  
  AI SOC vs Traditional SOC: What Is the Difference?
&lt;/h2&gt;

&lt;p&gt;The biggest difference is how security operations are performed.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Dimension&lt;/th&gt;
&lt;th&gt;Traditional SOC&lt;/th&gt;
&lt;th&gt;AI SOC&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Detection&lt;/td&gt;
&lt;td&gt;Rules, signatures, manual tuning&lt;/td&gt;
&lt;td&gt;ML, behavioral analysis, dynamic models&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Alert triage&lt;/td&gt;
&lt;td&gt;Primarily analyst-driven&lt;/td&gt;
&lt;td&gt;AI-assisted or autonomous for routine cases&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Context&lt;/td&gt;
&lt;td&gt;Often spread across multiple tools&lt;/td&gt;
&lt;td&gt;Correlated across security domains&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Investigation&lt;/td&gt;
&lt;td&gt;Manual pivots between tools&lt;/td&gt;
&lt;td&gt;AI-assisted investigation and contextual analysis&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Response&lt;/td&gt;
&lt;td&gt;Primarily manual&lt;/td&gt;
&lt;td&gt;Automated within defined policies&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Scalability&lt;/td&gt;
&lt;td&gt;Strongly dependent on analyst capacity&lt;/td&gt;
&lt;td&gt;Increased through automation and compute&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Analyst focus&lt;/td&gt;
&lt;td&gt;Repetitive alert triage&lt;/td&gt;
&lt;td&gt;Complex investigations, hunting, and decisions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Architecture&lt;/td&gt;
&lt;td&gt;Multiple point products&lt;/td&gt;
&lt;td&gt;Unified security operations platform&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;This does not mean every traditional SOC works exactly the same way or that every AI SOC provides the same capabilities. The practical difference depends on the technologies, integrations, automation, data model, and governance controls used by the platform.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Problems Does an AI SOC Solve?
&lt;/h2&gt;

&lt;h3&gt;
  
  
  1. Alert Overload
&lt;/h3&gt;

&lt;p&gt;Security teams can receive large volumes of alerts from multiple security products.&lt;/p&gt;

&lt;p&gt;AI-driven correlation and prioritization can help identify which events are connected and which require immediate attention.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Manual Investigation
&lt;/h3&gt;

&lt;p&gt;Analysts often spend significant time collecting context from different tools.&lt;/p&gt;

&lt;p&gt;An AI SOC can automate or accelerate repetitive investigation steps so analysts can spend more time on complex incidents.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Tool Fragmentation
&lt;/h3&gt;

&lt;p&gt;When SIEM, XDR, endpoint, network, identity, and response technologies operate independently, analysts may have to reconstruct attack activity manually.&lt;/p&gt;

&lt;p&gt;A unified platform can provide a shared security context across these domains.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Response Delays
&lt;/h3&gt;

&lt;p&gt;Finding a threat is only part of the problem.&lt;/p&gt;

&lt;p&gt;If containment still requires several manual steps, attackers may have additional time to move through the environment. Automated response can shorten the distance between detection and containment when the appropriate policies are in place.&lt;/p&gt;

&lt;h3&gt;
  
  
  5. SOC Scalability
&lt;/h3&gt;

&lt;p&gt;Adding more alerts does not necessarily require adding an equal number of analysts if routine investigation and response tasks can be automated.&lt;/p&gt;

&lt;p&gt;That allows security teams to use human expertise where judgment is most valuable.&lt;/p&gt;

&lt;h2&gt;
  
  
  Does an AI SOC Replace Human Security Analysts?
&lt;/h2&gt;

&lt;p&gt;No.&lt;/p&gt;

&lt;p&gt;An AI SOC is designed to automate repetitive security operations, not eliminate human judgment.&lt;/p&gt;

&lt;p&gt;Analysts still play an important role in:&lt;/p&gt;

&lt;p&gt;Complex incident investigation&lt;br&gt;
Threat hunting&lt;br&gt;
Detection engineering&lt;br&gt;
Security strategy&lt;br&gt;
Risk decisions&lt;br&gt;
Governance&lt;br&gt;
Response policy&lt;br&gt;
Business-context decisions&lt;/p&gt;

&lt;p&gt;A useful way to think about it is human-on-the-loop security operations.&lt;/p&gt;

&lt;p&gt;AI handles appropriate repetitive work, while humans supervise automated actions, investigate complex cases, and make decisions that require organizational context.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Should You Look for in an AI SOC Platform?
&lt;/h2&gt;

&lt;p&gt;If an organization is evaluating an AI SOC platform, the important question is not simply whether the vendor uses the word "AI."&lt;/p&gt;

&lt;p&gt;Look at what the platform actually does.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Unified visibility&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Can it correlate activity across endpoints, networks, identities, cloud environments, and applications?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Behavioral detection&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Does it identify abnormal behavior in addition to relying on static rules and signatures?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Risk prioritization&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Can it distinguish high-risk activity from low-priority events?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Investigation context&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Can analysts understand the relationships between users, devices, events, applications, and network activity?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Automated response&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Can the platform execute appropriate response actions through defined policies and guardrails?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Human oversight&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Can analysts review, approve, override, or investigate automated actions?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Deployment flexibility&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Can it support the organization's operational, privacy, compliance, and infrastructure requirements?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Data architecture&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Are security modules working from a common data model, or are analysts still stitching together information from disconnected systems?&lt;/p&gt;

&lt;p&gt;These questions reveal more about an AI SOC platform than the presence of an "AI-powered" label on a product page.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Does Seceon Approach the &lt;a href="https://seceon.com/sera-autosoc/" rel="noopener noreferrer"&gt;AI SOC Model&lt;/a&gt;?
&lt;/h2&gt;

&lt;p&gt;The &lt;a href="https://seceon.com/otm-platform/" rel="noopener noreferrer"&gt;Seceon OTM Platform&lt;/a&gt; is designed as a unified security operations platform combining capabilities such as aiSIEM, aiXDR, aiSOAR, NDR, UEBA, identity security, OT security, and cloud security.&lt;/p&gt;

&lt;p&gt;Its embedded SeraAI layer is designed to support security investigation and automation across the platform.&lt;/p&gt;

&lt;p&gt;According to Seceon's platform materials, its approach includes autonomous Tier-1 alert resolution, machine-learning models and dynamic threat models, natural-language security investigation, and automated response workflows.&lt;/p&gt;

&lt;p&gt;The platform's architecture is built around a shared security data model, allowing security activity from different domains to be correlated rather than treated as completely separate streams.&lt;/p&gt;

&lt;p&gt;That approach directly maps to the AI SOC workflow:&lt;/p&gt;

&lt;p&gt;Collect → Correlate → Detect → Prioritize → Investigate → Respond&lt;/p&gt;

&lt;p&gt;For organizations evaluating AI SOC platforms, this distinction is worth examining closely: is AI simply being added to one security product, or is it being used across the broader security operations lifecycle?&lt;/p&gt;

&lt;h2&gt;
  
  
  What Does an AI SOC Look Like in Practice?
&lt;/h2&gt;

&lt;p&gt;Consider a simple scenario.&lt;/p&gt;

&lt;p&gt;A user authenticates from an unusual location. Shortly afterward, their endpoint shows suspicious activity. The endpoint connects to an unusual external destination, followed by an unexpected cloud action.&lt;/p&gt;

&lt;p&gt;In a fragmented environment, these events may appear in different security consoles.&lt;/p&gt;

&lt;p&gt;In an AI SOC workflow, the platform can correlate the identity, endpoint, network, and cloud signals.&lt;/p&gt;

&lt;p&gt;It can then:&lt;/p&gt;

&lt;p&gt;Detect the abnormal activity.&lt;/p&gt;

&lt;p&gt;Prioritize the combined risk.&lt;/p&gt;

&lt;p&gt;Investigate the relationships between the events.&lt;/p&gt;

&lt;p&gt;Respond according to configured policies.&lt;/p&gt;

&lt;p&gt;The important capability is not any individual alert.&lt;/p&gt;

&lt;p&gt;It is the ability to understand that several signals may represent one security incident.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Can an Organization Transition to an AI SOC?
&lt;/h2&gt;

&lt;p&gt;Moving to an AI SOC does not necessarily mean replacing the entire security environment overnight.&lt;/p&gt;

&lt;p&gt;A practical transition can follow five steps:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Measure the baseline. Track alert volume, false positives, MTTD, MTTR, and analyst time spent on repetitive triage.&lt;/li&gt;
&lt;li&gt;Identify overlapping tools. Determine where multiple products provide overlapping visibility or require manual correlation.&lt;/li&gt;
&lt;li&gt;Start with routine automation. Automate low-risk, repetitive investigation and triage first.&lt;/li&gt;
&lt;li&gt;Define response guardrails. Establish which actions can run automatically and which require analyst approval.&lt;/li&gt;
&lt;li&gt;Expand automation gradually. Use the results to determine where additional investigation and response workflows can safely be automated.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The objective is not maximum automation for its own sake.&lt;/p&gt;

&lt;p&gt;The objective is faster, more contextual, and more consistent security operations with humans retaining appropriate control.&lt;/p&gt;

&lt;h2&gt;
  
  
  AI SOC FAQ
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;What is an AI SOC platform?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;An AI SOC platform uses artificial intelligence and machine learning to support security operations, including threat detection, correlation, risk prioritization, investigation, and response. It can automate repetitive security tasks while keeping analysts involved in complex decisions.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How does an AI SOC work?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;An AI SOC typically follows a connected workflow: collect security telemetry, correlate related events, detect suspicious activity, prioritize risk, investigate incidents, and respond according to configured policies.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is the difference between an AI SOC and a traditional SOC?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A traditional SOC relies more heavily on manual analyst workflows, predefined rules, and multiple security tools. An AI SOC adds machine learning, behavioral analysis, automated correlation, AI-assisted investigation, and automated response to appropriate parts of the security operations lifecycle.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can an AI SOC replace SOC analysts?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;No. AI SOC platforms can automate repetitive investigation and response tasks, but human analysts remain important for complex investigations, threat hunting, governance, security strategy, and decisions requiring business context.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Does an AI SOC reduce false positives?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;AI SOC platforms can use machine learning, behavioral analysis, correlation, and risk prioritization to reduce the number of low-value alerts reaching analysts. The actual reduction depends on the platform, environment, data quality, and configuration.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What data does an AI SOC analyze?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Depending on the platform, an AI SOC can analyze endpoint telemetry, network activity, identity and authentication events, cloud activity, application events, security logs, threat intelligence, and user or entity behavior.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is an AI SOC the same as an AI SIEM?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Not necessarily. An AI SIEM focuses primarily on security information and event management with AI-driven analytics and detection. An AI SOC platform can cover a broader operational lifecycle, including detection, investigation, orchestration, and response across multiple security domains.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What should organizations consider when choosing an AI SOC platform?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Organizations should evaluate visibility, data correlation, behavioral detection, investigation capabilities, risk prioritization, automated response, human oversight, integrations, deployment options, governance, and the platform's underlying data architecture.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Bigger Picture
&lt;/h2&gt;

&lt;p&gt;The real shift from a traditional SOC to an AI SOC is not simply the addition of artificial intelligence.&lt;/p&gt;

&lt;p&gt;It is the move from isolated alerts and manual workflows toward connected, context-driven security operations.&lt;/p&gt;

&lt;p&gt;An effective AI SOC should be able to answer six fundamental questions:&lt;/p&gt;

&lt;p&gt;What happened?&lt;/p&gt;

&lt;p&gt;What is connected to it?&lt;/p&gt;

&lt;p&gt;How risky is it?&lt;/p&gt;

&lt;p&gt;What actually happened?&lt;/p&gt;

&lt;p&gt;What should happen next?&lt;/p&gt;

&lt;p&gt;Can the appropriate response happen automatically?&lt;/p&gt;

&lt;p&gt;That is what turns AI from a feature into an operational capability.&lt;/p&gt;

&lt;p&gt;For modern security teams, the goal is not to remove the analyst from security operations.&lt;/p&gt;

&lt;p&gt;It is to remove as much unnecessary work as possible between detection and understanding, and between understanding and response.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>aisoc</category>
      <category>securityoperations</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Hackers Hacked Hackers: What the ShinyHunters–Clop Attack Reveals About Modern Cybersecurity</title>
      <dc:creator>Anurag Singh</dc:creator>
      <pubDate>Tue, 22 Sep 2026 11:14:26 +0000</pubDate>
      <link>https://dev.to/anuragseceon/hackers-hacked-hackers-what-the-shinyhunters-clop-attack-reveals-about-modern-cybersecurity-427m</link>
      <guid>https://dev.to/anuragseceon/hackers-hacked-hackers-what-the-shinyhunters-clop-attack-reveals-about-modern-cybersecurity-427m</guid>
      <description>&lt;p&gt;Seceon Team · Security · September 2026&lt;/p&gt;

&lt;p&gt;Most Companies Spend Their Security Budget Trying to Stop Attackers From Getting In. What Happens When the Attackers Themselves Become the Target?&lt;/p&gt;

&lt;p&gt;That sounds like something from a movie.&lt;/p&gt;

&lt;p&gt;This week, it happened on the dark web.&lt;/p&gt;

&lt;p&gt;One cybercrime group reportedly breached another cybercrime group's infrastructure, stole access to its systems, and turned the attack into an extortion campaign.&lt;/p&gt;

&lt;h2&gt;
  
  
  Hackers Hacking Hackers
&lt;/h2&gt;

&lt;p&gt;On September 19, BleepingComputer reported that ShinyHunters had breached the data leak site operated by Clop, also known as Cl0p.&lt;/p&gt;

&lt;p&gt;The attackers reportedly exploited an unauthenticated file-upload vulnerability in the Grav CMS used by the site. They initially uploaded a small file, then later claimed they had gained broader access to the server.&lt;/p&gt;

&lt;p&gt;Reuters subsequently reported that ShinyHunters claimed it had discovered a vulnerability in Clop's software and used it to gain control of parts of the group's infrastructure. Cybersecurity researchers interviewed by Reuters said the clash appeared genuine, although some of the attackers' claims could not be independently verified.&lt;/p&gt;

&lt;p&gt;Then the unusual part happened.&lt;/p&gt;

&lt;p&gt;The attacker became the victim.&lt;/p&gt;

&lt;p&gt;ShinyHunters began demanding money from Clop and threatened to publish information it claimed to have stolen.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Same Security Problems Still Apply
&lt;/h2&gt;

&lt;p&gt;There is an interesting lesson here.&lt;/p&gt;

&lt;p&gt;Cybercriminal groups don't have some magical security layer that makes them immune to the vulnerabilities they exploit against everyone else.&lt;/p&gt;

&lt;p&gt;They still have:&lt;/p&gt;

&lt;p&gt;Vulnerable web applications&lt;br&gt;
Exposed services&lt;br&gt;
Authentication weaknesses&lt;br&gt;
Misconfigured systems&lt;br&gt;
Valuable credentials&lt;br&gt;
Sensitive logs&lt;br&gt;
Privileged accounts&lt;br&gt;
Software dependencies&lt;/p&gt;

&lt;p&gt;The difference is that attackers are constantly looking for these weaknesses.&lt;/p&gt;

&lt;p&gt;So when one criminal group finds a weakness in another group's infrastructure, the same attack lifecycle applies.&lt;/p&gt;

&lt;p&gt;Discover. Exploit. Gain access. Expand control. Steal information.&lt;/p&gt;

&lt;p&gt;The names of the organizations involved may change, but the underlying security problem doesn't.&lt;/p&gt;

