Skip to content
Resources

Intel reports, articles,
and press.

Primary research and editorial from the Blacklight AI team. Every fortnight, a new Cybersecurity Intel Report lands here. Articles cover Agentic AI deployment, regulatory frameworks, and the SOC operating model. Press releases and partnership announcements sit alongside.

All resources

Article

Private Equity Has a Cyber Problem It Can't Diligence Its Way Out Of

Cyber risk has moved from the deal table to the hold period. 80% of PE firms are hit during ownership, at $2.1M a time, and you cannot diligence your way out of a risk that changes every day you hold the company.

Read more
Article

What Agentic AI Actually Changes in the SOC, and the Six Questions to Ask Before You Sign

Every security vendor now claims agentic AI. Most have added a chat box to a dashboard. Here is what genuinely changes in security operations in 2026, what does not, and the six questions that separate an autonomous platform from an agent bolted onto someone else's stack.

Read more
Article

Autonomous Detection Engineering: How the SOC's Detection Library Can Write and QA Itself

Detection-as-code still leaves humans writing, tuning and retiring every rule. Autonomous detection engineering closes the loop: the platform observes what can be detected, proposes what should be, proves each candidate against your real data, and deploys only what adds value.

Read more
Article

The Autonomous SOC Is Not Coming. Something Better Is.

For two years the industry sold a SOC with no humans in it. It was never real. That is not a setback: it is the most clarifying thing to happen to security operations in years. Once you stop chasing the SOC that will never exist, you can build the one that should.

Read more
Intel № 13

Trust abuse, industrialised: one ERP zero-day, one poisoned integration, 74,000 firewalls

Automotive & manufacturingInsuranceTelecomsTechnology & softwareEducation

A synchronised disclosure cluster lands as one Oracle PeopleSoft zero-day claims victims across automotive, insurance and medical devices. A single compromised SaaS integration drains CRM data from security's best-known vendors. And verified admin credentials circulate for almost 74,000 FortiGate firewalls, with no new CVE at all.

Read the report
Intel № 12

The perimeter is the platforms you trust: PeopleSoft, Splunk and a poisoned plugin store

EducationInsurancePharma & healthcareManufacturing & agricultureTechnology

A single Oracle PeopleSoft zero-day cascades into 100+ organisations including a US regulator. A CVSS 9.8 flaw turns Splunk, the defender's own eyes, into an attack surface with a three-day federal patch deadline. And a plugin-store supply chain harvests the AI API keys of nearly 70,000 developers.

Read the report
Intel № 11

The fortnight belonged to the telephone: vishing, fake IT support and backups burned behind them

TelecomsTravel & hospitalityLegalPublic sector & humanitarian

Nearly 6 million cruise-line customers and 4.9 million telecoms accounts exposed, both starting with a phone call. The FBI warns law firms about fake IT-support calls. Iran-linked operators wipe recovery layers, not just production. Your helpdesk, your SaaS and your backups are now primary attack surface.

Read the report
Intel № 10

When the defences are the target: security tools exploited, a supply-chain worm, and the patching gap

HealthcarePharma & life sciencesRetail & franchiseTechnology & software

Two security products actively exploited in the same week. A self-replicating npm worm rips through GitHub and a major observability vendor. A municipal health system loses 1.8 million people's biometrics through a third party. And the DBIR confirms it: exploitation has overtaken stolen credentials as the number-one way in.

Read the report
Intel № 09

Trust infrastructure under assault: a CA compromised, a SaaS mega-breach, 1.5M servers exposed

EducationTechnology & softwareFood & supply chainMedia

A certificate authority is socially engineered and Defender turns on legitimate software. An education SaaS giant is extorted over data claimed to cover 275 million users. And an authentication bypass in cPanel leaves 1.5 million internet-facing servers exposed. Almost nothing this fortnight began with malware on a laptop.

Read the report
Intel № 08

Encryption is now optional: the fortnight extortion went pure-exfiltration

Financial servicesHealthcareHospitalityProfessional services

Three enterprises extorted through Salesforce in seven days, none of them encrypted. Microsoft's largest Patch Tuesday of 2026 lands with a SharePoint zero-day already being exploited. And CISA's Known Exploited Vulnerabilities catalog grows by eight entries in a week.

Read the report
Intel № 07

Breached upstream: the fortnight attackers arrived as trusted traffic

HealthcareGovernmentManufacturingConnected & IoT

One poisoned open-source scanner cascades into a tier-1 network vendor and the European Commission. Ransomware at a single software supplier disrupts most Dutch hospitals. And a state actor turns thousands of home routers into a silent credential-harvesting layer.

