Cyber Resilience Act Countdown: HarfangLab’s Nutanix Integration & Cost-Effective AI Code Audits

RED ALERT LABS’ NOTICE: CYBER RESILIENCE ACT STARTS CARRY IMPACT

Be ready before 11 September 2026. From that date, manufacturers must be able to report actively exploited vulnerabilities and severe product-security incidents under the CRA. Red Alert Labs helps you design, document, test, and operate the vulnerability handling and reporting chain required to meet this new obligation. 

HARFANGLAB AT GISEC DUBAI, PARTNERS WITH NUTANIX AND COMMENTS THE EVOLUTION OF ITS PRODUCTS

The French Threat management leading vendor will exhibit at GISEC on September 16-18, 2026.

Just before this event, a partnership agreement was announced between HARFANGLAB and NUTANIX; Nutanix, a specialist in hybrid multicloud solutions, announced on Thursday, August 20, the integration of HarfangLab’s protection and detection capabilities into its virtualized infrastructures. The company aims to better secure its users’ hypervisors, virtual machines, and workloads from a single platform.

The goal is also to minimize the impact on the performance of Nutanix environments through the integration of a lightweight agent. This platform integrates several layers of security. The first, Attack Surface Management (ASM), aims to identify vulnerabilities in virtual machines and detect unknown or unauthorized assets. The second, Endpoint Protection Platform (EPP), detects and blocks malicious files and executables. The third, Endpoint Detection and Response (EDR), detects advanced threats (ransomware, DLL sideloading, etc.) through heuristic and behavioral analysis, indicators of compromise (IOCs), and AI.

The platform also includes investigation and remediation features such as automatic blocking, quarantine, alert correlation, remote endpoint access, whitelist management, and false positive optimization.

PRODUCT CORNER:

40% of our customers are now using HarfangLab AI in their day-to-day operations, and that number continues to grow, says Anouck Tellier, deputy CEO of the company.

They use it for :

Contextualising and correlating security events and attack paths

Diving deeper into detection signals and detection engineering

Getting a better understanding of specific HarfangLab platform features

And automated whitelisting is quickly climbing the ranks as one of the most relevant use cases.

Our users are validating our approach: AI should not be bolted on, but built in. It should not be generic, it should serve SOC analysts immediate needs and clear use cases. This is the compass that drives HarfangLab AI with still more to come.

AIKIDO BETTER TO DETECT VULNERABILITIES FOR A SMALLER COST

We here reproduce a post by AIKIDO. 

Last week, Anthropic finally released Mythos for enterprises, so we benchmarked it against our own harness. Turns out our harness found more vulnerabilities with smaller models. So we wrote a blog post on how we achieved this.

Bottom line: a single agent using Mythos will find more vulnerabilities than an agent using Sonnet. But if you put 4 agents using Sonnet and group their individual findings, you end up with more findings at a lower cost.

So we exploited this to the extreme. Our harness spawns hundreds of agents with frontier small models to find all the vulnerabilities in a codebase. Obviously, the results might be noisier. We fix that by using smarter models on the steps that require more intelligence, such as eliminating the false positives.

In the end, our AI Code Analysis rediscovered 76% of the known vulnerabilities on our benchmark application, versus 67% for Mythos (and 65% for Codex Security). Our harness also ended up costing only half of what Mythos cost us (customer price for both).

Turns out the harness matters even more than the model.

SEKOIA : ANOTHER CONVERGING VIEW ON HOW TO MAKE THE BEST OF AI FOR SOCs

In a remarkable post, Fabien Dombard explains how AI can really be helpful to SOC operators, and … how it can be a mistake. To give a flavour : 

Here’s the pattern I keep running into. A team buys an “AI SOC” product, points it at the alert queue, and expects magic. It triages a subset of alerts against a few pre-built scenarios, prints a verdict, and moves on. It looks like progress. It’s a faster way to be wrong. An agent that reasons only over the alert in front of it is working blind. It doesn’t know whether that host is a domain controller or a test box. It doesn’t know that the user just failed MFA twice from a new country. It doesn’t know the destination IP was flagged by threat intelligence three hours ago. It’s a very confident analyst who’s been handed a single line of a case file and asked to close it.That’s the whole difference between AI on a SOC and a SOC built for AI.

Read the full article here 

Share:

More Posts