Date:

Cyber activity rarely begins when conflict erupts. By the time the first airstrike lands, the groundwork — the access, the intelligence, the pre-positioned capabilities — has often been in place for months. This panel examines what this looks like in practice.

A ceasefire may now be in place, but it does not extend to the cyber domain. Intrusions are continuing, dark web coordination remains active, and not everything that has emerged fits neatly into the expected narrative. Targets have included infrastructure where few anticipated it — including cloud infrastructure in the Gulf region. And monitoring of the dark web is surfacing connections that reach well beyond the named parties to this conflict.

Building on our previous discussion from “Cybersecurity in a Fragmented World”, this panel brings together threat intelligence practitioners from Cisco Talos, Rapid7, and SOCRadar for a candid, practitioner-level look at what they are seeing right now: state-sponsored intrusions, hacktivist operations, opportunistic criminal activity, and the increasingly blurred boundary between espionage, organized crime, and outright warfare in the digital gray zone.

The panelists will share specific observations from their current intelligence — some expected, some surprising — and translate what they are seeing into guidance that security teams can act on today.

Register here.

Back to Events