# threat detection

Published articles for threat detection.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Transform and route security logs to Microsoft Sentinel tables using Observability Pipelines

DevFeed: [Transform and route security logs to Microsoft Sentinel tables using Observability Pipelines](<https://devfeed.tech/articles/transform-and-route-security-logs-to-microsoft-sentinel-tables-using-observability-pipelines-31547.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/observability-pipelines-microsoft-sentinel-packs/>)

Author: Zara Boddula; Danielle Park

Published: 2026-09-16T00:00:00Z

Content type: tutorial

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [observability pipelines](<https://devfeed.tech/topics/observability-pipelines.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [azure](<https://devfeed.tech/tags/azure.md>), [cisco-meraki](<https://devfeed.tech/tags/cisco-meraki.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [fortigate](<https://devfeed.tech/tags/fortigate.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [pipelines](<https://devfeed.tech/tags/pipelines.md>), [security](<https://devfeed.tech/tags/security.md>), [siem](<https://devfeed.tech/tags/siem.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

Datadog's Observability Pipelines Packs transform firewall, VPN, and network detection logs into Microsoft Sentinel table schemas before ingestion. The post describes Packs for Palo Alto Networks, Fortinet, Cisco ASA, Cisco Meraki, and ExtraHop, including filtering and noise reduction to help control Sentinel ingest volume while retaining visibility.

### Source excerpt

Learn how Observability Pipelines Packs map security logs to Microsoft Sentinel schemas and help control downstream ingest volume.

## Abnormal AI: Amazon Bedrock AgentCore for agentic email security at scale

DevFeed: [Abnormal AI: Amazon Bedrock AgentCore for agentic email security at scale](<https://devfeed.tech/articles/abnormal-ai-amazon-bedrock-agentcore-for-agentic-email-security-at-scale-21546.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/machine-learning/abnormal-ai-amazon-bedrock-agentcore-for-agentic-email-security-at-scale/>)

Author: Aswin Vasudevan

Published: 2026-09-14T21:22:45Z

Content type: article

Language: en

Sources: [Artificial Intelligence](<https://devfeed.tech/sources/artificial-intelligence.md>)

Topics: [Amazon Bedrock AgentCore](<https://devfeed.tech/topics/amazon-bedrock-agentcore.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [Amazon Bedrock](<https://devfeed.tech/topics/amazon-bedrock.md>), [Security](<https://devfeed.tech/topics/security.md>), [Serverless](<https://devfeed.tech/topics/serverless.md>), [API](<https://devfeed.tech/topics/api.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [AWS CloudTrail](<https://devfeed.tech/topics/aws-cloudtrail.md>), [Amazon CloudWatch](<https://devfeed.tech/topics/amazon-cloudwatch.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>)

Tags: [advanced-300](<https://devfeed.tech/tags/advanced-300.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [agents](<https://devfeed.tech/tags/agents.md>), [amazon-bedrock-agentcore](<https://devfeed.tech/tags/amazon-bedrock-agentcore.md>), [amazon-cloudwatch](<https://devfeed.tech/tags/amazon-cloudwatch.md>), [amazon-s3](<https://devfeed.tech/tags/amazon-s3.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [api](<https://devfeed.tech/tags/api.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-cloudtrail](<https://devfeed.tech/tags/aws-cloudtrail.md>), [code](<https://devfeed.tech/tags/code.md>), [customer-solutions](<https://devfeed.tech/tags/customer-solutions.md>), [data](<https://devfeed.tech/tags/data.md>), [data-processing](<https://devfeed.tech/tags/data-processing.md>), [security](<https://devfeed.tech/tags/security.md>), [serverless](<https://devfeed.tech/tags/serverless.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

Abnormal AI uses Amazon Bedrock AgentCore Code Interpreter as an ephemeral, serverless compute scratch pad for real-time inline email threat detection. The article describes its sandbox isolation, networking and file-handling options, preloaded Python capabilities, observability integrations, and use at billion-message scale.

### Source excerpt

Learn how Abnormal AI deployed Amazon Bedrock AgentCore Code Interpreter as an ephemeral compute scratch pad for the agents behind its real-time email threat detection at billion-message scale, plus the sandbox design decisions and practical lessons for builders deploying Code Interpreter in production.

## Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection

DevFeed: [Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection](<https://devfeed.tech/articles/unmasking-cloud-identities-from-behavioral-clustering-to-automated-detection-17391.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/behavioral-clustering-map-to-cloud-identities/>)

Author: Osher Jacob

Published: 2026-09-14T10:00:01Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [AWS CloudTrail](<https://devfeed.tech/topics/aws-cloudtrail.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [Machine learning](<https://devfeed.tech/topics/machine-learning.md>), [Algorithms](<https://devfeed.tech/topics/algorithms.md>), [SQL](<https://devfeed.tech/topics/sql.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>)

Tags: [algorithms](<https://devfeed.tech/tags/algorithms.md>), [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [aws-cloudtrail](<https://devfeed.tech/tags/aws-cloudtrail.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-cybersecurity-research](<https://devfeed.tech/tags/cloud-cybersecurity-research.md>), [cloud-detection](<https://devfeed.tech/tags/cloud-detection.md>), [devops](<https://devfeed.tech/tags/devops.md>), [iam](<https://devfeed.tech/tags/iam.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [post](<https://devfeed.tech/tags/post.md>), [sql](<https://devfeed.tech/tags/sql.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

This article presents a behavioral clustering model for mapping cloud identities to functional roles using activity patterns from audit logs. It applies unsupervised machine learning with UMAP and HDBSCAN to data from more than 40,000 identities across 125 cloud environments, and shows how the resulting map can support automated threat detection. The article also explains how lightweight heuristics extracted from the map can classify identities at scale using standard SQL, reducing the need for continuous resource-intensive machine learning pipelines.

### Source excerpt

We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The post Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection appeared first on Unit 42.

## AuthKit vs Better Auth for B2B SaaS

DevFeed: [AuthKit vs Better Auth for B2B SaaS](<https://devfeed.tech/articles/authkit-vs-better-auth-for-b2b-saas-17462.md>)

Original publisher: [Read original article](<https://workos.com/blog/authkit-vs-better-auth-b2b>)

Author: WorkOS

Published: 2026-09-14T00:00:00Z

Content type: comparison

Language: en

Sources: [WorkOS Blog](<https://devfeed.tech/sources/workos-blog.md>)

Topics: [Software as a service](<https://devfeed.tech/topics/saas.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [Security](<https://devfeed.tech/topics/security.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [Frameworks](<https://devfeed.tech/topics/frameworks.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Passkeys](<https://devfeed.tech/topics/passkeys.md>)

Tags: [auth](<https://devfeed.tech/tags/auth.md>), [comparison](<https://devfeed.tech/tags/comparison.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [logs](<https://devfeed.tech/tags/logs.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [vercel](<https://devfeed.tech/tags/vercel.md>)

### AI overview

This comparison examines AuthKit and Better Auth as platforms for B2B SaaS products selling to enterprise IT buyers. It argues that both now provide core capabilities such as SSO, SCIM, and audit logs, so the meaningful differences are provider coverage, where user lifecycle management begins, and contractual responsibility. The article also describes Better Auth's hosted infrastructure, dashboard, SIEM drain, self-service provisioning, and threat detection features, while noting its convergence with AuthKit on enterprise requirements.

### Source excerpt

Both ship SSO, SCIM and audit logs now. The comparison that decides enterprise deals has moved to the long tail: provider coverage, where user lifecycle actually starts, and who is contractually on the hook.

## CrowdStrike Falcon Guardian Defines the Next Generation of AI Security

DevFeed: [CrowdStrike Falcon Guardian Defines the Next Generation of AI Security](<https://devfeed.tech/articles/crowdstrike-falcon-guardian-defines-the-next-generation-of-ai-security-8307.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/falcon-guardian-defines-next-generation-of-ai-security/>)

Author: Michael Devins

Published: 2026-09-12T11:17:51.295154Z

Content type: release

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-gateway](<https://devfeed.tech/tags/ai-gateway.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [platform](<https://devfeed.tech/tags/platform.md>), [securing-ai](<https://devfeed.tech/tags/securing-ai.md>), [security](<https://devfeed.tech/tags/security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

CrowdStrike announces Falcon Guardian, an AI detection and response solution for discovering, monitoring, investigating, and securing AI agents at runtime. It adds an AI gateway and connects agent activity with endpoint telemetry to support threat response.

### Source excerpt

A new flagship AI detection and response solution delivers runtime protection for AI agents, introduces a new AI gateway, and extends expert-led defense.

## Welcome to APNIC 62

DevFeed: [Welcome to APNIC 62](<https://devfeed.tech/articles/welcome-to-apnic-62-10861.md>)

Original publisher: [Read original article](<https://blog.apnic.net/2026/09/08/welcome-to-apnic-62/>)

Author: Timothy Hildred

Published: 2026-09-08T03:33:07Z

Content type: article

Language: en

Sources: [APNIC Blog](<https://devfeed.tech/sources/apnic-blog.md>)

Topics: [Internet](<https://devfeed.tech/topics/internet.md>), [Networks](<https://devfeed.tech/topics/networks.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [DNSSEC](<https://devfeed.tech/topics/dnssec.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [FIRST](<https://devfeed.tech/topics/first.md>)

Tags: [apnic-62](<https://devfeed.tech/tags/apnic-62.md>), [community](<https://devfeed.tech/tags/community.md>), [conference](<https://devfeed.tech/tags/conference.md>), [conferences](<https://devfeed.tech/tags/conferences.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [dnssec](<https://devfeed.tech/tags/dnssec.md>), [event](<https://devfeed.tech/tags/event.md>), [events](<https://devfeed.tech/tags/events.md>), [india](<https://devfeed.tech/tags/india.md>), [ipv4](<https://devfeed.tech/tags/ipv4.md>), [ipv6](<https://devfeed.tech/tags/ipv6.md>), [nixi](<https://devfeed.tech/tags/nixi.md>), [nro](<https://devfeed.tech/tags/nro.md>), [policy-sig](<https://devfeed.tech/tags/policy-sig.md>), [tech-matters](<https://devfeed.tech/tags/tech-matters.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

APNIC 62 in Mumbai previews technical, security, IPv6 deployment, DNSSEC, threat-detection, community, and policy sessions, alongside keynote talks, social events, newcomer activities, and NRO NC voting information.

### Source excerpt

APNIC welcomes you to Mumbai, India for APNIC 62. Here is what you can look forward to over the coming days.

## Stop runtime threats with Workload Protection response actions

DevFeed: [Stop runtime threats with Workload Protection response actions](<https://devfeed.tech/articles/stop-runtime-threats-with-workload-protection-response-actions-2311.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/stop-runtime-threats-with-workload-protection-response-actions/>)

Author: Théo Putegnat; Taylor Overturf

Published: 2026-09-04T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [Processes](<https://devfeed.tech/topics/processes.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [datadog-agent](<https://devfeed.tech/tags/datadog-agent.md>), [processes](<https://devfeed.tech/tags/processes.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [workload-protection](<https://devfeed.tech/tags/workload-protection.md>)

### AI overview

Datadog Workload Protection adds automated and manual runtime response actions. Agent rules can terminate matching malicious processes automatically, while analysts can investigate signals and respond manually.

### Source excerpt

When a runtime threat appears, every step costs time. Datadog Workload Protection can now kill processes and isolate workloads with automated and manual response actions.

## Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation

DevFeed: [Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation](<https://devfeed.tech/articles/detecting-multi-stage-attacks-on-aws-a-guide-to-cross-service-signal-correlation-4678.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/security/detecting-multi-stage-attacks-on-aws-a-guide-to-cross-service-signal-correlation/>)

Author: Nisha Kashyap

Published: 2026-08-26T17:39:19Z

Content type: article

Language: en

Sources: [AWS Security Blog](<https://devfeed.tech/sources/aws-security-blog.md>)

Topics: [Amazon Web Services (AWS)](<https://devfeed.tech/topics/amazon-web-services-aws.md>), [Security](<https://devfeed.tech/topics/security.md>), [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [Amazon CloudWatch Logs](<https://devfeed.tech/topics/amazon-cloudwatch-logs.md>), [AWS CloudTrail](<https://devfeed.tech/topics/aws-cloudtrail.md>), [VPC Flow Logs](<https://devfeed.tech/topics/vpc-flow-logs.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [advanced-300](<https://devfeed.tech/tags/advanced-300.md>), [amazon-cloudwatch](<https://devfeed.tech/tags/amazon-cloudwatch.md>), [amazon-cloudwatch-logs](<https://devfeed.tech/tags/amazon-cloudwatch-logs.md>), [amazon-guardduty](<https://devfeed.tech/tags/amazon-guardduty.md>), [amazon-route-53](<https://devfeed.tech/tags/amazon-route-53.md>), [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [aws-cloudtrail](<https://devfeed.tech/tags/aws-cloudtrail.md>), [aws-security-hub](<https://devfeed.tech/tags/aws-security-hub.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [guide](<https://devfeed.tech/tags/guide.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [logs](<https://devfeed.tech/tags/logs.md>), [s3](<https://devfeed.tech/tags/s3.md>), [security](<https://devfeed.tech/tags/security.md>), [security-blog](<https://devfeed.tech/tags/security-blog.md>), [security-identity-compliance](<https://devfeed.tech/tags/security-identity-compliance.md>), [shared-responsibility-model](<https://devfeed.tech/tags/shared-responsibility-model.md>), [technical-how-to](<https://devfeed.tech/tags/technical-how-to.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [vpc-flow-logs](<https://devfeed.tech/tags/vpc-flow-logs.md>)

