
News for today:
- [Abnormal AI] Three new capabilities. Abnormal AI added three new capabilities to its email security platform: support for additional detection controls and custom detection models; AI agent review of messages flagged by DLP rules; and better AI-powered phishing coaching. On the second: Email DLP Rules combine explicit outbound policy controls (built with regex, phrase matching, metadata conditions, Boolean logic, and exclusions) with contextual review from an AI Triage Agent. The agent evaluates a rule’s intent, the sender, and the surrounding message context, then auto-releases benign messages and quarantines likely violations while recording every verdict in an outbound log for audit visibility. It is designed to give organizations a practical way to enforce outbound policy without taking on the manual review burden that many DLP deployments create at scale. Abnormal AI
- [SentinelOne] New joint research with Tenable. SentinelOne and Tenable combined their respective data sets to derive new perspectives on vulnerability exploitation. Key finding after doing so: threat actors focus on susceptible vendor ecosystems more than individual CVEs. The research finds that exposure data and runtime detection converge on the same edge-device vendor surfaces 79% of the time, while they share only 21% overlap at the individual vulnerability level. Both state-sponsored actors and ransomware operators draw from the same small set of high-severity, actively exploited vulnerabilities. The surfaces are consistent and the actors are not. That distinction matters for how defenders prioritize; a pattern Tenable has termed the “Persistently Targeted Vendor.” This is the idea that a small set of vendor product lines, not individual CVEs, is the durable unit of risk over time. SentinelOne
- [CloudEagle] AI token consumption and budgeting. CloudEagle introduced the private beta of a new consumption tracking and budgeting app for AI. AI spend does not wait for a monthly budget review; it moves at the speed of every prompt an employee sends. Enterprises need to see that spend as it happens and cap it while there is still budget left to protect. Budgeting for AI should work the way the technology does, continuously, not once a quarter …. A finance team looking at a $40,000 monthly AI bill cannot do much with it. The same team looking at which department drove 60% of it, and which agent workflow accounted for most of that, has something to act on. CloudEagle
- [Semperis] Active Directory oops. A security researcher at Semperis found two severe vulnerabilities for privilege escalation in Active Directory; Microsoft has fixed both of them. For one of them: attackers could make two different accounts or services appear to have the same name. This identity confusion could disrupt access to business-critical systems, force some services to use a weaker authentication method, or help an attacker impersonate a highly privileged user. ResetNightmare is the more serious of the two vulnerabilities because, under certain conditions, it could enable a low-privileged attacker to take control of an entire Active Directory domain. Semperis
- [LevelBlue] New SOC in Sydney. LevelBlue added a new SOC in Sydney to expand its MSP services for Australian customers – mixing local delivery with global security operations prowess. Designed to support Australian organizations, particularly critical infrastructure owners and operators, the Sydney SOC provides access to onshore security analysts, local escalation pathways, and expertise in the Australian regulatory environment, backed by the scale, threat intelligence, and 24/7 coverage of LevelBlue’s global security operations. LevelBlue

