Binary Defense
Corporate/Government Newsroom
With 86,400 seconds in a day, you need a trusted security partner to shield you for every single one. At Binary Defense, that’s the promise we make to our clients. We know that the best cybersecurity protection for your business takes a team of real people detecting real threats in real time. Source
Actions
Media Outlet details
| Scope | Consumer |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesBinary Defense Names Industry Veteran Rafal Los as Chief Strategy Officer
CLEVELAND – July 28, 2026 – Binary Defense, the trusted Managed Detection and Response (MDR) and enterprise defense provider, today announced the appointment of Rafal Los as Chief Strategy Officer. In this role, Los will report directly to CEO and Founder David Kennedy and lead market-facing strategy across sales, sales engineering, customer success, marketing, channel, and technology alliances while helping expand Binary Defense's voice across the broader cybersecurity community.
The Queue Was Never the Job
Walk into almost any security operations center and the first thing you'll see is a queue. A list of alerts, ranked by severity, waiting for a human to work them from the top. The whole operation is organized around emptying that list faster than it fills. We hire against it, we build shift schedules around it, we measure analysts on how quickly they acknowledge and close it. For about twenty years, the queue has been the job. Start with the arithmetic, because it's brutal.
The Analyst's New Job Description
The Tines 2025 Voice of the SOC Analyst report found that 71% of SOC analysts report burnout and 64% are considering leaving within the year. The SANS 2025 SOC Survey found that satisfaction with generative AI tools ranks last among SOC technologies. Those two numbers tell the same story from different angles. The analyst job is being squeezed between two pressures. The deterministic work is moving to agents, which is good, because that's where most of the burnout was coming from.
BLUERABBIT: A Golang-Based Backdoor with Ransomware and Destructive Capabilities
A full-featured backdoor with file encryption, drive wiping, and a C2 channel that looks like normal message broker traffic. Meet BLUERABBIT, this Golang-based backdoor, attributed to a likely Iran-nexus threat actor, routes its command-and-control through RabbitMQ (AMQP) for tasking, Redis for state management, and MinIO for S3-compatible data exfiltration.
Machines Triage. Humans Decide.
The AI-orchestrated cyberespionage campaign that Anthropic disclosed in late 2025, the most agentic offensive operation publicly documented, required humans at four to six decision points per campaign. The attackers had every incentive to run the operation fully autonomously. They kept humans in the loop anyway, for the calls that mattered. They knew where the AI couldn't be trusted to decide. That same structural question is the one defenders have to answer.
Attackers Went Agentic First
Mandiant's M-Trends 2026 report puts the median time from initial access to handoff to a secondary threat group at 22 seconds in 2025. In 2022, that same median sat above eight hours. What changed is not that attackers got smarter. What changed is that initial access brokers started pre-staging secondary group malware before the handoff, turning what used to be a marketplace transaction into an automated delivery pipeline. The number is a readout on an assembly line, not a creativity contest.
The Metric to Anchor Your Agentic SOC Evaluation On
AI is fundamentally changing how we run security operations. I see it inside our own SOC every day. Analysts are going deeper on the work that matters because the routine work moves faster. The agentic wave is the next step in that change, and there's real promise in it. But the way the industry evaluates agentic SOC products hasn't caught up with what those products are doing. That's the gap I want to walk through here. The category is moving fast and the technology is genuinely impressive.
Chasing Phantoms: How a Multi-Stage Stealer Abuses Signed Binaries to Disappear
Information stealers continue to be one of the most prolific and damaging malware categories facing organizations today. They are fast, lightweight, and purpose-built to siphon credentials, session tokens, and financial data before defenders have time to respond.
Remote Support to Ransomware Foothold: Stopping a Pre-Ransomware Intrusion
The Difference Between an Alert and a Detection Most of what this attacker did looked completely normal. They authenticated with valid credentials. They accessed systems through a trusted remote support platform. They ran tools that IT administrators use every day. Individually, none of it would have raised a flag worth acting on. That's the point.
How NightBeacon Cuts SOC Alert Fatigue Without Replacing Analysts
The Problem Every SOC Is Living With Every SOC analyst knows the feeling. The queue is full. The alerts keep coming. And the vast majority of them, sometimes 90% or more, turn out to be nothing. False positives are the silent tax on every security operation. They burn time, erode trust in tooling, and create the exact kind of fatigue that lets real threats slip through. It's not a people problem. The analysts are good.