### AI overview

This article explains how security engineers can detect multi-stage attacks on AWS by correlating signals across services with business context. It presents examples using CloudWatch Logs Insights and discusses expanding the correlations into an automated pipeline.

### Source excerpt

A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetCallerIdentity from a source address it hasn't previously used. Within minutes, [...]

## Machine vs. machine: The new reality of cybersecurity in ANZ

DevFeed: [Machine vs. machine: The new reality of cybersecurity in ANZ](<https://devfeed.tech/articles/machine-vs-machine-the-new-reality-of-cybersecurity-in-anz-4790.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/cybersecurity-in-australia-new-zealand>)

Author: Jeremy Pell

Published: 2026-08-26T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Frontier AI](<https://devfeed.tech/topics/frontier-ai.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [data-architecture](<https://devfeed.tech/topics/data-architecture.md>), [AI Platforms/Deployment](<https://devfeed.tech/topics/ai-platforms-deployment.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [agentic-ai-cybersecurity-security-research](<https://devfeed.tech/tags/agentic-ai-cybersecurity-security-research.md>), [australia](<https://devfeed.tech/tags/australia.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data-architecture](<https://devfeed.tech/tags/data-architecture.md>), [endpoint-security-siem-security](<https://devfeed.tech/tags/endpoint-security-siem-security.md>), [frontier-ai](<https://devfeed.tech/tags/frontier-ai.md>), [policy](<https://devfeed.tech/tags/policy.md>), [research](<https://devfeed.tech/tags/research.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

Frontier AI is accelerating cyberattacks across Australia and New Zealand to machine speed, while defensive capabilities, policy, data visibility, and operational security are struggling to keep pace. Survey findings from more than 850 IT and cybersecurity professionals highlight gaps between regulatory intent and real-world protection, as well as the need for searchable, unified data architectures to support reliable AI-enabled defence.

### Source excerpt

Frontier AI has accelerated cyber threats to machine speed, leaving many ANZ organisations vulnerable. Our latest research reveals how fragmented data and visibility gaps hinder defence and why a unified platform is essential to battle threats.

## Detect vulnerabilities in LLM applications with Datadog's AI-native SAST

DevFeed: [Detect vulnerabilities in LLM applications with Datadog's AI-native SAST](<https://devfeed.tech/articles/detect-vulnerabilities-in-llm-applications-with-datadog-s-ai-native-sast-2229.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/ai-native-sast-detect-llm-vulnerabilities/>)

Author: Jon Green; Bahar Shah

Published: 2026-08-20T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [AI, ML & Data Engineering](<https://devfeed.tech/topics/ai-ml-data-engineering.md>), [ci](<https://devfeed.tech/topics/ci.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [applications](<https://devfeed.tech/tags/applications.md>), [ci](<https://devfeed.tech/tags/ci.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [llm](<https://devfeed.tech/tags/llm.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Datadog describes an AI-native SAST capability for finding LLM-specific application vulnerabilities, including prompt injection, excessive agency, and hidden-context exposure. It uses code context and data-flow reasoning, verifies findings, and surfaces results in pull requests and CI checks.

### Source excerpt

Datadog Code Security's AI-native SAST helps detect vulnerabilities specific to the OWASP Top 10 for LLM Applications before they reach production.

## How to manage risk from unfixed Kubernetes CVEs

DevFeed: [How to manage risk from unfixed Kubernetes CVEs](<https://devfeed.tech/articles/how-to-manage-risk-from-unfixed-kubernetes-cves-2281.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/how-to-manage-unfixed-kubernetes-cves/>)

Author: Mallory Mooney

Published: 2026-08-10T00:00:00Z

Content type: tutorial

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Amazon Elastic Kubernetes Service](<https://devfeed.tech/topics/amazon-elastic-kubernetes-service.md>)

Tags: [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [logs](<https://devfeed.tech/tags/logs.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article explains how to assess exposure to four unfixed Kubernetes CVEs and use audit-log detection queries to investigate relevant activity.

