惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
T
ThreatConnect
SecWiki News
SecWiki News
F
Future of Privacy Forum
AWS News Blog
AWS News Blog
C
Cisco Blogs
A
Arctic Wolf
Vercel News
Vercel News
The GitHub Blog
The GitHub Blog
Scott Helme
Scott Helme
V
V2EX
博客园 - 叶小钗
阮一峰的网络日志
阮一峰的网络日志
K
Kaspersky official blog
G
Google Developers Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
P
Privacy International News Feed
C
Cyber Attacks, Cyber Crime and Cyber Security
N
News | PayPal Newsroom
Schneier on Security
Schneier on Security
NISL@THU
NISL@THU
Microsoft Azure Blog
Microsoft Azure Blog
量子位
The Hacker News
The Hacker News
Stack Overflow Blog
Stack Overflow Blog
Security Latest
Security Latest
M
Microsoft Research Blog - Microsoft Research
Google Online Security Blog
Google Online Security Blog
博客园_首页
C
CXSECURITY Database RSS Feed - CXSecurity.com
I
InfoQ
Google DeepMind News
Google DeepMind News
Y
Y Combinator Blog
The Cloudflare Blog
Microsoft Security Blog
Microsoft Security Blog
Martin Fowler
Martin Fowler
Cisco Talos Blog
Cisco Talos Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
Troy Hunt's Blog
F
Fox-IT International blog
S
Security @ Cisco Blogs
博客园 - 司徒正美
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
C
Comments on: Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
L
LINUX DO - 最新话题
GbyAI
GbyAI
Project Zero
Project Zero
腾讯CDC
T
Tailwind CSS Blog

