{
  "version": "https://jsonfeed.org/version/1.1",
  "title": "Babels",
  "home_page_url": "https://babels.dev/articles",
  "feed_url": "https://babels.dev/feed.json",
  "description": "AI Detection Engineering Solutions and News for Cyber Defense Practitioners",
  "items": [
    {
      "id": "https://babels.dev/articles/clickfix-to-cash-out-anatomy-of-a-mexican-banking-fraud",
      "url": "https://babels.dev/articles/clickfix-to-cash-out-anatomy-of-a-mexican-banking-fraud",
      "title": "ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit",
      "summary": "Detect the initial infection chain with `cmd /c curl ... | cmd.exe` and later stages like `ClipCursor`, UAC loops, or kiosk mode browser launches.",
      "content_text": "Detect the initial infection chain with `cmd /c curl ... | cmd.exe` and later stages like `ClipCursor`, UAC loops, or kiosk mode browser launches.",
      "date_published": "2026-07-08T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "threat-hunting"
      ],
      "external_url": "https://www.elastic.co/security-labs/mexican-banking-fraud-scmbanker-ref6045",
      "author": {
        "name": "Elastic Security Labs"
      }
    },
    {
      "id": "https://babels.dev/articles/felons-fraudsters-flog-offensive-cybersecurity-startup",
      "url": "https://babels.dev/articles/felons-fraudsters-flog-offensive-cybersecurity-startup",
      "title": "Felons, Fraudsters Flog Offensive Cybersecurity Startup",
      "summary": "Understanding this actor's brazen exploit acquisition model helps detection teams monitor and hunt for activities related to the sale and development of new vulnerabilities rather than just known malware.",
      "content_text": "Understanding this actor's brazen exploit acquisition model helps detection teams monitor and hunt for activities related to the sale and development of new vulnerabilities rather than just known malware.",
      "date_published": "2026-07-08T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "threat-hunting"
      ],
      "external_url": "https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/",
      "author": {
        "name": "Krebs on Security"
      }
    },
    {
      "id": "https://babels.dev/articles/meet-the-33-cybersecurity-startups-joining-the-gemini",
      "url": "https://babels.dev/articles/meet-the-33-cybersecurity-startups-joining-the-gemini",
      "title": "Meet the 33 cybersecurity startups joining the Gemini Startup Forum",
      "summary": "Highlights emerging security domains like EDR for AI agents and the push toward quantum-resistant infrastructure.",
      "content_text": "Highlights emerging security domains like EDR for AI agents and the push toward quantum-resistant infrastructure.",
      "date_published": "2026-07-08T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "siem",
        "incident-response"
      ],
      "external_url": "https://cloud.google.com/blog/products/identity-security/meet-the-33-cybersecurity-startups-joining-the-gemini-startup-forum/",
      "author": {
        "name": "Google Cloud — Security & Identity"
      }
    },
    {
      "id": "https://babels.dev/articles/drive-proactive-security-prioritize-risks-with-google-threat",
      "url": "https://babels.dev/articles/drive-proactive-security-prioritize-risks-with-google-threat",
      "title": "Drive proactive security, prioritize risks with Google Threat Intelligence and Wiz ASM",
      "summary": "Automates the prioritization of which exposures matter most by correlating known exploits against your specific environment.",
      "content_text": "Automates the prioritization of which exposures matter most by correlating known exploits against your specific environment.",
      "date_published": "2026-07-07T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "incident-response"
      ],
      "external_url": "https://cloud.google.com/blog/products/identity-security/drive-proactive-security-prioritize-risks-with-google-threat-intelligence-and-wiz-asm/",
      "author": {
        "name": "Google Cloud — Security & Identity"
      }
    },
    {
      "id": "https://babels.dev/articles/the-ghost-in-the-database-recovering-active-adfs-signing",
      "url": "https://babels.dev/articles/the-ghost-in-the-database-recovering-active-adfs-signing",
      "title": "The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI",
      "summary": "Monitor Event ID 385 to detect configuration drift and enforce automated certificate management for safer key lifecycle handling.",
      "content_text": "Monitor Event ID 385 to detect configuration drift and enforce automated certificate management for safer key lifecycle handling.",
      "date_published": "2026-07-07T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "threat-hunting",
        "siem"
      ],
      "external_url": "https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi/",
      "author": {
        "name": "Google Cloud — Threat Intelligence"
      }
    },
    {
      "id": "https://babels.dev/articles/shift-into-high-gear-with-agents-securing-the-software",
      "url": "https://babels.dev/articles/shift-into-high-gear-with-agents-securing-the-software",
      "title": "Shift into high gear with agents: Securing the software-defined vehicle",
      "summary": "Detection engineers can monitor the entire trust chain from certificate validation and JWT issuance down to granular NATS subject permissions rather than chasing leaked keys.",
      "content_text": "Detection engineers can monitor the entire trust chain from certificate validation and JWT issuance down to granular NATS subject permissions rather than chasing leaked keys.",
      "date_published": "2026-07-06T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "siem",
        "incident-response"
      ],
      "external_url": "https://cloud.google.com/blog/products/identity-security/shift-into-high-gear-with-agents-securing-the-software-defined-vehicle/",
      "author": {
        "name": "Google Cloud — Security & Identity"
      }
    },
    {
      "id": "https://babels.dev/articles/fbi-seizes-netnut-proxy-platform-popa-botnet",
      "url": "https://babels.dev/articles/fbi-seizes-netnut-proxy-platform-popa-botnet",
      "title": "FBI Seizes NetNut Proxy Platform, Popa Botnet",
      "summary": "Understanding how compromised home networks are used as exit nodes helps engineers model adversary obfuscation and identify indicators from NetNut's SDK/backend infra.",
      "content_text": "Understanding how compromised home networks are used as exit nodes helps engineers model adversary obfuscation and identify indicators from NetNut's SDK/backend infra.",
      "date_published": "2026-07-02T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "threat-hunting"
      ],
      "external_url": "https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/",
      "author": {
        "name": "Krebs on Security"
      }
    },
    {
      "id": "https://babels.dev/articles/google-s-continued-disruption-of-malicious-residential-proxy",
      "url": "https://babels.dev/articles/google-s-continued-disruption-of-malicious-residential-proxy",
      "title": "Google’s Continued Disruption of Malicious Residential Proxy Networks",
      "summary": "Detection engineers can use shared indicators for NetNut's SDKs and C2 to identify malicious proxy activity and compromised home devices used as exit nodes.",
      "content_text": "Detection engineers can use shared indicators for NetNut's SDKs and C2 to identify malicious proxy activity and compromised home devices used as exit nodes.",
      "date_published": "2026-07-02T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "threat-hunting"
      ],
      "external_url": "https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks/",
      "author": {
        "name": "Google Cloud — Threat Intelligence"
      }
    },
    {
      "id": "https://babels.dev/articles/inside-elastic-infosec-s-agentic-soc-cutting-alert-triage",
      "url": "https://babels.dev/articles/inside-elastic-infosec-s-agentic-soc-cutting-alert-triage",
      "title": "Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3",
      "summary": "Offload routine triage to code so analysts only touch high-signal, non-deterministic investigations.",
      "content_text": "Offload routine triage to code so analysts only touch high-signal, non-deterministic investigations.",
      "date_published": "2026-07-02T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "siem"
      ],
      "external_url": "https://www.elastic.co/security-labs/alert-triage-agentic-soc-elastic-workflows",
      "author": {
        "name": "Elastic Security Labs"
      }
    },
    {
      "id": "https://babels.dev/articles/google-cloud-confirmed-to-offer-a-safer-choice-for-eu-public",
      "url": "https://babels.dev/articles/google-cloud-confirmed-to-offer-a-safer-choice-for-eu-public",
      "title": "Google Cloud confirmed to offer a safer choice for EU public sector organizations with Dutch DPIA approval",
