Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Watch what happens when your AI agent actually knows how to investigate

A SOC analyst spots suspicious activity from an internal IP. They need to understand what is happening. They open their SIEM's built-in AI assistant and type: "Tell me about 192.168.0.10." The assistant checks the entity store. Nothing. The analyst rephrases: "This is in our environment. Can you please check the logs and walk me through what's going on with this device?" A moment later, the assistant returns a summary. The host is involved in Windows file sharing and remote administration.

Hunting Citrix NetScaler Zero-Days with Corelight

Citrix’s security bulletin CTX697096, the NetScaler security blog, and WatchTowr’s vulnerability FAQ describe an urgent situation for organizations using NetScaler ADC and NetScaler Gateway. Two vulnerabilities (CVE-2026-88771 and CVE-2026-88772) are known to be exploited. CISA confirms active exploitation globally and has added both to its Known Exploited Vulnerabilities catalog.

Canada Raises the Bar for Critical Infrastructure Cybersecurity. Is Your Network Ready?

Canada has taken a significant step toward strengthening national cyber resilience. With Royal Assent now granted to Bill C-8, the Government of Canada is establishing a new framework for protecting critical cyber systems and securing the country's most essential services.

Investigate your network in plain English: introducing Natural Language Query

Every SOC analyst has been there. An alert fires. You know what you need to find. Maybe it's all outbound connections from a specific host that spiked overnight. Maybe it's every DNS query over 100 characters from a subnet you're watching. You know the question. What you don't know is the exact query syntax you need to ask it. So you open the documentation. You search for field names. You try a query, get it wrong, adjust, and try again. Minutes pass.

Post-Quantum Cryptography: The upgrade nobody asked for (but everyone's getting)

Post-Quantum Cryptography (PQC) is the security equivalent of showing up at the airport and discovering TSA changed the rules overnight again: Laptops out, laptops in, shoes off, shoes on, and declare your shampoo like it’s contraband uranium. You can argue with the signage, but the plane is still leaving, and compliance is not optional. The good news is you don’t need a physics degree, a quantum computer, or a wellness crystal to deal with it.

The water system attacks were simple. Securing OT isn't.

Recent cyberattacks against U.S. water and wastewater systems have put some familiar operational technology (OT) security problems back in the headlines. Federal agencies have warned about malicious actors targeting internet-facing programmable logic controllers (PLCs), changing device configurations, and disrupting operations at utilities across multiple states.

Recognizing and detecting data exfiltration

Every breach that lands a CISO in front of the board has a common final act: Data leaving the building. Attackers don't get paid for breaking in. They get paid for what they take out. And by the time stolen data appears on an extortion site or in a regulator's inbox, the window to stop the damage has already closed. That is what makes exfiltration so dangerous. It rarely looks like an emergency.

From shadow AI visibility to AI threat detection

AI adoption is outpacing enterprise control. The 2026 Verizon DBIR found that 45% of employees regularly use AI on corporate devices, and 67% of those users access AI through non-corporate accounts. Cyberhaven Labs reports that 39.7% of data sent to AI tools is sensitive, while endpoint AI app adoption grew 509% year over year.

Corelight Sensor v29.2: Visibility into multi-stage intrusions, Shadow AI governance, and self-managing sensors

With Corelight Sensor v29.2, generally available September 16, 2026, your team gains the ability to behaviorally detect and disrupt multi-stage intrusions, govern AI usage across your network without decryption, and deploy sensors in minutes instead of hours. This post covers what’s new and how it accelerates your security operations.

Cryptography is negotiated, not configured: Why PQC readiness needs network data

Post-quantum cryptography (PQC), and the many ways it intersects with IT and cybersecurity, is becoming increasingly important to organizations of every size. While it seemed like an esoteric concept a few years ago, relegated to cryptographers' conference talks, it’s now something that comes up in many of our customer conversations.