Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI Agents Are Forcing Us to Rethink Identity

Since joining BlueVoyant in May, I’ve spent my first 100 days listening. I've had conversations with nearly 50 customers and partners across industries and geographies, as well as the broader security industry, engaging with leaders at Black Hat last month. What I heard reinforced something I believe strongly: the security challenges organizations face today are changing faster than the traditional enterprise security model was designed to handle.

Never Join AI Telemetry on Byte Counts

A browser sensor reports that somebody pasted 18,000 characters into an AI tool. A network sensor reports a 24 kilobyte upload to the same destination. Joining those two records on size looks reasonable and is the wrong instinct. ‍ The two numbers describe different objects with several transformations between them, and the transformations do not all run in the same direction. The error cannot even be signed, which rules out a tolerance as well as an equality. ‍

Post-Quantum Cryptography: You Cannot Migrate What You Cannot See

On June 22, 2026, President Trump signed Executive Order 14412, accelerating the federal government’s transition to post-quantum cryptography. The order brings key migration deadlines forward from 2035 to 2030-2031 for high-value and high-impact systems. The Department of War followed with its own Post-Quantum Cryptography (PQC) Strategy, which sets additional deadlines and warns that a cryptographically relevant quantum computer is an existential threat to military missions.

AI Autonomy: How to Find the Autonomy Your Agents Already Have

AI agents are only as autonomous as the credentials behind them. This article talks about the Cloud Security Alliance's autonomy framework, why an agent's intended boundaries rarely match its actual access, and how GitGuardian helps close that gap through detection, remediation, and prevention.

Why Better Context Makes AI More Accurate, Faster, and Less Expensive

Ask an AI system a question about your business and, before it can answer, it has another problem to solve: What information actually matters? It has to find the right files. Determine which version is current. Understand how those files relate to a project, client, deal, or other piece of work. Figure out which information applies to the person asking. Then assemble enough of that information to make a useful decision. For someone who works in the business every day, much of that is obvious.

How to configure Microsoft 365 for maximum security

If someone wanted to cause serious damage to your organisation, where would they start? Not with your filing cabinets. Not with your server room. They’d probably start with your Microsoft 365 tenant, because that’s where your emails, files and customer data live, and where your entire operation runs. Thankfully, Microsoft 365 comes with powerful security capabilities built in. However, having those capabilities and being protected by them are two different things.

8 Best AI Tools for DevOps in 2026

SUMMARY Building an effective AI DevOps stack in 2026 comes down to balancing platform-native assistants for workflow speed with specialized engines for security, infrastructure, and delivery governance. This guide evaluates the 8 leading tools across both categories to help you select the right mix for your architecture and security requirements. This approach reflects a fundamental shift in engineering capabilities.

The Egnyte Context Layer: The Business Context AI Needs

AI is only as good as the context behind it. Standard AI tools simply retrieve information, but Egnyte understands your industry. By automatically connecting your content, people, projects, and systems, Egnyte builds the deep business context AI needs to deliver accurate, trustworthy answers. Reduce retrieval steps, lower operating costs, and empower your team to move industry-specific work forward faster—without compromising security.

Emerging Threat: (CVE-2026-76461) Cisco Secure Email Gateway Root RCE via Email Parsing

CVE-2026-76461 is a SQL injection vulnerability in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway, caused by insufficient validation of message content before it reaches a database query. An attacker who sends a crafted email message containing SQL statements can have those statements executed by the appliance as it processes the message. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).

Phishing Emails Use New Technique to Bypass Microsoft 365 Security Filters

Threat actors are using phishing emails with blank SMTP sender fields to bypass Microsoft 365 security filters, according to researchers at ReliaQuest. Microsoft 365 Exchange Online uses a feature called “RejectDirectSend” to block unauthenticated Direct Send emails from an organization’s trusted domain. If an attacker omits the domain field from these emails, however, RejectDirectSend will no longer block the messages.