Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

DLP for AI: Protecting Sensitive Data in the Age of AI

Employees paste code into ChatGPT. They drop customer lists into Gemini for a quick summary. They upload a contract to an AI note-taker before a meeting starts. None of it feels risky in the moment. But all of it can walk sensitive data straight out of your organization. AI DLP exists to close that gap.

The EU AI Act Is Here. Is Your AI Environment Ready?

AI has moved from experimentation to operational reality. Last year saw a 50% rise in access to AI for employees, with 88% of organizations using AI in at least one business function. Competitive pressure is accelerating AI adoption. While this creates opportunity, it also creates a new level of operational risk.

The MemcycoFM Show: Ep 27 - What Is Agentic Threat Intelligence?

In the recently published blog from Memcyco titled "What Is Agentic Threat Intelligence?", we discussed agentic threat intelligence as an emerging CTI model. Bounded agents support repetitive investigation work, such as collection, enrichment, prioritization, and evidence packaging, while analysts retain control over takedown and escalation decisions. Vendor briefings are full of “agentic AI” right now. Most of them describe the same thing: faster dashboards and smarter alerts. That is not agentic threat intelligence.

TITAN AI Demo Series: How MAX Managed Questionnaires Eliminates Your Assessment Backlog

SecurityScorecard's MAX Managed Questionnaires handles your entire vendor questionnaire process end-to-end, design, outreach, response collection, and expert analysis — with no additional headcount required. In this installment of SecurityScorecard's Demo Tuesday series, see MAX Managed Questionnaires in action and what your security program looks like when your team is free to focus on risk strategy instead of assessment admin.

A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed

On July 3, 2026, the Albanian communications authority (AKEP), the operator of the.AL country-code top-level domain (TLD) of Albania, attempted a DNSSEC key rollover. Something went wrong, resulting in DNSSEC validation failures. Any validating DNS resolver receiving these signatures was required by the DNSSEC specification to reject them and return errors to clients. That includes 1.1.1.1, the public DNS resolver operated by Cloudflare.

MCP Data Exfiltration: How AI Agents Leak Sensitive Data Through MCP Tool Calls

Model Context Protocol (MCP) is what turns an AI assistant into an AI agent. It’s the standardized bridge that lets models call real tools – read files, query databases, send messages, pull emails. That capability is the whole point. It’s also what makes MCP environments a target. Most deployments were scoped for what the agent needed to do. Not for what happens when that access is turned against the organization.

The Top 5 Questions Security Leaders Are Asking About Coding Agents

The discussion during our recent webinar made one thing clear. Security teams aren't asking whether coding agents will become part of the enterprise. They're asking how to adopt them safely. The audience questions focused on practical concerns that many organizations are facing today, from autonomous execution to supply chain risk and governance. Here are the five questions that generated the most discussion.

France's ANSSI Sets New Post-Quantum Cryptography Milestones: What It Means for Your Security Strategy

Quantum computers capable of breaking today’s encryption may still be years away, but France’s National Cybersecurity Agency (ANSSI) believes organisations shouldn’t wait to prepare. At the France Quantum Conference on June 16, 2026, ANSSI announced new milestones for the adoption of Post-Quantum Cryptography (PQC). ANSSI recommends that organisations prioritise purchasing quantum-safe security products by 2030. The most important message, however, isn’t about 2030.

Finding Just Got Free: That's Why Fixing Is the Only Game That Matters

When Anthropic revealed Claude Mythos and Project Glasswing, the industry did what the industry always does with a frontier-AI story: it reached for the alarm. The headlines, Reddit threads, and back-channel conversations all focused on the same things: All of that is real, and none of it is the part that should keep a security leader up at night. Here is the part that should.