惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
H
Hacker News: Front Page
Stack Overflow Blog
Stack Overflow Blog
B
Blog
I
InfoQ
GbyAI
GbyAI
T
The Blog of Author Tim Ferriss
F
Fortinet All Blogs
Y
Y Combinator Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
月光博客
月光博客
Hugging Face - Blog
Hugging Face - Blog
爱范儿
爱范儿
F
Full Disclosure
Hacker News - Newest:
Hacker News - Newest: "LLM"
Recent Announcements
Recent Announcements
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Jina AI
Jina AI
T
Tailwind CSS Blog
S
Secure Thoughts
P
Privacy International News Feed
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
L
LINUX DO - 最新话题
H
Hackread – Cybersecurity News, Data Breaches, AI and More
C
Cybersecurity and Infrastructure Security Agency CISA
Last Week in AI
Last Week in AI
W
WeLiveSecurity
Google Online Security Blog
Google Online Security Blog
P
Privacy & Cybersecurity Law Blog
D
DataBreaches.Net
Engineering at Meta
Engineering at Meta
Know Your Adversary
Know Your Adversary
P
Palo Alto Networks Blog
I
Intezer
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Project Zero
Project Zero
V2EX - 技术
V2EX - 技术
H
Heimdal Security Blog
博客园 - Franky
阮一峰的网络日志
阮一峰的网络日志
D
Darknet – Hacking Tools, Hacker News & Cyber Security
T
Troy Hunt's Blog
V
Vulnerabilities – Threatpost
H
Help Net Security
Martin Fowler
Martin Fowler
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
G
GRAHAM CLULEY
博客园 - 【当耐特】

Infoblox Blog

FedRAMP DDI Management with Infoblox Government Cloud Inside a Global Procurement-Themed AiTM Phishing Campaign The Missing Link in the Anti-Scam Chain: Why DNS Belongs in the Room. (DNS, GASA, Global Anti-Scam Alliance, DNS Threat Intelligence) Oracle Cloud Discovery for Universal Asset Insights | Infoblox Why Asset Discovery Integrations Start with Network Intelligence Infoblox Kentik Acquisition: AI-Driven Network and Security Intelligence Proxyware actor behind fake 7-Zip is bigger than you think! Using Protective DNS to Dismantle Global Scam Networks | Infosecurity Europe 2026 Residential Proxies: Why DNS Is the Stronger Play NIST Maps DNS Security to the Cybersecurity Framework 2.0 Trusted Infrastructure Data for AI and AgenticOps | Infoblox DCloud Uni-App: One Framework, 236,000+ Scam Sites Operation Endgame VS SocGholish Fake Updates Human Judgment Hacks: How Lookalike Domains Work Residential Proxies in the Wild Unlocking Universal DDI on Equinix: Infoblox Brings Cloud-First DDI to Equinix Network Edge “Headless”? What Is It and Do I Need to Go There? The Alert Is Already Too Late The Half of Your Attack Surface Nobody Owns Infoblox Earns Terraform Partner Premier Status for NIOS Provider What 550 Security Leaders Just Told Us about the Age of AI, and Why Preemptive Digital Risk Protection Can’t Wait Lookalike Domains Expose the iPhone Theft Economy Amusing Numerology: Analysis of the Numbers in Domain Names 4 Trends Shaping the Future of Network Operations Preemptive Threat Disruption at Scale: How Infoblox and Axur Turn External Risk into Protection Why the Axur Acquisition Marks a Turning Point for Preemptive Security Don’t Wait To Be Attacked: Stop Phishing, C2 and Data Exfiltration with Infoblox Threat Intelligence in AWS Network Firewall Hold the Phone! International Revenue Share Fraud Driven by Fake CAPTCHAs AI, Project Glasswing and DNS: Beyond Vulnerabilities Three Infoblox Integrations with Google Cloud That Give Enterprise Teams More Control Over Their Networks Protective DNS: Why Telcos Are Turning to DNS as the Platform for Consumer Security Automating Infoblox DDI with Red Hat Ansible | Configuration as Code for DNS, DHCP and IPAM Hiding in Plain Sight: Abusing Composite Domain Names What You Cannot See is Hurting You Most NIST SP 800-81r3: A Long-Overdue Wake-Up Call for DNS Security Patterns, Pirates, and Provider Action: What We Learned Working with Keitaro NIST SP 800-81r3: What’s New? No Reach, No Risk: The Keitaro Abuse in Modern Cybercrime Distribution Unified Asset Visibility: A Strategic Imperative for CIOs and CISOs Infoblox Partners with Leading SASE Vendors to Modernize DNS and DHCP for Distributed Enterprises NIST DNS Security Best Practices: Top 5 Takeaways Break out the bubbly: NIST SP 800-81r3 has been published! Empowering Women to Lead in APJ: Infoblox at the Leadership Summit for Women in Technology, AI & Cyber
Meet Your Security Analyst’s New AI Teammate | Infoblox IQ
Krupa Srivatsan · 2026-06-29 · via Infoblox Blog

When Threats Move at AI Speed, You Need to Respond at AI Speed

Threat investigation and response has always been a complex, cumbersome process. Alerts came in; analysts triaged them mostly manually, painstakingly looking at logs, trying to identify which ones were critical and then kicking off remediation actions again with a lot of manual effort. It is time-consuming and error prone.

