SANS Cybersecurity Blog
Blog
Actions
Media Outlet details
| Scope | Trade/B2B |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesThe Security Autonomy Matrix: Deciding What Your AI Agents May Do on Their Own
As security leaders, we are deciding, workflow by workflow, how much work to hand to AI and how independently it may act. Consider an AI agent that removes phishing messages from user mailboxes. It can safely read every mailbox, yet one wrong deletion can permanently remove a legitimate message. Should that agent delete messages on its own, or should a person approve each deletion? The Security Autonomy Matrix helps security leaders make these decisions deliberately and capture them in one place.
From Alerts to Adversaries: A Pragmatic Guide to Launching (and Maturing) Your Threat Hunting Program
If your security team is still waiting for an alert before it starts investigating, you’re playing the reactive game. Threat hunting flips that script — it puts humans in the loop to proactively find threats tools miss and to continually harden and improve your environment with every iteration. What is Threat Hunting ? A lot of people and companies have tried to create a definition for threat hunting.
The Role of AI in Cybersecurity
Nearly every layer of how attackers operate and how organizations defend themselves leverages applied artificial intelligence. While this has been true for years with simpler incarnations of AI, ongoing developments in speed, scale, autonomy, and complex reasoning have dramatically expanded the role of AI in cybersecurity.
The Idaho Murders: Remembering Kaylee, Xana, Maddie, and Ethan
Now that Netflix has aired, the same questions keep coming in from media, family, friends, and strangers online: Why did we get this case? Did we find his motive? Will we be called back if he gets a trial? Did Netflix pay us, and what did we make on the case over 1.5 years? Easy one first: Nobody paid us. Not Netflix, not the families, not the state of Idaho. We worked this case for free. "We" includes, my husband Jared, and our companies, SANS and Cellebrite.
VulnOps: A CISO’s Guide to Starting Implementation
For years, a green remediation dashboard has been the number one item security leaders take into a board meeting: tickets closed on time, service level agreements met, and a program that, by those measures, appeared to be working. Those metrics are now measuring the wrong thing. They track how fast a team closes tickets but say very little about how much exploitable exposure is still live in the environment, or for how long.
Nine Questions That Tell You Whether Your Team Could Handle an AI-Run Attack
An AI agent recently ran a four-day autonomous attack against a real company. This was an actual intrusion, in which the agent independently conducted reconnaissance, gains access, and moved lateral through a production environment defended by a real security team. That team survived it, then did something rare in this industry: they talked openly about what went wrong. One line from the team’s debrief has stuck with everyone who heard it: "There were alerts. They did not rise to the right level.
Mythos: Forget the Model. Follow the Workflow.
In early April 2026, Anthropic announced Claude Mythos Preview, a model initially restricted to vetted partners through a private partnership with selected security companies, called Project Glasswing. Mythos was pitched as a frontier system built specifically for autonomous cyber operations, including writing offensive code, identifying exploits, and finding vulnerabilities. Selected companies were able to test and experiment with Mythos across various security topics.
Beyond the Security Stack: The Governance Toolkit Every CISO Needs
Ask someone to describe a CISO's toolkit and the conversation almost always starts with security technology. SIEMs, EDR platforms, vulnerability scanners, and threat intelligence services dominate the discussion. They're all important, but they're not what fills the day of the average security leader. The longer you spend in the role, the more you realise that being a CISO is less about operating security tools and more about operating a business function.
"Stop Freaking Out and Start Fixing Things": Five Takeaways From the SANS Panel on the OpenAI / Hugging Face Breach
On Tuesday, SANS hosted a live community panel on the OpenAI / Hugging Face breach, titled "The Sandbox Let It Out. The Guardrails Locked Us Out.", in partnership with the Cloud Security Alliance. Ed Skoudis, President of the SANS Technology Institute, moderated, with James Lyne, CEO of the SANS Institute; Ciaran Martin, Director of the SANS Cyber Leaders Network; Rob T.
Stay Ahead of Ransomware: The Evolution from Encryption to Extortion
On the July episode of SANS Stay Ahead of Ransomware livestream, we explored a significant shift in the threat landscape: ransomware operators are increasingly abandoning encryption in favor of data theft and extortion-only attacks.