Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

What's New in LogRhythm SIEM for October 2026

The October 2026 LogRhythm SIEM release modernizes self-hosted security operations with an in-place migration from Elasticsearch to OpenSearch, a next-generation self-service reporting engine, generative AI collectors, and a community Model Context Protocol (MCP) server. The release also includes backend and API updates that improve event drilldown, rule administration, network routing, and telemetry quality while helping organizations maintain control of sensitive security data.

The Agentic SOC Isn't Coming for Analysts' Jobs. It's Coming for Their Tabs.

An agentic SOC uses AI-powered investigation, analysis, and automation to gather data, connect activity, and handle repetitive investigative work. Analysts remain in control and focus on judgment, prioritization, and response. This addresses the need for machine-speed security operations as AI agents gain autonomy and Tier 1 access to systems. Spend five minutes watching a security analyst at work and the “AI will replace analysts” headline starts to sound out of touch.

The New CISO Ep. 151 - Sean Murphy | Complacency Kills: Why More Discomfort Might Fix Your Burnout

Sean Murphy spent more than twenty years in the CISO chair and walked away from it while things were going well. In this episode of The New CISO, he returns to talk with Steve Moore about trading the operational seat for a field CISO role at F5 — and why getting too good at the job was the warning sign.

What OpenAI's Misalignment Reports Tell Security Teams About AI Agents

AI Agents are no longer the new insider threat. They’ve become firmly planted as the primary challenge for security leaders when it comes to insider threat activity. They have credentials, they act autonomously, and increasingly, they can take real actions on real systems. How would you know when one of your digital workers starts doing something it’s never done before?

The New CISO Ep. 150 - Sherri Douville | Engineering Trust in AI Agents with Open-Source Tools

In this episode of The New CISO, host Steve Moore welcomes Sherri Douville for a conversation that sits outside the show's usual lane — less war story, more blueprint. Sherri works alongside CISOs rather than inside the role, and arrives with a pointed argument about what the job is becoming.

The Autonomous Insider: Rethinking Insider Risk for the Agentic Era

Insider threat models have historically had one thing in common: somewhere in the chain, there is a person. That person may be malicious or negligent. Their credentials may have been compromised. Their actions may be intentional or accidental. But there is still a human principal at the center of the risk. Agentic AI is beginning to challenge that assumption.

What CRN's 2026 Annual Report Card Says About the Next Phase of AI Security

AI security is entering a more demanding phase. The market is moving beyond who can add AI to a product and toward who can make it useful in the real world — across existing security environments, partner ecosystems, and day-to-day operations. CRN’s 2026 Annual Report Card offers a useful snapshot of that shift. In the AI Security category, Exabeam earned the top overall score at 90.6, leading all four subcategories and every one of the 21 individual evaluation criteria.

Features Don't Win Budget Conversations. Operational Evidence Does.

CISOs can strengthen security budget conversations by replacing feature comparisons with measurable operational evidence. Establish the current burden, show how an investment changes security operations, and connect those improvements to financial impact. Metrics such as alert volume, analyst investigation time, manual effort, and capacity gained help CFOs evaluate security investments in terms of cost, benefit, predictability, and measurable business value. Every CISO has been there.

Why Autonomy Breaks Traditional Security Operations Workflows

Autonomy breaks traditional security operations workflows because AI agents can act continuously and independently inside approved environments. When activity is initiated and executed without a human in the loop, event-by-event review and short correlation windows fail to capture progression, intent, and accumulated risk.