thehackernews.com 12 Sept 2026, 10:24 UTC

AI Alerts Surge 685%, But SOCs Face a Flood of False Positives

CyberSIXT Evidence Panel Source marked as original reporting

THE Hacker News report analyzes a surge in AI-related activity within enterprise security operations centres (SOCs) over the past year. It notes that AI-related alerts still make up a tiny share of total alerts—about 0.43%—but that volume has grown by 685% from February to June 2026. The authors classify AI-triggered SOC alerts into three buckets: 94.1% noise (legitimate pre‑AI detections firing on current AI‑driven work), 5.8% genuine security risks, and 0.02% real attacks.

The picture emphasizes that the principal burden on SOCs is not a wave of AI-enabled breaches but an avalanche of misleading alerts, with a small, quiet core of genuine exposures that can be buried by the noise. Automated triage often suppresses nearly 82% of AI alerts, and only about 5.4% reach human analysts, underscoring that severity labels for AI activity can be misleading.

The article breaks down two drivers of AI activity: technical, where developers run coding agents that perform routine tasks (opening tunnels, reading credential stores, etc.), and consumer‑grade tools accessed by employees via OAuth and data uploads. It highlights examples where perceived “real attacks” were actually legitimate developer activity or false positives, such as AI‑driven credential dumping or reverse‑shell patterns. Real external threats observed include phishing that leverages AI brand names.

Practical responses recommended include tuning legacy detections to reduce noise, enforcing third‑party data-sharing policies, and isolating AI tools (eg, in containers or VMs) to separate user and agent activity and limit credential access, enabling SOCs to scale with AI adoption without being overwhelmed.

View full article

Article by CyberSIXT