That whole rhythm is now coming under even greater stress. Attackers now use AI to automate reconnaissance, generate single-use malware, personalize campaigns at scale and mutate their infrastructure faster than defenders can keep up. The result is a flood of alerts and a shrinking window to make the right call before the business is exposed. Analysts have very little time to understand what’s happening, decide what matters and act to contain threats.

The numbers tell the story. Alert volume increased over the prior year for 88 percent of organizations, and 64 percent say detection, triage and investigation remain heavily manual.1 Meanwhile, analysts pivot across an average of 10.9 consoles to piece together a single investigation, 46 percent of alerts turn out to be false positives and 42 percent never get investigated at all.2 It’s no wonder 75 percent of security leaders worry their security operations center (SOC) is losing pace with new cyberthreats.1

And the final tipping point is the fact that the average “attacker breakout time” is now only 29 minutes,3 meaning it takes only that amount of time from initial network access to lateral movement and further escalation of the threat.

Adding more tools or pushing more raw data into the security information and event management (SIEM) hasn’t solved this. It has often made it worse. What teams need is a way to cut through the noise at the earliest control point, connect related activity into something meaningful, simplify the whole investigation process and help analysts act faster with confidence.

That’s exactly what we built Infoblox IQ for Threat Defense to do.

The Real Barriers to Security Efficiency

Talk to almost any security team and the same three challenges surface again and again.

The first is simply dealing with alerts. Analysts sift through overwhelming volumes of noisy alerts, and false positives bury the real issues. Traditional prioritization methods just aren’t keeping pace with alert growth, so too much time goes to triaging things that never deserved a deeper look.

The second is complex investigations. To reconstruct what happened, analysts pivot across DNS, network, endpoint, cloud and identity tools, stitching context together manually. That slows investigations, adds operational friction and drives up SIEM and downstream processing costs.

The third is doing the work with the staff and skills on hand. Short-staffed teams struggle to keep up with investigation, tuning and integrations, while too much analyst time goes to low-value manual work instead of real risk reduction. Burnout and turnover make consistency even harder to maintain. These aren’t problems you solve by working harder. They’re problems you solve by changing how the work gets done.

An Agentic AI Teammate for Easier and Faster Investigations

Infoblox IQ for Threat Defense helps security and networking teams defend the business against AI-driven and other advanced threats more effectively. At its core, it helps security teams focus on the threats that matter most.

The idea comes down to three things: See what matters first. Investigate faster and with ease. Respond in one automated workflow.

See what matters first. Instead of flooding analysts with more noise, Infoblox IQ for Threat Defense uses DNS intelligence, network data and AI-driven threat correlation to surface the threats and anomalies that actually deserve attention. Analysts start in the right place rather than digging for it.

Investigate easier and faster with full context that reveals the who, what and when behind every event. Analysts can simply ask questions in natural language about detected events and access correlated DNS, network, asset, user and security context—without pivoting across multiple tools, screens or logs. Asset/user attribution becomes very easy and guided next steps help accelerate investigation and response from a single workspace.

Move from detection to response in one-click automated workflow. When an issue surfaces, analysts can investigate, decide and act in one connected, automated experience rather than bouncing between separate tools, queues and handoffs. Actions can be automated, but analyst control, approvals and auditability stay central.

Why does DNS give us such an advantage here? Because most modern attacks depend on it. Flexible attacker infrastructure and dynamic command-and-control systems use DNS to reach victims, move laterally and maintain communications. That reliance turns DNS into an early, high-value control point for spotting and stopping malicious activity, and Infoblox has spent years researching and generating original threat intelligence to use in DNS systems.

Just as important is what this approach protects against: black-box automation. Because the stakes are higher in an AI-driven threat landscape, human oversight matters more, not less. Analysts stay in control of higher-risk decisions, actions remain visible and auditable, and AI handles the low-value manual work so people can focus on real risk.

There’s a broader story here too. Infoblox IQ for Threat Defense is part of Infoblox IQ, which means the same assistant, actions and context work more consistently across the entire Infoblox platform, giving teams a simpler, more unified workspace rather than yet another disconnected dashboard.

A Smarter Way to Go from Detection to Action

The answer to better security isn’t to ask already-stretched analysts to absorb more noise, more tools and more manual work. It’s to give them a teammate that helps them focus on what matters, understand it faster and act on it with confidence.

That’s the promise of Infoblox IQ for Threat Defense: better security outcomes with less manual triage, less swivel-chair work and a clearer path from signal to investigation to remediation, all while amplifying the SIEM, security orchestration, automation and response (SOAR) and security investments teams already have.

In a world where every organization is increasingly a target, and threats evolve by the minute, that combination of speed, simplicity and control is exactly what modern security teams need. We’re excited to put it to work for your team.

Footnotes

  1. Pulse of the AI SOC Report 2025. Devry, Jane. Cybersecurity Insiders. August 26, 2025.
  2. Microsoft State of the SOC. Lefferts, Rob. Microsoft Security. February 17, 2026.
  3. CrowdStrike 2026 Global Threat Report. CrowdStrike, 2026.