Feed aggregator

Show HN: On This Day

Hacker News - Thu, 07/09/2026 - 10:58am

Article URL: https://otd.dhimantparekh.com/

Comments URL: https://news.ycombinator.com/item?id=48847029

Points: 1

# Comments: 0

Categories: Hacker News

Are Bug Bounties Cooked?

Hacker News - Thu, 07/09/2026 - 10:56am
Categories: Hacker News

New "Revenue Larping Trend" is this real?

Hacker News - Thu, 07/09/2026 - 10:54am

Article URL: https://www.larp.website/

Comments URL: https://news.ycombinator.com/item?id=48846928

Points: 1

# Comments: 0

Categories: Hacker News

Ask HN: What would you do if you had coded a better web browser than Firefox?

Hacker News - Thu, 07/09/2026 - 10:51am

Ask HN: what would you do if you had vibe-coded a better web browser than Firefox? Ie. More secure, more maintainable, less surveillance, more cool etc.

https://github.com/nordstjernen-web/nordstjernen

Comments URL: https://news.ycombinator.com/item?id=48846879

Points: 3

# Comments: 1

Categories: Hacker News

Before iOS 27, Don't Forget to Check Out These iOS 26.4 Features

CNET Feed - Thu, 07/09/2026 - 10:34am
New emoji and video podcasts are just a couple features the update brought to your device in March.
Categories: CNET

I Wrote a New Book for Corelight

Tao Security - Thu, 07/09/2026 - 10:33am

TLDR: I wrote a new book for Corelight called NDR Essentials. It's free at that link. This is the 10th book that I've authored or co-authored. The rest are all posted at taosecurity.com.  Why?

It was time.

That’s what I thought when I heard that Corelight wanted to update its 2021 book on network detection and response (NDR). Tamara Crawford, who owned the project, scheduled a meeting with me and asked if I might be interested in helping, depending on who might write the text.

I volunteered immediately to write the whole book, but I had a few conditions. The text had to be at least 100 pages long, because 100 pages is my personal dividing line between “book” and “white paper.” I needed the freedom to cover the topics I wanted to address, and to not be told what to write. I wanted to show the four network security monitoring (NSM) data types working in a vendor-neutral manner, with technical details. Finally, I knew this project would take several months to research, write, lay out, proofread, and complete. Once Corelight agreed, I was ready to begin.

My goal for the book was to show how high-fidelity network evidence can power successful incident detection and response operations. For decades, digital security relied on the flawed premise that the “right” security controls could stop malicious activity. History, however, has repeatedly shown that prevention eventually fails. Victory belongs to the defender who accepts that intrusions are inevitable and who implements aggressive post-compromise interdiction and containment.

Security teams have the best chance to stop an adversary before they accomplish their mission when they leverage network security monitoring data and the latest AI and automation assistants. Therefore, this book equips practitioners with the tools and mindsets necessary to hunt through network evidence and diminish attacker dwell time.

The book begins with a chapter that defines risk, threat, vulnerability, and asset value in the context of cybersecurity. It explains seven risk management strategies, NDR’s role in the security cycle, four sources of situational awareness, the importance of time and how to measure it, and a variety of NDR-specific topics like where and how to monitor, costs vs. benefits, and the difference between NSM and NDR.

Chapter 2 is all about the four types of NSM data. I show examples of full content data via terminal and graphical interfaces, and what it can do for analysts. I briefly demonstrate how to obtain and analyze extracted content, then show how transaction data can answer many of the key questions asked by security analysts. The chapter concludes with alert data, which has become more significant in an age of smarter and more precise AI capabilities.

Chapter 3 is the first of two chapters demonstrating workflows for security investigators. This chapter examines how alert data from a sufficiently capable NDR can identify suspicious and malicious activity. It includes four cases, showing how lateral movement, expired SSL certificates, outbound reconnaissance, and malicious remote desktop protocol behavior manifest in alerts.

Chapter 4 presents the other side of investigative workflows, relying on threat hunting to reveal adversary activity. Properly collected, rendered, and displayed NSM data is crucial, because you can’t really hunt without high-quality evidence. The chapter includes six cases, showing how file name mismatches, unusual downloads, large data transfers, coordinated exfiltration, lateral movement, and certificates appear when exposed via threat hunting.

Chapter 5 explores how artificial intelligence and automation technologies are bringing powerful new capabilities to security teams. I start by discussing the generation of alerts at the edge and at the center, then I share how AI can help with investigating suspicious and malicious activity. I conclude with advice on the best use of agentic triage and how AI will integrate with tools while enabling new capabilities.

