Security Vision SIEM Adds Monitoring for Missing Logs, Correlation Quality, and SOC SLA Compliance
Security Vision has released a major update to its SIEM platform. The new version monitors not only external attackers but also the stability of the data sources feeding the system, the performance of correlation rules, and the progress of ongoing investigations by analysts.
One of the key additions is monitoring for collection stability. Administrators can now oversee each individual source, configure acceptable deviations in event volume, and receive automatic notifications when events suddenly cease. This capability is intended to surface blind spots proactively rather than after an incident has already occurred.
A separate dashboard displays the quality of correlation rules. Rules can be tested against simulated events, and the platform supports import and export in Sigma format, simplifying the transfer of detection content between different systems.
The StatAnalyser service tracks atypical behavior using statistical rules and marks suspicious incidents with a dedicated indicator. Investigations benefit from a new retrospective process-chain builder inside each incident card. The system automatically runs additional queries to reconstruct parent processes, user sessions, and lateral movement across hosts, giving analysts a more coherent view of the compromise instead of isolated events.
The platform also monitors the SOC team itself. A new dashboard tracks SLA compliance during incident handling and allows managers to drill from aggregate statistics down to the performance of individual analysts.
Together these features aim to create a closed, manageable cycle for SOC operations: verify that data is actually arriving, assess detection quality, identify anomalies, reconstruct attack paths, and oversee team response. The updated SIEM is positioned as an active control point for the entire investigation process rather than a passive log repository.
Related articles
From Scanner Overload to Manual Insight: A Bug Bounty Hunter's Journey
A young researcher recounts his transition from automated scanning to thoughtful manual analysis in Bug Bounty programs. After completing a broad information security course covering cryptography, networks, Docker, databases, and OWASP Top 10, he initially approached real-world targets with the same scanner-heavy mindset used in labs. Months of fruitless results led to burnout and a six-month break working in construction. Returning with a new focus, he studied hundreds of public HackerOne reports to understand researcher reasoning and anomaly detection. This shift enabled his first valid, unreported finding and fundamentally changed his methodology. Today the 18-year-old university student balances Bug Bounty with reconnaissance, machine learning, and personal projects while emphasizing deep application understanding over tool volume.
Bypassing Paid Export on AI 3D Generation Sites via Browser Network Inspection
A detailed walkthrough shows how users can retrieve AI-generated 3D models in GLB format from services that normally require a paid subscription for export. The method relies on opening the browser developer console, filtering network requests for .glb files after model generation completes, and opening the intercepted asset in a new tab. Examples using Tripo3D and Hi3D demonstrate that the generated model and textures are already present on the client side even when the export button remains disabled. Additional steps address compatibility issues with 3ds Max by recommending conversion through gltf.report with Draco compression before import. The technique also covers post-processing in ZBrush for auto-retopology and format conversion to OBJ. The article notes that such workarounds exist because many AI platforms limit free exports while still rendering full models locally.
National Platform Max Begins Testing Advertising Tools to Monetize User Attention
The Russian national platform Max has started internal testing of new advertising instruments designed to convert user attention into sellable ad inventory. According to the company's press service, the tests are already underway inside the application, although the exact placement, visual format, and eligibility criteria for advertisers remain undisclosed. The move marks a significant shift for the platform, which previously operated without visible commercial advertising. Observers note that Max could become one of the largest domestic digital advertising channels if the tests prove successful. No timeline has been given for a public rollout or for the publication of detailed advertising policies.
Yandex Drops Earbuds Under X-Ray Microtomography: Detailed Internal Analysis of First AI-Powered TWS Headphones
Engineers used non-destructive X-ray microtomography to examine Yandex Drops, the company's first TWS earbuds featuring the Alice AI voice assistant. The scan revealed an eight-layer HDI PCB, three microphones per earbud arranged in a dual feedforward plus feedback ANC configuration, an 11 mm driver, and a QFN-packaged SoC with NPU. No hardware disconnect point was identified in the microphone signal path within visually accessible traces, connectors, and vias. Battery dimensions, coil windings in the case, and internal flex routing were measured directly from calibrated voxel data. The study also confirmed contact-based charging via spring-loaded claw contacts and a Hall-effect sensor in the case lid. The work demonstrates how industrial micro-CT can support hardware security reviews without destroying the sample.