AntiMalware•July 18, 2026•🇷🇺Translated from Russian

Solar SIEM 2026.2 Adds Full Solar JSOC Detection Library, TI Feeds Support, Enhanced AI Agent and Multi-Tenancy

GC Solar has released Solar SIEM 2026.2, introducing several major enhancements designed to reduce the manual effort traditionally required when deploying a security information and event management platform.

The most significant addition is the complete library of detection rules developed by Solar JSOC. This knowledge base was accumulated over 14 years of continuous monitoring and incident investigation across the infrastructures of approximately 300 customers. Organizations no longer need to spend months creating their own rule sets tailored to specific environments; instead, they receive battle-tested detection scenarios that enable identification of complex attacks at the earliest stages of deployment.

According to Solar JSOC statistics for 2025, the center processed 1.16 million security events after filtering out false positives. Customers confirmed more than 33,000 incidents. The most common threat types were malicious software, responsible for 36 percent of cases, and attempts at unauthorized access, which accounted for 23 percent.

The update also introduces support for TI Feeds. Solar SIEM can now automatically load indicators of compromise from the Solar 4RAYS database as well as from customer-provided external sources and correlate them in real time against events collected from the monitored infrastructure.

Capabilities of the built-in AI agent have been substantially expanded. Previously limited to analyzing data contained within an incident card, the agent can now independently access and examine raw source data, conduct deeper investigation, and propose subsequent response actions. This functionality is intended to accelerate initial triage and reduce routine workload for security analysts.

Another important new feature is multi-tenancy. Multiple organizations can now be connected to a single Solar SIEM installation while their event streams remain fully isolated. This architecture primarily targets holdings, MSSP providers, and large enterprises with numerous separate divisions.

More than 40 companies of varying sizes participated in the pilot testing of the new version. Overall, Solar SIEM 2026.2 shifts the emphasis from lengthy manual configuration toward immediate use of a ready-made knowledge base, enabling effective security monitoring even without maintaining a large internal SOC team.

Related articles

AntiMalware•Other

Bureau 1440 Unveils Satellite Internet Terminals Reaching 700 Mbps for Industrial and Rail Use

Bureau 1440 presented three satellite terminal models at the Digital Solutions forum in Russia. The 1440 ULTRA model supports data speeds up to 700 Mbps and is designed for remote industrial sites and infrastructure, operating both stationary and in motion. The company reduced the terminal's weight by 30 percent while maintaining 600 by 600 mm dimensions and adding IP67 dust and water protection. The 1440 ZEMLYA variant is already undergoing tests on Russian Railways trains, including Lastochka and Sapsan services, and is rated for operation at speeds up to 400 km/h. A compact 1440 MINI concept aims for around 100 Mbps in a 300 by 300 mm portable form factor intended for rescue teams and expeditions. All models are being developed alongside the company's low-orbit satellite constellation, with test connections already active on rail lines and in remote settlements. Sales have not yet begun, and the company will announce availability separately while noting that maximum speeds are not guaranteed in every environment.

AntiMalware•Other

GTA V Unofficial Browser Port Runs Locally via WebAssembly Using Leaked Rockstar Sources

Enthusiasts created an unofficial port of GTA V that executes the game directly in the browser through WebAssembly without any cloud streaming. The project compiled the original RAGE engine to wasm64 and built a compatibility layer translating DirectX 11 calls to WebGPU. Game assets were served over HTTP while JavaScript handled input and saves, and AudioWorklet managed audio. The port retained Euphoria physics and Scaleform interfaces but removed Bink video playback. Requirements ranged from 3 to 16 GB of RAM, supporting both story mode and free roam. The site was taken offline shortly after launch, first displaying a thank-you message and later redirecting to adult content. Analysis of the build confirmed debug symbols and developer file paths consistent with leaked Rockstar source code.

Habr•Other

PKI Storm: Managing 100,000 Simultaneous Certificate Requests in Kubernetes Recovery Scenarios

A large organization's PKI infrastructure faced a critical bottleneck when a data center outage triggered simultaneous startup of tens of thousands of Kubernetes pods, each requiring mTLS certificates. The existing setup using ESAUS and Citadel routed all requests through external certificate authorities that could only sustain 50-70 RPS against an incoming burst of 100,000 requests. Average daily load of 10-11 RPS had masked the thundering herd risk during mass recovery. Scaling the CA 15x was rejected due to cost and the fundamental dependency on real-time signing. The team introduced pre-issuance of certificates stored in a dedicated Unified Secret Storage (ЕХС) layer that supports 14,000 RPS reads while the CA continues normal operation. This architectural separation of issuance and consumption reduced recovery time from nearly 24 minutes to seconds while shifting focus to secure secret lifecycle management including KRA key protection.

AntiMalware•Other

MinTsifry Considers Annual 10 Billion Rubles Support Package for Russian AI Development

Russia's Ministry of Digital Development is discussing a state support package worth up to 10 billion rubles per year aimed at local AI developers. The proposed funding would cover technology development, pilot launches, and compensation for computing resources. According to Kommersant, 8 billion rubles are planned for development and implementation while 2 billion would offset computational costs. Mechanisms under consideration include subsidized loans through authorized banks and grants covering up to 80 percent of pilot project costs in priority sectors. The initiative remains in discussion with no final parameters or launch timelines confirmed yet. Industry experts note that clear selection criteria and transparent reporting will be essential to prevent intermediaries and ensure fair access for independent teams.