### Source excerpt

Learn how to confirm whether your cluster is exposed to unfixed Kubernetes CVEs and build detection queries using Kubernetes audit logs.

## Normalize security logs to Google SecOps UDM with Observability Pipelines

DevFeed: [Normalize security logs to Google SecOps UDM with Observability Pipelines](<https://devfeed.tech/articles/normalize-security-logs-to-google-secops-udm-with-observability-pipelines-2301.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/observability-pipelines-google-secops/>)

Author: Danielle Park

Published: 2026-07-27T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [amazon-vpc](<https://devfeed.tech/tags/amazon-vpc.md>), [google-cloud](<https://devfeed.tech/tags/google-cloud.md>), [google-secops](<https://devfeed.tech/tags/google-secops.md>), [logs](<https://devfeed.tech/tags/logs.md>), [mapping](<https://devfeed.tech/tags/mapping.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [security](<https://devfeed.tech/tags/security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [vpc-flow-logs](<https://devfeed.tech/tags/vpc-flow-logs.md>)

### AI overview

The article explains how Observability Pipelines Google SecOps packs normalize security logs into the Unified Data Model before they reach Google SecOps.

### Source excerpt

Learn how Observability Pipelines normalizes your telemetry to Google SecOps UDM, enabling both consistent investigations across sources and precise upstream control over your SIEM ingest.

## Runtime security monitoring and threat detection: Protecting production without slowing developers

DevFeed: [Runtime security monitoring and threat detection: Protecting production without slowing developers](<https://devfeed.tech/articles/runtime-security-monitoring-and-threat-detection-protecting-production-without-slowing-developers-12218.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/runtime-security-monitoring-and-threat-detection-protecting-production-without-slowing-developers>)

Author: Ajay Chankramath

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Security](<https://devfeed.tech/topics/security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [internal developer platform](<https://devfeed.tech/topics/internal-developer-platform.md>), [eBPF](<https://devfeed.tech/topics/ebpf.md>), [Network](<https://devfeed.tech/topics/network.md>), [Processes](<https://devfeed.tech/topics/processes.md>)

Tags: [blog-post](<https://devfeed.tech/tags/blog-post.md>), [containers](<https://devfeed.tech/tags/containers.md>), [developer](<https://devfeed.tech/tags/developer.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [firewalls](<https://devfeed.tech/tags/firewalls.md>), [internal-developer-platform](<https://devfeed.tech/tags/internal-developer-platform.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [network](<https://devfeed.tech/tags/network.md>), [platform](<https://devfeed.tech/tags/platform.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [processes](<https://devfeed.tech/tags/processes.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

This article explains how runtime security monitoring protects production workloads from threats that static scans may miss, including privilege escalation, container escapes, unexpected processes, sensitive file access, and suspicious network connections. It presents kernel-level monitoring, including eBPF, as a way to provide continuous protection while embedding security policies into the platform and minimizing developer friction.

### Source excerpt

Runtime security monitoring detects zero-days, container escapes, and privilege escalations in production. Discover how eBPF enables 'invisible, always-on' protection for platform engineers

## Protect AWS Strands Agents with Datadog AI Guard

DevFeed: [Protect AWS Strands Agents with Datadog AI Guard](<https://devfeed.tech/articles/protect-aws-strands-agents-with-datadog-ai-guard-2228.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/ai-guard-aws-strands-agents/>)

Author: Kola Akinnibi; Vijay George; Emmanuelle Lejeail; Alexa Levine

Published: 2026-07-08T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [Strands Agents](<https://devfeed.tech/topics/strands-agents.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [agent observability](<https://devfeed.tech/topics/agent-observability.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agent-observability](<https://devfeed.tech/tags/agent-observability.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [app-api-protection](<https://devfeed.tech/tags/app-api-protection.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [aws](<https://devfeed.tech/tags/aws.md>), [monitor](<https://devfeed.tech/tags/monitor.md>), [orchestration](<https://devfeed.tech/tags/orchestration.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [responses](<https://devfeed.tech/tags/responses.md>), [security](<https://devfeed.tech/tags/security.md>), [strands-agents](<https://devfeed.tech/tags/strands-agents.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [tool](<https://devfeed.tech/tags/tool.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

Datadog AI Guard integrates with AWS Strands Agents through a Strands plugin that evaluates prompts, model responses, and tool interactions during agent execution. It uses Strands lifecycle hooks to monitor or block unsafe behavior, centralize enforcement, and detect multistep attacks in the context of a full agent session.