&lt;h2&gt;
  
  
  A Vulnerability Is Only the Beginning
&lt;/h2&gt;

&lt;p&gt;The Grav CMS vulnerability reportedly gave ShinyHunters an initial way into Clop's infrastructure.&lt;/p&gt;

&lt;p&gt;But an initial foothold doesn't automatically explain the entire incident.&lt;/p&gt;

&lt;p&gt;Security teams need to understand what happened after the first successful action.&lt;/p&gt;

&lt;p&gt;Did the attacker access other systems?&lt;/p&gt;

&lt;p&gt;Did they obtain credentials?&lt;/p&gt;

&lt;p&gt;Did they modify applications?&lt;/p&gt;

&lt;p&gt;Did they access logs?&lt;/p&gt;

&lt;p&gt;Did they move laterally?&lt;/p&gt;

&lt;p&gt;Did they establish persistence?&lt;/p&gt;

&lt;p&gt;Did they access data that wasn't required for the original exploit?&lt;/p&gt;

&lt;p&gt;This is why simply knowing that a vulnerability exists isn't enough.&lt;/p&gt;

&lt;p&gt;The real security question is what that vulnerability allows an attacker to do.&lt;/p&gt;

&lt;h2&gt;
  
  
  This Is Where Attack Paths Matter
&lt;/h2&gt;

&lt;p&gt;Imagine a vulnerability rated as high risk.&lt;/p&gt;

&lt;p&gt;On its own, that tells you something.&lt;/p&gt;

&lt;p&gt;Now add context.&lt;/p&gt;

&lt;p&gt;The vulnerable application is internet-facing.&lt;/p&gt;

&lt;p&gt;It has privileged access.&lt;/p&gt;

&lt;p&gt;It connects to an internal database.&lt;/p&gt;

&lt;p&gt;The same environment contains sensitive credentials.&lt;/p&gt;

&lt;p&gt;An attacker has already started interacting with the system.&lt;/p&gt;

&lt;p&gt;Suddenly, the vulnerability isn't just a CVE on a spreadsheet.&lt;/p&gt;

&lt;p&gt;It's part of an attack path.&lt;/p&gt;

&lt;p&gt;That distinction matters for modern security operations because attackers rarely stop after the first successful exploit.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Hard Part Is Connecting the Signals
&lt;/h2&gt;

&lt;p&gt;A vulnerability scanner might identify the vulnerable application.&lt;/p&gt;

&lt;p&gt;An identity system might show an unusual login.&lt;/p&gt;

&lt;p&gt;A network tool might detect suspicious traffic.&lt;/p&gt;

&lt;p&gt;An endpoint tool might flag a new process.&lt;/p&gt;

&lt;p&gt;A cloud platform might record a configuration change.&lt;/p&gt;

&lt;p&gt;Each alert can look manageable on its own.&lt;/p&gt;

&lt;p&gt;Put them together, and they can tell a very different story.&lt;/p&gt;

&lt;p&gt;This is one reason unified security visibility matters.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://seceon.com/otm-platform/" rel="noopener noreferrer"&gt;Seceon OTM&lt;/a&gt; brings together security signals across network, endpoint, identity, cloud, and application environments so security teams can investigate activity with broader context instead of treating every alert as an isolated event.&lt;/p&gt;

&lt;p&gt;The goal isn't simply to collect more alerts.&lt;/p&gt;

&lt;p&gt;It's to understand how individual events connect to an attack.&lt;/p&gt;

&lt;h2&gt;
  
  
  Cybercrime Is Becoming More Like an Ecosystem
&lt;/h2&gt;

&lt;p&gt;There is another interesting takeaway from this incident.&lt;/p&gt;

&lt;p&gt;Cybercrime isn't a collection of completely independent attackers anymore.&lt;/p&gt;

&lt;p&gt;Groups share exploits.&lt;/p&gt;

&lt;p&gt;They compete for access.&lt;/p&gt;

&lt;p&gt;They steal from each other.&lt;/p&gt;

&lt;p&gt;They use common infrastructure.&lt;/p&gt;

&lt;p&gt;They target the same vulnerabilities.&lt;/p&gt;

&lt;p&gt;And sometimes they attack the infrastructure of their own competitors.&lt;/p&gt;

&lt;p&gt;Reuters reported that the current dispute between ShinyHunters and Clop is connected to an earlier conflict involving an Oracle E-Business Suite exploit. Clop later used that vulnerability in data-theft campaigns affecting numerous organizations.&lt;/p&gt;

&lt;p&gt;That means threat intelligence isn't only about identifying who is attacking your organization.&lt;/p&gt;

&lt;p&gt;It is also about understanding how the broader threat ecosystem is behaving.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Security Teams Should Take Away
&lt;/h2&gt;

&lt;p&gt;The unusual part of this story shouldn't distract from the familiar lesson underneath it.&lt;/p&gt;

&lt;p&gt;Attackers look for weak points.&lt;/p&gt;

&lt;p&gt;They exploit exposed systems.&lt;/p&gt;

&lt;p&gt;They abuse credentials.&lt;/p&gt;

&lt;p&gt;They move when they find opportunities.&lt;/p&gt;

&lt;p&gt;And they don't care whether the target considers itself a "security-conscious" organization.&lt;/p&gt;

&lt;p&gt;That means security teams need visibility across the full chain:&lt;/p&gt;

&lt;p&gt;Vulnerability → Exposure → Access → Behavior → Movement → Impact&lt;/p&gt;

&lt;p&gt;If you can see only the first step, you're seeing the vulnerability.&lt;/p&gt;

&lt;p&gt;If you can see the whole chain, you're seeing the attack.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Can hackers attack other hackers?&lt;/strong&gt;&lt;br&gt;
Yes. Cybercriminal groups can target each other's infrastructure, credentials, applications, or data. In September 2026, Reuters reported that ShinyHunters claimed to have breached rival group Clop's infrastructure. Researchers quoted by Reuters said the conflict appeared genuine, although some claims from the attackers could not be independently verified.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What happened between ShinyHunters and Clop?&lt;/strong&gt;&lt;br&gt;
ShinyHunters reportedly breached Clop's data leak infrastructure and defaced its site. BleepingComputer confirmed the initial file upload and defacement, while some broader claims about stolen data and private keys remained unverified.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why isn't vulnerability management enough?&lt;/strong&gt;&lt;br&gt;
A vulnerability tells you that a weakness exists. It doesn't necessarily tell you whether the vulnerable asset is exposed, what access it provides, whether attackers are using it, or what could happen after exploitation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is an attack path in cybersecurity?&lt;/strong&gt;&lt;br&gt;
An attack path describes how an attacker can move from an initial weakness or access point toward higher-value systems, identities, data, or other assets.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why does security correlation matter?&lt;/strong&gt;&lt;br&gt;
Security correlation connects signals from different parts of an environment. A suspicious login, vulnerable application, unusual process, and unexpected network&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>threatintelligence</category>
      <category>vulnerabilitymanagement</category>
      <category>infosec</category>
    </item>
    <item>
      <title>When AI Goes Beyond the Test Environment, Who Is Securing the AI?</title>
      <dc:creator>Anurag Singh</dc:creator>
      <pubDate>Mon, 21 Sep 2026 08:48:05 +0000</pubDate>
      <link>https://dev.to/anuragseceon/when-ai-goes-beyond-the-test-environment-who-is-securing-the-ai-20cf</link>
      <guid>https://dev.to/anuragseceon/when-ai-goes-beyond-the-test-environment-who-is-securing-the-ai-20cf</guid>
      <description>&lt;p&gt;A security test was supposed to attack fake companies.&lt;/p&gt;

&lt;p&gt;Instead, an AI model reached three real ones.&lt;/p&gt;

&lt;p&gt;In May 2026, Google's Gemini accessed and breached systems belonging to three companies during a cybersecurity evaluation conducted by Irregular. The test environment was intended to be isolated, but unintended internet access allowed Gemini to reach real-world systems.&lt;/p&gt;

&lt;p&gt;That changes the conversation around AI security.&lt;/p&gt;

&lt;p&gt;The biggest risk may not be what an AI agent can do. It may be what happens when we give it access to the wrong environment.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Problem Wasn't Just the AI
&lt;/h2&gt;

&lt;p&gt;The evaluation was designed around simulated targets.&lt;/p&gt;

&lt;p&gt;But once Gemini had unintended internet access, it was able to use publicly available information and credentials to access real systems. In one case, the model reportedly guessed credentials until it gained access. In two others, credentials found in a public repository helped it reach protected systems.&lt;/p&gt;

&lt;p&gt;Google said Gemini stopped its activity after recognizing that the systems were real, and the affected organizations were notified.&lt;/p&gt;

&lt;p&gt;But the incident exposes something security teams should take seriously.&lt;/p&gt;

&lt;p&gt;An AI agent doesn't need to be malicious to become a security problem.&lt;/p&gt;

&lt;p&gt;It only needs access, autonomy, and the wrong boundary.&lt;/p&gt;

&lt;h2&gt;
  
  
  AI Agents Are Changing the Security Boundary
&lt;/h2&gt;

&lt;p&gt;Traditional applications usually do what they are programmed to do.&lt;/p&gt;

&lt;p&gt;AI agents can interpret information, make decisions, use tools, access systems, and continue through multi-step tasks.&lt;/p&gt;

&lt;p&gt;That creates a different security model.&lt;/p&gt;

&lt;p&gt;An agent might have access to:&lt;/p&gt;

&lt;p&gt;Cloud environments&lt;br&gt;
APIs&lt;br&gt;
Code repositories&lt;br&gt;
Credentials&lt;br&gt;
Internal applications&lt;br&gt;
Browsers&lt;br&gt;
Databases&lt;br&gt;
External websites&lt;/p&gt;

&lt;p&gt;The more tools an agent can use, the more important the boundaries around those tools become.&lt;/p&gt;

&lt;p&gt;A mistake that would normally stop at a screen can become an action across multiple systems.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Credential Problem Is Still There
&lt;/h2&gt;

&lt;p&gt;There is another important lesson here.&lt;/p&gt;

&lt;p&gt;The AI didn't need some futuristic zero-day to get access.&lt;/p&gt;

&lt;p&gt;It used things that already existed.&lt;/p&gt;

&lt;p&gt;Public information.&lt;/p&gt;

&lt;p&gt;Credentials.&lt;/p&gt;

&lt;p&gt;Internet access.&lt;/p&gt;

&lt;p&gt;Weak boundaries.&lt;/p&gt;

&lt;p&gt;That matters because organizations can spend heavily on advanced AI security while still leaving basic access paths exposed.&lt;/p&gt;

&lt;p&gt;AI doesn't eliminate old security problems. It can make them faster to exploit.&lt;/p&gt;

&lt;h2&gt;
  
  
  Security Testing Needs Security Controls Too
&lt;/h2&gt;

&lt;p&gt;This incident also raises an uncomfortable question.&lt;/p&gt;

&lt;p&gt;Who is monitoring the security agent while it is testing security?&lt;/p&gt;

&lt;p&gt;If an AI system can scan, discover, authenticate, execute actions, and move through an environment autonomously, the test itself needs guardrails.&lt;/p&gt;

&lt;p&gt;That means security testing environments need:&lt;/p&gt;

&lt;p&gt;Strict network isolation&lt;br&gt;
Explicit allowlists&lt;br&gt;
Clear target boundaries&lt;br&gt;
Credential controls&lt;br&gt;
Continuous monitoring&lt;br&gt;
Immediate containment mechanisms&lt;br&gt;
Logging of every agent action&lt;/p&gt;

&lt;p&gt;A test environment cannot simply be considered safe because the targets are supposed to be fake.&lt;/p&gt;

&lt;p&gt;The environment itself has to be treated as part of the attack surface.&lt;/p&gt;

&lt;h2&gt;
  
  
  This Is Where Continuous Validation Matters
&lt;/h2&gt;

&lt;p&gt;This is also why security validation cannot be limited to checking whether a control exists.&lt;/p&gt;

&lt;p&gt;Organizations need to understand what happens when a real attack path is exercised.&lt;/p&gt;

&lt;p&gt;Can an attacker reach the asset?&lt;/p&gt;

&lt;p&gt;Can credentials be abused?&lt;/p&gt;

&lt;p&gt;Can the attacker move from one system to another?&lt;/p&gt;

&lt;p&gt;Does the security stack detect the behavior?&lt;/p&gt;

&lt;p&gt;Can the SOC respond before the activity spreads?&lt;/p&gt;

&lt;p&gt;This is the problem &lt;a href="https://seceon.com/" rel="noopener noreferrer"&gt;Seceon&lt;/a&gt; &lt;a href="https://seceon.com/aibas360/" rel="noopener noreferrer"&gt;aiBAS360&lt;/a&gt; is built around: continuously simulating realistic attack techniques and validating whether existing security controls actually detect and respond to them.&lt;/p&gt;

&lt;p&gt;The goal isn't simply to generate another security report.&lt;/p&gt;

&lt;p&gt;It's to answer a much more practical question:&lt;/p&gt;

&lt;p&gt;"If someone actually tried this attack path, would our defenses stop it?"&lt;/p&gt;

&lt;h2&gt;
  
  
  The New Security Question
&lt;/h2&gt;

&lt;p&gt;AI agents are becoming capable of performing increasingly complex tasks.&lt;/p&gt;

&lt;p&gt;That means security teams need to move beyond asking:&lt;/p&gt;

&lt;p&gt;"Is this AI model safe?"&lt;/p&gt;

&lt;p&gt;The better question is:&lt;/p&gt;

&lt;p&gt;"What can this AI access, what can it change, and what happens if it makes the wrong decision?"&lt;/p&gt;

&lt;p&gt;That applies to AI used for cybersecurity as much as AI used for business operations.&lt;/p&gt;

&lt;p&gt;An agent with no access has limited impact.&lt;/p&gt;

&lt;p&gt;An agent with broad access and weak controls can become a completely different security problem.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Bigger Takeaway
&lt;/h2&gt;

&lt;p&gt;The Gemini incident wasn't a conventional cyberattack against those three companies.&lt;/p&gt;

&lt;p&gt;It was a security evaluation that crossed its intended boundary.&lt;/p&gt;

&lt;p&gt;And that's exactly why it matters.&lt;/p&gt;

&lt;p&gt;As AI agents become more autonomous, the boundary between testing, automation, and real-world action is becoming thinner.&lt;/p&gt;

&lt;p&gt;Security teams can't assume that an AI agent will always stay inside the box.&lt;/p&gt;

&lt;p&gt;They need to continuously test the box itself.&lt;/p&gt;

&lt;p&gt;Because the next security failure may not come from an attacker breaking through your defenses.&lt;/p&gt;

&lt;p&gt;It may come from a trusted AI system being given access to something it was never supposed to reach.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;FAQ&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What happens when an AI agent gets access to real systems?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;An AI agent can potentially interact with real applications, credentials, APIs, cloud environments, and other systems. If access boundaries are weak, an action intended for a test environment can have real-world consequences.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why are AI agents becoming a cybersecurity concern?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;AI agents can interpret information, use tools, make decisions, and perform multi-step actions. This creates a larger security boundary than traditional software and makes access controls, monitoring, and containment increasingly important.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How can organizations secure AI agents?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Organizations should apply strict network isolation, allowlists, credential controls, least-privilege access, continuous monitoring, and clear boundaries around what an AI agent can access or modify.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why is security validation important for AI environments?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Security validation helps organizations determine whether their controls actually detect and stop realistic attack paths rather than simply confirming that a security control exists.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How can Seceon aiBAS360 help with security validation?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Seceon aiBAS360 continuously simulates realistic attack techniques to validate security controls and identify gaps across an organization's environment.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Source: Reuters, September 2026.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>aisecurity</category>
      <category>securitytesting</category>
      <category>breachandattacksimulation</category>
    </item>
    <item>
      <title>Malware Doesn't Need a Command Server Anymore</title>
      <dc:creator>Anurag Singh</dc:creator>
      <pubDate>Fri, 18 Sep 2026 08:14:30 +0000</pubDate>
      <link>https://dev.to/anuragseceon/malware-doesnt-need-a-command-server-anymore-bdj</link>
      <guid>https://dev.to/anuragseceon/malware-doesnt-need-a-command-server-anymore-bdj</guid>
      <description>&lt;p&gt;For years, one of the basic assumptions in malware detection was that compromised systems eventually need to communicate with some attacker-controlled infrastructure.&lt;/p&gt;

