惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Threat Research - Cisco Blogs
Google DeepMind News
Google DeepMind News
H
Help Net Security
H
Hackread – Cybersecurity News, Data Breaches, AI and More
MyScale Blog
MyScale Blog
Webroot Blog
Webroot Blog
Stack Overflow Blog
Stack Overflow Blog
T
The Blog of Author Tim Ferriss
D
Docker
L
LangChain Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Know Your Adversary
Know Your Adversary
A
About on SuperTechFans
U
Unit 42
NISL@THU
NISL@THU
M
MIT News - Artificial intelligence
T
The Exploit Database - CXSecurity.com
K
Kaspersky official blog
Martin Fowler
Martin Fowler
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Hacker News - Newest:
Hacker News - Newest: "LLM"
Engineering at Meta
Engineering at Meta
Blog — PlanetScale
Blog — PlanetScale
Scott Helme
Scott Helme
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 【当耐特】
WordPress大学
WordPress大学
Attack and Defense Labs
Attack and Defense Labs
P
Proofpoint News Feed
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
TaoSecurity Blog
TaoSecurity Blog
B
Blog RSS Feed
小众软件
小众软件
G
Google Developers Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
S
SegmentFault 最新的问题
博客园 - 司徒正美
腾讯CDC
大猫的无限游戏
大猫的无限游戏
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Application and Cybersecurity Blog
Application and Cybersecurity Blog
S
Security @ Cisco Blogs
aimingoo的专栏
aimingoo的专栏
W
WeLiveSecurity
V
Vulnerabilities – Threatpost
N
News and Events Feed by Topic
Google Online Security Blog
Google Online Security Blog
Cisco Talos Blog
Cisco Talos Blog
C
Check Point Blog