Security

Trump Mobile confirms reports of customer data exposure, unsure whether to notify those impacted Exclusive: Marketing & merchandise firm Branded Products listed by Qilin ransomware Bank on it: AI-driven cyber crime is reshaping financial sector threats Alert! National Anti-Scam Centre and ASIC warns Aussies of fake crypto trading platforms Report: AI-driven exploitation beats phishing as most popular initial access strategy Exclusive: Victorian regional newspaper alleged hacked ransomware group Exclusive: Victorian regional newspaper allegedly hacked by ransomware group State Library of NSW responding to April cyber intrusion Over 50% of API banking attacks happen in Asia-Pacific, report finds Microsoft patches pair of Microsoft Defender zero-days following active exploitation EU wins global cybersecurity competition following digital partnership with Australia Report: Rapid7 warns AI-driven attacks are accelerating vulnerability exploitation Warning! Hackers spotted exploiting poorly patched SonicWall SSL VPN appliances 7-Eleven confirms cyber attack following ShinyHunters claims Busted! Vulnerability remediation is broken, a new report says Exclusive: US fintech firm OpenAI is using for linking bank accounts to ChatGPT discloses years-long cyber incident Thales and Google Cloud launch sovereign cloud operation in Germany Cyber fraud attacks up 17%, new findings reveal Australian Signals Directorate warns of device code phishing activity targeting Microsoft 365 users US banking regulators pause cyber exams for banks to allow Mythos patching Barracuda partners with CyberCert to simplify SMB1001 compliance for Australian SMEs Op-Ed: The reality of data-centric security and Attribute-based Access Control (ABAC) Exclusive: INC Ransom claims cyber attack on Australian engineering service company Op-Ed: To pay, or not to pay… That is the existential ransomware question Cyber Insurance for Small Business: When Getting Hacked Stops Everything Operation Ramz: INTERPOL arrests 201 in MENA region cybercrime operation Exclusive: Australian College of Business Intelligence investigating Qilin ransomware claims Exclusive: Major cleaning and facility services firm confirms third-party cyber incident Sentenced: 35-year-old Melbourne man jailed over phone porting scam Exclusive: Bluize confirms cyber incident, launches investigation US cyber agency warns of active exploitation of Microsoft Exchange Server spoofing vulnerability Three scammers charged following gold bullion purchase using scam profits Exclusive: Qilin ransomware group claims responsibility for Generation Life hack Exclusive: Hospitality IT provider allegedly breached by Qilin Exclusive: Tassie hospitality group confirms CMD Organization ransomware attack 80% of Aussies organisations face identity attacks, survey finds British Airways allegedly breached as hackers claim to have stolen pilot data Q&A with Adam Meyers: “It's going to be an absolute bloodbath.” Act now! Cisco patches ‘perfect 10’ Cisco Catalyst SD-WAN Controller vulnerability AI revolution? CVE disclosures jump by up to 500% for some vendors Report: Business email compromise attacks surged dangerously in April Kick-off! 2026 FIFA World Cup to be a prime target for scammers, cyber criminals Scope Systems confirms cyber incident, says no data loss occurred Instructure breach: ShinyHunters says ‘matter has been resolved’ Rapid7 launches Cyber GRC program to connect compliance with live risk data Australian Federal Budget 2026: The industry perspective Op-Ed: Microsoft May Patch Tuesday reveals 137 vulnerabilities Federal Budget 2026: The state of cyber security spending for the coming year OpenAI offers EU early access to its cyber security model Exclusive: Aussie firm Earth Systems listed by INC Ransom hacking group Op-Ed: Why Middle East tensions demand immediate action on OT security Aussie schools breach: Instructure boss “reaches agreement” with ShinyHunters to not release data Institute of Public Accountants members hit by data breach Union demands answers on Qantas AI plans 1 in 3 small businesses don't think they're a cyber target, new research finds Exclusive: Aussie toy distributor listed by M3rx ransomware Exclusive: Australian Computer Society investigating possible breach after ShinyHunters hack claims The industry speaks – part 2: World Password Day 2026 Aussie schools breach: The Instructure hack “transcends an isolated IT incident” Exclusive: Aussie car part importer Strategic Imports allegedly breached by threat actors New South Wales, other states, investigating Instructure/Canvas data breach Australian Cyber Security Centre warns of ClickFix campaign leveraging Australian infrastructure Queensland Department of Education confirms students & staff impacted by ShinyHunters data breach ACMA takes action against SpinTel & Yomojo over mobile number fraud violations The Industry Speaks, Part 1: World Password Day 2026 Qualys and Converge tie cyber insurance pricing to real-time security posture Fakeout: Iranian APT caught hiding behind Chaos ransomware activity Exclusive: Australian energy management firm allegedly breached by SafePay Real estate giant Cushman & Wakefield confirms cyber incident, Qilin and ShinyHunters claim attack CrowdStrike expands Project QuiltWorks as more partners join AI security coalition Hacked: ALS discloses cyber incident, unauthorised access to IT systems Microsoft the main target of AI phishing attacks, report uncovers Attackers increasingly turning to trusted security tools to compromise Aussie victims Exclusive: Champion Homes confirms customer data compromised in “cyber event” Australia, Japan commit to partnership to meet cyber security challenges & strengthen cyber defences NSW Treasury cyber incident contained, impact no longer ‘significant’ WA rental scam surge: Tenants targeted with fake $500 discount trap Aussie Information Commissioner launches Privacy Awareness Week 2026 Unregistered branded text messages to be labelled ‘Unverified’ from 1 July Exclusive: Major Australian jewellery brand confirms cyber incident Watch this! Komari server monitor tool abused by hackers Act Now! ACSC warns of active exploitation of cPanel & WHM critical vulnerability Exclusive: Kiwi electrical contractor confirms cyber attack Exclusive: Prime Properties listed as breach victim by M3rx ransomware DigiCert launches AI Trust architecture to secure agents, models, and content Winners of the 2026 Australian Cyber Awards unveiled Op-Ed: Redefining performance in the AI-powered SOC NZ council cyber attack leads to ID and financial data being exposed Alert! Wave of fake toll, parking scams impacting countries worldwide, including Australia and New Zealand Vect unveiled: Inside an emerging ransomware group’s affiliate network Exclusive: Gelatissimo confirms unauthorised access, investigates DragonForce hack claims Aussie ice-cream franchise Gelatissimo suffers alleged hack by DragonForce Anthropic Mythos: The model, the myth and the mundane​ Report: Aussie small businesses doing it tough as job scams double, losses rise Cyber attacks on medical devices pose ‘significant’ impact on real-life patient care Twisted Firestarter! Aussie, US, and UK cyber agencies warn of Cisco malware campaign Generation Life informs customers of “cyber incident” as owner shares incident with ASX CBA launches new scam-finding AI agent Sri Lankan government hack sees $3.7m destined for Australia stolen CrowdStrike extends cloud threat detection to Google Cloud
Op-Ed: Why CISOs are drowning in alerts but missing the real threat
Keith Bulfin · 2026-05-26 · via Security