&lt;p&gt;A domain. An IP address. A command-and-control server. Something security teams can discover, block, investigate, or take down.&lt;/p&gt;

&lt;p&gt;But attackers are finding another option.&lt;/p&gt;

&lt;p&gt;What if the command infrastructure is a public blockchain?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The Blockchain Can Become the Dead Drop&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A new Chainalysis report describes a technique it calls Blockchain Dead Drops (BDD).&lt;/p&gt;

&lt;p&gt;Instead of keeping malware instructions on a conventional server, attackers can place instructions in blockchain transactions or smart contracts. An infected device can then retrieve those instructions when needed.&lt;/p&gt;

&lt;p&gt;The important part isn't that malware suddenly became blockchain-based.&lt;/p&gt;

&lt;p&gt;The malware can still get onto a device through more conventional methods, such as malicious downloads or supply-chain attacks.&lt;/p&gt;

&lt;p&gt;The difference comes later.&lt;/p&gt;

&lt;p&gt;Instead of asking a compromised machine to contact a traditional command server, attackers can use blockchain infrastructure as a durable communication layer.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why Would Attackers Do This?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Traditional command infrastructure has weaknesses.&lt;/p&gt;

&lt;p&gt;A domain can be seized.&lt;/p&gt;

&lt;p&gt;A server can be taken offline.&lt;/p&gt;

&lt;p&gt;An IP address can be blocked.&lt;/p&gt;

&lt;p&gt;A hosting provider can terminate an account.&lt;/p&gt;

&lt;p&gt;A public blockchain introduces a different problem for defenders.&lt;/p&gt;

&lt;p&gt;The data written to the blockchain remains recorded, and the infrastructure itself isn't something a security team can simply shut down.&lt;/p&gt;

&lt;p&gt;Chainalysis says this durability can allow campaigns to continue even after domains, servers, or repositories associated with an operation have been disrupted.&lt;/p&gt;

&lt;p&gt;That's the interesting security shift.&lt;/p&gt;

&lt;p&gt;The attacker doesn't necessarily need infrastructure that they control completely. They can use infrastructure that already exists publicly.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The Numbers Are Getting Harder to Ignore&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;According to Chainalysis, malicious writes associated with blockchain dead drops increased from an average of 2.06 per day to 11.1 per day, a 440% increase in less than a year. The company is tracking this activity across five major blockchains and more than a dozen malware strains.&lt;/p&gt;

&lt;p&gt;Chainalysis also says the technique has attracted nation-state activity, including operators associated with North Korea and Iran.&lt;/p&gt;

&lt;p&gt;That doesn't mean every blockchain transaction is suspicious.&lt;/p&gt;

&lt;p&gt;It means defenders have another place where malicious infrastructure can hide.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The Visibility Problem Is Bigger Than the Blockchain&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This creates an interesting challenge for security operations.&lt;/p&gt;

&lt;p&gt;A traditional investigation might look for:&lt;/p&gt;

&lt;p&gt;Suspicious DNS requests&lt;br&gt;
Connections to known malicious IPs&lt;br&gt;
Unusual HTTP traffic&lt;br&gt;
Repeated beaconing&lt;br&gt;
Abnormal process activity&lt;br&gt;
Known command-and-control domains&lt;/p&gt;

&lt;p&gt;But what happens when the attacker doesn't depend on a conventional C2 server?&lt;/p&gt;

&lt;p&gt;The investigation has to become more focused on behavior and context.&lt;/p&gt;

&lt;p&gt;What process is making the connection?&lt;/p&gt;

&lt;p&gt;Which endpoint is generating it?&lt;/p&gt;

&lt;p&gt;Is the traffic normal for that system?&lt;/p&gt;

&lt;p&gt;Did the activity start after another suspicious event?&lt;/p&gt;

&lt;p&gt;Is the same behavior appearing across multiple machines?&lt;/p&gt;

&lt;p&gt;The blockchain may be where the attacker stores instructions, but the compromised endpoint still has to retrieve and act on them.&lt;/p&gt;

&lt;p&gt;That's where endpoint and network telemetry remain important.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Security Teams Can't Block What They Can't See&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This is where broader security visibility becomes valuable.&lt;/p&gt;

&lt;p&gt;Platforms such as &lt;a href="https://seceon.com/" rel="noopener noreferrer"&gt;Seceon OTM&lt;/a&gt; are designed to bring together security signals across network, endpoint, identity, cloud, and application environments.&lt;/p&gt;

&lt;p&gt;That doesn't mean a security platform automatically detects every blockchain dead drop.&lt;/p&gt;

&lt;p&gt;It means security teams can investigate the surrounding behavior instead of relying only on known malicious domains or fixed indicators.&lt;/p&gt;

&lt;p&gt;If a normally quiet endpoint suddenly begins communicating with unusual destinations, starts a suspicious process, and shows other abnormal activity, those signals can provide useful context even when the attacker's infrastructure isn't a traditional C2 server.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The C2 Problem Is Changing&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Attackers don't always need to build better infrastructure.&lt;/p&gt;

&lt;p&gt;Sometimes they can simply find infrastructure that defenders don't control.&lt;/p&gt;

&lt;p&gt;Cloud services changed the way attackers host malware.&lt;/p&gt;

&lt;p&gt;Legitimate platforms created new ways to blend malicious traffic with normal traffic.&lt;/p&gt;

&lt;p&gt;Now public blockchains are being used as another layer for durable command infrastructure.&lt;/p&gt;

&lt;p&gt;The lesson isn't that blockchain itself is dangerous.&lt;/p&gt;

&lt;p&gt;It's that security assumptions become dangerous when attackers find a way around them.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What Security Teams Should Take Away&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The old question was:&lt;/p&gt;

&lt;p&gt;"What malicious server is this machine communicating with?"&lt;/p&gt;

&lt;p&gt;The modern question is broader:&lt;/p&gt;

&lt;p&gt;"What is this machine doing, why is it doing it, and does that behavior make sense in context?"&lt;/p&gt;

&lt;p&gt;That shift matters because infrastructure can change.&lt;/p&gt;

&lt;p&gt;Domains disappear.&lt;/p&gt;

&lt;p&gt;Servers get seized.&lt;/p&gt;

&lt;p&gt;IPs rotate.&lt;/p&gt;

&lt;p&gt;Attackers move to legitimate services.&lt;/p&gt;

&lt;p&gt;And now, in some campaigns, blockchain transactions and smart contracts can become part of the communication layer.&lt;/p&gt;

&lt;p&gt;The more durable the attacker's infrastructure becomes, the more important behavioral visibility becomes for defenders.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The Bigger Takeaway&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Cybersecurity has always involved an infrastructure arms race.&lt;/p&gt;

&lt;p&gt;Defenders build systems to detect and block attacker infrastructure.&lt;/p&gt;

&lt;p&gt;Attackers find ways to make that infrastructure harder to disrupt.&lt;/p&gt;

&lt;p&gt;Blockchain dead drops are another example of that evolution.&lt;/p&gt;

&lt;p&gt;The future of threat detection can't depend only on knowing where attackers are hosting their servers.&lt;/p&gt;

&lt;p&gt;Sometimes, the infrastructure isn't theirs.&lt;/p&gt;

&lt;p&gt;It's already everywhere.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>malware</category>
      <category>threatintelligence</category>
      <category>infosec</category>
    </item>
    <item>
      <title>You Have One Identity. Your Security Stack Sees Seven.</title>
      <dc:creator>Anurag Singh</dc:creator>
      <pubDate>Tue, 08 Sep 2026 10:05:50 +0000</pubDate>
      <link>https://dev.to/anuragseceon/you-have-one-identity-your-security-stack-sees-seven-3591</link>
      <guid>https://dev.to/anuragseceon/you-have-one-identity-your-security-stack-sees-seven-3591</guid>
      <description>&lt;p&gt;I was mapping out access for a mid-sized engineering org a while back, and we hit a wall almost immediately: nobody could tell us, with confidence, how many accounts one senior engineer actually had.&lt;/p&gt;

&lt;p&gt;By the time we finished counting, the answer was seven. Active Directory account. Okta identity. An AWS IAM role. A GitHub account with org-admin on two repos. Microsoft 365 access. A VPN identity. A privileged role in a cloud console nobody remembered granting.&lt;/p&gt;

&lt;p&gt;Seven accounts. One person. And not one system in that stack had the full picture.&lt;/p&gt;

&lt;p&gt;That's not a rare setup. It's basically the default now, especially for anyone touching infrastructure, CI/CD, or cloud resources regularly. And it creates a strange asymmetry: for your SOC, that's seven disconnected pieces of data sitting in seven different consoles. For an attacker who compromises just one of those seven, it's one identity with several paths into the org, and they only need to find the weakest one.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Identity You Can See Isn't the Identity You Actually Have
&lt;/h2&gt;

&lt;p&gt;Identity data is scattered by design. Directories, identity providers, cloud platforms, SaaS apps, HR systems, PAM tools, VPNs, databases — each one knows a slice of the truth about an account, and almost none of them know the whole story about the person or entity behind it.&lt;/p&gt;

&lt;p&gt;Here's a scenario worth sitting with. A developer suddenly accesses a repository they've never touched. Around the same time, that same person authenticates from an unfamiliar location, picks up a new privilege, and reaches a cloud resource they don't normally go near.&lt;/p&gt;

&lt;p&gt;Any one of those, alone, has a boring explanation. New project, new laptop, new access request that hasn't been revoked yet. But stacked together, on the same identity, in a short window, that combination starts looking a lot less boring. The hard part was never really detecting each event individually. Most tools can do that. The hard part is realizing all four events belong to the same person, and understanding what that person can actually reach if they've been compromised.&lt;/p&gt;

&lt;h2&gt;
  
  
  Accounts Aren't the Same Thing as Identities
&lt;/h2&gt;

&lt;p&gt;Traditional identity monitoring hands security teams siloed views almost by default. Active Directory shows one account. Okta shows another. AWS shows a third. Every SaaS app you add stacks another account and another set of permissions on top.&lt;/p&gt;

&lt;p&gt;Which creates a pretty basic mismatch: the security team sees accounts. What they actually need to understand is identities. That gap matters more as an org scales, because a dormant account can quietly become active, a privileged identity can start behaving differently, a service account can touch an application it's never touched before, and permissions can pile up on someone's profile for years without anyone reviewing why they're still there. Without something correlating those accounts back to one entity, all of that stays scattered across dashboards nobody's cross-referencing in real time.&lt;/p&gt;

&lt;h2&gt;
  
  
  Risk Isn't a Single Login Event
&lt;/h2&gt;

&lt;p&gt;Not every identity carries the same weight. A standard employee account behaving exactly like it always does is a non-event. A privileged admin account suddenly reaching for something unfamiliar is not. A dormant account waking up isn't the same story as a service account running its normal, scheduled workload.&lt;/p&gt;

&lt;p&gt;Treating all of these the same way, as isolated login events, is part of why alert fatigue exists in the first place. What actually matters is a continuously updated read on which identities are becoming risky right now, not a static list of who technically has an account.&lt;/p&gt;

&lt;h2&gt;
  
  
  Knowing an Identity Is Risky Isn't the Same as Knowing What It Can Reach
&lt;/h2&gt;

&lt;p&gt;This is the part that's easy to skip past. A privileged identity connected to a dozen applications, several groups, and multiple cloud resources represents a very different level of exposure than a similarly "risky-looking" identity that's isolated to one low-value system. If either one gets compromised, the actual damage depends entirely on its access paths, not just on the fact that something looked unusual.&lt;/p&gt;

&lt;p&gt;Being able to visualize that, what applications an identity touches, which groups it belongs to, what privileged access it holds, and what the realistic blast radius looks like if it's compromised, turns "this account triggered an alert" into something an analyst can actually act on.&lt;/p&gt;

&lt;h2&gt;
  
  
  Detection Is Only Half the Problem
&lt;/h2&gt;

&lt;p&gt;Finding a risky identity is the easier half. The harder question is what happens in the minutes right after that.&lt;/p&gt;

&lt;p&gt;If every high-risk identity requires a manual ticket, a handoff to another team, and three rounds of approval before anything happens, your response time is going to lose to an attacker who's already moving. This is exactly the kind of decision that benefits from being pre-approved and automated for high-confidence cases: lock the account, force MFA re-enrollment, clean up a dormant identity, contain a privileged account that's acting outside its normal pattern. Not to cut humans out of the loop, but to cut the unnecessary waiting out of the cases where the evidence is already clear.&lt;/p&gt;

&lt;h2&gt;
  
  
  Identity Attacks Rarely Look Like Malware
&lt;/h2&gt;

&lt;p&gt;One of the more frustrating things about identity-based attacks is that they often skip the part your endpoint tools are built to catch. There's no malicious file, no obvious exploit. Just a valid credential, used in a way that doesn't quite match how it's normally used: impossible travel, an MFA bypass, credential stuffing, a privileged identity reaching somewhere it's never gone before.&lt;/p&gt;

&lt;p&gt;Every one of those can look completely legitimate to a control that's only checking "is this credential valid." The behavior around the credential is usually where the real story is, which is exactly why this has to be a correlation problem, not a single-signal detection problem.&lt;/p&gt;

&lt;h2&gt;
  
  
  This Gets Worse, Not Better, at MSSP Scale
&lt;/h2&gt;

&lt;p&gt;For a single enterprise, identity fragmentation might mean juggling a dozen systems. For an MSSP managing multiple customers, that same fragmentation exists per tenant, and it multiplies. Different identity providers, different directories, different cloud environments, different policies, times however many customers you're responsible for. Without a centralized way to score and monitor identity risk across tenants, analysts end up manually switching between disconnected consoles for every single customer, which doesn't scale past a handful of accounts.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where I've Found This Actually Gets Solved
&lt;/h2&gt;

&lt;p&gt;I'll be upfront: I work with Seceon. What convinced me this was worth writing about wasn't a feature list, it was watching how their aiSecurity UIDGuard360 handles the seven-accounts-one-person problem specifically. It resolves fragmented accounts across directories, cloud, HR, and SaaS sources into a single canonical identity, and scores risk continuously across credential, privilege, activity, access, behavioral, and compliance signals instead of treating every login as its own isolated event.&lt;/p&gt;

&lt;p&gt;That's the shift that actually matters here. Not another dashboard, another data source connected to the pile. The difference between an analyst starting an investigation with "this account generated an alert" versus starting with "this person has these seven accounts, these privileges, and this level of risk right now" is enormous, and it's the difference that decides whether an investigation takes twenty minutes or two hours.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Real Shift
&lt;/h2&gt;