      "summary": "Validates Google Cloud’s security posture through independent audit, reducing compliance risk for public sector migrations.",
      "content_text": "Validates Google Cloud’s security posture through independent audit, reducing compliance risk for public sector migrations.",
      "date_published": "2026-07-01T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "siem"
      ],
      "external_url": "https://cloud.google.com/blog/products/identity-security/google-cloud-confirmed-to-offer-a-safer-choice-for-eu-public-sector-organizations-with-dutch-dpia-approval/",
      "author": {
        "name": "Google Cloud — Security & Identity"
      }
    },
    {
      "id": "https://babels.dev/articles/new-idc-study-the-business-value-of-mandiant-consulting",
      "url": "https://babels.dev/articles/new-idc-study-the-business-value-of-mandiant-consulting",
      "title": "New IDC study: The business value of Mandiant Consulting",
      "summary": "Use third-party validation and quantified business metrics to justify security investments and resource allocation at the executive level.",
      "content_text": "Use third-party validation and quantified business metrics to justify security investments and resource allocation at the executive level.",
      "date_published": "2026-07-01T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "incident-response"
      ],
      "external_url": "https://cloud.google.com/blog/products/identity-security/new-idc-study-how-mandiant-transforms-security-into-a-competitive-advantage/",
      "author": {
        "name": "Google Cloud — Security & Identity"
      }
    },
    {
      "id": "https://babels.dev/articles/sigma-to-elastic-pitfalls",
      "url": "https://babels.dev/articles/sigma-to-elastic-pitfalls",
      "title": "Three Pitfalls When Converting SIGMA Rules to Elastic",
      "summary": "Most broken SIGMA-to-Elastic conversions come down to three fixable causes: mismatched field mappings, ignored log-source scoping, and skipping post-conversion tuning against real data.",
      "content_text": "Most broken SIGMA-to-Elastic conversions come down to three fixable causes: mismatched field mappings, ignored log-source scoping, and skipping post-conversion tuning against real data.",
      "date_published": "2026-07-01T00:00:00.000Z",
      "tags": [
        "sigma",
        "elastic",
        "detection-engineering"
      ],
      "external_url": "https://example.com/sigma-elastic-pitfalls",
      "author": {
        "name": "Alex Rivera — Blue Team Notes"
      }
    },
    {
      "id": "https://babels.dev/articles/train-triage-repeat-the-ai-agent-changing-how-we-fight",
      "url": "https://babels.dev/articles/train-triage-repeat-the-ai-agent-changing-how-we-fight",
      "title": "Train, triage, repeat: The AI agent changing how we fight phishing",
      "summary": "Offload high-volume triage to an automated pipeline so analysts can focus on nuanced threat hunting instead of manual classification.",
      "content_text": "Offload high-volume triage to an automated pipeline so analysts can focus on nuanced threat hunting instead of manual classification.",
      "date_published": "2026-06-30T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "incident-response"
      ],
      "external_url": "https://redcanary.com/blog/threat-detection/phishing-ai-agent/",
      "author": {
        "name": "Red Canary"
      }
    },
    {
      "id": "https://babels.dev/articles/cloud-ciso-perspectives-how-google-cloud-security-uses-ai",
      "url": "https://babels.dev/articles/cloud-ciso-perspectives-how-google-cloud-security-uses-ai",
      "title": "Cloud CISO Perspectives: How Google Cloud Security uses AI internally",
      "summary": "Demonstrates how agentic workflows can automate high-volume tasks like security review, vulnerability verification, and patch generation at scale.",
      "content_text": "Demonstrates how agentic workflows can automate high-volume tasks like security review, vulnerability verification, and patch generation at scale.",
      "date_published": "2026-06-29T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "ci-cd"
      ],
      "external_url": "https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-how-google-cloud-security-uses-ai-internally/",
      "author": {
        "name": "Google Cloud — Security & Identity"
      }
    },
    {
      "id": "https://babels.dev/articles/from-bing-search-to-ransomware-bumblebee-and-adaptixc2",
      "url": "https://babels.dev/articles/from-bing-search-to-ransomware-bumblebee-and-adaptixc2",
