Critical Start has released SOC AI, a production-proven framework of ten specialized agents that brings auditable, AI-led investigation, hunting, and response to MDR. Every action carries a complete audit trail, and the platform's deterministic foundation keeps the SOC at full capacity even if AI is ever unavailable.
Attackers are combining fake CAPTCHA "verification" workflows with email routing misconfigurations to impersonate internal senders — a layered social engineering approach driving credential theft, session token compromise, and persistent access across Windows and macOS environments.
When an attacker tried to weaken Microsoft Defender across a customer's production Azure environment, Critical Start's SOC caught it, reversed it, and shut the door — all in 28 minutes.
83% of security professionals experience breaches despite having tools in place — often due to simple misconfigurations. In this webinar, Critical Start's Field CISO Tim Bandos demonstrates PAT, a free tool that analyzes your entire Microsoft security stack, identifies gaps across identity, endpoint, email and cloud, and shows you exactly what to fix and why.
A maintainer account hijack pushed two malicious Axios versions carrying a cross-platform RAT to 83M weekly downloads — attributed with high confidence to DPRK's BlueNoroff/Lazarus Group.