# Security @ Cisco Blogs

Check out the latest cybersecurity news and trends from Cisco Security. If it's connected, you're protected.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

DevFeed: [Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time](<https://devfeed.tech/articles/black-hat-usa-2026-building-the-agentic-soc-one-live-event-at-a-time-8414.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/bhusa-2026-soc/>)

Author: Jessica (Bair) Oppenheimer

Published: 2026-09-07T15:00:58Z

Content type: article

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [NOC](<https://devfeed.tech/topics/noc.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [agentic-soc](<https://devfeed.tech/tags/agentic-soc.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [cisco-secure-access](<https://devfeed.tech/tags/cisco-secure-access.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [duo](<https://devfeed.tech/tags/duo.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network-operations-center](<https://devfeed.tech/tags/network-operations-center.md>), [noc](<https://devfeed.tech/tags/noc.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>), [splunk-cloud](<https://devfeed.tech/tags/splunk-cloud.md>), [splunk-enterprise-security](<https://devfeed.tech/tags/splunk-enterprise-security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [thousandeyes](<https://devfeed.tech/tags/thousandeyes.md>)

### AI overview

Cisco describes its work protecting the Black Hat USA 2026 network alongside NOC leaders and technology partners. The team combined security telemetry and workflows to support visibility, detection engineering, threat hunting, malware analysis, AI protection, and Agentic SOC development.

### Source excerpt

Cisco is the Security Cloud Provider for the Black Hat conferences. Learn about the latest innovations for the Agentic SOC.

## Thrown into the SOC: A Black Hat First-Timer's Story

DevFeed: [Thrown into the SOC: A Black Hat First-Timer's Story](<https://devfeed.tech/articles/thrown-into-the-soc-a-black-hat-first-timer-s-story-8410.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/bhusa-2026-soc-first-timer/>)

Author: Danny Rodriguez

Published: 2026-09-07T15:00:54Z

Content type: article

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [Incident response](<https://devfeed.tech/topics/incident-response.md>), [incident](<https://devfeed.tech/topics/incident.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [cisco-secure-access](<https://devfeed.tech/tags/cisco-secure-access.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [cisco-xdr](<https://devfeed.tech/tags/cisco-xdr.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [duo](<https://devfeed.tech/tags/duo.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [network-operations-center](<https://devfeed.tech/tags/network-operations-center.md>), [noc](<https://devfeed.tech/tags/noc.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>), [splunk-cloud](<https://devfeed.tech/tags/splunk-cloud.md>), [splunk-enterprise-security](<https://devfeed.tech/tags/splunk-enterprise-security.md>), [tools](<https://devfeed.tech/tags/tools.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

A first-time SOC analyst reflects on a short Black Hat NOC rotation, focusing on evidence-based alert triage, uncertainty, and how AI agents can help investigators ask better questions.

### Source excerpt

A Black Hat SOC analyst shares how agentic workflows, Splunk ES, packet evidence, and human mentorship accelerated triage & investigation in the NOC/SOC.

## Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes

DevFeed: [Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes](<https://devfeed.tech/articles/troubleshooting-wi-fi-at-black-hat-usa-2026-with-thousandeyes-8405.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/bhusa-2026-noc-thousandeyes/>)

Author: Alex Guckin

Published: 2026-09-07T15:00:39Z

Content type: article

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [Network Operations Center](<https://devfeed.tech/topics/network-operations-center.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Duo](<https://devfeed.tech/topics/duo.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [dns](<https://devfeed.tech/tags/dns.md>), [duo](<https://devfeed.tech/tags/duo.md>), [metrics](<https://devfeed.tech/tags/metrics.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [network-operations-center](<https://devfeed.tech/tags/network-operations-center.md>), [noc](<https://devfeed.tech/tags/noc.md>), [operations](<https://devfeed.tech/tags/operations.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>), [splunk-cloud](<https://devfeed.tech/tags/splunk-cloud.md>), [splunk-enterprise-security](<https://devfeed.tech/tags/splunk-enterprise-security.md>), [thousandeyes](<https://devfeed.tech/tags/thousandeyes.md>)

### AI overview

A behind-the-scenes account of using ThousandEyes monitoring nodes and dashboards to troubleshoot Wi-Fi performance and roaming issues in the Black Hat USA 2026 Network Operations Center.

### Source excerpt

A behind-the-scenes look at troubleshooting Wi-Fi in the Black Hat USA 2026 Network Operations Center with ThousandEyes.