### Source excerpt

Monitor and help protect AWS Strands Agents by using Datadog AI Guard to evaluate prompts, model responses, and tool calls inline.

## Reduce SAST false positives with agentic evaluation and Bits Memories

DevFeed: [Reduce SAST false positives with agentic evaluation and Bits Memories](<https://devfeed.tech/articles/reduce-sast-false-positives-with-agentic-evaluation-and-bits-memories-2307.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/sast-triage-agentic-evaluation-bits-memories/>)

Author: Cole Maring

Published: 2026-07-06T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [Static code analysis](<https://devfeed.tech/topics/static-code-analysis.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [bits ai](<https://devfeed.tech/topics/bits-ai.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [bits-ai](<https://devfeed.tech/tags/bits-ai.md>), [code](<https://devfeed.tech/tags/code.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [learn](<https://devfeed.tech/tags/learn.md>), [post](<https://devfeed.tech/tags/post.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [tools](<https://devfeed.tech/tags/tools.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

Datadog's Static Code Analysis uses Bits AI agentic evaluation to investigate SAST findings across a repository, combining related code paths, callers, and validators with organization-specific knowledge from Bits Memories. The goal is to distinguish true vulnerabilities from false positives and speed security triage.

### Source excerpt

Learn how Bits AI in Datadog Static Code Analysis uses repository-wide reasoning and custom context to help make security triage faster and more accurate.

## How Artemis Security runs 69x faster detection queries with ClickHouse Cloud

DevFeed: [How Artemis Security runs 69x faster detection queries with ClickHouse Cloud](<https://devfeed.tech/articles/how-artemis-security-runs-69x-faster-detection-queries-with-clickhouse-cloud-4966.md>)

Original publisher: [Read original article](<https://clickhouse.com/blog/artemis-security-real-time-threat-detection>)

Author: ClickHouse

Published: 2026-07-01T13:47:42Z

Content type: article

Language: en

Sources: [ClickHouse Blog](<https://devfeed.tech/sources/clickhouse-blog.md>)

Topics: [Security Attacks](<https://devfeed.tech/topics/security-attacks.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [AI, ML & Data Engineering](<https://devfeed.tech/topics/ai-ml-data-engineering.md>), [debugging](<https://devfeed.tech/topics/debugging.md>), [cpu](<https://devfeed.tech/topics/cpu.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [analytics](<https://devfeed.tech/tags/analytics.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [claude](<https://devfeed.tech/tags/claude.md>), [clickhouse](<https://devfeed.tech/tags/clickhouse.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cpu](<https://devfeed.tech/tags/cpu.md>), [data](<https://devfeed.tech/tags/data.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [json](<https://devfeed.tech/tags/json.md>), [logs](<https://devfeed.tech/tags/logs.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [security](<https://devfeed.tech/tags/security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

Artemis Security uses ClickHouse Cloud for real-time threat detection over large volumes of log and telemetry data. The article reports faster detection and investigative queries through query coalescing and materialized JSON-field extraction.

### Source excerpt

Artemis Security cut detection query times 69x and investigative lookups up to 60x using ClickHouse query coalescing, materialized extraction, and AI-powered debugging with Claude.

## Preparing for OMB M-26-14: How Datadog supports federal logging maturity

DevFeed: [Preparing for OMB M-26-14: How Datadog supports federal logging maturity](<https://devfeed.tech/articles/preparing-for-omb-m-26-14-how-datadog-supports-federal-logging-maturity-2302.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/omb-m-26-14-federal-logging-maturity/>)

Author: Chris Leffler; Sophie Wang

Published: 2026-06-29T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Security](<https://devfeed.tech/topics/security.md>), [Security Operations Center](<https://devfeed.tech/topics/security-operations-center.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [bits-ai](<https://devfeed.tech/tags/bits-ai.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [govcloud](<https://devfeed.tech/tags/govcloud.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [observability](<https://devfeed.tech/tags/observability.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [security-operations-center](<https://devfeed.tech/tags/security-operations-center.md>), [soc](<https://devfeed.tech/tags/soc.md>), [systems](<https://devfeed.tech/tags/systems.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [workflow-automation](<https://devfeed.tech/tags/workflow-automation.md>)

### AI overview

This article explains how OMB Memorandum M-26-14 changes federal logging guidance from prescriptive requirements to a risk- and maturity-based model. It describes continuous event monitoring and threat hunting, investigation, response, and forensics, including centralized security telemetry, visibility across IT, OT, and IoT environments, threat detection, searchable and retrievable logs, cross-source correlation, incident response, and forensic analysis. It also presents Datadog as a unified observability and security platform for helping agencies meet these requirements.