Read the report
Intel № 06

No endpoint required: APIs, phone calls and device codes did the work

HealthcareGovernmentEducationFinancial services

An API authorisation flaw exposes 2.7 million benefits records over 24 quiet days. One hour of vishing access lifts 900,000 records from an identity-protection firm. And a commoditised iOS exploit chain with three zero-days spreads across multiple threat actors.

Read the report
Intel № 05

Seeded months ago: the fortnight old breaches came due

HealthcareManufacturingEnergyFinancial services

A healthcare IT breach runs undetected for eleven months before 3.4 million patients are told. Cloud keys stolen in last year's SaaS supply-chain theft unlock a petabyte-scale claim against a Canadian BPO. And 13 KEV additions in a fortnight span browsers, ICS gear and AI tooling.

Read the report
Intel № 04

They logged in: the fortnight attackers stopped breaking in

HealthcareFinancial servicesGovernmentHospitality

A vishing crew compromises CarGurus, Wynn Resorts and Figure without a single exploit. France's national bank registry is read for 16 days with one stolen credential and no MFA. And a CVSS-10 Cisco SD-WAN bypass triggers a federal emergency directive with 48-hour deadlines.

Read the report
Intel № 03

Abused trust: phones, updates and helpdesks did the breaking in

EnergyTelecommunicationsFinancial servicesGovernment

A vishing crew talks its way past MFA at a Dutch telecom and reaches 6.2 million customers. Romania's national oil pipeline operator is breached via an infostealer on one admin's personal device. And Notepad++'s own update channel is hijacked by a state-sponsored espionage group.

Read the report
Intel № 02

No encryption required: the fortnight of the mega-leak

Retail & luxuryManufacturingFinancial servicesGovernment

72 million Under Armour records surface online, an extortion crew dumps SoundCloud, Crunchbase and Betterment data after failed negotiations, and 1.4 TB of Nike R&D walks out the door. Not one headline incident used encryption, and a state actor weaponised an Office zero-day in days.

Read the report
Intel № 01

Weaponised the same day: 2026 opens at exploit speed

HealthcareFinancial servicesEducationHospitality

A CVSS-10 HPE OneView flaw is botnet-weaponised the day CISA flags it. Ransomware takes down three quarters of a South Korean conglomerate's servers, putting 9.6 million accounts at risk. And a single phishing attack at a Canadian regulator ends with 750,000 investors exposed.

Read the report
Press

Blacklight achieves ISO/IEC 27001:2022 certification

Blacklight's information-security management system has been independently certified to the ISO/IEC 27001:2022 standard, covering the full platform and managed SOC operations.

Read more
Press

Blacklight opens its Middle East presence at the DIFC Innovation Hub

Blacklight has formally opened operations at the Dubai International Financial Centre's Innovation Hub, deepening its support for regulated industries across the Middle East.

Read more
Press

Blacklight is now available on the AWS Marketplace

Procurement just got simpler — Blacklight SIEM, SOAR and SOCaaS are now listed on the AWS Marketplace, with private-offer pricing and committed-spend drawdown for AWS customers.

Read more
Article

Who Should Make the First Triage Decision in a Modern SOC?

The average SOC receives nearly 4,000 alerts per day. Two-thirds are never investigated. When speed determines whether a breach is contained or catastrophic, who — or what — should decide what gets looked at first?

Read more
Press

Blacklight AI named Top Vendor — Security Operations Platform 2024

Blacklight AI has been named "Top Vendor – Security Operations Platform" by the prestigious GEC Media Awards 2024 in Dubai.

Read more
Article

Cybersecurity for Critical Infrastructure Industries

Critical sectors across energy, water, telecommunications and transportation are prime targets for nation-state actors and ransomware crews. Mixed IT/OT, growing IoT and rising geopolitical tension demand a tailored defensive posture.

Read more
On the way

More intel,
landing soon.

New intel reports, research and briefings are already in the pipeline. Get a ping the moment they publish, no noise in between.

Notify me
In the pipeline 02
  • Research The Agentic SOC TechBrief.
  • Press Blacklight AI wire feed.
Subscribe

Get the fortnightly
Cybersecurity Intel Report.

Named breaches, exploited CVEs, threat actor movement, and Blacklight's CISO action list. Every fortnight, one page, one call to action.

This is the public report. Blacklight platform customers receive a contextualised threat-intel stream inside their console, mapped to the assets and frameworks in their own environment.

By subscribing you'll be added to the Blacklight intel distribution list. Unsubscribe any time — one click, no questions.