## Distributed Latency Monitoring at Black Hat

DevFeed: [Distributed Latency Monitoring at Black Hat](<https://devfeed.tech/articles/distributed-latency-monitoring-at-black-hat-8417.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/bhusa-2026-te-latency/>)

Author: Adam Kilgore

Published: 2026-09-07T15:00:37Z

Content type: article

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [dashboards](<https://devfeed.tech/topics/dashboards.md>)

Tags: [black-hat](<https://devfeed.tech/tags/black-hat.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [dns](<https://devfeed.tech/tags/dns.md>), [latency](<https://devfeed.tech/tags/latency.md>), [linux](<https://devfeed.tech/tags/linux.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [network-operations-center](<https://devfeed.tech/tags/network-operations-center.md>), [noc](<https://devfeed.tech/tags/noc.md>), [security](<https://devfeed.tech/tags/security.md>), [thousandeyes](<https://devfeed.tech/tags/thousandeyes.md>)

### AI overview

The article describes a ThousandEyes-based monitoring mesh at Black Hat USA that tracks latency, availability, download speed, and protocol-specific behavior. It combines dashboards and automated tests with on-demand Linux command-line checks for rapid troubleshooting.

### Source excerpt

Learn how the Black Hat NOC/SOC used ThousandEyes, Linux command-line testing, and packet evidence to monitor distributed latency, isolate DNS issues, and validate network performance during a live cybersecurity event.

## Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)

DevFeed: [Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)](<https://devfeed.tech/articles/building-a-risk-based-secure-network-analytics-detection-with-splunk-detection-editor-alpha-8412.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/bhusa-2026-soc-sna/>)

Author: Aditya Sankar

Published: 2026-09-07T15:00:32Z

Content type: article

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [Network](<https://devfeed.tech/topics/network.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [black-hat](<https://devfeed.tech/tags/black-hat.md>), [building](<https://devfeed.tech/tags/building.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data](<https://devfeed.tech/tags/data.md>), [dns](<https://devfeed.tech/tags/dns.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [network-operations-center](<https://devfeed.tech/tags/network-operations-center.md>), [noc](<https://devfeed.tech/tags/noc.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>), [splunk-cloud](<https://devfeed.tech/tags/splunk-cloud.md>), [splunk-enterprise-security](<https://devfeed.tech/tags/splunk-enterprise-security.md>)

### AI overview

This article explains how to use Splunk Detection Editor (Alpha) to develop a Cisco Secure Network Analytics detection and add its alarms as risk events in Splunk Enterprise Security. It covers SPL development and testing, sample data, risk scoring, CIM fields, and investigation drilldowns, with risk-based alerting used to correlate behavior over time.

### Source excerpt

At Black Hat USA, we used Splunk Detection Editor Alpha to turn Cisco SNA alarms into risk events with context, drilldowns & analyst-ready investigation paths.

## Black Hat USA 2026: Safeguarding DNS with Secure Access

DevFeed: [Black Hat USA 2026: Safeguarding DNS with Secure Access](<https://devfeed.tech/articles/black-hat-usa-2026-safeguarding-dns-with-secure-access-8407.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/bhusa-2026-soc-dns/>)

Author: Steve Vida

Published: 2026-09-07T15:00:32Z

Content type: article

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [NOC](<https://devfeed.tech/topics/noc.md>)

Tags: [apple](<https://devfeed.tech/tags/apple.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [cisco-secure-access](<https://devfeed.tech/tags/cisco-secure-access.md>), [cisco-security-cloud](<https://devfeed.tech/tags/cisco-security-cloud.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [cisco-xdr](<https://devfeed.tech/tags/cisco-xdr.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [dns](<https://devfeed.tech/tags/dns.md>), [google](<https://devfeed.tech/tags/google.md>), [network-operations-center](<https://devfeed.tech/tags/network-operations-center.md>), [noc](<https://devfeed.tech/tags/noc.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>), [splunk-cloud](<https://devfeed.tech/tags/splunk-cloud.md>), [splunk-enterprise-security](<https://devfeed.tech/tags/splunk-enterprise-security.md>), [statistics](<https://devfeed.tech/tags/statistics.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

Cisco reports on using Secure Access and DNS telemetry to protect the Black Hat USA 2026 network. The article highlights blocking unapproved encrypted DNS resolvers, DNS request statistics, and activity classified as hacking.

### Source excerpt

Cisco is the Security Cloud Provider for the Black Hat conferences, over a decade providing DNS Security. Learn about protecting DNS with Secure Access.

