Google researchers say bad actors are deploying novel AI tools for operations, using LLMs to develop malware, and selling illicit models on underground forums.
Trellix has integrated its Helix security operations platform with Hyperautomation, which will help SOC teams automate investigations, enrich threat context, and accelerate response.
New integration feeds verified runtime data from Contrast’s ADR platform into Microsoft Sentinel, giving SOC teams and MSSPs real-time visibility into active exploits inside production applications.
Graylog’s Fall 2025 release introduces explainable AI, secure MCP access, and AWS Security Data Lake integration to help SOCs detect threats faster and manage data more efficiently.