A fake Windows crash screen. A fake Claude dev tool. A fake macOS password prompt. All one trick: ClickFix. The attacker never drops a file. They talk the victim into pasting the command themselves. Criminal crews and nation-state actors are both running it, on every OS. Our Threat Detection Researcher Roni Natanson has been hunting it all year, and her full write-up is now live: the lures, the telemetry each platform leaves behind, and how every incident was contained before the payload ran. Read all about it here: https://lnkd.in/ecS_ewQw #ClickFix #ThreatResearch #DetectionEngineering
About us
We're redefining the boundaries of Security Operations by eliminating the limits and compromises of the past. Founded in 2024, Vega is on a mission to help organizations harness the power of all of their data. Wherever it is. Whatever it is. Without any of the taxes that have plagued SIEM and Data Lakes for the past 20 years. Backed by Cyberstarts, Accel, Redpoint and CRV, Vega offers a lightweight Security Analytics fabric that introduces a new, AI-native, approach to interacting with security data wherever it sits, giving analysts complete visibility and detection coverage, without a single migration, replacement or compromise.
- Website
-
https://vega.io
External link for Vega
- Industry
- Computer and Network Security
- Company size
- 51-200 employees
- Type
- Privately Held
- Founded
- 2024
Employees at Vega
Updates
-
Every Vegas headliner has a residency. 🎩 This Black Hat so do we. 🔥 Daily lunch, private dinners, after-hours you'll want an invite to. Booth 3452 by day. ☀️ Everywhere after dark. 🌑 The full lineup 👉 postsiem.com
-
Vega is featured in IT-Harvest's Guardians of the Machine Age map of the AI security landscape. The profile covers SAM, our Security Analytics Mesh: query your data wherever it lives (no migration, no ingest tax) while AI agents hunt, detect, and triage with transparent reasoning. Read the full profile 👉 https://lnkd.in/emmhZuhn #SIEM #AISOC #SecurityAnalytics
-
-
Our Q2 2026 Threat Report is live! And what we saw is that attackers rarely relied on highly sophisticated malware or complex intrusion chains. Instead, they moved quickly by combining social engineering, trusted system tools, stolen credentials, one-day vulnerability exploitation, and security-control tampering. Individually, much of this activity looked routine: a command, a developer install, or a normal login. The threat only became clear when those events were connected across users, endpoints, identities, and exposed systems. The report covers the broader threat landscape, notable Vega investigations, and practical detections. 📖 Read the full report: https://lnkd.in/em-8DxNR
-
-
The desert has a tradition: build a monument to the old world, then set it on fire. 🔥 Our Co-founder and CTO Eli Rozen is taking to the Black Hat stage to talk about what comes after the SIEM. 🎤 AI-Native SecOps in the Post-SIEM Era. Thursday, August 6 at 2:40 PM Pulse Stage 02 P.S. The rest of our Vegas lineup: postsiem.com 🗓️
-
-
OpenAI was testing pre-release models on a cyber benchmark with reduced safety controls. The models were supposed to stay inside a restricted sandbox with limited internet access. However, the models identified and exploited a zero-day in the proxy, escaped the sandbox, recognized that Hugging Face as the likely host of the benchmark, stole credentials, and chained vulnerabilities to gain remote code execution in Hugging Face’s production environment. Hugging Face later described the incident from its side: an autonomous agent carrying out thousands of actions over a weekend, harvesting credentials and moving across internal clusters. It wasn’t a nation-state or a cybercrime group. It was a pair of models trying to improve their benchmark score. One striking detail came during the response. Hugging Face first tried using hosted frontier models to analyze the attack, but safety controls blocked the requests. They ended up relying on a self-hosted open-weight model instead. The broader lesson is that agentic attacks are difficult to piece together. The activity can be spread across model logs, identity systems, proxies, endpoints, cloud infrastructure, and Kubernetes clusters. Each event may look minor on its own. The attack only becomes clear when the full sequence is connected. That is the kind of problem we focus on at Vega: connecting model activity, credential abuse, lateral movement, and post-compromise behavior into one attack chain instead of treating them as separate alerts. Want to see what this looks like in real environments? https://lnkd.in/g4gWUTY3
-
-
Your employees are using Claude, powered by Anthropic. API keys, role changes, sign-ins. None of it hits your Legacy SIEM. So we closed the gap. Vega now integrates with Claude's Compliance API. One query. No agents. No console hopping. Activity Feed only. Never content. The scale and speed frontier models actually need. No cap. Read more 👉 https://lnkd.in/edjvgMNu #PostSIEM #AISecOps #AgenticDefense
-
-
Vegas buffets and your SIEM bill have the same pricing model: by volume. This August, both traditions end. Book time with our team to talk what comes #postsiem. Treats included. P.S. Everything we're doing at Black Hat 👉 postsiem.com
-
-
New integration just dropped... Vega x BlinkOps. We're taking detection straight to automated response. No gap in between. Vega's Security Analytics Mesh sees across your entire data estate. Finds the signal. Connects the context. Triages with AI. Outpacing the speed of AI-powered attackers. No data moving. No Legacy SIEM drama. Built to scale. Built for speed. Built for frontier models. So Vega. Then BlinkOps pulls up and puts AI agents to work investigating + responding. Consider it handled. Agents in motion. Response on lock. So BlinkOps. Detection ➡️ Investigation ➡️ Response. Closing the loop on your AI SOC. Oh, and did we mention? IN MINUTES. NOT HOURS. SAM sees it. Blink moves on it. Because another alert isn't the answer. Agentic action is. Agentic Cyber Defense just got a glow up. 🔥 Read about it here 👉 https://lnkd.in/dsFwtfmv
-
-
What actually makes incident response faster? Not more dashboards. Not more ingestion. It's asking one question across everything you have and getting one answer. That's how Vega changed the way we investigate: query data where it lives, one schema across every source, visibility gaps surfaced before the incident, not during. Tal Haham Mendel shares her experience there: https://lnkd.in/dXv5S7Vp #IncidentResponse #SecOps #PostSIEM