Search Security Resources and Information from TechTarget

How to operationalize threat modeling with AI | TechTarget CISO First fully agentic ransomware attack sparks readiness concerns | TechTarget Evaluating secure enterprise browsers vs. security plugins | TechTarget The AI vulnerability storm is here: Is your security program ready? | TechTarget Perimeter to posture: A roadmap to zero trust maturity | TechTarget TLS certificate lifetime changes: What CISOs must do now | TechTarget The agentic AI 8 key aspects of a mobile device security audit program | TechTarget Why mobile security audits are important in the enterprise | TechTarget Beyond the perimeter: The shift to data-centric protection | TechTarget How to conduct a mobile app security audit | TechTarget NO FAKES Act advances: What CISOs need to know | TechTarget What CISOs should know about AI runtime security | TechTarget As Q-Day looms, 90% of systems are unprepared for PQC | TechTarget A CISO Most security pros say their culture is Zscaler lays out its vision to secure the AI era at Zenith Live | TechTarget The OpenClaw security risks every CISO needs to know | TechTarget Cloud security metrics and KPIs: A CISO Florida public sector training on SimSpace cyber range: Case study | TechTarget Reporters' Notebook — Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security It's time to update incident response for the AI era How to build AI security guardrails without blocking innovation The prosecution gap: Why cybercrimes go unpunished AI in cyberdefense: Learning from threat actors' playbooks Top identity and access management risks CISO role changes as cyber-risk appetites in the C-suite grow CISO's guide to data minimization Researchers build autonomous AI worm that can reason and adapt How to secure data at rest, in use and in motion How to find cyber-risk data sources for a FAIR analysis Lost in translation: Cybersecurity board reporting for CISOs How to prepare security controls for future AI regulations EO 14390 raises stakes for enterprise cybersecurity First month of Mythos Preview testing exposes 10K flaws OT attacks shift from recon to physical control, raising stakes For CISOs, dawn of OpenAI Daybreak brings good and bad news Gartner Security & Risk Management Summit 2026: Adapting for AI | TechTarget Inside business email compromise attacks: Real-world examples Verizon 2026 DBIR: 6 key takeaways for CISOs Identity security for AI agents: The proliferation challenge How to build a business impact analysis checklist Taking care of business: The CISO's role in a cyber crisis What CISOs need to know about AI audit logs SOC vs. MDR: What CISOs need to consider Instructure cyberattack reignites ransom payment debate Transform SIEM rules with behavior-based threat detection CISO's guide: How to test an incident response plan How to implement zero trust for AI Data after the breach: Economics of the dark web The breakup: Why CISOs are decoupling data from their SIEMs | TechTarget News brief: Security worries and warnings as AI use expands How to construct an effective security controls evaluation 5 leading enterprise password managers to consider Claude Mythos changes the AI security threat matrix Buyer 6 things to check in your cyber insurance policy fine print How cyber insurance helped with breach recovery -- or not News brief: Critical infrastructure, OT cybersecurity attacks Tape's strategic role in modern data protection Top zero-trust use cases in the enterprise What every CISO should consider before a SIEM migration CISO's guide to centralized vs. federated security models Shadow code: The hidden threat for enterprise IT How to fix cybersecurity's agentic AI identity crisis 5 top SIEM use cases in the enterprise Top 8 e-signature software providers for 2026 How do digital signatures work? News brief: AI woes continue for security leaders Deepfake era demands proof-based security, not just awareness Is SOAR dead or alive? Sort of The push for digital sovereignty: What CISOs need to know Beyond awareness: Human risk management metrics for CISOs Cybersecurity in the age of AI means bigger, faster threats At RSAC 2026, AI optimism and anxiety -- and an MIA U.S. government Inside the SOC that secured RSAC 2026 Conference How to roll out an enterprise passkey deployment How to improve the SOC analyst experience -- and why it matters How contact centers detect and prevent fraud News brief: Iranian cyberattacks target U.S. water, energy CISO checklist: Cybersecurity platform or marketing ploy? RSAC 2026 Conference: Key news and industry analysis | TechTarget Next-generation firewall buyer's guide for CISOs Contact center monitoring best practices for CX leaders RSAC 2026: Cyber insurance and the rise of ransomware Agentic AI's role in amplifying and creating insider risks RSAC 2026 recap: AI security and network security trends Identity security at RSAC 2026: The new enterprise dynamics Meaningful metrics demonstrate the value of cyber-resiliency What to know about red team testing and the law News brief: Iran cyberattacks escalate, U.S. targets named 5 top SOC-as-a-service providers and how to evaluate them Cloud security architecture: Enterprise cloud blueprint for CISOs Contact center compliance checklist for modern workforces How AI caught a malicious North Korean insider at Exabeam Watch your words: Tim Brown's advice for CISOs News brief: U.S. absence at RSAC sparks leadership concerns Network security management challenges and best practices 10 enterprise secure remote access best practices
How agentic AI threat intelligence aids NGO cyber defense: Case study | TechTarget
Sean Michael Kerner · 2026-06-27 · via Search Security Resources and Information from TechTarget

NGOs often lack the resources and expertise to defend against modern threat actors. Learn how one nonprofit is harnessing agentic AI threat intelligence to flip the script.

Nonprofits serving vulnerable populations sit at the uncomfortable intersection of sensitive data, global exposure and limited security resources.

Geneva-based Protect.ngo, formerly the CyberPeace Institute, helps nonprofit and nongovernmental organizations (NGOs) navigate those challenges with free cybersecurity support. To fulfill its mission, Protect.ngo, itself a nonprofit, must continually identify and analyze the threats that target its nearly 700 member organizations -- far easier said than done.

The problem: When manual monitoring isn't enough

When Protect.ngo started in 2018, its cybersecurity analysts relied on open source intelligence skills to track publicly reported cyberattacks against the nonprofits in its network. The process involved manually checking news outlets, dark web forums, social media and other sources.

"Many [NGOs] have a smaller digital footprint," said Miles Collins, a cyberthreat analyst at Protect.ngo. "This can make it more difficult to detect whether they have been targeted and to gather enough evidence for technical attribution."

With no unified view of the threat landscape facing NGOs and other civil society organizations, the work was time-consuming, inconsistent and unwieldy. The results also failed to give Protect.ngo analysts the real-time insights they needed to properly analyze and prioritize emerging and ongoing security threats. The scale of Protect.ngo's monitoring activities compounded the challenge, with hundreds of member organizations spanning different regions, sectors and operating environments.

These challenges notwithstanding, it was critical that analysts detect attacks quickly and consistently, both for immediately affected organizations and their peers. A threat surfacing in one corner of the Protect.ngo network could have implications for countless other NGOs. Plus, any missed or delayed detections could create gaps in the public records upon which researchers and policymakers depend.