Network defenders have more information at their fingertips than ever before… But the basics are still being missed.

Across the global cyber security industry, organisations are investing billions into AI systems, monitoring platforms, cyber infrastructure, governance frameworks, compliance operations, and automated detection capability.

Yet despite this unprecedented investment, the threat landscape continues to accelerate.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

Cyber-enabled fraud is increasing.

Ransomware groups are becoming more sophisticated.

Identity compromise is evolving rapidly.

AI-assisted phishing attacks are scaling globally.

And organised criminal networks continue adapting faster than many institutions can respond.

This raises an uncomfortable but increasingly important question: Why are organisations seeing more alerts, more data, more monitoring capability, and more visibility – yet still struggling to stay ahead of emerging threats?

In my view, the answer sits in what I describe as the operational intelligence gap.

For many years, cyber security environments focused primarily on technical visibility:

  • detect anomalies,
  • monitor behaviour,
  • identify patterns,
  • flag irregularities,
  • and automate response.

AI has accelerated this capability dramatically.

Modern systems are now exceptionally effective at processing enormous volumes of information and identifying technical abnormalities at scale. But while AI is highly effective at recognising patterns, it still struggles with something fundamentally human: intent.

And intent matters.

Sophisticated threat actors are no longer simply attacking systems blindly. Increasingly, organised cyber groups operate more like adaptive businesses – constantly testing environments, analysing behavioural weaknesses, identifying governance blind spots, exploiting operational inconsistency, and adjusting methodologies in real time.

This is where many organisations remain vulnerable. Most monitoring systems are designed to identify what is happening technically. Far fewer environments are capable of interpreting why it is happening operationally.

That distinction is becoming critically important.

Many cyber environments now generate overwhelming volumes of alerts, notifications, anomalies, and behavioural indicators. But more visibility does not necessarily create more understanding.

In fact, many organisations are now facing a form of operational saturation:

  • too much data,
  • too many alerts,
  • too many disconnected signals,
  • and insufficient capability to interpret adaptive behavioural threat patterns coherently.

For SMEs, the problem is often even more significant.

Large enterprises may at least possess dedicated cyber teams, governance structures, AI capability, and specialised monitoring systems. SMEs, however, frequently assume cyber risk remains primarily a technology problem that can be solved through software deployment, endpoint protection, or outsourced monitoring.

Increasingly, that assumption is becoming dangerous.

Modern threat actors exploit behaviour as much as technology. They exploit trust. Routine. Human inconsistency. Governance lag. Poor operational visibility. Weak escalation culture. Fragmented communication. And small configuration gaps that appear operationally insignificant in isolation.

The issue is no longer simply system compromise. It is behavioural manipulation operating inside increasingly complex digital environments.

This is why AI alone will not solve the cyber problem.

AI will remain an extraordinarily powerful capability layer – but future resilience will depend on something broader: the integration of AI capability, operational intelligence, behavioural interpretation, governance oversight, and human-led strategic analysis.

Because ultimately, cyber security is no longer simply about detecting technical anomalies. It is about understanding adaptive human behaviour operating behind them.

And that may become one of the defining security challenges of the next decade.


Keith Bulfin is the founder of the Applied Financial Intelligence Programme and author of the bestselling book Undercover. His background includes work across global financial intelligence, organised crime investigations, illicit finance systems, and operational intelligence environments involving international agencies and investigations.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.

Tags: