Prophet AI Blog

Discover the Prophet AI Blog, your go-to source for the latest security insights and news, helping you stay ahead in threat detection and investigation.

The Hugging Face Breach: Part Incident Report, Part Product Launch

OpenAI's own models caused the Hugging Face breach. Marketing or not, the tradecraft was real: what the first agent-run intrusion means for your SOC team.

July 22, 2026
Ajmal Kohgadai

Emerging Threat Response Shouldn't Start With a 6 A.M. Scramble

Prophet AI Threat Researcher turns emerging threat intelligence into hunts that run automatically and rerun as reporting changes. Now generally available.

July 22, 2026
Jamie Scott

Discover Prophet AI for Security Operations

See for yourself how AI can transform the way security teams operate

The SOC Hierarchy of Needs: A Maturity Model for Modern Operations

From Alert Management to Posture Improvements, this guide maps the SOC Hierarchy of Needs for modern security teams

February 11, 2026
Ajmal Kohgadai

5 AI SOC Best Practices

Unlock the full potential of an AI SOC. Discover 5 operational best practices to eliminate alert backlogs, enforce consistency, and unshackle detection engineers

February 3, 2026
Jon Hencinski
Gourav Nagar

Zoom Phishing Email: Unmasking a Novel TOAD Attack Hidden in Legitimate Infrastructure

Prophet AI discovered a novel TOAD attack weaponizing Zoom’s legitimate infrastructure to bypass Secure Email Gateways. Learn how attackers abuse "Display Names" to mimic PayPal and how Prophet AI detects these "verified" phishing threats.

January 28, 2026
Augusto Barros

How to keep up with talent attrition in a SOC?

Stop the "revolving door" of SOC turnover. Discover how AI-enabled automation eliminates Level 1 toil, reduces alert noise, and transforms your SOC from a burnout factory into a fulfilling career

January 23, 2026
Augusto Barros

Prophet AI in Action: Unmasking "Zombie" Credentials in Subsidiary Infrastructure

"Dead" keys can still open doors. Read the case study of how Prophet AI investigated a dormant AWS access key attack, automating response and remediation to mere minutes.

January 23, 2026
Augusto Barros