&lt;p&gt;Identity security has spent years focused on authentication, MFA, and access reviews. Those still matter. But modern identity attacks don't stop at the login screen. An attacker compromises an identity, reaches an application, touches cloud infrastructure, picks up a privileged role, and starts moving toward something valuable. The identity is the thread connecting every one of those steps.&lt;/p&gt;

&lt;p&gt;Which means the real question was never just "how many identities do we have." It's closer to: who does this identity actually belong to, what can it reach, how does its behavior compare to normal, and what happens the moment something about it changes.&lt;/p&gt;

&lt;p&gt;That's a harder problem than counting accounts. It's also the one that actually matters.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>identitysecurity</category>
      <category>ai</category>
      <category>security</category>
    </item>
    <item>
      <title>A Human Attacker Used AI Agents to Run a 10-Hour Intrusion. Here's What That Actually Means for Your Pipeline.</title>
      <dc:creator>Anurag Singh</dc:creator>
      <pubDate>Mon, 07 Sep 2026 11:14:15 +0000</pubDate>
      <link>https://dev.to/anuragseceon/a-human-attacker-used-ai-agents-to-run-a-10-hour-intrusion-heres-what-that-actually-means-for-3kd2</link>
      <guid>https://dev.to/anuragseceon/a-human-attacker-used-ai-agents-to-run-a-10-hour-intrusion-heres-what-that-actually-means-for-3kd2</guid>
      <description>&lt;p&gt;The most unsettling number in cybersecurity right now might be 10 hours.&lt;/p&gt;

&lt;p&gt;Not 10 days. Not 10 weeks. 10 hours.&lt;/p&gt;

&lt;p&gt;In a recent Unit 42 investigation, researchers responded to an enterprise intrusion where a human threat actor used frontier AI models and attack-specific agentic frameworks to automate large parts of the attack. The result: more than 50 MITRE ATT&amp;amp;CK techniques compressed into less than 10 hours, work that would normally take a human operator roughly two weeks.&lt;/p&gt;

&lt;p&gt;The attack didn't stop at getting a foothold. The AI agents mapped the internal environment, searched source repositories, obtained root credentials, triggered unauthorized CI/CD activity, and targeted cloud AI infrastructure.&lt;/p&gt;

&lt;p&gt;If you work anywhere near a CI/CD pipeline, a source repo, or a cloud deployment key, that list should sound uncomfortably familiar. This wasn't an attack on some abstract "enterprise network." It moved through the exact systems most engineering teams touch every day.&lt;/p&gt;

&lt;h2&gt;
  
  
  Attacks Used to Be Sequential. Now They're Parallel.
&lt;/h2&gt;

&lt;p&gt;Defenders have long thought about intrusions as a chain: initial access, discovery, credential access, lateral movement, persistence, exfiltration. The steps were never the hard part for attackers. Time was. Reconnaissance takes time. Finding a usable credential takes time. Understanding an unfamiliar environment takes time.&lt;/p&gt;

&lt;p&gt;AI agents change that math. Instead of one operator working through each step by hand, several agents can work through different parts of an environment at once, one testing credentials while another maps cloud resources while a third pokes at a CI/CD pipeline. The attacker stops moving through the kill chain step by step and starts running several branches of it simultaneously.&lt;/p&gt;

&lt;p&gt;Picture the difference. A traditional intrusion looks roughly like: compromise, investigate, find credentials, move, repeat. An agentic one looks more like a fan-out: compromise, then in parallel, map the environment, search repositories, test credentials, identify cloud resources, poke at CI/CD, hunt for privileged access — all running at once instead of in sequence.&lt;/p&gt;

&lt;p&gt;That parallelism is the real shift, and it's specifically bad news for anything resembling modern software delivery, where a repo, a CI runner, an API token, and a cloud deployment target are all sitting a few hops apart from each other.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Part of This Story Developers Should Actually Care About
&lt;/h2&gt;

&lt;p&gt;Most write-ups on this kind of intrusion focus on the SOC's problem. But look again at what the agents actually did: searched source repositories, created activity around CI/CD, obtained credentials, and moved into cloud infrastructure. That's not a SOC-only story. That's a software supply chain story.&lt;/p&gt;

&lt;p&gt;A few uncomfortable questions worth sitting with if you maintain a pipeline:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How long does a leaked CI/CD token stay valid?&lt;/strong&gt; If a token doesn't expire quickly and isn't scoped tightly, an agent that finds it has plenty of runway to use it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Does your CI system log and alert on unexpected pipeline triggers&lt;/strong&gt;, or would an off-schedule build just blend into normal noise? An automated attacker doesn't need to trigger a deploy at 3 AM to look suspicious if your pipeline runs constantly anyway.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Are your repo access tokens scoped to what they actually need&lt;/strong&gt;, or does "make it work" access accumulate the same way over-permissioned service accounts do everywhere else? An agent doesn't need a superuser credential if a moderately-permissioned one gets it 80% of the way there.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Would unusual repository access even stand out?&lt;/strong&gt; A read on a repo nobody usually touches is exactly the kind of low-noise signal that traditional monitoring wasn't built to catch, because it doesn't look like "an attack." It looks like someone browsing code.&lt;/p&gt;

&lt;p&gt;None of these are new problems. They're the same access-hygiene questions security teams have been asking about human credentials for years. What's changed is the speed at which something can find and use a weak answer to any one of them.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why the SOC's Bottleneck Is Now a Race Against Compute
&lt;/h2&gt;

&lt;p&gt;Most SOCs already run into a familiar wall: too many alerts, too many dashboards, too few analysts. Add an automated attacker to that picture and a new asymmetry shows up. A human analyst might spend 20 minutes deciding whether an authentication anomaly matters. In that same 20 minutes, an automated attacker can be testing several other paths in parallel. The defender's bottleneck is human attention. The attacker's bottleneck is increasingly just compute, and compute scales a lot faster than headcount.&lt;/p&gt;

&lt;p&gt;That's the actual problem underneath the AI-vs-AI framing people reach for. It's not really "attackers have AI so defenders need AI." It's that a tool watching only endpoint telemetry can't understand an attack moving through identity, cloud, source code, CI/CD, and AI infrastructure in the same hour. Neither can a tool watching only network traffic, or only identity. Each one has a piece of the story. The attacker doesn't care which product owns which alert. It cares about the relationships between systems, so that's what the defense has to see too.&lt;/p&gt;

&lt;h2&gt;
  
  
  Six Events, Six Alerts, or One Attack
&lt;/h2&gt;

&lt;p&gt;Here's a version of how that plays out. A developer account authenticates from an unusual location. A few minutes later, that same identity accesses a repository it doesn't normally touch. Shortly after, a new API token gets created. Then a CI/CD pipeline kicks off unexpectedly. Not long after that, a cloud workload starts talking to a new external destination. And finally, a privileged account performs an administrative action nobody scheduled.&lt;/p&gt;

&lt;p&gt;Looked at individually, that's six alerts, each with a plausible innocent explanation. Looked at together, in that order, in that timeframe, it's one attack. That gap between six isolated alerts and one understood attack is exactly where most SOCs are still losing time.&lt;/p&gt;

&lt;h2&gt;
  
  
  What an Attack Graph Gives You That an Alert List Doesn't
&lt;/h2&gt;

&lt;p&gt;An alert list tells you something happened, somewhere, at some point. An attack graph asks a different set of questions: who initiated it, which identity was involved, which device was used, what changed afterward, which systems were touched, what credentials appeared, what network connections followed, which cloud resources got accessed, what happened next.&lt;/p&gt;

&lt;p&gt;That second model is a lot closer to how these intrusions actually unfold, because attacks are relationships between events, not a pile of isolated ones. This is also why SIEM isn't going away even as the conversation shifts toward AI-driven detection. When an attack moves this fast, historical and cross-domain context is worth more, not less. The problem was never that SIEM collects too little data. It's that collecting data and understanding relationships between events are two different jobs, and most SOC workflows still treat the first one as if it were the second.&lt;/p&gt;

&lt;h2&gt;
  
  
  Detection Alone Buys You Very Little Time
&lt;/h2&gt;

&lt;p&gt;Here's the part worth sitting with: detecting an event in seconds doesn't help much if it then takes two hours to figure out that the event is connected to five other things. A fast detection followed by a slow investigation is still, functionally, a slow response, and an automated attacker doesn't need much of that gap to keep moving.&lt;/p&gt;

&lt;p&gt;That reframes what a security platform actually needs to be good at. Detection is table stakes. The harder, more valuable capability is compressing the distance between an event happening and someone (or something) understanding what it's actually connected to.&lt;/p&gt;

&lt;h2&gt;
  
  
  This Is the Problem Seceon Is Built Around
&lt;/h2&gt;

&lt;p&gt;I'll be upfront: I work with Seceon, so weigh this accordingly.&lt;/p&gt;

&lt;p&gt;What drew me to their approach specifically is that it doesn't try to solve this with a smarter alert. It's built so that an identity anomaly, an endpoint event, a network connection, and a cloud action can be evaluated together instead of separately, because that's the only way a six-alert sequence like the one above gets recognized as one attack instead of six tickets in six different queues. The AI part isn't the interesting bit on its own. What it has access to see, and whether it can connect that across identity, endpoint, network, and cloud, is what actually determines whether it's useful during something moving this fast.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Analyst's Job Is Changing, Not Disappearing
&lt;/h2&gt;

&lt;p&gt;None of this makes the human analyst less relevant. If anything, it raises the value of good judgment, because the routine work, opening repetitive alerts, manually cross-referencing dashboards, reconstructing an obvious attack chain by hand, is exactly the kind of thing that should get automated away. What shouldn't get automated away is deciding whether a high-confidence containment action is actually the right call, threat hunting for the stuff automation won't catch, and understanding what an incident actually means for the business behind it.&lt;/p&gt;

&lt;p&gt;The goal was never to remove the analyst from the loop. It's to remove the waiting around the analyst.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Real Takeaway
&lt;/h2&gt;

&lt;p&gt;The significance of the Unit 42 investigation isn't just that AI was involved in an attack. It's that AI compressed a workflow that would normally require serious human effort and time into something that fit inside a single work morning. More than 50 techniques. Multiple layers of an enterprise. Credentials, repositories, CI/CD, cloud infrastructure. All inside a dramatically shorter window than defenders have historically had to work with.&lt;/p&gt;

&lt;p&gt;That's not really a story about AI being scary. It's a story about the amount of time available for detection and response getting smaller, in systems a lot of engineering teams touch every single day. The attacker doesn't need to be smarter than the SOC. It just needs to be faster, and right now, speed is the thing most security architectures aren't built for.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;What is an agentic AI attack?&lt;/strong&gt;&lt;br&gt;
An agentic AI attack is an intrusion where a threat actor uses autonomous or semi-autonomous AI agents to carry out parts of the attack, reconnaissance, credential testing, lateral movement, without manually executing each step. This lets a single human operator run an intrusion at a speed and scale that would normally require a coordinated team.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How did attackers use AI in the Unit 42 investigation?&lt;/strong&gt;&lt;br&gt;
According to Unit 42's reporting, a human threat actor used frontier AI models and attack-specific agentic frameworks to automate large parts of an enterprise intrusion, compressing over 50 MITRE ATT&amp;amp;CK techniques into under 10 hours, including mapping the environment, searching source repositories, obtaining credentials, and triggering unauthorized CI/CD activity.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why is CI/CD a target in AI-driven attacks?&lt;/strong&gt;&lt;br&gt;
CI/CD pipelines typically hold or generate credentials, deployment keys, and access to source code and cloud infrastructure, all in one place. For an automated agent searching for a fast path to privileged access, a pipeline with loosely scoped tokens or under-monitored triggers is a high-value target.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can traditional SIEM tools detect agentic AI attacks?&lt;/strong&gt;&lt;br&gt;
SIEM remains useful for centralized, cross-domain visibility, but detecting an agentic attack usually requires correlating identity, endpoint, network, and cloud signals together rather than reviewing them in separate consoles. A SIEM that only stores logs without helping connect those signals across domains will still miss the pattern.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Does AI-driven attack automation mean human analysts become less important?&lt;/strong&gt;&lt;br&gt;
No. It shifts what analysts spend time on. Routine work like triaging repetitive alerts or manually reconstructing an attack chain becomes a better fit for automation, while human judgment becomes more valuable for validating high-confidence response actions, threat hunting, and understanding business impact.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>ai</category>
      <category>devops</category>
      <category>security</category>
    </item>
    <item>
      <title>Your Network Router May Be a Blind Spot. Attackers Are Counting on It.</title>
      <dc:creator>Anurag Singh</dc:creator>
      <pubDate>Thu, 03 Sep 2026 09:30:32 +0000</pubDate>
      <link>https://dev.to/anuragseceon/your-network-router-may-be-a-blind-spot-attackers-are-counting-on-it-2doa</link>
      <guid>https://dev.to/anuragseceon/your-network-router-may-be-a-blind-spot-attackers-are-counting-on-it-2doa</guid>
      <description>&lt;p&gt;A security team can monitor endpoints.&lt;/p&gt;

&lt;p&gt;It can monitor identities.&lt;/p&gt;

&lt;p&gt;It can collect cloud logs.&lt;/p&gt;

&lt;p&gt;It can deploy EDR, XDR, SIEM and network monitoring.&lt;/p&gt;

&lt;p&gt;But what happens when the infrastructure carrying the traffic is compromised?&lt;/p&gt;

&lt;p&gt;That question became much more interesting after new research into the China-nexus threat actor known as Fire Ant.&lt;/p&gt;

&lt;p&gt;Sygnia reported that Fire Ant expanded its activity beyond VMware environments and targeted Cisco IOS XR routers, TACACS authentication infrastructure and Linux management hosts.&lt;/p&gt;

&lt;p&gt;The concerning part wasn't simply that routers were compromised.&lt;/p&gt;

&lt;p&gt;It was what attackers did &lt;strong&gt;after getting control of trusted infrastructure&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Router Wasn't Just a Router Anymore
&lt;/h2&gt;

&lt;p&gt;A compromised endpoint usually gives an attacker access to a system.&lt;/p&gt;

&lt;p&gt;A compromised router can give something much more valuable:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Perspective.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;According to Sygnia's investigation, Fire Ant used compromised routers to capture network traffic and create covert connectivity.&lt;/p&gt;

&lt;p&gt;That changes the role of the compromised device.&lt;/p&gt;

&lt;p&gt;It is no longer just another asset inside the network.&lt;/p&gt;

&lt;p&gt;It becomes a place from which the attacker can observe how the environment communicates.&lt;/p&gt;

&lt;p&gt;And that's a very different security problem.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Trust Layer Is Becoming an Attack Surface
&lt;/h2&gt;

&lt;p&gt;Most security programs focus heavily on:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Endpoints&lt;/li&gt;
&lt;li&gt;Servers&lt;/li&gt;
&lt;li&gt;Applications&lt;/li&gt;
&lt;li&gt;Cloud workloads&lt;/li&gt;
&lt;li&gt;User identities&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Network infrastructure can receive less attention because it is often treated as foundational infrastructure rather than an active security boundary.&lt;/p&gt;

&lt;p&gt;But routers, authentication servers and management hosts sit in extremely privileged positions.&lt;/p&gt;

&lt;p&gt;They help determine:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Where traffic goes&lt;/li&gt;
&lt;li&gt;Who can authenticate&lt;/li&gt;
&lt;li&gt;Which systems can communicate&lt;/li&gt;
&lt;li&gt;How administrators manage infrastructure&lt;/li&gt;
&lt;li&gt;What security telemetry gets generated&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Compromise those layers and an attacker may gain more than access.&lt;/p&gt;

&lt;p&gt;They may gain &lt;strong&gt;control over the environment's visibility and trust relationships&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  When Your Logs Can't Be Trusted
&lt;/h2&gt;

&lt;p&gt;This is one of the most interesting parts of the Fire Ant investigation.&lt;/p&gt;

&lt;p&gt;Sygnia reported that the attackers manipulated telemetry and evidence sources, including router logging and authentication-related records.&lt;/p&gt;

&lt;p&gt;That creates a difficult question for defenders:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What if the system generating your evidence has also been compromised?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Security teams often assume that logs are telling them what happened.&lt;/p&gt;

&lt;p&gt;But sophisticated attackers can attempt to modify, suppress or bypass the evidence.&lt;/p&gt;

&lt;p&gt;That means security monitoring cannot always depend on a single telemetry source.&lt;/p&gt;

&lt;h2&gt;
  
  
  One Alert May Not Tell the Story
&lt;/h2&gt;

&lt;p&gt;Imagine this:&lt;/p&gt;

&lt;p&gt;A network device shows an unusual configuration change.&lt;/p&gt;

&lt;p&gt;At roughly the same time, an administrator account authenticates in an unusual way.&lt;/p&gt;

&lt;p&gt;A management server starts communicating with an unexpected destination.&lt;/p&gt;

&lt;p&gt;Network traffic begins moving through a previously unseen path.&lt;/p&gt;

&lt;p&gt;Individually, each event may look explainable.&lt;/p&gt;

&lt;p&gt;Together, they may describe an intrusion.&lt;/p&gt;

&lt;p&gt;This is where &lt;strong&gt;cross-domain correlation&lt;/strong&gt; becomes important.&lt;/p&gt;

&lt;p&gt;The SOC needs to connect:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Network + Identity + Authentication + Endpoint + Configuration + Behavior&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;instead of investigating each alert independently.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Network Detection Needs More Context
&lt;/h2&gt;

&lt;p&gt;Network monitoring can tell you that something unusual is happening.&lt;/p&gt;

&lt;p&gt;But context tells you whether it matters.&lt;/p&gt;

&lt;p&gt;For example:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Unusual network connection&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;is one signal.&lt;/p&gt;

&lt;p&gt;But:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Unusual network connection + privileged identity + unexpected configuration change + abnormal management activity&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;is a much stronger investigation lead.&lt;/p&gt;

&lt;p&gt;The difference isn't necessarily another detection rule.&lt;/p&gt;

&lt;p&gt;It's the ability to connect the evidence.&lt;/p&gt;

&lt;h2&gt;
  
  
  The New Challenge for Security Teams
&lt;/h2&gt;

&lt;p&gt;For years, security teams have asked:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Are we collecting enough logs?”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The better question today may be:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;“Are we collecting enough independent evidence to know when one source is lying?”&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That is a very different security mindset.&lt;/p&gt;

&lt;p&gt;A resilient SOC shouldn't depend entirely on one platform, one log source or one security control.&lt;/p&gt;

&lt;p&gt;It should be able to compare signals across different parts of the environment.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where SIEM Still Matters
&lt;/h2&gt;

&lt;p&gt;This doesn't make SIEM less important.&lt;/p&gt;

&lt;p&gt;It makes centralized security analytics more important.&lt;/p&gt;

&lt;p&gt;A SIEM can provide the historical context needed to understand:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Authentication activity&lt;/li&gt;
&lt;li&gt;Network events&lt;/li&gt;
&lt;li&gt;Configuration changes&lt;/li&gt;
&lt;li&gt;System activity&lt;/li&gt;
&lt;li&gt;Privileged actions&lt;/li&gt;
&lt;li&gt;Security alerts&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;But the real value comes from what the SOC can do with that data.&lt;/p&gt;

&lt;p&gt;If every event remains isolated, analysts still have to manually connect the dots.&lt;/p&gt;

&lt;p&gt;If events are correlated across multiple security domains, an investigation can start from a much stronger position.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where XDR and NDR Add Context
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;NDR&lt;/strong&gt; can help identify unusual network behavior.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;XDR&lt;/strong&gt; can connect signals across security layers.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;UEBA&lt;/strong&gt; can help identify abnormal user and entity behavior.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;SIEM&lt;/strong&gt; provides centralized investigation and historical context.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;SOAR&lt;/strong&gt; can help automate defined response actions.&lt;/p&gt;

&lt;p&gt;The important part is not simply having all these technologies.&lt;/p&gt;

&lt;p&gt;It's whether they can work together when an attacker moves between them.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where Seceon OTM Fits
&lt;/h2&gt;

&lt;p&gt;This is one reason a unified security architecture can be useful.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Seceon OTM&lt;/strong&gt; brings together capabilities including SIEM, XDR, NDR, UEBA, SOAR, identity, cloud and other security telemetry within a unified security model.&lt;/p&gt;

&lt;p&gt;For a network-focused incident, that means the investigation doesn't have to stop at:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;“The router generated an alert.”&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The SOC can look for related activity across:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Network&lt;/li&gt;
&lt;li&gt;Identity&lt;/li&gt;
&lt;li&gt;Endpoint&lt;/li&gt;
&lt;li&gt;Cloud&lt;/li&gt;
&lt;li&gt;Authentication&lt;/li&gt;
&lt;li&gt;User behavior&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That broader context can help security teams determine whether a network anomaly is simply an operational issue or part of a larger attack path.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Blind Spot Isn't Always Where You Think
&lt;/h2&gt;

&lt;p&gt;Security teams naturally focus on the systems that attackers are known to target.&lt;/p&gt;

&lt;p&gt;But sophisticated threat actors don't always attack the final destination first.&lt;/p&gt;

&lt;p&gt;Sometimes they attack the infrastructure that provides:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;access&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;visibility&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;trust&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;or&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;connectivity.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That's why network infrastructure deserves the same security attention as endpoints and cloud workloads.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Security Teams Should Reconsider
&lt;/h2&gt;

&lt;p&gt;A modern security architecture should ask:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Are network devices continuously monitored?&lt;/li&gt;
&lt;li&gt;Are authentication systems treated as high-value assets?&lt;/li&gt;
&lt;li&gt;Can security teams detect unusual configuration changes?&lt;/li&gt;
&lt;li&gt;Are network events correlated with identity activity?&lt;/li&gt;
&lt;li&gt;Can telemetry from different sources be investigated together?&lt;/li&gt;
&lt;li&gt;What happens if one logging source is compromised?&lt;/li&gt;
&lt;li&gt;Are privileged infrastructure systems included in threat hunting?&lt;/li&gt;
&lt;li&gt;Can the SOC validate suspicious activity using independent evidence?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These questions can expose gaps that a traditional “more alerts = more visibility” approach may miss.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Bigger Lesson
&lt;/h2&gt;

&lt;p&gt;Fire Ant is a useful reminder that attackers don't always need to break through the front door.&lt;/p&gt;

&lt;p&gt;Sometimes they target the systems that control the doors.&lt;/p&gt;

&lt;p&gt;Sometimes they target the systems that authenticate the people using those doors.&lt;/p&gt;

&lt;p&gt;And sometimes they target the systems that tell defenders what happened.&lt;/p&gt;

&lt;p&gt;That means cybersecurity visibility has to go beyond endpoints and applications.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The infrastructure that connects, authenticates and observes the environment needs to be part of the security picture too.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Because if attackers control the infrastructure you trust, the biggest problem may not be that you can't detect the attack.&lt;/p&gt;

&lt;p&gt;It may be that you're looking at an incomplete version of what actually happened.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Why are attackers targeting network infrastructure?
&lt;/h3&gt;

&lt;p&gt;Network devices can provide privileged access, visibility into traffic and potential paths toward connected systems. Recent Fire Ant research showed how compromised Cisco routers were used as operational platforms for traffic collection and covert connectivity.&lt;/p&gt;

&lt;h3&gt;
  
  
  How can SIEM help detect compromised network infrastructure?
&lt;/h3&gt;

&lt;p&gt;SIEM can centralize and correlate network, authentication, configuration and other security events. This can help analysts identify relationships that may not be visible when each telemetry source is investigated separately.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can Seceon OTM monitor network and identity activity together?
&lt;/h3&gt;

&lt;p&gt;Seceon OTM is designed to bring together security telemetry across areas including network, identity, endpoint, cloud and other security domains. This allows related activity to be investigated within a broader security context.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is the role of NDR in detecting router-related attacks?
&lt;/h3&gt;

&lt;p&gt;NDR can help identify unusual communication patterns, unexpected connections and abnormal network behavior. Its value increases when network signals can be correlated with identity, endpoint and authentication activity.&lt;/p&gt;

&lt;h3&gt;
  
  
  What should organizations do if they suspect a network device is compromised?
&lt;/h3&gt;

&lt;p&gt;Organizations should preserve relevant evidence, validate configurations, review authentication activity, examine network telemetry and compare information across independent sources. A compromised device should not automatically be treated as a fully trustworthy source of forensic evidence.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is monitoring endpoints enough for modern threat detection?
&lt;/h3&gt;

&lt;p&gt;No.&lt;/p&gt;

&lt;p&gt;Endpoints remain important, but modern attacks can involve network infrastructure, identity systems, cloud services, authentication platforms and management systems.&lt;/p&gt;

&lt;p&gt;Security teams need visibility across the environment rather than focusing on one security layer.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Thought
&lt;/h2&gt;

&lt;p&gt;The most dangerous blind spot in a network isn't always an unknown vulnerability.&lt;/p&gt;

&lt;p&gt;Sometimes it's a &lt;strong&gt;trusted system nobody expected to become part of the attack.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Routers authenticate.&lt;/p&gt;

&lt;p&gt;Routers connect.&lt;/p&gt;

&lt;p&gt;Routers observe.&lt;/p&gt;

&lt;p&gt;That makes them security assets, not just networking assets.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;If the SOC doesn't have visibility into the infrastructure that connects the environment, it may be missing part of the attack story.&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>cybersecurity</category>
      <category>iot</category>
      <category>security</category>
    </item>
    <item>
      <title>AI Is Coming for Critical Infrastructure. Can Traditional SOCs Keep Up?</title>
      <dc:creator>Anurag Singh</dc:creator>
      <pubDate>Wed, 02 Sep 2026 07:05:56 +0000</pubDate>
      <link>https://dev.to/anuragseceon/ai-is-coming-for-critical-infrastructure-can-traditional-socs-keep-up-gma</link>
      <guid>https://dev.to/anuragseceon/ai-is-coming-for-critical-infrastructure-can-traditional-socs-keep-up-gma</guid>
      <description>&lt;p&gt;A power grid does not get a second chance.&lt;/p&gt;

&lt;p&gt;A water utility cannot simply “reset” its environment.&lt;/p&gt;

&lt;p&gt;A manufacturing plant cannot treat an OT incident like another endpoint alert.&lt;/p&gt;

&lt;p&gt;That is what makes the current shift in cyberattacks so important.&lt;/p&gt;

&lt;p&gt;Attackers are increasingly using AI to accelerate reconnaissance, identify weaknesses and automate parts of the attack lifecycle.&lt;/p&gt;

&lt;p&gt;Recent reporting has highlighted AI-enhanced attacks against interconnected energy systems, including operational technology environments.&lt;/p&gt;

&lt;p&gt;The question is no longer whether AI will be used in cyberattacks.&lt;/p&gt;

&lt;p&gt;It is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can security operations detect and respond at the same speed?&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The Critical Infrastructure Attack Surface Has Changed
&lt;/h2&gt;

&lt;p&gt;Critical infrastructure used to look relatively isolated.&lt;/p&gt;

&lt;p&gt;Today, that picture is very different.&lt;/p&gt;

&lt;p&gt;Power generation, utilities, manufacturing, transportation and other industrial environments increasingly connect:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;IT networks&lt;/li&gt;
&lt;li&gt;OT networks&lt;/li&gt;
&lt;li&gt;Cloud services&lt;/li&gt;
&lt;li&gt;Remote access systems&lt;/li&gt;
&lt;li&gt;Identity platforms&lt;/li&gt;
&lt;li&gt;IoT devices&lt;/li&gt;
&lt;li&gt;Third-party systems&lt;/li&gt;
&lt;li&gt;Industrial control systems&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That connectivity creates operational advantages.&lt;/p&gt;

&lt;p&gt;It also creates more paths into environments where a cyber incident can eventually become a physical or business disruption.&lt;/p&gt;

&lt;p&gt;And attackers understand this.&lt;/p&gt;

&lt;h2&gt;
  
  
  AI Is Reducing the Time Between Discovery and Exploitation
&lt;/h2&gt;

&lt;p&gt;AI doesn't necessarily need to invent an entirely new attack technique.&lt;/p&gt;

&lt;p&gt;It can make existing techniques faster.&lt;/p&gt;

&lt;p&gt;AI can help attackers:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Analyze large amounts of technical information&lt;/li&gt;
&lt;li&gt;Identify potentially vulnerable systems&lt;/li&gt;
&lt;li&gt;Automate reconnaissance&lt;/li&gt;
&lt;li&gt;Generate or modify attack code&lt;/li&gt;
&lt;li&gt;Improve social engineering&lt;/li&gt;
&lt;li&gt;Find weaknesses across connected environments&lt;/li&gt;
&lt;li&gt;Adapt attacks based on discovered information&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That changes the defender's problem.&lt;/p&gt;

&lt;p&gt;The issue isn't simply:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;“Can we detect the attack?”&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;It's:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;“Can we understand what is happening before the attacker moves to the next system?”&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  OT Security Makes This Even Harder
&lt;/h2&gt;

&lt;p&gt;Traditional IT security often assumes that an affected machine can be isolated.&lt;/p&gt;

&lt;p&gt;OT environments have different constraints.&lt;/p&gt;

&lt;p&gt;A security team may be dealing with:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Legacy systems&lt;/li&gt;
&lt;li&gt;PLCs&lt;/li&gt;
&lt;li&gt;Industrial protocols&lt;/li&gt;
&lt;li&gt;Long equipment lifecycles&lt;/li&gt;
&lt;li&gt;Limited patch windows&lt;/li&gt;
&lt;li&gt;Remote operational access&lt;/li&gt;
&lt;li&gt;Safety requirements&lt;/li&gt;
&lt;li&gt;Systems that cannot simply be taken offline&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This creates a major SOC challenge.&lt;/p&gt;

&lt;p&gt;An alert on an endpoint might look harmless by itself.&lt;/p&gt;

&lt;p&gt;But combine it with:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;identity activity + network behavior + unusual OT communication + endpoint telemetry&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;and the situation can look very different.&lt;/p&gt;

&lt;p&gt;That's where correlation becomes more important than simply collecting more alerts.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Problem Isn't a Lack of Security Data
&lt;/h2&gt;

&lt;p&gt;Most modern organizations already generate enormous amounts of telemetry.&lt;/p&gt;

&lt;p&gt;The problem is that the data often lives in different places.&lt;/p&gt;

&lt;p&gt;One system sees the endpoint.&lt;/p&gt;

&lt;p&gt;Another sees network traffic.&lt;/p&gt;

&lt;p&gt;Another sees identity.&lt;/p&gt;

&lt;p&gt;Another monitors cloud activity.&lt;/p&gt;

&lt;p&gt;Another protects OT.&lt;/p&gt;

&lt;p&gt;Another generates vulnerability alerts.&lt;/p&gt;

&lt;p&gt;The SOC analyst is then expected to connect the dots.&lt;/p&gt;

&lt;p&gt;That model becomes increasingly difficult when attackers are moving faster.&lt;/p&gt;

&lt;h3&gt;
  
