Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The latest News and Information on Security Incident and Event Management.

SIEM-as-a-Service offering leverages Elastic for unified cybersecurity across the US government

The US Cybersecurity and Infrastructure Security Agency (CISA) has launched a SIEM-as-a-Service (SIEMaaS) offering for federal civilian agencies, featuring Elastic Security on Elastic Cloud. SIEMaaS delivers a cloud-based platform for next-generation, AI-powered threat analytics, incident response, and open-standards-based cybersecurity data ingestion.

AI can do what now?! - Detecting financial fraud with Elastic Security

Financial fraud is increasingly cyber-enabled, requiring organizations to detect complex campaigns across transactions, identities, and digital systems faster and with greater accuracy. Join cybersecurity experts Lisa Jones-Huff and Joe Murin as they discuss how Elastic Security applies AI, machine learning, and generative AI to modern fraud detection. They’ll share how Elastic Security helps teams connect signals, reduce noise, accelerate investigations, and scale fraud prevention through emerging frameworks and standards across financial services organizations.

Ep 35: RSAC FOMO? Dojo AI Demo

As we gear up for RSA Conference, we give viewers a sneak peek at Sumo Logic's SOC analyst agent, which turns a 45-minute analyst investigation into a five-minute AI-powered sprint. We walk through live demos showing how the agent automatically generates queries, maps threats to MITRE ATT&CK, and hands you recommended remediation actions all without making you switch tabs or tools. We also show off MCP integration that lets teams collaborate on active investigations right from Slack, because no one should be chained to their war room when there's dinner to be had.

The Future of Intelligent SOC -- Customer Brown Bag -- March 19th, 2026

Join us as Christopher explores how to build a modern, intelligent SOC with decision-ready detection, shared adversary context, and automated response that empowers faster, more confident security operations, featuring the role of the Sumo Logic SOC Agent in streamlining investigations and accelerating response.

Cyber Resilience: The Key to Maintaining Business Operations

As a child, rubber bands almost seemed magical. They would stretch to fit a size or shape. They could be flung across a room, although not ever at another person and certainly not a sibling. Their resilience means that they would always return to their original shape after being stretched, flung, or twisted.

Exabeam: Real Intelligence. Real Security. Real Fast.

Security teams today face machine-speed threats, growing complexity, and overwhelming data. Exabeam helps you stay ahead with powerful AI, behavioral analytics, and automation designed to accelerate threat detection, investigation, and response (TDIR). With hyper-fast search, advanced analytics, and intelligent automation, Exabeam enables security teams to uncover threats faster, reduce manual work, and gain insights other tools miss. Since 2014, we’ve put AI and machine learning at the core of security operations—helping organizations modernize their SOC and improve outcomes at scale.

How SA Power Networks Accelerated Threat Detection with Exabeam

The small but mighty cyber security team at SA Power Networks, the sole electricity distributor for the state of South Australia, was challenged to keep up with numerous responsibilities, including preventive controls, patch management, and detect/respond functions. After choosing and implementing Exabeam, the platform has delivered the anticipated value: streamlining and accelerating the company’s TDIR function, strengthening security team bonds and collaboration, and cementing the critical link between security and business initiatives.

What's new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations

Security teams face a threat landscape shaped by AI-driven attacks and identity misuse. Adversaries increasingly rely on compromised identities to blend in as legitimate users, making attacks harder to detect and slower to contain. On average, organizations take 241 days to identify and contain a breach.1 While threats have evolved, legacy SIEMs have not kept pace.

Falcon Next-Gen SIEM Supports Third-Party EDR Tools, Starting with Microsoft Defender

CrowdStrike is expanding CrowdStrike Falcon Next-Gen SIEM to support third-party endpoint detection and response (EDR) solutions — beginning with Microsoft Defender — with no Falcon sensor required. This evolution will enable organizations to modernize their SOC without replacing existing endpoint agents. Adversaries are moving faster than ever, exploiting cross-domain gaps across endpoint, identity, network, and cloud.