### Source excerpt

Learn how Datadog helps federal agencies prepare for OMB M-26-14 by providing centralized telemetry data, threat detection, and automated incident response.

## Automatically enrich security logs with MITRE ATT&CK context before they reach your SIEM

DevFeed: [Automatically enrich security logs with MITRE ATT&CK context before they reach your SIEM](<https://devfeed.tech/articles/automatically-enrich-security-logs-with-mitre-att-ck-context-before-they-reach-your-siem-2291.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/mitre-attack-enrichment-packs-observability-pipelines/>)

Author: Danielle Park

Published: 2026-06-24T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [observability pipelines](<https://devfeed.tech/topics/observability-pipelines.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [aws](<https://devfeed.tech/tags/aws.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [log-management](<https://devfeed.tech/tags/log-management.md>), [logs](<https://devfeed.tech/tags/logs.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [network](<https://devfeed.tech/tags/network.md>), [observability](<https://devfeed.tech/tags/observability.md>), [observability-pipelines](<https://devfeed.tech/tags/observability-pipelines.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

This article explains how Observability Pipelines uses MITRE ATT&CK Enrichment Packs to automatically map security logs and events to common attacker tactics and techniques before they reach a SIEM, data lake, or archive. It describes the initial packs for Okta, Palo Alto, FortiGate, and AWS WAF, covering identity, firewall, network, and web security activity.

### Source excerpt

Learn how Observability Pipelines enriches security logs with MITRE ATT&CK tactics and techniques before routing them to your SIEM or storage destination.

## Automate threat hunting with Datadog Cloud SIEM

DevFeed: [Automate threat hunting with Datadog Cloud SIEM](<https://devfeed.tech/articles/automate-threat-hunting-with-datadog-cloud-siem-2237.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/bits-threat-hunting/>)

Author: Vera Chan; Sean Storer

Published: 2026-06-09T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [AI Bots](<https://devfeed.tech/topics/ai-bots.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [cloud-siem](<https://devfeed.tech/tags/cloud-siem.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [logs](<https://devfeed.tech/tags/logs.md>), [security](<https://devfeed.tech/tags/security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

Datadog introduces Bits Threat Hunting, an autonomous Cloud SIEM agent that performs AI-driven, hypothesis-based searches of telemetry to identify attacker behavior and deviations before alerts fire.

### Source excerpt

Learn how Bits Threat Hunting helps security teams proactively identify attacker behavior with AI-driven, hypothesis-based threat hunting.

## Detect source code attacks with Datadog Code Threat Detection

DevFeed: [Detect source code attacks with Datadog Code Threat Detection](<https://devfeed.tech/articles/detect-source-code-attacks-with-datadog-code-threat-detection-2258.md>)

Original publisher: [Read original article](<https://www.datadoghq.com/blog/datadog-code-threats/>)

Author: Kassen Qian; Daniel Blazquez; Christoph Hamsen

Published: 2026-06-09T00:00:00Z

Content type: article

Language: en

Sources: [Datadog | The Monitor blog](<https://devfeed.tech/sources/datadog-the-monitor-blog.md>)

Topics: [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [review](<https://devfeed.tech/tags/review.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Datadog Code Threat Detection analyzes GitHub pull requests with AI-assisted analysis to identify malicious code changes and attempts to compromise CI/CD pipelines, secrets, and release workflows.

### Source excerpt

Learn how Datadog Code Threat Detection helps teams detect malicious pull requests and source code attacks targeting CI/CD workflows, secrets, and software releases.

## How to Design SIEM Alerts for Real-Time Application Security Monitoring

DevFeed: [How to Design SIEM Alerts for Real-Time Application Security Monitoring](<https://devfeed.tech/articles/siem-alerts-everything-you-need-to-know-20056.md>)

Original publisher: [Read original article](<https://www.honeybadger.io/blog/siem-alerts/>)

Author: Muhammed Ali

Published: 2026-05-21T07:00:00Z

Content type: tutorial

Language: en

Sources: [Honeybadger](<https://devfeed.tech/sources/honeybadger.md>)

Topics: [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [real-time](<https://devfeed.tech/topics/real-time.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devops-articles](<https://devfeed.tech/tags/devops-articles.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [security](<https://devfeed.tech/tags/security.md>), [security-events](<https://devfeed.tech/tags/security-events.md>), [siem](<https://devfeed.tech/tags/siem.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

This tutorial explains SIEM alerts, their role in application security, and how SIEM platforms aggregate and correlate logs and security events to identify suspicious behavior. It also provides practical alert examples and describes configuring simple alerts with Honeybadger Insights.

