GlobeNewswire by notified

Intezer Research Finds Enterprises Miss Dozens of Real Threats Each Year by Ignoring “Low-Severity” Alerts

3.2.2026 15:02:00 CET | GlobeNewswire by notified | Press release

Share

Analysis of more than 25 million security alerts shows traditional risk tolerance no longer aligns with modern attack behavior

NEW YORK , Feb. 03, 2026 (GLOBE NEWSWIRE) -- Intezer, the AI SOC platform for enterprise powered by ForensicAI, today released its 2026 AI SOC Report for CISOs, based on the forensic analysis of more than 25 million security alerts across live enterprise environments. The research reveals a critical disconnect between how security teams prioritize alerts and where threats actually originate, with dozens of real threats per organization each year traced back to alerts typically classified as low-severity or informational.

The findings highlight a long-standing challenge in security operations. When alert volume increases faster than enterprise SOC teams can scale, low-severity and informational alerts are deprioritized as part of acceptable risk. Intezer examined alerts across endpoint, cloud, identity, network, and phishing telemetry and found that nearly 1% of confirmed incidents originated from alerts initially labeled as low-severity. At endpoints, that figure rose to almost 2%. For a typical enterprise generating hundreds of thousands of alerts annually, this translates into approximately 50 real threats and potential cyber breaches per year that are likely never investigated.

“Security teams have normalized the idea that some risk must be accepted because it is impossible to investigate everything,” said Itai Tevet, CEO and co-founder of Intezer. “Our research shows that this acceptance is increasingly misaligned with how modern attacks unfold. When genuine threats consistently emerge from alerts we have trained ourselves to ignore, the definition of acceptable risk needs to be reexamined.”

Key Findings from the 2026 AI SOC Report

  • Endpoint protection frequently reports success while systems remain compromised — Over half of all endpoint alerts were not automatically mitigated by their endpoint protection solution. Of these non-mitigated alerts, almost 9% were confirmed as malicious. Additionally, 1.6% of alerts that underwent live forensic endpoint scanning were found to have active compromise even though endpoint security tools indicated the threat had been mitigated.
  • Attackers favor stealth and persistence over noisy exploitation — Cloud alerts were dominated by defense evasion and persistence techniques, reflecting attackers’ focus on long-term access and abuse of legitimate services rather than immediate disruption.
  • Phishing has shifted from attachments to browsers and trusted platforms — Fewer than 6% of malicious phishing emails contained attachments. Most relied on links, language, and abuse of legitimate services such as code sandboxes, cloud file sharing, and CAPTCHA mechanisms to evade detection.
  • Identity telemetry produces high volumes of alerts with low signal — Location anomalies and impossible travel alerts were rarely malicious, with only about 2% indicating a real compromise. VPN usage, mobile behavior, and overlapping security tools were the primary drivers of false positives.
  • Cloud misconfigurations remain persistent and widespread — The majority of cloud posture findings involve legacy or default configurations, particularly in Amazon S3, including missing encryption, weak access controls, and lack of logging.
  • Companies still rely on perimeter security rather than zero-trust security — Intezer observed widespread transmission of credentials and sensitive data over unencrypted internal protocols, indicating that many organizations still assume internal networks are trustworthy rather than enforcing zero-trust principles such as encryption in transit and continuous verification.

Implications for Security Leaders
Intezer’s data shows that what most organizations view as “acceptable risk” is no longer justified in an era in which AI-driven forensic analysis can operate at enterprise scale. As alert volume continues to escalate, driven by the expanding attack surface and AI-orchestrated cyber attacks, organizations need deeper analysis of every signal, particularly those that have historically been deprioritized due to volume rather than true risk. With AI capable of performing high-fidelity forensic analysis across all alerts, organizations that continue to rely on aggressive triage and selective investigation may be underestimating their exposure.

Download the report and register to join the Intezer research team on February 4, at 12 p.m. ET for a webinar providing an in-depth analysis of these findings and what it means for SOC leaders and their teams.

Research Methodology
The 2026 AI SOC Report for CISOs is based on Intezer’s analysis of security activity observed across its global customer base throughout 2025. The research examined more than 25 million security alerts, spanning 10 million monitored endpoints and identities; 180 million analyzed files; 82,000 endpoint forensic investigations, including live memory scans; and telemetry from 7 million IP addresses, 3 million domains and URLs, and over 550,000 phishing emails. The dataset covers activity across 206 countries and territories. All findings were aggregated and anonymized, with no customer-identifying or sensitive information accessed or retained.

About Intezer
Intezer AI SOC delivers 24/7, forensic-grade cyber alert triage across 100% of alerts, with less than 2% escalated for human review, dramatically accelerating incident response. Powered by ForensicAI™, Intezer specializes in deep forensic investigation to deliver unmatched accuracy and speed, significantly reducing cyber risk and enabling security teams to operate effectively without reliance on outsourced services. Intezer is trusted by global enterprises including NVIDIA, MGM Resorts, Equifax, Salesforce, and Ferguson. Learn more at www.intezer.com.

Media Contact
Jennifer Tanner
Look Left Marketing
intezer@lookleftmarketing.com

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/00c434de-bd67-439b-a4c6-71863c4e2a24

Subscribe to releases from GlobeNewswire by notified

Subscribe to all the latest releases from GlobeNewswire by notified by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from GlobeNewswire by notified

Iveco Group signs a 150 million euro term loan facility with Cassa Depositi e Prestiti to support investments in research, development and innovation11.6.2024 12:00:00 CEST | Press release

Turin, 11th June 2024. Iveco Group N.V. (EXM: IVG), a global automotive leader active in the Commercial & Specialty Vehicles, Powertrain and related Financial Services arenas, has successfully signed a term loan facility of 150 million euros with Cassa Depositi e Prestiti (CDP), for the creation of new projects in Italy dedicated to research, development and innovation. In detail, through the resources made available by CDP, Iveco Group will develop innovative technologies and architectures in the field of electric propulsion and further develop solutions for autonomous driving, digitalisation and vehicle connectivity aimed at increasing efficiency, safety, driving comfort and productivity. The financed investments, which will have a 5-year amortising profile, will be made by Iveco Group in Italy by the end of 2025. Iveco Group N.V. (EXM: IVG) is the home of unique people and brands that power your business and mission to advance a more sustainable society. The eight brands are each a

DSV, 1115 - SHARE BUYBACK IN DSV A/S11.6.2024 11:22:17 CEST | Press release

Company Announcement No. 1115 On 24 April 2024, we initiated a share buyback programme, as described in Company Announcement No. 1104. According to the programme, the company will in the period from 24 April 2024 until 23 July 2024 purchase own shares up to a maximum value of DKK 1,000 million, and no more than 1,700,000 shares, corresponding to 0.79% of the share capital at commencement of the programme. The programme has been implemented in accordance with Regulation No. 596/2014 of the European Parliament and Council of 16 April 2014 (“MAR”) (save for the rules on share buyback programmes set out in MAR article 5) and the Commission Delegated Regulation (EU) 2016/1052, also referred to as the Safe Harbour rules. Trading dayNumber of shares bought backAverage transaction priceAmount DKKAccumulated trading for days 1-25478,1001,023.01489,100,86026:3 June 20247,0001,050.597,354,13027:4 June 20245,0001,055.705,278,50028:6 June20243,0001,096.273,288,81029:7 June 20244,0001,106.174,424,68

Landsbankinn hf.: Offering of covered bonds11.6.2024 11:16:36 CEST | Press release

Landsbankinn will offer covered bonds for sale via auction held on Thursday 13 June at 15:00. An inflation-linked series, LBANK CBI 30, will be offered for sale. In connection with the auction, a covered bond exchange offering will take place, where holders of the inflation-linked series LBANK CBI 24 can sell the covered bonds in the series against covered bonds bought in the above-mentioned auction. The clean price of the bonds is predefined at 99,594. Expected settlement date is 20 June 2024. Covered bonds issued by Landsbankinn are rated A+ with stable outlook by S&P Global Ratings. Landsbankinn Capital Markets will manage the auction. For further information, please call +354 410 7330 or email verdbrefamidlun@landsbankinn.is.

Relay42 unlocks customer intelligence with a new insights and reporting module, powered by Amazon QuickSight11.6.2024 11:00:00 CEST | Press release

AMSTERDAM, June 11, 2024 (GLOBE NEWSWIRE) -- Relay42, a leading European Customer Data Platform (CDP), is leveraging Amazon QuickSight to power its new real-time customer intelligence, reporting, and dashboard module. Harnessing the breadth and quality of customer data, the new Insights module empowers marketing teams to dive deep into customer behaviors and gain invaluable insights into the performance of their marketing programs across all online, offline, paid, and owned marketing channels. Preview of the Relay42 Insights module, in pre-beta version Key capabilities of the Relay42 Insights module include: Deep insights into customer behaviors: With the Relay42 Insights module, marketers can ask unlimited questions about their data and gain a deeper understanding of how to serve their customers more effectively. Simplicity with AI-powered querying: Marketers can use artificial intelligence to query their data using natural language search, reducing the reliance on data scientists. Us

Metasphere Labs Announces X Spaces Event on the Topic of Green Bitcoin Mining and Sound Money for Sustainability11.6.2024 10:30:00 CEST | Press release

VANCOUVER, British Columbia, June 11, 2024 (GLOBE NEWSWIRE) -- Metasphere Labs Inc. (formerly Looking Glass Labs Ltd., "Metasphere Labs" or the "Company") (Cboe Canada: LABZ) (OTC: LABZF) (FRA: H1N) is thrilled to announce an engaging Twitter Spaces event on Green Bitcoin mining, energy markets, and sustainability on July 3, 2024 at 2 p.m. ET. Follow us on X at MetasphereLabs for updates and to join the event. What We'll Discuss Bitcoin Mining Basics: Understand the fundamentals of Bitcoin mining.Energy Market Dynamics: Explore how Bitcoin mining interacts with energy markets.Sustainable Innovations: Learn about our efforts to promote sustainability in Bitcoin mining.Sound Money: Discover how tamper-proof currency can enhance stability.Efficient Payment Rails: See how fast, neutral payment systems support humanitarian projects.Carbon Footprint: Compare Bitcoin's environmental impact with traditional banking. "We're excited to host this event and dive into the critical topics of Bitcoin

World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye