// FEATURED_ANALYSIS
-
The SIEM Dilemma: Why Modern SOCs Are Drowning in Data and Starved for Context
-> EXAMINE_LOGFor over two decades, the SIEM (Security Information and Event Management) system has served as the heart of the SOC (Security Operations Center) – and why not? It promised to aggregate logs from every server, firewall, router and app into a central repository that you could easily search and gain visibility into enterprise risk. Unfortunately, for many, it failed to fulfill its prophecy, let’s look into why!
-
Shadow AI: The New Perimeter No One is Guarding
-> EXAMINE_LOGIf there’s one thing my years in operational IT taught me, it’s that when security gets in the way of productivity, users will always find a workaround. Right now, Shadow AI is the ultimate example of that friction. Developers aren’t pasting proprietary code into LLM prompts to breach the company; they’re doing it at 2:00 AM because they just want to ship their sprint on time. Blocking AI entirely is…
// THE_BREACH_FILES
-
Case #003: The Key to the Kingdom
Target: Microsoft Date: January 2024 Threat Actor: Storm-0558 / Midnight Blizzard (Russian SVR) Attack Vector: Stolen Signing Key & Non-Human Identity Exploitation Impact: Widespread geopolitical fallout, severe reputational damage and…
-
Case #002: Trojan Supply Chain Attack
Target: SolarWinds (and ~18,000 downstream customers) Date: December 2020 Threat Actor: APT29 / Cosy Bear / Nobelium (Russian SVR) Attack Vector: Software Supply Chain Compromise (Code Build Injection) Impact: Estimated…
-
Case #001: The $100 Million Phone Call
Target: MGM Resorts International Date: September 2023 Threat Actor: Scattered Spider / ALPHV Attack Vector: Voice Phishing (Vishing) & MFA Bypass Impact: $100m+ operational loss
// ALL_SYSTEM_LOGS
-
Case #003: The Key to the Kingdom
-> ACCESS_ARCHIVETarget: Microsoft Date: January 2024 Threat Actor: Storm-0558 / Midnight Blizzard (Russian SVR) Attack Vector: Stolen Signing Key & Non-Human Identity Exploitation Impact: Widespread geopolitical fallout, severe reputational damage and overhaul of cloud identity architecture
-
Case #002: Trojan Supply Chain Attack
-> ACCESS_ARCHIVETarget: SolarWinds (and ~18,000 downstream customers) Date: December 2020 Threat Actor: APT29 / Cosy Bear / Nobelium (Russian SVR) Attack Vector: Software Supply Chain Compromise (Code Build Injection) Impact: Estimated $90m+, corporate damages across victim networks in the billions
-
Case #001: The $100 Million Phone Call
-> ACCESS_ARCHIVETarget: MGM Resorts International Date: September 2023 Threat Actor: Scattered Spider / ALPHV Attack Vector: Voice Phishing (Vishing) & MFA Bypass Impact: $100m+ operational loss
-
The SIEM Dilemma: Why Modern SOCs Are Drowning in Data and Starved for Context
-> ACCESS_ARCHIVEFor over two decades, the SIEM (Security Information and Event Management) system has served as the heart of the SOC (Security Operations Center) – and why not? It promised to aggregate logs from every server, firewall, router and app into a central repository that you could easily search and gain visibility into enterprise risk. Unfortunately,…
-
Shadow AI: The New Perimeter No One is Guarding
-> ACCESS_ARCHIVEIf there’s one thing my years in operational IT taught me, it’s that when security gets in the way of productivity, users will always find a workaround. Right now, Shadow AI is the ultimate example of that friction. Developers aren’t pasting proprietary code into LLM prompts to breach the company; they’re doing it at 2:00…
-
The ECH Dilemma: Balancing Web Privacy Against Enterprise Perimeter Visibility
-> ACCESS_ARCHIVEWe’ve spent years trusting the browser padlock to keep our web traffic safe, but enterprise firewalls relied on a quiet compromise to keep networks secure. Now, with ECH encrypting the final piece of plain text in the TLS handshake, the network packet is officially going blind.