Home / Companies / Stream.Security / Blog / July 2026

July 2026 Summaries

2 posts from Stream.Security

Filter
Month: Year:
Post Summaries Back to Blog
In the exploration of building an agentic Security Operations Center (SOC), the text outlines a scenario where an AI-driven attack unfolds from a single stolen credential with low-privileged access to Lambda functions. This attack demonstrates the power of AI to escalate privileges rapidly, highlighting the vulnerabilities within cloud environments when an identity with limited permissions can potentially lead to account takeover. Despite taking a wrong turn by attempting to guess an S3 bucket name, the AI managed to gain admin-level access by leveraging an over-permissive API, illustrating how modern cloud attacks can be executed swiftly and without the need for sophisticated exploits. The narrative underscores the challenge for human SOCs to keep pace with such attacks, as the AI operates without delays and can swiftly adjust its tactics. The attack, loud in its execution and generating multiple alerts across different systems, appears as separate incidents to human analysts, but is in fact a single coordinated effort. The text sets the stage for subsequent discussions on designing effective defenses and leveraging AI to synthesize these alerts into a coherent response, aiming to prevent further exploitation before critical access is achieved.
Jul 28, 2026 1,205 words in the original blog post.
A Security Architect's role extends beyond deeply understanding technology stacks to include respecting legacy systems, balancing business needs, and integrating security within mixed environments under real constraints. This involves acknowledging defense gaps and working closely with the Security Operations Center (SOC) to ensure those gaps are covered, transforming the architect's responsibilities as AI starts redefining SOC operations. The emergence of agentic systems, which are taking over many human roles in triage and investigation, necessitates that architects now actively participate in designing SOCs as systems rather than organizations. This shift requires architects to ensure that AI-driven SOCs have the necessary context and boundaries to operate effectively, highlighting the importance of the architect's role in defining what automated actions are permissible. This series will explore the practical implications of these changes by using realistic cloud attack scenarios, demonstrating how AI SOCs can identify and respond to threats efficiently, with architects playing a crucial role in shaping the response capabilities.
Jul 27, 2026 1,235 words in the original blog post.