Tuesday, October 6, 2026
Follow on LinkedIn

ANY.RUN

From Telemetry to Defense: How SOC and MSSP Leaders Can Build Intelligence-Led Threat Monitoring 

Every function in a security operations center, from alert triage to incident response, depends on how well threats are monitored. Yet many SOCs and managed security providers still treat monitoring as log collection: ingest everything, match against static indicator...

Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster 

Investigating a phishing alert often means working through several layers of activity before an analyst can confidently close or escalate the case. Modern campaigns can hide malicious activity behind encrypted traffic, CAPTCHA challenges, redirects, browser scripts, and token-based authentication,...

How US SOCs and MSSPs Can Use Threat Intelligence to Detect Phishing Infrastructure Earlier 

Phishing remains one of the most persistent problems for security teams, as the challenge is no longer limited to identifying suspicious emails.  Behind a single malicious link there may be a newly registered domain, a compromised website, a redirector, a...

The Visibility Gap in Phishing Detection: Where Sandboxing Makes a Difference 

The difficult part of phishing detection for a security team often begins after the initial alert.  A suspicious URL may look clean at first glance, leaving the analyst with a familiar question: Is this a false positive, or is there...

Scaling SOC Capabilities: How Threat Intelligence Cuts Triage Time and Burnout 

A suspicious IP, unfamiliar domain, or file hash can trigger an investigation in seconds. Understanding what that indicator means can take much longer.  An IOC rarely tells the full story. Analysts may need to determine what threat it is associated...

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap 

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate the challenge many modern SOCs face.  Indicators lose relevance quickly. New infrastructure appears daily. SOCs struggle to keep up.  This is happening because malware campaigns increasingly...

New N0va Phishkit Targets North America and EU: A Growing Identity Risk for SOCs  

Recently, ANY.RUN researchers uncovered N0va, a new phishkit targeting organizations across North America and the EU, including government, technology, consulting, and healthcare.  What makes N0va especially relevant for SOC leaders is how it spreads the attack across different layers. Legitimate authentication, trusted brand lures,...

Phishing Powers 80% of Attacks on US Companies: How SOCs Can Detect It Early 

Phishing remains one of the most effective ways for attackers to gain access to corporate environments. From 2013-2023, the FBI recorded 158,436 US victims of Business Email Compromise (BEC), with over $20 billion in reported losses.  The FBI specifically warns that phishing is used to...

Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations

Researchers tie the LinX Coders phishing-as-a-service toolkit to 9,332 compromise events across 94 countries, with 63.7% of victims in the United States and stolen session cookies accounting for more than half of all outcomes. A phishing-as-a-service (PhaaS) toolkit tracked as...

Trusted Vendors Are Becoming Attack Paths: How US and EU Enterprises Can Reduce the Risk 

A trusted supplier can become an attack path overnight.  Large US and EU enterprises often rely on hundreds of vendors, giving attackers plenty of opportunities to hide malicious activity inside legitimate emails, files, and business workflows.  The window to react is...

Latest News

Latest News