Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal.

SOCtember.com

Always First. Fast SOC News.

A Security Operations Centre news desk for the people who detect, investigate, contain, and learn from cyber incidents.

Latest

Full desk

RESPONSE · WASHINGTON

CISA Flags TeamCity Flaw CVE-2026-63077 as Used in Ransomware Campaigns

WASHINGTON - The Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities catalog so that CVE-2026-63077, a critical JetBrains TeamCity On-Premises flaw, is now marked with known ransomware campaign use. Trade press reported the KEV change on Wednesday, September 23, 2026. CISA first added the vulnerability to the catalog on August 5, 2026, after evidence of active exploitation. The live KEV feed lists knownRansomwareCampaignUse as Known for this CVE.

Noah Park, Response, New York

Read the story

Text desk note. No incident photograph.

THREAT INTEL · SINGAPORE

Arista Confirms Actively Exploited VeloCloud Orchestrator Flaw

SINGAPORE - Arista Advisory 0183, published September 22, 2026 and revised to 1.1 on September 23, 2026, covers CVE-2026-93952 in the on-premises VeloCloud Orchestrator. The flaw was discovered externally and is actively exploited.

Priya Shah, Threat Intel, Singapore

Read the story
A technician at monitors in a data-center monitoring room. Not a photograph of an Arista or VeloCloud incident.
Photo: Derrick Coetzee

THREAT INTEL · SAN JOSE

Talos Documents CLOSEDQUORUM, Windows Implant That Lets AI Models Vote on C2 Moves

SAN JOSE - Cisco Talos researchers have documented CLOSEDQUORUM, which they describe as the first publicly reported Windows implant in their knowledge that uses a panel of commercial large language models as tactical command and control after deployment. The finding appears in a Talos blog by Ryan Fetterman dated Tuesday, September 22, 2026, and was uncovered with CAIRN, Talos' new open-source toolkit for tracking AI-integrated malware. Talos has not confirmed in-the-wild deployment.

Priya Shah, Threat Intel, Singapore

Read the story

Text desk note. No incident photograph.

TOOLS · AUSTIN

Microsoft Previews ISOC in Defender to Unify SIEM and Threat Protection for Agentic SOCs

AUSTIN - Microsoft on September 23, 2026, announced Integrated Security Operations Center, or ISOC, in Microsoft Defender, a preview foundation that puts SIEM and native threat protection on one shared platform so analysts and agents can investigate and act without stitching separate stacks. Rob Lefferts (Microsoft Security Blog) said agent-driven attacks raise the cost of handoffs between detection and protection. ISOC is the operations layer of Microsoft's agentic stack begun in July 2026 with Project Perception; agents supply speed while people set priorities. Microsoft points to Attack Disruption as a protection loop using telemetry, exposure insights, and threat intelligence. ISOC is a Defender preview, not a vendor-neutral SIEM.

James Whitford, Tools, Austin

Read the story

Text desk note. No incident photograph.

OPINION · LONDON

Alert Fatigue Is a Detection Pipeline Failure, Not an Analyst Character Flaw

LONDON - SOCs still treat missed alerts as a people problem. Detection engineering evidence says most alert fatigue is manufactured upstream in the detection pipeline. Future of SecOps (Aug 2026, Marta K.) described a review that blamed an analyst after a shift queue of more than 800 alerts, including EDR and identity duplicates of one medium-severity credential anomaly. Alert fatigue is volume, noise, duplication, and weak prioritization exceeding review capacity. Intezer (THN Sep 12, 2026): ~16.9M SOC alerts Feb-Jun 2026; ~73k AI-related (0.43%), up 685%; of AI-related, 94.1% benign tool use, 5.8% unsafe/policy, 0.02% confirmed attacks; no confirmed org-agent takeovers. ISACA 2025 via FoS: 55% understaffed; 38% need 3-6 months to fill entry-level. Fix: measure FP/duplicate/backlog/TTA by rule; tune defaults; correlate; severity contracts; rule owners; triage feedback. AI triage helps enrichment but cannot retire orphan rules.

Elena Vos, Opinion, London

Read the story

Text desk note. No incident photograph.

Did You Know

DETECTION · LONDON

Untuned Alerts Can Hide Active Intrusions From the SOC

LONDON - Organization B had an established baseline and a finer-tuned alert system. After medium-severity payload alerts, defenders isolated compromised workstations within minutes (within 10, 2, and 20 minutes across three hosts), cutting command and control and forcing the red team into an assume-breach model. CISA's lesson for operations teams: establish and continuously maintain baselines, refine alerting so routine administrative activity is filtered, and treat untuned detection stacks as a direct cause of missed intrusions.

Ava Okello, Detection, London

Read the explainer

Text desk note. No incident photograph.

A technician at monitors in a data-center monitoring room. Layout photograph, not live news.
Photo: Derrick Coetzee

Section

Detection

Sourced item filed.

Read the story