top of page
Blog, Press, Updates and More.


Beyond the Patch: Why Behavioral Analysis is the Only Cure for the Linux Zero-Day Wave
It is not you, it is a Linux Zero-Day Avalanche The long-held illusion of inherent Linux security has shattered. The operating system isn't taking a beating from a wave of new malware—it is being structurally dismantled by an avalanche of zero-day vulnerabilities unearthed by agentic AI. For years, a dangerous myth persisted across many IT departments: Linux is secure by default. Because commodity malware and phishing historically targeted Windows endpoints, Linux systems, th
Joseph Ghaziri
Aug 44 min read


The Skepticism Gap: Why Autonomous AI Agents Are Easily Exploited
How an AI based Search can turn a mundane task like searching for the best food for my cat can Hijack Your Identity As organizations rush to deploy autonomous AI agents to manage daily workflows, a critical flaw in how these models process data has opened a dangerous new exploit vector: Indirect Prompt Injection. For decades, basic human skepticism has been our strongest frontline defense. If a regular user scrolls through an online forum like Reddit and spots an out-of-conte
Joseph Ghaziri
Aug 43 min read


How Sentio SIEM can help you achieve your ISO27001
Deploying a SIEM (Security Information and Event Management) system within your infrastructure provides immense value and helps you check off critical requirements during an ISO 27001 certification audit. A robust SIEM drives compliance by extracting actionable value from the logs you already collect and store. Benefits of Deploying Sentio SIEM Centralized Environment: Sentio SIEM serves as a centralized housing for all your logs. It seamlessly ingests data from mainstream so
Emanuel Falzon
Aug 43 min read


Inside the Enterprise Risk Profile of Residential Proxies
On July 2nd, 2025, a user known as 'Admirable-Raccoon597' on reddit claims to have downloaded a mouse configuration tool from their official website. Upon noticing suspicious activity, they investigated further and discovered that the software contained a hidden trojan identified as 'Synaptics.exe'. This incident was not isolated; another user reported finding similar malware embedded within the software for another gaming mouse utility tool. Talk about a mouse becoming a RAT
Pranav Kalidas
Aug 43 min read


FortiGate Devices in the Crosshairs: What Organizations Need to Know and Do Now
FortiGate Devices Under Increased Attack: What Organizations Need to Know Over the past several months, Fortinet customers have faced a series of security incidents involving FortiGate firewalls. Recent campaigns have demonstrated how quickly threat actors can move from initial access to full administrative control of a device, often creating unauthorized accounts, modifying firewall configurations, and establishing persistent access before organizations realize they have bee
Stanislav Stoychev
Jun 243 min read


The Compounding Advantage: Why the Best Security Automation Requires Human Correlation
Automated scale with human insight to build an evolving defense Let’s say it’s 10:00 PM Friday. A User opens a Phishing email before finishing work for the day. Ten minutes later, automated malicious tools breach the account and begin aggressively downloading the organization’s entire mailbox infrastructure. If enterprise relies strictly on manual tracking, security operations center (SOC) won't see this activity until they log in at 9:00 AM on Monday morning. Because modern
Nootan Ranga Nayak
Jun 243 min read


A reality check for SOC teams relying blindly on geographic log parameters
Predictable Local Activity May Reduce Analyst Vigilance For SOC analysts who spend their days triaging Microsoft 365 login events, the daily routine often falls into a predictable pattern. Security teams often implement a binary triage logic: local logins are automatically marked as benign, while foreign logins undergo a deeper analysis verification. This creates a dangerous security gap. Logins from local IP: Check the sign-in IP \rightarrow If it’s a local IP \rightarrow Cl
Emanuel Falzon
Jun 243 min read


Why root access is no longer the end of an attack
A Linux system is running normally, with no alerts, no suspicious activity, and nothing out of place. Somewhere in the background, however, a low-privileged account exists on that machine, this could be a compromised user, a container escape, or simply reused credentials that were never rotated. At some point, that access is used, not to deploy malware or trigger alarms, but simply to execute a small piece of code that blends into normal activity. Moments later, the attacker
Brandon Spiteri
Jun 243 min read


Why Session Tokens Are the Ultimate Threat Vector
How adversaries bypass Multi-Factor Authentication and the continuous analytics required to stop them. For years, organizations relied on a singular security gospel: enforce strong passwords, enable Multi-Factor Authentication (MFA), and your cloud environments are secure. For a long time, this layer of defense worked efficiently by neutralizing bulk credential stuffing and basic phishing campaigns. However, the threat landscape has shifted dramatically, and sophisticated adv
Joseph Ghaziri
May 254 min read


How to Think Like an Investigator Instead of an Alert Reviewer
Security incidents are solved through context and correlation - not alert queues. Most SOC environments are optimized for speed. Analysts are measured by ticket closures, SLA adherence, and alert throughput. On paper, that sounds efficient. In practice, it creates a dangerous habit: reviewing alerts instead of investigating incidents. An alert is not an investigation. It is a signal that something may require attention. Yet many security teams treat alerts as isolated tasks i
Andy Urlep
May 254 min read


