Recent developments in detection engineering have focused on enhancing security measures for Microsoft Copilot, cloud environments, and non-human identities (NHIs). Detection rule repositories have seen significant updates, with 82 new and 328 modified rules across platforms such as Elastic, KQL, Splunk, Sigma, and YARA. New detection rules specifically target Microsoft 365 Copilot account compromise, including suspicious authentication patterns, usage anomalies, and prompt injection attempts, as well as eDiscovery log analysis. Additional rules address attacks against Ollama servers, covering DDoS, remote code execution, data exfiltration, and prompt injection, reflecting the growing threat landscape for AI-powered services. Azure environments have received new detection logic for destructive actions, such as Restore Point Collection and Storage Account deletions, and for identifying critical identity compromises in Microsoft Entra ID, including admin-confirmed compromises and Privileged Identity Management (PIM) failures. AWS detection coverage has improved with rules for federated user logins lacking multi-factor authentication, as well as enhanced monitoring for root user and IAM privilege escalation activities. Auth0 detections now correlate successful logins with suspicious TLS fingerprints, increasing the ability to spot anomalous access. Updates also refine detection of advanced process and memory manipulation techniques, such as API calls from spoofed parent processes, return-oriented programming (ROP) gadgets, image hollowing, and direct syscalls. System tampering, including boot file owner changes, is now more effectively detected. The focus on NHIs is growing, with organizations recognizing the need to modernize threat detection and response for these entities, as highlighted by guidance on using ITDR playbooks for NHI compromise. The cybersecurity community is also discussing the operational impact of AI in security operations centers (SOCs), noting that AI-driven tools can increase alert volumes and complexity. Industry newsletters emphasize the importance of consolidating cloud security platforms to manage risk in dynamic environments and highlight the ongoing challenges posed by the rapid adoption of AI and cloud technologies. Security leaders are encouraged to prioritize critical assets and adapt detection strategies to address evolving threats, particularly those targeting identity and access management systems. The integration of AI into detection engineering is transforming how threat intelligence is operationalized, enabling faster and more accurate rule creation. As organizations face increasing complexity in their security environments, staying informed about the latest detection rule changes and best practices is essential for maintaining robust defenses. The collective updates and guidance underscore the need for continuous improvement in detection engineering to keep pace with sophisticated adversaries and emerging attack vectors.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
The newsletter highlights Cisco’s open-source Project CodeGuard, intended to add guardrails to AI-assisted code generation. It was presented in the context of growing concern over agentic AI and insecure dependency selection.
The newsletter says an F5 source-code exposure led to a CISA emergency directive and broader community discussion about implications and recovery. The incident was compared by some observers to SolarWinds in terms of recovery challenges.
The newsletter reports widespread outages tied to AWS’s us-east-1 region that cascaded into broader internet service disruptions. It also notes public speculation that staffing losses at AWS may be contributing to reliability problems.
A major cyber incident affecting Jaguar Land Rover reportedly stopped production for five weeks and disrupted thousands of businesses across its supply chain. The incident’s impact was estimated at £1.9 billion.
Between October 13 and October 20, 2025, security repositories published new and updated detection rules, including coverage for the 'Shai Hulud' NPM supply-chain attack. The digest says the updates also added detections for cloud destructive actions, identity compromise, and multiple malware families.
According to claims summarized in the newsletter, China’s Ministry of State Security said the U.S. NSA exploited vulnerabilities in a foreign mobile phone brand’s messaging service to steal sensitive information. The alleged activity was said to have occurred during 2022 and 2023.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
detectionengineering.net
Open sourceresilientcyber.io
Open sourceresilientcyber.io
Open sourcedetections-digest.rulecheck.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.