AntiMalwareJuly 18, 2026🇷🇺Translated from Russian

Solar SIEM 2026.2 Adds Full Solar JSOC Detection Library, TI Feeds Support, Enhanced AI Agent and Multi-Tenancy

GC Solar has released Solar SIEM 2026.2, introducing several major enhancements designed to reduce the manual effort traditionally required when deploying a security information and event management platform.

The most significant addition is the complete library of detection rules developed by Solar JSOC. This knowledge base was accumulated over 14 years of continuous monitoring and incident investigation across the infrastructures of approximately 300 customers. Organizations no longer need to spend months creating their own rule sets tailored to specific environments; instead, they receive battle-tested detection scenarios that enable identification of complex attacks at the earliest stages of deployment.

According to Solar JSOC statistics for 2025, the center processed 1.16 million security events after filtering out false positives. Customers confirmed more than 33,000 incidents. The most common threat types were malicious software, responsible for 36 percent of cases, and attempts at unauthorized access, which accounted for 23 percent.

The update also introduces support for TI Feeds. Solar SIEM can now automatically load indicators of compromise from the Solar 4RAYS database as well as from customer-provided external sources and correlate them in real time against events collected from the monitored infrastructure.

Capabilities of the built-in AI agent have been substantially expanded. Previously limited to analyzing data contained within an incident card, the agent can now independently access and examine raw source data, conduct deeper investigation, and propose subsequent response actions. This functionality is intended to accelerate initial triage and reduce routine workload for security analysts.

Another important new feature is multi-tenancy. Multiple organizations can now be connected to a single Solar SIEM installation while their event streams remain fully isolated. This architecture primarily targets holdings, MSSP providers, and large enterprises with numerous separate divisions.

More than 40 companies of varying sizes participated in the pilot testing of the new version. Overall, Solar SIEM 2026.2 shifts the emphasis from lengthy manual configuration toward immediate use of a ready-made knowledge base, enabling effective security monitoring even without maintaining a large internal SOC team.

Related articles

AntiMalwareOther

StormWall Releases StormWall Appliance for On-Premises DDoS Protection

StormWall has introduced StormWall Appliance, a software solution that filters DDoS attacks inside the customer's own infrastructure rather than routing traffic to an external cloud. The product is aimed primarily at banks, hosting providers, internet service providers, and organizations with strict requirements for infrastructure availability and data control. It supports fully isolated networks through offline licensing with a hardware key and can operate independently or in a hybrid mode with StormWall's cloud platform. The appliance handles attacks at OSI layers L3 through L5, including volumetric floods, TCP stack attacks, reflection and amplification schemes, DNS attacks, and gaming protocols. It also processes TLS and QUIC traffic without decryption using DPDK and proprietary algorithms. Deployment takes as little as one day, with a 30-day free trial available after installation.

HabrOther

Developer Builds Custom Bouncer Tool to Automatically Block .env and SSH Probing on VPS

A system administrator running a small VPS with Caddy and static sites grew tired of constant password guessing attempts against SSH and repeated probes for files like .env, wp-admin, and config.php.bak. Instead of relying on Fail2ban, which required complex jail and filter configuration, the admin created a lightweight Rust-based tool named Bouncer. The program first crawls the site to build a list of legitimate paths, then monitors access logs and systemd journal entries for SSH invalid user attempts. IPs that generate multiple 404 responses for unknown paths or trigger SSH invalid user messages are added to an nftables set for automatic blocking. Special immediate bans are applied for direct hits on sensitive files such as /.env. The tool avoids double-counting SSH log lines, skips historical log replay on startup, and integrates directly with existing nftables rules without requiring additional runtime dependencies.

AntiMalwareOther

Russia Plans to Expand MAX Messenger with Unified Ticket Purchases Across All Transport Types

The Russian Ministry of Transport is developing new features for the MAX messenger to allow users to plan routes and purchase tickets for urban transport, trains, airplanes, and sea or river vessels within a single application. First Deputy Minister Konstantin Pashkov stated that the platform already supports verification of eligibility for discounted travel and handling of travel documents. Future plans include greater reliance on biometric identification, enabling passengers to complete bookings digitally and board using camera recognition without showing QR codes or physical documents. The initiative forms part of a gradual transition, with no immediate plans to phase out existing payment methods. New regulations effective from September 1 permit confirmation of social benefits through MAX and the use of biometric services where carriers have the required equipment. No specific timeline for full implementation of integrated ticketing has been provided.

AntiMalwareOther

5G Icon Appears on Select iPhones for Russian Users as Operators Expand Coverage

Some iPhone owners in Russia have observed the 5G indicator replacing LTE in the status bar, marking the first signs of fifth-generation network access on Apple devices. The change has been confirmed by a RIA Novosti correspondent but remains limited to a portion of users, with no official details released on supported models, carriers, or regions. Russian operators from the Big Four launched 5G services in 16 cities one week earlier, granting potential access to roughly 10 million subscribers. The initial rollout operates primarily on previously allocated LTE spectrum bands, delivering an estimated 20-25% increase in network throughput. Unlike Android devices, where the Ministry of Digital Development planned to enable compatible hardware directly, iPhone activation requires Apple to authorize specific operator frequencies and network configurations. Observers note that the presence of the 5G icon does not yet guarantee widespread deployment or significant speed gains, as performance depends on coverage, spectrum, device model, and network load.