Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Static credentials are still AI's easiest way in

Netwrix's 2026 research found a 4x gap in breach rates between organizations where AI has significantly grown their identity count and those where it hasn't. Static credentials are AI’s easiest way in: passwords, keys, and tokens that never expire and never get checked. AI didn't invent the over-privileged credential, it just found the fastest way to use one.

Active Directory isn't going away. Your group policy setup might be as brittle as COBOL

A Reddit thread on r/activedirectory asking whether Active Directory is going away pulled in loads of comments, and the most upvoted answer compared AD to COBOL: still running, still critical, still not going anywhere. That comparison holds up when you check whether COBOL is still used today, since it runs core banking and government systems decades after its supposed retirement. The real risk for most IT teams isn't AD disappearing.

Your AI deployment might be out of policy

Most AI deployment policies stop at approved chat interfaces. Meanwhile, employees install browser copilots, AI extensions, and third-party plugins that never touch Microsoft's management stack. IT can't configure what it can't see, and Group Policy and Intune only govern Microsoft's world. This post covers what actually happens once AI tools show up outside policy, five things most teams miss, and how PolicyPak enforces controls directly on the apps and browser extensions themselves.

What engineering leaders can learn from stoicism

“A man’s worth is no greater than the worth of his ambitions.” Marcus Aurelius wrote that almost two thousand years ago, in a private journal he never intended anyone to read. Coming from a man who held every title Rome could give, it’s a telling way to measure worth: not by what you hold, but by what you aim at. It has stuck with me, because everything I’ve seen in my career backs it up. Deep technical knowledge is where great engineering starts.

The AI agent working for you probably has more access than you do

Say a sales rep uses an AI assistant to help manage their pipeline. The rep has role-based access to Salesforce, scoped to their territory and their accounts. The assistant, wired in through an API integration, often doesn't have that same scoping. It authenticates as a service account with broad read and write access across the org, because that was faster to set up than a permission model that matches what the actual user is allowed to see.