      "title": "From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira",
      "summary": "This case highlights a multi-stage campaign from initial SEO lure to credential theft and ransomware deployment — useful for building detections across the full kill chain (sideloading, persistence, lateral movement).",
      "content_text": "This case highlights a multi-stage campaign from initial SEO lure to credential theft and ransomware deployment — useful for building detections across the full kill chain (sideloading, persistence, lateral movement).",
      "date_published": "2026-06-29T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "incident-response"
      ],
      "external_url": "https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/",
      "author": {
        "name": "The DFIR Report"
      }
    },
    {
      "id": "https://babels.dev/articles/the-bear-necessities-a-look-at-the-drivers-dynamics-and",
      "url": "https://babels.dev/articles/the-bear-necessities-a-look-at-the-drivers-dynamics-and",
      "title": "The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem",
      "summary": "Understanding these evolving tactics and the use of AI helps defenders anticipate wider targeting beyond Ukraine and build more comprehensive detection strategies.",
      "content_text": "Understanding these evolving tactics and the use of AI helps defenders anticipate wider targeting beyond Ukraine and build more comprehensive detection strategies.",
      "date_published": "2026-06-29T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "incident-response"
      ],
      "external_url": "https://cloud.google.com/blog/topics/threat-intelligence/pro-russia-influence-ecosystem/",
      "author": {
        "name": "Google Cloud — Threat Intelligence"
      }
    },
    {
      "id": "https://babels.dev/articles/why-babels",
      "url": "https://babels.dev/articles/why-babels",
      "title": "Why Babels: Sharper Detection Engineering in the Age of AI",
      "summary": "Babels exists to make high-quality detection engineering more accessible — pairing open-source tooling with AI-assisted workflows so practitioners can convert, validate, and deploy detections faster.",
      "content_text": "Babels exists to make high-quality detection engineering more accessible — pairing open-source tooling with AI-assisted workflows so practitioners can convert, validate, and deploy detections faster.",
      "date_published": "2026-06-28T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "ai",
        "announcement"
      ],
      "author": {
        "name": "Arjun G. Raman — Babels"
      }
    },
    {
      "id": "https://babels.dev/articles/securing-agentic-ai-with-perimeter-guardrails-what-s-new-in",
      "url": "https://babels.dev/articles/securing-agentic-ai-with-perimeter-guardrails-what-s-new-in",
      "title": "Securing agentic AI with perimeter guardrails: What's new in VPC Service Controls",
      "summary": "VPC Service Controls act as a critical safety net by blocking data exfiltration at the API layer even when an agent possesses valid IAM credentials.",
      "content_text": "VPC Service Controls act as a critical safety net by blocking data exfiltration at the API layer even when an agent possesses valid IAM credentials.",
      "date_published": "2026-06-26T00:00:00.000Z",
      "tags": [
        "detection-engineering",
        "threat-hunting"
      ],
      "external_url": "https://cloud.google.com/blog/products/identity-security/securing-agentic-ai-whats-new-in-vpc-service-controls/",
      "author": {
        "name": "Google Cloud — Security & Identity"
      }
    },
    {
      "id": "https://babels.dev/articles/stockstay-another-day-the-latest-addition-to-turla-s",
      "url": "https://babels.dev/articles/stockstay-another-day-the-latest-addition-to-turla-s",
      "title": "STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus",
      "summary": "Detection can focus on inter-process communication via WM_COPYDATA messages and the use of websocket-sharp for C2 tunneling.",
      "content_text": "Detection can focus on inter-process communication via WM_COPYDATA messages and the use of websocket-sharp for C2 tunneling.",
      "date_published": "2026-06-25T00:00:00.000Z",
      "tags": [
        "threat-hunting",
        "incident-response"
      ],
      "external_url": "https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering/",
      "author": {
        "name": "Google Cloud — Threat Intelligence"
      }
    }
  ]
}