If you’re a security leader, such as a CISO or director, you’ll probably be most interested in Chapters 1 and 5. You should ensure your teams have the data described in Chapters 2-4. If you’re a security analyst, you’ll probably be most interested in Chapters 2-4, although you should be familiar with the concepts and strategies in Chapters 1 and 5. If you’re familiar with my previous works, you will be happy to see that this book has a certain amount of “future-proofing” embedded. I did not explain how to install any specific tools, nor did the tools I use rely on strict display technologies. All of the examples in Chapter 2 use open source tools with stable outputs, such as Tshark, Wireshark®, Zeek®, and Suricata®.

I hope readers find the book relevant to their security work and a decent introduction to adding NSM data from capable NDRs to their investigations. This book is only the beginning of what can be done once teams have access to high-fidelity network evidence. If you’d like to know more about the book, Vince Stoffer interviewed me for the Corelight podcast, and that episode will be available on YouTube, Spotify, and Apple Podcasts. As I say at the end of every episode, “we will see you on the network.” Read NDR Essentials to learn how high-fidelity network evidence can strengthen your security program!


Copyright 2003-2020 Richard Bejtlich and TaoSecurity (taosecurity.blogspot.com and www.taosecurity.com)
Categories: Tao Security

UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge

Security Week - Thu, 07/09/2026 - 10:19am

Two announcements on July 7, 2026, demonstrate the government’s determination to improve the level of cybersecurity within the UK.

The post UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge appeared first on SecurityWeek.

Categories: SecurityWeek

When assessing cybersecurity risk, be sure to consider the scope of the project, your organization's specific assets and leadership's tolerance for risk.

Security Wire Weekly - Thu, 07/09/2026 - 10:17am
When assessing cybersecurity risk, be sure to consider the scope of the project, your organization's specific assets and leadership's tolerance for risk.
Categories: Security Wire Weekly

Admins will want to focus on issuing corrections for the large number of flaws, some of which require no user interaction, in Windows RRAS and Microsoft Office.

Security Wire Weekly - Thu, 07/09/2026 - 10:17am
Admins will want to focus on issuing corrections for the large number of flaws, some of which require no user interaction, in Windows RRAS and Microsoft Office.
Categories: Security Wire Weekly

AI tools streamline threat modeling by automating repetitive tasks and helping security teams prioritize risks more effectively. But human oversight is still critical.

Security Wire Daily News - Thu, 07/09/2026 - 10:17am
AI tools streamline threat modeling by automating repetitive tasks and helping security teams prioritize risks more effectively. But human oversight is still critical.

The NCSC has shared more details of its national AI Cyber Shield initiative, but experts say the project faces serious delivery challenges

Computer Weekly Feed - Thu, 07/09/2026 - 10:17am
The NCSC has shared more details of its national AI Cyber Shield initiative, but experts say the project faces serious delivery challenges
Categories: Computer Weekly

The path is now clear for preowned software reseller ValueLicensing’s market abuse case against Microsoft to go ahead

Computer Weekly Feed - Thu, 07/09/2026 - 10:17am
The path is now clear for preowned software reseller ValueLicensing’s market abuse case against Microsoft to go ahead
Categories: Computer Weekly

Tell us who you think should be included in Computer Weekly’s 2026 list of the 50 Most Influential Women in UK Technology

Computer Weekly Feed - Thu, 07/09/2026 - 10:17am
Tell us who you think should be included in Computer Weekly’s 2026 list of the 50 Most Influential Women in UK Technology
Categories: Computer Weekly

Today's Best Storage Deal? This 4TB SanDisk SSD at $420 for the Next Few Hours

CNET Feed - Thu, 07/09/2026 - 10:11am
The SanDisk 4TB Extreme Portable SSD, a CNET top pick, is 53% off for the next few hours only.
Categories: CNET

Show HN: EvenKeel – a free financial planning chatbot

Hacker News - Thu, 07/09/2026 - 10:06am

EvenKeel is an LLM-powered chatbot that helps with budgeting, financial planning, retirement savings, tax optimization, etc.

It is a harness around Gemini 3 Flash Preview that provides a library of skills for things like: evaluating a house purchase, insurance planning, portfolio asset allocation, etc. as well as tools for doing financial math and Monte-Carlo simulations.

You can upload files as well as chat, and as you go, it updates a "Financial Picture" with relevant facts about your situation, so you can see what data has been collected, track goals, etc. this picture along with recent chat interactions is fed into the model each turn so the most important details are always in context.

Your data can be exported or account deleted from the Settings page at any time, or you can interact anonymously until LLM spending gets too hot.

Hope you find it helpful!

Comments URL: https://news.ycombinator.com/item?id=48846108

Points: 1

# Comments: 0

Categories: Hacker News

Pages