[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQOJsxZ5Eesw8GcZ1AlqWzbdDLUVovBsxEyB-XkXJLIA":3},{"article":4,"iocs":48,"watch_terms":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"6476bfda-8dde-459a-85ef-69ae65c8dd04","The agentic SOC—Rethinking SecOps for the next decade","the-agentic-soc-rethinking-secops-for-the-next-decade-7f3479","In the SOC of the future, autonomous defense moves at machine speed, agents add context and coordination, and humans focus on judgment, risk, and outcomes. The post The agentic SOC—Rethinking SecOps for the next decade appeared first on Microsoft Security Blog.","Microsoft's Incident Response team identified Storm-2755, a financially motivated threat actor conducting targeted attacks against Canadian employee accounts. The attackers compromise employee profiles to redirect salary payments to attacker-controlled accounts, representing a novel \"payroll pirate\" attack vector. The research highlights emerging threats in the identity and access management space with direct financial impact.","Microsoft DART tracks Storm-2755 threat actor targeting Canadian employees for payroll diversion attacks.","April 9 12 min read Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees Microsoft Incident Response – Detection and Response Team (DART) researchers observed an emerging, financially motivated threat actor, tracked as Storm-2755, compromising Canadian employee accounts to gain unauthorized access to employee profiles and divert salary payments to attacker-controlled accounts.","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F04\u002F09\u002Fthe-agentic-soc-rethinking-secops-for-the-next-decade\u002F","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002Fwp-content\u002Fuploads\u002F2026\u002F04\u002F961d56a4-4488-429d-9008-f5c6db2acb8c-1024x576.png","2026-04-09T19:00:00+00:00","2026-04-09T22:00:12.556923+00:00",7,[18,21,24],{"name":19,"type":20},"Storm-2755","threat_actor",{"name":22,"type":23},"Microsoft","vendor",{"name":25,"type":26},"Identity and Access Management","technology","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":27,"icon":29,"name":30,"slug":31},null,"Threat Intelligence","threat-intelligence",[33,38,43],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":39},{"id":40,"icon":29,"name":41,"slug":42},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":44},{"id":45,"icon":29,"name":46,"slug":47},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",[49],{"type":50,"value":19,"context":51},"malware","Financially motivated threat actor conducting payroll diversion attacks",[22]]