Securing the Mind: How Cyber Reasoning Systems Are Rewriting the Attack Surface
A deep dive into the operational shift from patching static vulnerabilities to validating autonomous system logic. To understand how Cyber Reasoning Systems (CRS) are rewriting the attack surface, you first need to shift how you think about “what is being attacked.” At CyberSift, telemetry shows that Security Operations Center (SOC) analysts are increasingly interacting with CRS framework architectures, and their daily work is already being shaped by it. Instead of drowning u
Joseph Ghaziri
May 253 min read


The 2026 Reality Check: Is Your DORA Compliance Hiding a "Resilience Debt"?
A blunt reality check for financial institutions transitioning from checklist compliance to operational maturity. It’s been over a year since the Digital Operational Resilience Act (DORA) became fully applicable. For many financial institutions, 2025 was a year of frantic patching, manual spreadsheet mapping, and "checking the box" to meet the deadline. But as we settle into 2026, a new crisis is emerging: Resilience Debt. What is Resilience Debt? Just like "Technical Debt" i
Timothe Toulain
May 254 min read


Shadow AI: The Security Risk of the Productivity Shortcut
A pragmatic guide to turning employee-driven telemetry blind spots into manageable, secure visibility. In the past, "Shadow IT" meant an employee bringing their own laptop to the office or installing an unauthorized piece of software to get their work done. Today, that trend has evolved into something much faster and more difficult to track: Shadow AI. At CyberSift, one of our motto is "you can't protect what you can't see." Shadow AI isn't just a policy violation; it's a ma
Timothe Toulain
May 254 min read


Linux Privilege Escalation Is a Visibility Problem
Recent Linux LPE vulnerabilities highlight how limited telemetry delays detection and response. Linux systems sit at the center of modern infrastructure. They run production workloads, cloud platforms, development environments, and critical internal services. Because of that, they are often seen as stable and trustworthy by default. Recent Linux privilege escalation vulnerabilities, including Fragnesia (CVE-2026-46300), Dirty Frag (CVE-2026-43284, CVE-2026-43500), and Copy F
Stanislav Stoychev
May 254 min read


From Alerts to Hours: The Hidden Cost of Noise
Over 1 Million Alerts — What’s Behind That Number? Over the last 7 days, this environment generated 1,107,211 alerts. At first glance, that sounds like strong security coverage. But here’s the reality: More alerts don’t mean more protection — they often mean more noise. The real question is not how many alerts were generated, but: How many of these actually matter? Use Case: SMB to Public IP To understand how this pattern behaves across the environment, we zoomed into a speci
Andy Urlep
Apr 293 min read


The Token is the Perimeter: Why OAuth is the New Frontier
The recent supply chain breach at Vercel highlights a critical blind spot: once an attacker hijacks a valid OAuth token, they don’t need to crack your password, they simply inherit your trust and walk right past your MFA No password is needed No MFA challenge is triggered No anomalous login event is created while the user is accepted Once a session token is issued, access is governed by the token alone, completely detached from the factors that created it. This is what an OAu
Pranav Kalidas
Apr 282 min read


Threat actors don't need your password or MFA to compromise your users
Cybersift is observing a modern type of phishing attacks on Office 365 users which deviate from the typical fake login web page, we analysts are typically accustomed to seeing. The new phishing attack utilizes device registration to compromise the victim’s account, meaning that the threat actor does not require to steal your password to gain entry. But this modern phishing attack is smarter than you might think. Case Study We analyzed a phishing email which utilized a device
Emanuel Falzon
Apr 283 min read


Deconstructing the Tor Exit Node Attack on Microsoft
Introduction As the digital backbone for millions of enterprises, Microsoft Office 365 has become the primary option for modern identity-based warfare. Today’s attackers don't just "log in" they meticulously craft digital fingerprints to mirror legitimate employees, attempting to slip past automated defense unnoticed. This analysis explores a high-severity incident where a corporate account was compromised through a combination of network anonymization and device metadata man
Nootan Ranga Nayak
Apr 282 min read


Detection Through Deception: Where It Fits in a Modern SOC Strategy
The visibility problem we keep running into Most SIEM deployments follow a familiar pattern: collect logs, apply rules, generate alerts. That approach works, but it starts to break down in one area we regularly see during investigations - telling the difference between legitimate activity and attacker behavior when both look the same. Attackers are no longer relying on obviously malicious tools. They use valid credentials, built-in admin utilities, and approved access paths.
Stanislav Stoychev
Apr 283 min read


Why SIEMs Need Strong Detection Engineering and How We Approach It at CyberSift
There is a recurring assumption in many environments: if the SIEM is properly configured, detection is “solved.” In reality, SIEMs don’t detect threats - they execute logic. And that logic is only as good as the assumptions behind it. What we consistently observe in real-world incidents is not a lack of SIEM coverage, but a lack of detection engineering discipline. At CyberSift, this is one of the core areas we continuously invest in: expanding, validating, and maintaining de
Stanislav Stoychev
Apr 282 min read
bottom of page
