Snare Insider Issue #15 – Oct 2026

Newsletter Issue #15 – Special Cyber Security Awareness Month Edition

The Threat Window Is Shrinking. Is Your Visibility Keeping Up?

October is Cybersecurity Awareness Month, and this year the Snare Insider is doing something different. Instead of one monthly issue, we are building the full Snare Insider over four weeks, one instalment at a time. This issue will continue to grow each week, so make sure you check back in each week.

Awareness is the starting point, but the teams we talk to want something more practical: what is changing, what it means for their environment, and one thing they can do about it this week.

Here is how the month unfolds.

Week 1 sets the scene with the Global Cyber Threat Pulse and a Threat Spotlight on the investigation gap.

Week 2 brings three feature articles timed with InfoSec World in Orlando and CyberCon in Melbourne.

Week 3 introduces the Snare perspective, the next evolution of Snare, a webinar and a practical playbook.

Week 4 rounds out the month.

Every instalment keeps the same thread: visibility before, during and after an incident matters more than ever. This week we start with the threat environment itself, because the case for better evidence begins with how quickly it is changing.

  • Attackers are moving faster. 88% of exploitation CrowdStrike observed against vulnerabilities with a public proof-of-concept in the first half of 2026 happened within 48 hours of release.
  • Identity is the attack path. Vishing intrusions doubled and device-code phishing attempts rose 15x in the same period — and ENISA’s 2026 Threat Landscape names social engineering and vulnerability exploitation as the two leading ways attackers get in across the EU.
  • Your historical evidence still matters. Global median dwell time rose to 14 days in Mandiant’s M-Trends 2026, and only 52% of compromises were first identified internally. Keeping the evidence is step one; being able to ask it questions fast is the next constraint.

The common thread: visibility before, during and after an incident matters more than ever.

TL:DR

1.Global Cyber Threat Pulse October 2026

Four regions. Four headline incidents, plus the smaller stories sitting alongside them. One recurring problem: organisations need independent, retained, searchable evidence.

AUSTRALIA — A THIRD-PARTY VULNERABILITY, NOT QUEST’S OWN SYSTEMS

Quest Apartment Hotels’ first disclosure described “primarily names, email addresses, and/or other contact details.” A mid-September update, after forensic analysis, confirmed about 1.99 million customers were affected, including 297,739 card numbers (46,727 with CVV), 104,268 passport and/or driver’s licence numbers and a small number of Medicare and NDIS numbers. The entry point was a vulnerability at a third-party service provider, not Quest’s own systems.

ASIA — THREE MONTHS BETWEEN ACCESS AND DISCLOSURE

A compromised maintenance-employee account gave attackers access to Japan’s Government Solution Service files in late June. A July investigation traced the entry point to an exploited VPN vulnerability, and the digital agency disclosed in September that more than 246,000 records were compromised. The sequence is the story: access in June, root cause in July, public disclosure in September.

UK/EUROPE — THE EMAIL PASSED EVERY TECHNICAL CHECK

Revolut confirmed it released customer identity data to an unauthorised third party after a fraudulent information request arrived from a real government agency’s domain and passed SPF, DKIM and DMARC. No system intrusion was involved: domain authenticity and requester authority are two different things.

US/NORTH AMERICA — THE API HAD NO RATE LIMIT

A threat actor claimed to have extracted 7.49 million customer records from a CenterPoint Energy public API said to lack rate limiting and adequate authentication. CenterPoint confirmed the breach in an SEC Form 8-K on 14 September, and class-action filings allege the exfiltration ran from 17 August to 1 September.

Threat Spotlight 

2.The Investigation Gap

This month we keep coming back to evidence: what gets collected, what gets retained, what’s still there when an investigation starts. That’s the right starting point — but it isn’t the whole problem. A second, quieter constraint sits right behind it: the investigation gap, the widening distance between how much security teams collect and how much of it is genuinely askable when it matters.

What the 2026 research says:

  • 79% of SOCs already use AI or machine learning somewhere in their operations; only 36% have integrated it into a defined SOC workflow (SANS 2026 SOC Survey, June 2026).
  • 24% of cyber leaders name enterprise-wide visibility as the single biggest barrier to SOC effectiveness — the top-ranked answer (SANS 2026 SOC Survey).
  • 70% of large SOCs are expected to be piloting AI agents for Tier 1 and Tier 2 operations by 2028, but only 15% will achieve measurable improvement without structured evaluation first (Gartner, 2026).

Read together, the picture is integration and context. Teams already have plenty of alerts and tools; what makes the difference is evidence integrated enough to ask a question across the whole environment at once. Retention answers “does the evidence still exist?” Integration answers “can someone find and use it, correlated, in the time an investigation has?” Four ordinary questions show where that matters:

  • “Has this account done this anywhere else in the last 90 days?”
  • “Did we see this indicator anywhere before the alert fired?”
  • “What changed on this host immediately before and after the event?”
  • “Is this pattern happening anywhere else in the environment right now?”

None of these are exotic — they’re the questions an analyst asks in the first ten minutes. In most environments, each still has to be hand-translated into platform-specific syntax, source by source, before it can even be asked.

Closing the gap takes three things at once: evidence that is collected and retained; evidence that is correlated and queryable in something closer to plain language than six query syntaxes; and, per Gartner’s caution, a querying layer that sits on evidence that’s already integrated. That third piece is where the Snare Insider goes later in the month, with a first full look at AskSnare, built on an evidence layer that’s already collected, normalised and correlated. Not a replacement for analyst judgement, and not the bolted-on AI SOC agent Gartner is cautioning against.

Source: SANS 2026 SOC Survey, June 2026; Gartner, “Validate the Promises of AI SOC Agents With These Key Questions,” 2026

Feature

Do This, This Week

Spend ten minutes pressure-testing your logging environment. Ask three questions:

  • Are we collecting the evidence we’d need to reconstruct an attack? Think beyond endpoint logs to identity, authentication, cloud platforms, network infrastructure, applications and privileged activity.
  • Are we retaining it long enough? Detection may happen today — the first sign of compromise may have occurred weeks or months earlier.
  • Could we actually retrieve and investigate it quickly? Collecting logs only has value if your team can access, search and analyse them fast once an incident occurs.

This Week’s Resources

The Cybersecurity Visibility Readiness Checklist

A practical checklist for security teams to assess:

Collection → Coverage → Integrity → Routing → Retention → Storage → Investigation → Incident Recovery

Use it to identify where gaps in your logging architecture could become gaps in your incident investigation.

Keep reading:

  • The 10 Questions Every CISO Should Be Able to Answer From Their Logs — a practical test of whether your organisation has the visibility required to investigate suspicious activity.
  • The Ransomware Investigation Playbook — what to log, retain and query at every stage of a ransomware intrusion, from initial access to extortion.

Week 2 Cyber Security Awareness Month

Next Week

Awareness is useful. Visibility is actionable.

Next week the Snare Insider grows: three feature articles timed with InfoSec World in Orlando and CyberCon in Melbourne — on proving what your AI did, the evidence investigators need after a detection, and the questions that follow an incident.

Cybersecurity Awareness Month | Week 2: Features from InfoSec World and CyberCon

Sources

This issue draws on primary regulatory text and named industry benchmarking rather than secondary summaries. Key sources:

CrowdStrike, “2026 Threat Hunting Report,” August 2026. crowdstrike.com/en-us/blog/crowdstrike-2026-threat-hunting-report/

ENISA, “Threat Landscape 2026,” September 2026. enisa.europa.eu/topics/cyber-threats/threat-landscape

Mandiant / Google Threat Intelligence Group, “M-Trends 2026,” 2026. cloud.google.com/blog/topics/threat-intelligence/m-trends-2026

SANS Institute, “2026 SOC Survey,” June 2026.

Gartner, “Validate the Promises of AI SOC Agents With These Key Questions,” Craig Lawson and Andrew Davies, 2026.

Snare Solutions
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.