By March 2025, Protect.ngo analysts had manually documented more than 295,000 threats, 760 vulnerabilities and 1,100 distinct attacks on NGOs -- and the threat landscape was only worsening.

The fix: AI joins the cause

Around the same time, Protect.ngo turned to AI to support the efforts of its human analysts. The organization deployed Dataminr's AI-powered threat intelligence platform, which has the following capabilities.

  • Aggregates information from diverse sources across the public, deep and dark web, including government advisories, social media, cyber threat boards, dark web forums, news outlets, vulnerability disclosures, breach reports and threat intelligence feeds.
  • Ingests and analyzes text, code, image and video data.
  • Uses agentic AI and large language models to autonomously analyze, enrich and contextualize data. The AI agents summarize incidents; correlate adversarial activity; identify patterns; and map relationships between cyber incidents, threat actors and targeted organizations.
  • Presents deduped, structured and contextualized intelligence alerts and briefs to human analysts in real time. Alerts include detailed source attribution, screenshots and background on threat actors involved.

According to Collins, he and his fellow analysts at Protect.ngo review and verify all AI-driven alert and intelligence data, ensuring its accuracy and reliability before determining next steps.

"Human analysts are still required when it comes to judging whether those claims are credible or not," Collins added. "As part of our methodological process, we always have an analyst reviewing AI output."

Human analysts are still required when it comes to judging whether those claims are credible or not.
Miles CollinsCyber threat analyst, Protect.ngo

In addition to supercharging cyberattack and threat monitoring for Protect.ngo's client organizations, Dataminr's AI threat intelligence technology informs the nonprofit's Cyber Tracer. The public platform tracks vulnerabilities, threats and attacks relevant to civil society organizations and supports ongoing research on conflict-zone cyberactivity, including the Russia-Ukraine war. NGOs, policymakers and researchers can use Cyber Tracer -- which also includes structured, domain-specific data from third-party partners Cloudflare, Bitsight and Kaduu -- to better mitigate risk and boost cyber resilience.

The results: Consolidated and contextualized threat intelligence data

At Protect.ngo, Collins said the core operational benefit of agentic AI threat intelligence has been the consolidation of diverse and far-flung event, threat and risk data. A single, deduped and contextualized feed means analysts spend less time collecting and organizing information and more time analyzing and prioritizing it.

AI-driven monitoring also extends coverage into channels that analysts at resource-constrained organizations rarely have the capacity to watch consistently, such as dark web forums where ransomware groups publish claims against victims that might not appear in conventional news sources.

The first alert on an exfiltrated database

The agentic threat intelligence workflow was initially tested during an incident involving a nonprofit in Protect.ngo's The Builders program, a matchmaking initiative that connects corporate cybersecurity volunteers with NGOs that need support.

In this event, a threat actor claimed to have exfiltrated data from the organization's environment and published a sample of the database online. Dataminr surfaced the alert before Protect.ngo volunteer analysts identified it through any other channel, Collins said, enabling them to quickly contact the organization with remediation support.

To date, Protect.ngo has recorded more than 878,000 threats, detected 1,084 vulnerabilities across NGOs, identified more than 2,000 attacks, quarantined more than 560,000 phishing emails and detected more than 315,000 exposed credentials.

A caveat: AI won't make up for poor cybersecurity hygiene

Despite Protect.ngo's positive experience with the AI threat intelligence platform, Collins warned that smaller organizations without dedicated security functions often lack the baseline controls that make such monitoring tools useful in the first place.

Organizations without in-house security staff should focus first on the basics -- MFA, VPNs, strong password management and software updates. "Avoid getting any complex tools before the foundational operational security is in place," he said.

Once that foundation exists, AI tools become a practical option. For resource-constrained teams, however, the risk then becomes treating AI as a substitute for human reasoning, insight and judgment, and the discipline that makes such tools meaningful.

"It is always important to keep in mind that AI can make mistakes and again, basic security practices remain the most important to implement," Collins said.

Sean Michael Kerner is an IT consultant, technology enthusiast and tinkerer. He has pulled Token Ring, configured NetWare and been known to compile his own Linux kernel. He consults with industry and media organizations on technology issues.

Dig Deeper on Security operations and management