  
  Detection without context creates noise.
&lt;/h3&gt;

&lt;h3&gt;
  
  
  Context without automation creates delay.
&lt;/h3&gt;

&lt;h3&gt;
  
  
  Automation without correlation creates risk.
&lt;/h3&gt;

&lt;p&gt;A modern security operation needs all three:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Context + Correlation + Controlled Automation&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What an AI-Driven SOC Should Actually Do
&lt;/h2&gt;

&lt;p&gt;An AI SOC should not simply generate more AI-generated alerts.&lt;/p&gt;

&lt;p&gt;That would make the problem worse.&lt;/p&gt;

&lt;p&gt;Instead, AI should help security teams move through the investigation lifecycle faster.&lt;/p&gt;

&lt;p&gt;A modern architecture should be able to:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Collect&lt;/strong&gt; telemetry across IT, OT, identity, cloud, endpoint and network environments.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Normalize&lt;/strong&gt; the data so different security signals can be understood together.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Correlate&lt;/strong&gt; seemingly unrelated events into meaningful attack patterns.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Establish behavioral baselines&lt;/strong&gt; to identify activity that doesn't fit normal behavior.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Investigate automatically&lt;/strong&gt; before sending every event to an analyst.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Prioritize incidents&lt;/strong&gt; based on risk and context rather than alert volume.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Respond within defined guardrails&lt;/strong&gt; when automated action is appropriate.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Keep humans in control&lt;/strong&gt; for decisions that require judgment, safety or business context.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;This is a fundamentally different operating model from simply adding another detection tool.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why SIEM Alone Isn't Enough
&lt;/h2&gt;

&lt;p&gt;SIEM remains important because security teams need centralized visibility and historical context.&lt;/p&gt;

&lt;p&gt;But modern environments require more than log collection.&lt;/p&gt;

&lt;p&gt;Consider a hypothetical incident:&lt;/p&gt;

&lt;p&gt;An employee account suddenly authenticates from an unusual location.&lt;/p&gt;

&lt;p&gt;A few minutes later, an endpoint starts communicating with an unfamiliar internal host.&lt;/p&gt;

&lt;p&gt;Network telemetry shows unusual traffic toward an OT segment.&lt;/p&gt;

&lt;p&gt;An industrial device then begins communicating in a pattern that hasn't appeared before.&lt;/p&gt;

&lt;p&gt;Looking at those events individually could produce several unrelated alerts.&lt;/p&gt;

&lt;p&gt;Looking at them together could reveal a developing intrusion.&lt;/p&gt;

&lt;p&gt;That is the difference between:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;alert management&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;and&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;threat detection.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Where XDR, UEBA and SOAR Fit
&lt;/h2&gt;

&lt;p&gt;This is where the modern SOC architecture becomes important.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;SIEM&lt;/strong&gt; provides centralized security data and investigation context.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;XDR&lt;/strong&gt; helps connect security signals across multiple control points.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;UEBA&lt;/strong&gt; helps identify unusual behavior involving users, entities and systems.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;NDR&lt;/strong&gt; provides visibility into network behavior.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;OT security&lt;/strong&gt; brings industrial environments into the security picture.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;SOAR&lt;/strong&gt; enables controlled response automation.&lt;/p&gt;

&lt;p&gt;The real value comes when these capabilities aren't operating as completely disconnected islands.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where Seceon OTM Fits
&lt;/h2&gt;

&lt;p&gt;This is also where &lt;strong&gt;Seceon OTM&lt;/strong&gt; fits into the broader AI SOC discussion.&lt;/p&gt;

&lt;p&gt;Seceon OTM is designed around a unified security architecture that brings together capabilities including &lt;strong&gt;SIEM, XDR, SOAR, NDR, UEBA, ITDR, cloud and OT security&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The important idea isn't simply having all of those product names.&lt;/p&gt;

&lt;p&gt;It is having the telemetry and security context available together so the SOC can investigate relationships between events.&lt;/p&gt;

&lt;p&gt;For a critical infrastructure environment, that matters because an identity event, endpoint event, network event and OT event may all be pieces of the same attack.&lt;/p&gt;

&lt;p&gt;Instead of asking:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;“Which tool generated this alert?”&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;the SOC can ask:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;“What is actually happening across the environment?”&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That is a much more useful question.&lt;/p&gt;

&lt;h2&gt;
  
  
  The New SOC Metric: Time to Understand
&lt;/h2&gt;

&lt;p&gt;Security teams have traditionally focused on metrics such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;MTTD&lt;/li&gt;
&lt;li&gt;MTTR&lt;/li&gt;
&lt;li&gt;Alert volume&lt;/li&gt;
&lt;li&gt;False-positive rate&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Those metrics still matter.&lt;/p&gt;

&lt;p&gt;But AI-driven attacks introduce another important question:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How long does it take the SOC to understand the attack?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Because detecting five separate alerts in five minutes isn't necessarily good detection.&lt;/p&gt;

&lt;p&gt;If analysts need another two hours to understand that those alerts belong to one attack chain, the organization is still operating slowly.&lt;/p&gt;

&lt;p&gt;The future SOC needs to reduce the distance between:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Event → Context → Investigation → Decision → Response&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What Security Teams Should Look for in an AI SOC
&lt;/h2&gt;

&lt;p&gt;If you're evaluating an AI-driven SOC platform, don't just ask:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;“Does it use AI?”&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Ask:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Can it correlate identity, endpoint, network, cloud and OT activity?&lt;/li&gt;
&lt;li&gt;Can it reduce repetitive L1 investigation?&lt;/li&gt;
&lt;li&gt;Can it establish behavioral baselines?&lt;/li&gt;
&lt;li&gt;Can it automatically investigate related events?&lt;/li&gt;
&lt;li&gt;Can analysts understand why an incident was prioritized?&lt;/li&gt;
&lt;li&gt;Can response actions operate within defined guardrails?&lt;/li&gt;
&lt;li&gt;Can it support hybrid and on-prem environments?&lt;/li&gt;
&lt;li&gt;Can it handle multi-tenant environments for MSSPs?&lt;/li&gt;
&lt;li&gt;Can it reduce dependence on multiple disconnected security tools?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Those questions are much more useful than simply comparing AI features on a datasheet.&lt;/p&gt;

&lt;h2&gt;
  
  
  Critical Infrastructure Doesn't Need More Noise
&lt;/h2&gt;

&lt;p&gt;The cybersecurity industry has spent years adding more sensors.&lt;/p&gt;

&lt;p&gt;The next challenge is making those sensors work together.&lt;/p&gt;

&lt;p&gt;As attackers use AI to accelerate reconnaissance and exploitation, defenders need to shorten the time between an abnormal event and a meaningful security decision.&lt;/p&gt;

&lt;p&gt;For IT environments, that can mean faster incident response.&lt;/p&gt;

&lt;p&gt;For OT and critical infrastructure, it can mean something much more important:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;preventing a cyber event from becoming an operational event.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The future of critical infrastructure security won't be defined by who has the most alerts.&lt;/p&gt;

&lt;p&gt;It will be defined by who can &lt;strong&gt;understand, prioritize and respond to the right signals fastest.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;And that is where the AI SOC becomes much more than another security product.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  How is Seceon OTM helping organizations build an AI SOC?
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;Seceon OTM&lt;/strong&gt; brings together capabilities such as SIEM, XDR, SOAR, NDR, UEBA, ITDR, cloud and OT security in a unified security architecture.&lt;/p&gt;

&lt;p&gt;The goal is to give security teams broader context across their environment so related identity, endpoint, network, cloud and OT signals can be correlated during an investigation.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is the difference between Seceon OTM and a traditional SIEM?
&lt;/h3&gt;

&lt;p&gt;A traditional SIEM primarily focuses on collecting, storing and analyzing security data.&lt;/p&gt;

&lt;p&gt;Seceon OTM extends that model by combining SIEM with capabilities such as XDR, SOAR, NDR and UEBA, allowing organizations to move from simply collecting alerts toward correlation, investigation and automated response.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can Seceon OTM support OT and critical infrastructure security?
&lt;/h3&gt;

&lt;p&gt;Yes. Seceon OTM includes OT security capabilities alongside IT, network, endpoint, identity and cloud visibility.&lt;/p&gt;

&lt;p&gt;This is particularly useful when organizations need to understand relationships between activity across IT and OT environments.&lt;/p&gt;

&lt;h3&gt;
  
  
  How does AI help reduce SOC alert fatigue?
&lt;/h3&gt;

&lt;p&gt;AI can help correlate related events, establish behavioral baselines, investigate routine alerts and prioritize incidents based on context.&lt;/p&gt;

&lt;p&gt;The objective isn't to create more automated alerts.&lt;/p&gt;

&lt;p&gt;It is to reduce the number of alerts that analysts have to investigate manually.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does an AI SOC replace security analysts?
&lt;/h3&gt;

&lt;p&gt;No.&lt;/p&gt;

&lt;p&gt;The strongest AI SOC model keeps humans involved for decisions that require judgment, governance, safety considerations and business context.&lt;/p&gt;

&lt;p&gt;AI should remove repetitive investigation work so analysts can spend more time on complex threats and strategic security decisions.&lt;/p&gt;

&lt;h3&gt;
  
  
  What should organizations look for in an AI SOC platform?
&lt;/h3&gt;

&lt;p&gt;Organizations should look beyond the “AI-powered” label.&lt;/p&gt;

&lt;p&gt;Important capabilities include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Cross-domain telemetry correlation&lt;/li&gt;
&lt;li&gt;Behavioral analytics&lt;/li&gt;
&lt;li&gt;Automated investigation&lt;/li&gt;
&lt;li&gt;Threat prioritization&lt;/li&gt;
&lt;li&gt;Controlled response automation&lt;/li&gt;
&lt;li&gt;IT and OT visibility&lt;/li&gt;
&lt;li&gt;Identity and endpoint context&lt;/li&gt;
&lt;li&gt;Hybrid and on-prem deployment options&lt;/li&gt;
&lt;li&gt;Reduced dependence on disconnected security tools&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Final Thought
&lt;/h2&gt;

&lt;p&gt;AI is changing the economics and speed of cyberattacks.&lt;/p&gt;

&lt;p&gt;Critical infrastructure cannot afford to respond at yesterday's speed.&lt;/p&gt;

&lt;p&gt;The answer isn't necessarily another security tool.&lt;/p&gt;

&lt;p&gt;It is a security operation that can connect the signals, understand the attack and act quickly without removing humans from the decision-making process.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The faster attackers can connect the dots, the faster defenders need to do the same.&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>ai</category>
      <category>iot</category>
      <category>security</category>
    </item>
    <item>
      <title>AI Agents Have Identities Too: Why Non-Human Identity Security Is Becoming a SOC Problem</title>
      <dc:creator>Anurag Singh</dc:creator>
      <pubDate>Tue, 01 Sep 2026 09:09:05 +0000</pubDate>
      <link>https://dev.to/anuragseceon/ai-agents-have-identities-too-why-non-human-identity-security-is-becoming-a-soc-problem-341k</link>
      <guid>https://dev.to/anuragseceon/ai-agents-have-identities-too-why-non-human-identity-security-is-becoming-a-soc-problem-341k</guid>
      <description>&lt;p&gt;Your security team knows how many employees have access to your systems.&lt;/p&gt;

&lt;p&gt;But do you know how many AI agents, service accounts, API keys, and automated workflows have access?&lt;/p&gt;

&lt;p&gt;That's becoming a much harder question in 2026.&lt;/p&gt;

&lt;p&gt;Organizations are rapidly adopting AI agents to automate everything from software development and customer support to data analysis and security operations.&lt;/p&gt;

&lt;p&gt;These agents don't just generate text.&lt;/p&gt;

&lt;p&gt;They authenticate.&lt;/p&gt;

&lt;p&gt;They access applications.&lt;/p&gt;

&lt;p&gt;They call APIs.&lt;/p&gt;

&lt;p&gt;They retrieve data.&lt;/p&gt;

&lt;p&gt;They execute workflows.&lt;/p&gt;

&lt;p&gt;And increasingly, they make decisions and take actions without a human sitting in front of every transaction.&lt;/p&gt;

&lt;p&gt;That creates a new cybersecurity challenge:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;AI agents need identities too.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;And those identities need to be secured.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Identity Problem Is Getting Bigger
&lt;/h2&gt;

&lt;p&gt;For years, identity security focused primarily on human users.&lt;/p&gt;

&lt;p&gt;Employees had accounts.&lt;/p&gt;

&lt;p&gt;Administrators had privileged accounts.&lt;/p&gt;

&lt;p&gt;Contractors had temporary access.&lt;/p&gt;

&lt;p&gt;Security teams built policies around those identities.&lt;/p&gt;

&lt;p&gt;Now add:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;AI agents&lt;/li&gt;
&lt;li&gt;Service accounts&lt;/li&gt;
&lt;li&gt;API keys&lt;/li&gt;
&lt;li&gt;Machine identities&lt;/li&gt;
&lt;li&gt;Bots&lt;/li&gt;
&lt;li&gt;Automated workflows&lt;/li&gt;
&lt;li&gt;Cloud workloads&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The number of identities inside an organization can grow far beyond its number of employees.&lt;/p&gt;

&lt;p&gt;And unlike humans, these identities can operate 24/7.&lt;/p&gt;

&lt;p&gt;That's where the risk becomes interesting.&lt;/p&gt;

&lt;p&gt;An employee might access an application a few times during the day.&lt;/p&gt;

&lt;p&gt;An automated agent might make thousands of API calls while nobody is watching.&lt;/p&gt;

&lt;p&gt;So the question becomes:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How do you know when an AI agent is behaving abnormally?&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What Happens When an AI Agent Gets Too Much Access?
&lt;/h2&gt;

&lt;p&gt;Imagine an organization deploys an AI agent to help developers.&lt;/p&gt;

&lt;p&gt;The agent has access to:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;GitHub → Cloud APIs → CI/CD → Internal Documentation → Databases&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Everything works normally for months.&lt;/p&gt;

&lt;p&gt;Then something changes.&lt;/p&gt;

&lt;p&gt;The agent suddenly starts:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Accessing repositories it never used before&lt;/li&gt;
&lt;li&gt;Calling unfamiliar APIs&lt;/li&gt;
&lt;li&gt;Requesting elevated permissions&lt;/li&gt;
&lt;li&gt;Downloading unusual amounts of data&lt;/li&gt;
&lt;li&gt;Communicating with an external service&lt;/li&gt;
&lt;li&gt;Triggering workflows outside its normal pattern&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of these events necessarily means the agent has been compromised.&lt;/p&gt;

&lt;p&gt;But together, they should raise a question:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is this normal behavior for this identity?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That's where traditional identity monitoring starts becoming insufficient.&lt;/p&gt;

&lt;h2&gt;
  
  
  The New Security Question: What Is the Identity Doing?
&lt;/h2&gt;

&lt;p&gt;Authentication tells you &lt;strong&gt;who or what&lt;/strong&gt; accessed a resource.&lt;/p&gt;

&lt;p&gt;Authorization tells you &lt;strong&gt;what it is allowed to access&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;But security operations also need to understand:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is it actually doing?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That's where behavioral analytics becomes important.&lt;/p&gt;

&lt;p&gt;Consider two scenarios.&lt;/p&gt;

&lt;h3&gt;
  
  
  Scenario 1
&lt;/h3&gt;

&lt;p&gt;An AI agent accesses the same API it uses every day.&lt;/p&gt;

&lt;p&gt;The request volume is normal.&lt;/p&gt;

&lt;p&gt;The destination is expected.&lt;/p&gt;

&lt;p&gt;The action matches its assigned workflow.&lt;/p&gt;

&lt;p&gt;Probably normal.&lt;/p&gt;

&lt;h3&gt;
  
  
  Scenario 2
&lt;/h3&gt;

&lt;p&gt;The same agent suddenly accesses a sensitive database, requests elevated privileges, and sends data to an unfamiliar external endpoint.&lt;/p&gt;

&lt;p&gt;The credentials may still be valid.&lt;/p&gt;

&lt;p&gt;The authentication may still be legitimate.&lt;/p&gt;

&lt;p&gt;But the behavior is unusual.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;That's a security signal.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Traditional SIEM Visibility Isn't Always Enough
&lt;/h2&gt;

&lt;p&gt;A SIEM can collect identity events.&lt;/p&gt;

&lt;p&gt;It can collect API logs.&lt;/p&gt;

&lt;p&gt;It can collect endpoint telemetry.&lt;/p&gt;

&lt;p&gt;It can collect cloud activity.&lt;/p&gt;

&lt;p&gt;It can collect network events.&lt;/p&gt;

&lt;p&gt;But collecting everything doesn't automatically mean you understand what's happening.&lt;/p&gt;

&lt;p&gt;The real value comes from connecting those signals.&lt;/p&gt;

&lt;p&gt;For example:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;AI agent authentication&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Privilege change&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Unusual API activity&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Endpoint anomaly&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Suspicious network connection&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Sensitive data access&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Individually, each event might look manageable.&lt;/p&gt;

&lt;p&gt;Together, they could represent an attack chain.&lt;/p&gt;

&lt;p&gt;This is why modern security operations increasingly need &lt;strong&gt;SIEM + XDR + UEBA + threat intelligence + automated response&lt;/strong&gt; working together.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where UEBA Fits
&lt;/h2&gt;

&lt;p&gt;UEBA stands for &lt;strong&gt;User and Entity Behavior Analytics&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;And the word "entity" matters.&lt;/p&gt;

&lt;p&gt;Because the entity doesn't always have to be a human.&lt;/p&gt;

&lt;p&gt;It could be:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A user&lt;/li&gt;
&lt;li&gt;A service account&lt;/li&gt;
&lt;li&gt;An API key&lt;/li&gt;
&lt;li&gt;A device&lt;/li&gt;
&lt;li&gt;A workload&lt;/li&gt;
&lt;li&gt;An AI agent&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;UEBA can help establish behavioral patterns and identify activity that deviates from those patterns.&lt;/p&gt;

&lt;p&gt;For an AI agent, that could mean understanding:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Which applications does it normally access?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Which APIs does it normally call?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How frequently does it operate?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Which resources does it normally touch?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What does its normal behavior look like?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Once you understand the baseline, abnormal behavior becomes easier to identify.&lt;/p&gt;

&lt;h2&gt;
  
  
  This Is Where Identity Security Meets XDR
&lt;/h2&gt;

&lt;p&gt;Identity security shouldn't exist in a separate security universe.&lt;/p&gt;

&lt;p&gt;Suppose an AI agent suddenly behaves abnormally.&lt;/p&gt;

&lt;p&gt;The next question isn't just:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"Is the identity suspicious?"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;It's:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"What else is happening around it?"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Maybe the endpoint associated with the workflow is communicating with a suspicious destination.&lt;/p&gt;

&lt;p&gt;Maybe another identity was compromised.&lt;/p&gt;

&lt;p&gt;Maybe a privilege escalation happened immediately before the unusual API calls.&lt;/p&gt;

&lt;p&gt;Maybe threat intelligence identifies the destination as malicious.&lt;/p&gt;

&lt;p&gt;Now identity activity becomes part of a much larger investigation.&lt;/p&gt;

&lt;p&gt;This is where &lt;strong&gt;XDR&lt;/strong&gt; can provide additional context by connecting signals across different security layers.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where Seceon OTM Fits
&lt;/h2&gt;

&lt;p&gt;This is one of the reasons Seceon's &lt;strong&gt;Open Threat Management (OTM) Platform&lt;/strong&gt; is relevant to this changing security model.&lt;/p&gt;

&lt;p&gt;OTM brings together capabilities including:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;SIEM + XDR + SOAR + UEBA + Threat Intelligence + Threat Hunting&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;within a unified security operations platform.&lt;/p&gt;

&lt;p&gt;Instead of treating identity, endpoint, network, cloud and application activity as completely separate investigations, OTM is designed to correlate those signals and provide broader context.&lt;/p&gt;

&lt;p&gt;For example:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Identity anomaly&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;UEBA detects abnormal behavior&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;XDR correlates endpoint and network activity&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Threat intelligence adds context&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;SIEM provides the event history&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;SOAR can automate an appropriate response&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The goal isn't simply to detect that an AI agent did something unusual.&lt;/p&gt;

&lt;p&gt;The goal is to understand:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What happened → why it matters → what else is connected → what should happen next&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That's a much more useful security question.&lt;/p&gt;

&lt;h2&gt;
  
  
  AI Agents Are Also Creating a New Access-Control Problem
&lt;/h2&gt;

&lt;p&gt;There's another issue that security teams shouldn't ignore.&lt;/p&gt;

&lt;p&gt;AI agents need permissions.&lt;/p&gt;

&lt;p&gt;And permissions can accumulate.&lt;/p&gt;

&lt;p&gt;An agent might start with access to one application.&lt;/p&gt;

&lt;p&gt;Then someone adds another integration.&lt;/p&gt;

&lt;p&gt;Then another API.&lt;/p&gt;

&lt;p&gt;Then another workflow.&lt;/p&gt;

&lt;p&gt;Six months later, nobody remembers exactly why the agent has access to everything it can reach.&lt;/p&gt;

&lt;p&gt;This is the same problem security teams have dealt with for years with human identities:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Excessive privileges.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The difference is that automated identities can operate much faster.&lt;/p&gt;

&lt;p&gt;If an overprivileged human account is compromised, the attacker may have access to sensitive resources.&lt;/p&gt;

&lt;p&gt;If an overprivileged AI agent is compromised or manipulated, it may be capable of taking automated actions across multiple systems.&lt;/p&gt;

&lt;p&gt;That's why &lt;strong&gt;AI agent identity governance&lt;/strong&gt; is becoming an important part of cybersecurity.&lt;/p&gt;

&lt;h2&gt;
  
  
  Security Teams Need an Inventory of Non-Human Identities
&lt;/h2&gt;

&lt;p&gt;You can't protect what you don't know exists.&lt;/p&gt;

&lt;p&gt;A practical starting point is building visibility into:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who has access?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What applications are they connected to?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What credentials do they use?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What permissions do they have?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;When were those permissions last reviewed?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What does normal behavior look like?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;And for AI agents:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What actions are they actually capable of taking?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This isn't just an IAM problem anymore.&lt;/p&gt;

&lt;p&gt;It's becoming part of security operations.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Should Security Teams Monitor?
&lt;/h2&gt;

&lt;p&gt;If your organization is deploying AI agents, consider monitoring:&lt;/p&gt;

&lt;h3&gt;
  
  
  1. Agent Identity
&lt;/h3&gt;

&lt;p&gt;Know which AI agents exist and which credentials they use.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Permissions
&lt;/h3&gt;

&lt;p&gt;Understand what resources each agent can access.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. API Activity
&lt;/h3&gt;

&lt;p&gt;Monitor unusual API calls, destinations, and request patterns.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Behavioral Changes
&lt;/h3&gt;

&lt;p&gt;Identify activity that differs significantly from the established baseline.&lt;/p&gt;

&lt;h3&gt;
  
  
  5. Privilege Escalation
&lt;/h3&gt;

&lt;p&gt;Watch for unexpected changes in permissions.&lt;/p&gt;

&lt;h3&gt;
  
  
  6. Data Access
&lt;/h3&gt;

&lt;p&gt;Monitor unusual access to sensitive information.&lt;/p&gt;

&lt;h3&gt;
  
  
  7. Network Activity
&lt;/h3&gt;

&lt;p&gt;Correlate agent behavior with network connections and endpoint activity.&lt;/p&gt;

&lt;h3&gt;
  
  
  8. Response Actions
&lt;/h3&gt;

&lt;p&gt;Have clear policies for what should happen when an agent behaves abnormally.&lt;/p&gt;

&lt;h2&gt;
  
  
  The MSSP Challenge Is Even Bigger
&lt;/h2&gt;

&lt;p&gt;For an MSSP, this problem scales quickly.&lt;/p&gt;

&lt;p&gt;One customer may have a handful of AI agents.&lt;/p&gt;

&lt;p&gt;Another may have hundreds of automated identities.&lt;/p&gt;

&lt;p&gt;Another may be running thousands of service accounts and API integrations.&lt;/p&gt;

&lt;p&gt;Now imagine monitoring all of that across dozens of customers.&lt;/p&gt;

&lt;p&gt;The MSSP needs to understand:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Which identity belongs to which customer?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is this behavior normal for that customer?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is the same attack pattern appearing across multiple environments?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Which incident should be investigated first?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This is where centralized, multi-tenant security operations become increasingly important.&lt;/p&gt;

&lt;p&gt;A platform such as &lt;strong&gt;Seceon OTM&lt;/strong&gt; can help MSSPs bring identity, endpoint, network, cloud and application security signals into a unified operational workflow.&lt;/p&gt;

&lt;p&gt;The objective isn't simply to monitor more identities.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;It's to make those identities understandable at security-operations scale.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The AI Agent Security Checklist
&lt;/h2&gt;

&lt;p&gt;Before deploying an AI agent into a production environment, security teams should be able to answer:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;What identity does the agent use?&lt;/li&gt;
&lt;li&gt;What permissions does it have?&lt;/li&gt;
&lt;li&gt;Which applications can it access?&lt;/li&gt;
&lt;li&gt;Which APIs can it call?&lt;/li&gt;
&lt;li&gt;What data can it retrieve?&lt;/li&gt;
&lt;li&gt;Can it create or modify resources?&lt;/li&gt;
&lt;li&gt;Can it escalate its privileges?&lt;/li&gt;
&lt;li&gt;How is its behavior monitored?&lt;/li&gt;
&lt;li&gt;What happens if its behavior becomes abnormal?&lt;/li&gt;
&lt;li&gt;How quickly can its credentials or access be revoked?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If those questions don't have clear answers, the agent may already represent an unmanaged attack surface.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Bigger Shift in Identity Security
&lt;/h2&gt;

&lt;p&gt;The traditional identity model was built around:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;People → Accounts → Applications&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The modern environment looks more like:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;People + AI Agents + Service Accounts + APIs + Workloads → Applications + Data + Infrastructure&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That's a much bigger identity ecosystem.&lt;/p&gt;

&lt;p&gt;And security operations need visibility across all of it.&lt;/p&gt;

&lt;p&gt;AI agents aren't going away.&lt;/p&gt;

&lt;p&gt;Neither are automation, APIs, cloud workloads, or machine identities.&lt;/p&gt;

&lt;p&gt;The organizations that adapt early will be the ones that treat these identities as &lt;strong&gt;first-class security entities&lt;/strong&gt;, rather than invisible infrastructure.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ: AI Agent Identity Security
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What is non-human identity security?
&lt;/h3&gt;

&lt;p&gt;Non-human identity security focuses on protecting machine identities such as service accounts, API keys, workloads, bots, and AI agents that authenticate and access organizational resources.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why do AI agents need identity security?
&lt;/h3&gt;

&lt;p&gt;AI agents often require credentials and permissions to access applications, APIs, data, and infrastructure. If those identities are compromised, overprivileged, or misused, the agent could potentially perform unauthorized actions.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is AI agent identity governance?
&lt;/h3&gt;

&lt;p&gt;AI agent identity governance involves managing an agent's identity, credentials, permissions, access lifecycle, and authorized actions throughout its operational lifetime.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can UEBA monitor AI agents?
&lt;/h3&gt;

&lt;p&gt;UEBA can analyze behavior from users and other entities. In environments where AI agents and automated identities generate telemetry, behavioral analytics can help identify activity that deviates from established patterns.&lt;/p&gt;

&lt;h3&gt;
  
  
  How can SIEM and XDR help with AI agent security?
&lt;/h3&gt;

&lt;p&gt;SIEM can centralize identity, cloud, application, endpoint, and network events. XDR can help correlate related signals across security layers, giving analysts broader context when investigating suspicious activity.&lt;/p&gt;

&lt;h3&gt;
  
  
  How does Seceon OTM address this problem?
&lt;/h3&gt;

&lt;p&gt;Seceon OTM combines &lt;strong&gt;SIEM, XDR, SOAR, UEBA, threat intelligence, and threat hunting&lt;/strong&gt; in a unified security operations platform. This allows security teams to correlate identity behavior with endpoint, network, cloud, and other security telemetry.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is AI agent security important for MSSPs?
&lt;/h3&gt;

&lt;p&gt;Yes. MSSPs managing multiple customer environments need visibility into human and non-human identities across different organizations. Centralized and multi-tenant security operations can help make that monitoring more scalable.&lt;/p&gt;

&lt;h2&gt;
  
  
  The New Identity Perimeter
&lt;/h2&gt;

&lt;p&gt;The identity perimeter is no longer just about employees.&lt;/p&gt;

&lt;p&gt;It includes everything that can authenticate and take action.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Users.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Service accounts.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;API keys.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Workloads.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;AI agents.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;And the security question is evolving with it.&lt;/p&gt;

&lt;p&gt;It's no longer enough to ask:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"Who logged in?"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;We need to ask:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"What identity is acting, what is it allowed to do, and does its behavior make sense?"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That's where identity security, UEBA, SIEM, XDR and automated response start coming together.&lt;/p&gt;

&lt;p&gt;And as AI agents become more common, that combination may become less of an advanced capability and more of a baseline requirement.&lt;/p&gt;

&lt;p&gt;AI agents are becoming part of the workforce.&lt;/p&gt;

&lt;p&gt;Their identities need to become part of the security model too.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>cybersecurity</category>
      <category>cloud</category>
      <category>identitysecurity</category>
    </item>
    <item>
      <title>MFA Is Enabled. So Why Are Attackers Still Getting In?</title>
      <dc:creator>Anurag Singh</dc:creator>
      <pubDate>Mon, 31 Aug 2026 08:52:29 +0000</pubDate>
      <link>https://dev.to/anuragseceon/mfa-is-enabled-so-why-are-attackers-still-getting-in-7cn</link>
      <guid>https://dev.to/anuragseceon/mfa-is-enabled-so-why-are-attackers-still-getting-in-7cn</guid>
      <description>&lt;p&gt;&lt;strong&gt;Your organization has MFA. Your users have strong passwords. Conditional access is enabled. So how is an attacker still getting into the account?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This is one of the uncomfortable questions security teams are facing in 2026.&lt;/p&gt;

&lt;p&gt;The problem is that attackers don't always need to defeat MFA.&lt;/p&gt;

&lt;p&gt;Sometimes, they simply go around it.&lt;/p&gt;

&lt;p&gt;Recent attacks against Microsoft 365 environments have included device-code phishing, session-token theft, password spraying and other techniques designed to obtain authenticated access even when MFA is enabled.&lt;/p&gt;

&lt;p&gt;And that changes the identity security conversation.&lt;/p&gt;

&lt;p&gt;The question is no longer:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"Do we have MFA?"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;It is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"What happens after authentication succeeds?"&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  MFA Protects the Login. What Protects the Session?
&lt;/h2&gt;

&lt;p&gt;Think about what happens when you sign into a SaaS application.&lt;/p&gt;

&lt;p&gt;You enter your credentials.&lt;/p&gt;

&lt;p&gt;You complete MFA.&lt;/p&gt;

&lt;p&gt;The application verifies you.&lt;/p&gt;

&lt;p&gt;Then it gives your browser a session token.&lt;/p&gt;

&lt;p&gt;From that point forward, the application often uses that session to recognize you.&lt;/p&gt;

&lt;p&gt;That's convenient.&lt;/p&gt;

&lt;p&gt;But it also creates another security problem.&lt;/p&gt;

&lt;p&gt;If an attacker obtains that authenticated session, they may not need your password or another MFA challenge to continue operating as you.&lt;/p&gt;

&lt;p&gt;The attacker isn't necessarily breaking MFA.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;They're stealing the proof that MFA already happened.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This is why session-token theft and session hijacking have become important identity-security concerns.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Attack Doesn't Always Look Like a Login Attack
&lt;/h2&gt;

&lt;p&gt;Imagine this.&lt;/p&gt;

&lt;p&gt;An employee signs into Microsoft 365 normally.&lt;/p&gt;

&lt;p&gt;MFA succeeds.&lt;/p&gt;

&lt;p&gt;Nothing looks suspicious.&lt;/p&gt;

&lt;p&gt;A few minutes later, an attacker starts using a stolen session.&lt;/p&gt;

&lt;p&gt;Now the security team sees:&lt;/p&gt;

&lt;p&gt;An authenticated user accessing a SaaS application.&lt;/p&gt;

&lt;p&gt;A new device or unusual location.&lt;/p&gt;

&lt;p&gt;Unusual mailbox activity.&lt;/p&gt;

&lt;p&gt;A privileged resource being accessed.&lt;/p&gt;

&lt;p&gt;Large amounts of data being downloaded.&lt;/p&gt;

&lt;p&gt;Suspicious communication from an endpoint associated with the account.&lt;/p&gt;

&lt;p&gt;Individually, some of these events may not trigger a high-confidence incident.&lt;/p&gt;

&lt;p&gt;Together, they tell a very different story.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;That's where identity security becomes a security operations problem.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The Real Problem Is the Context Around the Identity
&lt;/h2&gt;

&lt;p&gt;Identity systems can tell you that authentication happened.&lt;/p&gt;

&lt;p&gt;Endpoint security can tell you what happened on the device.&lt;/p&gt;

&lt;p&gt;Network security can tell you where the traffic went.&lt;/p&gt;

&lt;p&gt;Cloud security can tell you what resources were accessed.&lt;/p&gt;

&lt;p&gt;But an account takeover rarely stays inside one of those categories.&lt;/p&gt;

&lt;p&gt;The attacker may move through all of them.&lt;/p&gt;

&lt;p&gt;That's why modern detection needs to connect:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Identity + Endpoint + Network + Cloud + SaaS + User Behavior&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Instead of asking:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Was this login legitimate?"&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Security teams increasingly need to ask:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;"Does everything this identity is doing after the login make sense?"&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  This Is Where UEBA Becomes Important
&lt;/h2&gt;

&lt;p&gt;User and Entity Behavior Analytics, or UEBA, isn't simply about detecting a suspicious login.&lt;/p&gt;

&lt;p&gt;It's about understanding behavior.&lt;/p&gt;

&lt;p&gt;For example:&lt;/p&gt;

&lt;p&gt;A finance employee normally accesses a small group of applications during business hours.&lt;/p&gt;

&lt;p&gt;Suddenly, the same identity accesses several unfamiliar resources, downloads large amounts of data, and starts interacting with systems it has never used before.&lt;/p&gt;

&lt;p&gt;The login itself might have been valid.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The behavior isn't.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That's the kind of distinction behavioral analytics can help security teams identify.&lt;/p&gt;

&lt;p&gt;And this is where identity signals become much more useful when correlated with the rest of the security environment.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why SIEM Alone Isn't the Whole Answer
&lt;/h2&gt;

&lt;p&gt;SIEM remains critical because security teams need centralized visibility and historical security data.&lt;/p&gt;

&lt;p&gt;But collecting identity logs isn't the same as understanding an identity attack.&lt;/p&gt;

&lt;p&gt;Consider this chain:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;MFA authentication&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;New device&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Unusual user behavior&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Suspicious endpoint activity&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Abnormal network connection&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Sensitive data access&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Potential account takeover&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;If every signal lives in a different security product, the analyst has to manually connect the dots.&lt;/p&gt;

&lt;p&gt;That costs time.&lt;/p&gt;

&lt;p&gt;And during an active attack, time matters.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where Seceon OTM Fits
&lt;/h2&gt;

&lt;p&gt;This is one of the areas where Seceon's &lt;strong&gt;Open Threat Management (OTM) Platform&lt;/strong&gt; can be relevant.&lt;/p&gt;

&lt;p&gt;OTM brings together capabilities including:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;SIEM + XDR + UEBA + SOAR + Threat Intelligence + Threat Hunting&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;within a unified security operations platform.&lt;/p&gt;

&lt;p&gt;That matters because an identity anomaly shouldn't necessarily be investigated as an isolated identity event.&lt;/p&gt;

&lt;p&gt;It can be correlated with endpoint activity.&lt;/p&gt;

&lt;p&gt;Network behavior.&lt;/p&gt;

&lt;p&gt;Cloud activity.&lt;/p&gt;

&lt;p&gt;Threat intelligence.&lt;/p&gt;

&lt;p&gt;And other security signals.&lt;/p&gt;

&lt;p&gt;For example:&lt;/p&gt;

&lt;p&gt;An unusual login occurs.&lt;/p&gt;

&lt;p&gt;UEBA identifies behavior outside the normal baseline.&lt;/p&gt;

&lt;p&gt;XDR connects the identity activity with an endpoint anomaly.&lt;/p&gt;

&lt;p&gt;Threat intelligence adds context around suspicious infrastructure.&lt;/p&gt;

&lt;p&gt;SIEM provides the broader event history.&lt;/p&gt;

&lt;p&gt;SOAR can help automate appropriate response actions.&lt;/p&gt;

&lt;p&gt;Now the analyst isn't looking at six unrelated alerts.&lt;/p&gt;

&lt;p&gt;They're looking at a potential &lt;strong&gt;attack chain&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The identity is the starting point. The surrounding behavior tells the story.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The Biggest Identity Security Mistake
&lt;/h2&gt;

&lt;p&gt;One of the biggest mistakes organizations can make is treating authentication as the finish line.&lt;/p&gt;

&lt;p&gt;Authentication should be the beginning of continuous trust evaluation.&lt;/p&gt;

&lt;p&gt;A user successfully passing MFA doesn't automatically mean:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Every subsequent action is legitimate&lt;/li&gt;
&lt;li&gt;Every device associated with the session is trustworthy&lt;/li&gt;
&lt;li&gt;Every resource request is normal&lt;/li&gt;
&lt;li&gt;Every application interaction is expected&lt;/li&gt;
&lt;li&gt;Every session should remain valid&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Security needs to continue after authentication.&lt;/p&gt;

&lt;p&gt;That's especially important as organizations rely more heavily on cloud applications, SaaS platforms, APIs and remote access.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Should Security Teams Monitor After MFA?
&lt;/h2&gt;

&lt;p&gt;If you're reviewing your identity-security strategy in 2026, don't stop at MFA deployment.&lt;/p&gt;

&lt;p&gt;Look at what happens &lt;strong&gt;after&lt;/strong&gt; the user authenticates.&lt;/p&gt;

&lt;h3&gt;
  
  
  Session Activity
&lt;/h3&gt;

&lt;p&gt;Monitor unusual sessions, devices, locations and access patterns.&lt;/p&gt;

&lt;h3&gt;
  
  
  User Behavior
&lt;/h3&gt;

&lt;p&gt;Look for activity that significantly differs from the user's normal behavior.&lt;/p&gt;

&lt;h3&gt;
  
  
  Privilege Changes
&lt;/h3&gt;

&lt;p&gt;Watch for unexpected privilege escalation or access to sensitive resources.&lt;/p&gt;

&lt;h3&gt;
  
  
  Application Activity
&lt;/h3&gt;

&lt;p&gt;Monitor unusual SaaS and cloud application usage.&lt;/p&gt;

&lt;h3&gt;
  
  
  Endpoint Signals
&lt;/h3&gt;

&lt;p&gt;Correlate identity activity with what is happening on the user's device.&lt;/p&gt;

&lt;h3&gt;
  
  
  Network Behavior
&lt;/h3&gt;

&lt;p&gt;Look for unusual destinations, connections or traffic patterns associated with the identity.&lt;/p&gt;

&lt;h3&gt;
  
  
  Data Access
&lt;/h3&gt;

&lt;p&gt;Watch for abnormal downloads, transfers or access to sensitive information.&lt;/p&gt;

&lt;p&gt;The important word here is:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Correlation.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;One event rarely tells the whole story.&lt;/p&gt;

&lt;h2&gt;
  
  
  What About Phishing-Resistant MFA?
&lt;/h2&gt;

&lt;p&gt;This doesn't mean MFA is no longer useful.&lt;/p&gt;

&lt;p&gt;Quite the opposite.&lt;/p&gt;

&lt;p&gt;Strong authentication remains an important security control, and phishing-resistant methods can significantly improve resistance to credential-based attacks.&lt;/p&gt;

&lt;p&gt;But identity security shouldn't depend on a single control.&lt;/p&gt;

&lt;p&gt;Even with stronger authentication, organizations still need visibility into:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What happened after access was granted?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Because attackers don't always need to compromise the authentication mechanism itself.&lt;/p&gt;

&lt;p&gt;They may compromise the endpoint.&lt;/p&gt;

&lt;p&gt;Steal an active session.&lt;/p&gt;

&lt;p&gt;Abuse an authorized identity.&lt;/p&gt;

&lt;p&gt;Exploit excessive permissions.&lt;/p&gt;

&lt;p&gt;Or operate through a trusted application.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why This Matters for MSSPs
&lt;/h2&gt;

&lt;p&gt;For an MSSP, identity monitoring becomes even more complicated.&lt;/p&gt;

&lt;p&gt;Imagine managing security for 50 customers.&lt;/p&gt;

&lt;p&gt;Each customer has:&lt;/p&gt;

&lt;p&gt;Different identity providers.&lt;/p&gt;

&lt;p&gt;Different SaaS applications.&lt;/p&gt;

&lt;p&gt;Different users.&lt;/p&gt;

&lt;p&gt;Different access policies.&lt;/p&gt;

&lt;p&gt;Different normal behavior.&lt;/p&gt;

&lt;p&gt;Different risk profiles.&lt;/p&gt;

&lt;p&gt;An MSSP can't realistically investigate every identity event manually.&lt;/p&gt;

&lt;p&gt;The platform needs to help separate:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Normal behavior → Suspicious behavior → Potential attack&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;and provide enough context for analysts to act.&lt;/p&gt;

&lt;p&gt;This is where a unified security operations approach can become valuable.&lt;/p&gt;

&lt;p&gt;With &lt;strong&gt;Seceon OTM&lt;/strong&gt;, MSSPs can bring SIEM, XDR, UEBA, SOAR and threat intelligence into a centralized security operations workflow rather than treating identity activity as a completely separate security problem.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Identity Perimeter Is Changing
&lt;/h2&gt;

&lt;p&gt;The old security model was largely:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Protect the network perimeter.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Then it became:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Protect the endpoint.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Then:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Protect the identity.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;But today, none of these exist in isolation.&lt;/p&gt;

&lt;p&gt;An identity can be compromised through an endpoint.&lt;/p&gt;

&lt;p&gt;An endpoint can be controlled through a malicious application.&lt;/p&gt;

&lt;p&gt;A compromised identity can access cloud resources.&lt;/p&gt;

&lt;p&gt;Cloud activity can lead to data exposure.&lt;/p&gt;

&lt;p&gt;And network activity can reveal the attack.&lt;/p&gt;

&lt;p&gt;The modern security perimeter is increasingly a connected ecosystem.&lt;/p&gt;

&lt;p&gt;That's why security teams need visibility across the entire attack chain.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Question Security Teams Should Be Asking
&lt;/h2&gt;

&lt;p&gt;Don't ask only:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"Is MFA enabled?"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Ask:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"If an attacker gets past the login, how quickly would we know?"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That's a much harder question.&lt;/p&gt;

&lt;p&gt;And it's the one that matters.&lt;/p&gt;

&lt;p&gt;Because authentication tells you who successfully entered.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Security operations need to determine whether that person is actually behaving like themselves.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That's where identity analytics, UEBA, XDR, SIEM, threat intelligence and automated response start working together.&lt;/p&gt;

&lt;p&gt;And that's the direction Seceon is taking with &lt;strong&gt;OTM&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Not just detecting the login.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Understanding what happens next.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  FAQ: MFA Bypass and Identity Security
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Can attackers bypass MFA?
&lt;/h3&gt;

&lt;p&gt;Yes. Attackers can use techniques such as adversary-in-the-middle phishing, device-code phishing, MFA fatigue, credential theft and session-token theft to obtain or abuse authenticated access.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does MFA prevent account takeover?
&lt;/h3&gt;

&lt;p&gt;MFA significantly reduces the risk of many credential-based attacks, but it isn't a complete account-takeover defense. Attackers can target sessions, tokens, endpoints, applications and users after authentication.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is session-token theft?
&lt;/h3&gt;

&lt;p&gt;Session-token theft occurs when an attacker obtains a token representing an already authenticated session and uses it to impersonate the legitimate user.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is UEBA?
&lt;/h3&gt;

&lt;p&gt;UEBA stands for User and Entity Behavior Analytics. It analyzes behavioral patterns to identify activity that deviates from what is considered normal for a user or entity.&lt;/p&gt;

&lt;h3&gt;
  
  
  How can SIEM help detect identity attacks?
&lt;/h3&gt;

&lt;p&gt;SIEM can centralize identity, endpoint, network, cloud and application events, making it easier to investigate activity across different security domains and build a timeline of an incident.&lt;/p&gt;

&lt;h3&gt;
  
  
  How does Seceon OTM help with identity-related threats?
&lt;/h3&gt;

&lt;p&gt;Seceon OTM combines &lt;strong&gt;SIEM, XDR, UEBA, SOAR, threat intelligence and threat hunting&lt;/strong&gt; to correlate security signals across different environments. This can help security teams connect unusual identity behavior with endpoint, network and other security events.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is Seceon OTM useful for MSSPs?
&lt;/h3&gt;

&lt;p&gt;Yes. OTM is designed to support centralized and multi-tenant security operations, helping MSSPs monitor and investigate security activity across multiple customer environments.&lt;/p&gt;




&lt;h2&gt;
  
  
  MFA Was Never Supposed to Be the Whole Security Strategy
&lt;/h2&gt;

&lt;p&gt;MFA is important.&lt;/p&gt;

&lt;p&gt;Strong authentication is important.&lt;/p&gt;

&lt;p&gt;Identity controls are important.&lt;/p&gt;

&lt;p&gt;But none of them answer the most important question by themselves:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is this identity doing right now?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That's the question modern security operations need to answer continuously.&lt;/p&gt;

&lt;p&gt;Because the attacker doesn't care whether your dashboard says:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"MFA: Enabled."&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;They care whether they can operate as a trusted identity after authentication.&lt;/p&gt;

&lt;p&gt;And that's why identity security is no longer just an IAM problem.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;It's a SOC problem.&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>identitysecurity</category>
      <category>mfa</category>
      <category>security</category>
    </item>
  </channel>
</rss>