## Frontier AI just raised the stakes, and the old playbook won't hold up

DevFeed: [Frontier AI just raised the stakes, and the old playbook won't hold up](<https://devfeed.tech/articles/frontier-ai-just-raised-the-stakes-and-the-old-playbook-won-t-hold-up-8421.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/frontier-ai-just-raised-the-stakes-and-the-old-playbook-wont-hold-up/>)

Author: Jason Maynard

Published: 2026-09-04T15:00:46Z

Content type: opinion

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Code](<https://devfeed.tech/topics/code.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [Firefox](<https://devfeed.tech/topics/firefox.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-cybersecurity](<https://devfeed.tech/tags/ai-cybersecurity.md>), [claude](<https://devfeed.tech/tags/claude.md>), [frontier-ai](<https://devfeed.tech/tags/frontier-ai.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [security-for-ai](<https://devfeed.tech/tags/security-for-ai.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article argues that frontier AI is making vulnerability discovery dramatically faster, shifting the security bottleneck to remediation. It advocates layered defenses, an assume-breach mindset, and faster detection and response.

### Source excerpt

Frontier AI is accelerating vulnerability discovery. Learn why layered defenses, faster remediation, and cyber resilience matter more than ever.

## Crypto Agility: Why PQC Is Not a One-Time Upgrade

DevFeed: [Crypto Agility: Why PQC Is Not a One-Time Upgrade](<https://devfeed.tech/articles/crypto-agility-why-pqc-is-not-a-one-time-upgrade-8419.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/crypto-agility-why-pqc-is-not-a-one-time-upgrade/>)

Author: Hugo Vliegen

Published: 2026-09-03T15:00:56Z

Content type: article

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [networking](<https://devfeed.tech/topics/networking.md>), [Network design](<https://devfeed.tech/topics/network-design.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [cisco-sd-wan](<https://devfeed.tech/tags/cisco-sd-wan.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [networks](<https://devfeed.tech/tags/networks.md>), [post-quantum](<https://devfeed.tech/tags/post-quantum.md>), [quantum-computing](<https://devfeed.tech/tags/quantum-computing.md>), [sd-wan-security](<https://devfeed.tech/tags/sd-wan-security.md>), [security](<https://devfeed.tech/tags/security.md>), [security-for-ai](<https://devfeed.tech/tags/security-for-ai.md>)

### AI overview

The article explains why crypto agility is essential for long-lived network infrastructure adopting post-quantum cryptography. It argues that organizations should design systems to update cryptography continuously as standards, threats, and implementations evolve.

### Source excerpt

Learn why crypto agility is essential for PQC-ready networks--and how adaptable infrastructure helps organizations keep pace with evolving threats.

## From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For

DevFeed: [From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For](<https://devfeed.tech/articles/from-isolated-agents-to-collective-intelligence-why-a2a-is-the-protocol-the-agentic-soc-has-been-waiting-for-8402.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/a2a-mcp-open-protocol-stack-multi-agent-soc/>)

Author: Jeff Yeo

Published: 2026-08-28T15:00:11Z

Content type: article

Language: en

Sources: [Security @ Cisco Blogs](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [Agentic SOC](<https://devfeed.tech/topics/agentic-soc.md>), [Model Context Protocol (MCP)](<https://devfeed.tech/topics/model-context-protocol-mcp.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [agentic-soc](<https://devfeed.tech/tags/agentic-soc.md>), [agents](<https://devfeed.tech/tags/agents.md>), [announcement](<https://devfeed.tech/tags/announcement.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [artificial-intelligence-ai](<https://devfeed.tech/tags/artificial-intelligence-ai.md>), [integration](<https://devfeed.tech/tags/integration.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [model-context-protocol](<https://devfeed.tech/tags/model-context-protocol.md>), [security](<https://devfeed.tech/tags/security.md>), [workflow](<https://devfeed.tech/tags/workflow.md>)

### AI overview

This article presents A2A as a protocol for enabling agents from different vendors and platforms to hand work to one another in a multi-agent security operations center. It explains that A2A complements MCP: MCP connects agents to data and tools, while A2A connects agents to other agents. The article describes this as a conceptual architecture because production security-agent handoffs mediated by A2A are not yet shipping.

### Source excerpt

The Agentic SOC needs two protocols, not one. Learn how MCP and A2A work together as the vertical and horizontal layers of multi-agent security operations