Intelligence View
DaVinci Resolve 21 Adds Photo Editing and AI Search to Its Lineup
Blackmagic Design just dropped a major update for its popular video and color correction software. The release of DaVinci Resolve 21 brings some massive changes to the platform, expanding its focus beyond standard video workflows. For the…
It also introduces several new artificial intelligence tools designed to speed up the editing process. The company has debuted the new software soon after launching the Blackmagic URSA Cine Immersive 100G camera.
A dedicated photo page brings color grading to still pictures
The software now features a new Photo page built to handle image cropping and reframing. Editors can take the same color grading tools they use for video and apply them directly to photographs. This means you can use primary color correction, curves, and node-based tweaks on still shots while keeping the source resolution intact.
The update also includes a LightBox view that shows entire albums with your color grades applied. If you shoot with a Sony or Canon camera, you can tether it directly to the application and capture images straight into your folders.
New smart search tools scan media and fix blurry footage
A big part of this release revolves around smart search capabilities and automated visual fixes. The new IntelliSearch tool scans through your entire media pool to index specific objects, spoken words, or individual faces. This makes tracking down the right clip much faster. Another tool called CineFocus allows you to change a shot's focal point after recording to add background blur.
The software also offers facial editing tools that let you adjust a subject's age, reshape features, or quickly remove blemishes. If you have video footage that looks a bit soft or blurry, new additions like UltraSharpen and Motion Deblur can help salvage those clips.
Other upgrades include better text styling, multi-language spell check, emoji support, and native handling for Lottie animations. The public beta is available to download for free right now on the company website.
1. Sofort-Triage & Abwehrmaßnahmen
SOC Incident Playbook: Remote Code Execution (RCE) Defense
title: Detect Exploitation - DaVinci Resolve 21 Adds Photo Editing and AI Search to Its Lineup
id: 009eff32-2c74-45c1-a4e7-c185f8150ec7
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-25
logsource:
category: network_connection
product: any
detection:
selection:
CommandLine|contains:
- 'exploit'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_accessrule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-25"
description = "YARA Signature for "
strings:
$str = "DaVinci Resolve 21 Adds Photo " ascii wide
condition:
any of them
}index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("DaVinci Resolve 21 Adds Photo Editing an")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - countmessage: "*DaVinci Resolve 21 Adds Photo Editing an*"CommonSecurityLog
| where Message has "DaVinci Resolve 21 Adds Photo Editing an"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc2. Cyber Threat Intelligence & Forensik
MITRE ATT&CK Matrix Navigator 14 Taktiken
tsecurity.de Cognitive Threat RAG
Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich DaVinci Resolve 21 Adds Photo Editing an.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
- 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
- 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
- 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.