### Source excerpt

SIEM alerts help you detect suspicious behavior before it becomes a breach. But security monitoring can quickly turn into noisy dashboards and missed threats without the right approach. Read this article to learn how to design effective SIEM alerts and implement real-time security monitoring.

## What's New in Android Security and Privacy in 2026

DevFeed: [What's New in Android Security and Privacy in 2026](<https://devfeed.tech/articles/what-s-new-in-android-security-and-privacy-in-2026-7635.md>)

Original publisher: [Read original article](<https://blog.google/security/whats-new-in-android-security-privacy-2026/>)

Author: Eugene Liderman

Published: 2026-05-12T17:00:00Z

Content type: article

Language: en

Sources: [Security](<https://devfeed.tech/sources/security.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [Android Security](<https://devfeed.tech/topics/android-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [On-device AI](<https://devfeed.tech/topics/on-device-ai.md>), [Chrome](<https://devfeed.tech/topics/chrome.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [android-security](<https://devfeed.tech/tags/android-security.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [none](<https://devfeed.tech/tags/none.md>), [on-device-ai](<https://devfeed.tech/tags/on-device-ai.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

The article describes planned Android security and privacy enhancements for 2026, including verified financial calls to combat spoofed banking scams. Android can verify incoming calls through participating financial apps and automatically end calls that are not genuine. It also highlights expanded Live Threat Detection, which uses on-device AI to analyze app behavior and warn about suspicious activity.

### Source excerpt

New Android security and privacy features

## Latacora Achieves AWS Advanced Tier Services Partner Status

DevFeed: [Latacora Achieves AWS Advanced Tier Services Partner Status](<https://devfeed.tech/articles/latacora-achieves-aws-advanced-tier-services-partner-status-29190.md>)

Original publisher: [Read original article](<https://www.latacora.com/blog/2026/01/27/aws-advanced-tier-status/>)

Published: 2026-01-27T21:00:00Z

Content type: release

Language: en

Sources: [Latacora](<https://devfeed.tech/sources/latacora.md>)

Topics: [Amazon Web Services (AWS)](<https://devfeed.tech/topics/amazon-web-services-aws.md>), [Security & compliance, Cloud security](<https://devfeed.tech/topics/security-compliance-cloud-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>)

Tags: [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [iam](<https://devfeed.tech/tags/iam.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

Latacora announces that it has achieved Amazon Web Services (AWS) Advanced Tier Services Partner status within the AWS Partner Network. The company says the designation reflects validated technical expertise, AWS-certified professionals, and a proven record of customer success in cloud security and compliance.

### Source excerpt

We are thrilled to announce a major milestone for Latacora: we have achieved the Amazon Web Services (AWS) Advanced Tier Services Partner status within the AWS Partner Network (APN). This designation reflects Latacora's technical expertise and diligence in delivering exceptional cloud security and compliance solutions to our clients, and confirms that we have successfully completed a rigorous validation process demonstrating a proven track record of customer success delivered by a team of AWS-certified professionals with specialized technical capabilities.

## ESET Threat Report H2 2025

DevFeed: [ESET Threat Report H2 2025](<https://devfeed.tech/articles/eset-threat-report-h2-2025-8366.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-threat-report-h2-2025/>)

Author: Jiří Kropáč

Published: 2025-12-16T09:50:45Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Android](<https://devfeed.tech/topics/android.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [malware](<https://devfeed.tech/tags/malware.md>), [nfc](<https://devfeed.tech/tags/nfc.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

ESET's H2 2025 threat report describes rapid changes in the threat landscape, including the emergence of AI-driven malware such as PromptLock, major shifts in malware distribution, growth in ransomware activity, and increasingly sophisticated Android NFC threats.

### Source excerpt

A view of the H2 2025 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts

[Next page](<https://devfeed.tech/tags/threat-detection.md?cursor=WyIyMDI1LTEyLTE2VDA5OjUwOjQ1KzAwOjAwIiwgIjExYmQ0NGJjLThjNTYtNDBiMS1iMDFkLWU2OTUxZjRkNjc2NyJd>)