Press Release

Press Release: Critical Start Delivers SOC AI

Critical Start has released SOC AI, a production-proven framework of ten specialized agents that brings auditable, AI-led investigation, hunting, and response to MDR. Every action carries a complete audit trail, and the platform's deterministic foundation keeps the SOC at full capacity even if AI is ever unavailable.
June 2, 2026
Threat Intel

CRITICALSTART® Security Advisory: Strategic Phishing Campaigns Leverage CAPTCHA and Email Routing Misconfigurati

Attackers are combining fake CAPTCHA "verification" workflows with email routing misconfigurations to impersonate internal senders — a layered social engineering approach driving credential theft, session token compromise, and persistent access across Windows and macOS environments.
CRU
May 22, 2026
5 min read
Case Study

Disabling the Shield: AV Evasion Techniques

When an attacker tried to weaken Microsoft Defender across a customer's production Azure environment, Critical Start's SOC caught it, reversed it, and shut the door — all in 28 minutes.
Critical Start
May 15, 2026
3 min read
No Asterisk, Ep4: Improving Your Microsoft Security Posture: From Risk to Resilience
Webinar

No Asterisk, Ep4: Improving Your Microsoft Security Posture: From Risk to Resilience

83% of security professionals experience breaches despite having tools in place — often due to simple misconfigurations. In this webinar, Critical Start's Field CISO Tim Bandos demonstrates PAT, a free tool that analyzes your entire Microsoft security stack, identifies gaps across identity, endpoint, email and cloud, and shows you exactly what to fix and why.
Tim Bandos
April 17, 2026
[CS-TR-26-0401] The Hidden Threat of Unmanaged Machine Identities in Enterprises
Threat Intel

[CS-TR-26-0401] The Hidden Threat of Unmanaged Machine Identities in Enterprises

68% of breaches now involve machine identities. Discover why unmanaged NHIs are your biggest blind spot—and how to secure them.
April 1, 2026
Threat Intel

[CS-SA-26-0305] Security Advisory on Axios NPM Compromise

A maintainer account hijack pushed two malicious Axios versions carrying a cross-platform RAT to 83M weekly downloads — attributed with high confidence to DPRK's BlueNoroff/Lazarus Group.
Critical Start Cyber Research Unit
March 31, 2026
12 min read