Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

OpenMatter Network Introduces Verifiable Trust Layer for Secure Collaboration and AI Agents

OpenMatter Network today announced the launch of its cryptographically verifiable platform for secure collaboration and AI governance, built on a simple premise: Don't Trust Data. Prove It. For decades, organizations have relied on trust-based assumptions to secure data, execute workloads, and govern digital systems. But as data becomes increasingly distributed and AI agents begin operating autonomously across organizations, applications, and networks, those assumptions are being tested in new ways.

Reflectiz to Host Webinar, Joined by Taboola, on Securing Third-Party Marketing in the AI Era

Reflectiz, the web exposure management platform, today announced a live webinar with Taboola, "Securing Third-Party Marketing in the AI Era," taking place July 8 at 9 AM EDT / 3 PM CEST. Every marketing vendor a company approves can silently introduce third and fourth-party scripts that no security team ever reviewed. In the AI era, that invisible layer is expanding faster than point-in-time audits can track. The gap between what an organization approves and what actually executes on its site is where data leakage, regulatory exposure, and compliance failures happen.

Braintrust's Ankur Goyal: Code review doesn't cover prompts

Zero-Shot Learning is a podcast about how AI gets built, secured, and deployed. Hosted by Nancy Wang, 1Password CTO, and Dev Tagare, Senior Director of Engineering at Google, it’s a builder’s view of the architecture and the decisions it takes to ship with AI.

AI Is Breaking Defence in Depth Faster Than We Can Fix It

This episode explores how defence in depth is changing in an AI enabled business world, where code driven systems, supply chain risk and offensive AI are moving faster than defenders can react. It looks at why human in the loop is failing, why visibility still comes too late, and what modern cyber defence needs to become next.

What Is Privacy-by-Design and Why Is It Important?

Every AI application relies on data. From customer conversations and healthcare records to financial transactions, organizations process enormous volumes of sensitive information every day. As AI adoption grows, so does the need to protect that data from misuse, exposure, and compliance risks. This is why understanding what privacy by design entails has become a business necessity rather than just a compliance requirement.

The evolving fraud landscape in the age of AI with Tamas Kadar [334]

Today we're speaking with Tamas Kadar, CEO / Co-Founder of SEON, about building a safer digital world for businesses. We touch on fraud, how it's evolved in the age of AI, and what we can do to protect ourselves against it. Tamas' entrepreneurial path began at Corvinus University in Budapest, where the vision for SEON first took shape. Co-founding a cryptocurrency exchange opened his eyes to the scale and complexity of online fraud, sparking the idea for something better. In 2017, that “something better” became SEON.

The Four Biggest Gaps in Today's AI SOC Vendor Market

A year ago, a handful of vendors called themselves an “AI SOC.” Today, more than 100 do. The label now means whatever the person selling it needs it to mean, leaving security teams to buy very different products under the same two words. So let’s sort the market. Beneath the “agentic” branding, most AI SOC vendors fall into one of four categories, and none of them clears the bar. Each can look capable in a demo.

Shadow AI Explained: What It Is, Where It Hides, and What It Costs

Shadow AI is the term for AI tools, models, and capabilities that operate within an organization without formal approval, oversight, or governance. It is the enterprise AI equivalent of shadow IT, which is the unauthorized software and cloud services that proliferated as employees found faster ways to get work done than waiting for IT procurement cycles. The difference is that the consequences of unmanaged AI are considerably more significant than those of unmanaged software.

How to Discover and Control Shadow AI Agents in Your Environment

Most security programs have a working model for responding to shadow AI: identify the unsanctioned tools employees are using, sanction or block them, and update the acceptable use policy. That model worked, however imperfectly, when the threat was limited to web-based GenAI applications. It does not work when the threat is an autonomous agent, running locally on an endpoint, that reads the file system, calls external APIs, and transmits internal data.

A double-edged bleeding edge: Classifying AI threats

Sophos X-Ops presents a working taxonomy for attacks using, and targeting, AI Conversations about ‘AI threats’ typically collapse into one of two extremes. On the one hand, hype: unverified claims that don’t hold up to scrutiny and invite significant criticism. On the other, dismissal: it’s just old tradecraft with new branding.

From prompt to action: Al Security with Salt Security and CrowdStrike

As enterprises accelerate adoption of Generative AI, the security perimeter is rapidly expanding. This creates a new, largely unprotected attack surface: the Agentic Action Layer. In this on-demand webinar, @CrowdStrike and Salt Security introduce an AI-native security architecture that spans the full chain of intent-to-action. Learn how CrowdStrike Falcon AIDR protects the model runtime, prompts, inference, and LLM behavior, while Salt Security governs and defends the APIs, MCPs, and services where AI actions actually occur.

Proof Over Prediction: What Happens When You Actually Watch Who's Attacking AI Infrastructure

Customer telemetry shows how AI agents behave in a limited set of production environments and what risks they carry. Vulnerability research surfaces how those environments can be attacked. Both sources are valuable, but neither shows actual attacker behavior or how quickly they operationalize a new vulnerability once it's public.

AI-generated code is running wild inside the enterprise. Now what?

Restrict access to AI tools and you curb innovation. Open it up and security risks multiply. And then there's a third problem: approved tools behaving in unapproved ways. Security and IT leaders are navigating a new and fast-moving problem - employees using AI to build workflows, automations, and agents faster than anyone can track or govern. The question isn't whether it's happening. It's what to do about it.

Are Your AI Agents Going Rogue? (The Real Danger of Agentic AI)

ChatGPT is read-only, but AI Agents take action on your behalf. What happens when they go rogue? Discover the hidden cybersecurity risks of Agentic AI and unauthorized remote execution. AI gateways were built for a world where AI meant "prompt in, response out." That world is gone. Today, AI agents call APIs, trigger workflows, and take actions across your enterprise systems autonomously. This massive shift from passive data exfiltration to active, unauthorized execution requires a completely new security model where every input is treated as potentially hostile.

Shadow AI: Employees don't ask IT to use AI tools

Generative AI has gone mainstream, and your customers are already using it, whether IT knows it or not. Employees are turning to AI assistants to write emails, summarize documents, generate code, analyze spreadsheets, and speed up everyday work. Most are simply trying to be more productive. The problem?

How Retailers Can Build a Security Strategy for AI Shopping Assistants

AI shopping assistants have moved well past novelty. Deloitte reports that 63% of global retailers now agree that companies without AI agents will fall behind within two years. These systems already handle product discovery, purchase recommendations, loyalty redemptions, autonomous checkout sequences, and more.

Scaling security reviews at 1Password: Building an AI-powered pipeline

The developers and engineers here at 1Password are always working to improve our products. With all the active development to introduce features, fix bugs, and enhance the overall user experience, numerous code changes go into every release. We strive to ensure each iteration is better than the last and that new code doesn’t introduce vulnerabilities. A key part of this process is our Product Security (ProdSec) team’s review of all code changes that may have security implications.

Claude Tag Didn't Create Another Identity Problem. It Created a Control Risk.

Anthropic’s Claude Tag represents a meaningful shift in how AI agents operate inside the enterprise. Unlike traditional AI assistants that act on behalf of an individual user, Claude Tag introduces a shared AI agent with its own identity, credentials, service accounts, and permissions. That shared agent lives inside a Slack channel, builds context over time, connects to enterprise systems, and performs work for everyone in the conversation.

What Is Agentic AI Security? Why AI Agents Need a New Security Model

AI systems are starting to do more than generate answers. Across customer support, IT operations, software development, and internal business workflows, organizations are deploying AI agents that can retrieve information, use tools, interact with applications, and complete tasks with limited human involvement. This shift is happening quickly. According to a McKinsey Report, 62% of organizations are already experimenting with AI agents, while 23% are actively scaling them across parts of their business.

Snyk VulnBench JS 1.0: Can LLMs Find the Same Bugs Twice?

We ran 300 vulnerability-finding scans to measure how repeatable an agentic LLM security review is on the same code, prompt, and harness. The headline result is not that one scanner "wins" a self-referential leaderboard. It is that LLM security findings are unevenly repeatable: reference-matched findings were stable, but extra-model reports varied widely from run to run.

Executive Order 14409 Starts a 30-day Clock on Federal Cyber Defense

On June 2, 2026, President Trump signed Executive Order 14409, "Promoting Advanced Artificial Intelligence Innovation and Security." The framing is innovation first. But for federal network and security teams, the practical reality is a short, specific timeline to harden government systems, with AI now active on both sides of the cybersecurity equation. The deadlines are not aspirational.

Monitor Netskope ADEM scores and remediate with an AI chatbot

Automatically detect when user connectivity degrades in Netskope ADEM and respond instantly with an AI-powered Slack chatbot. In this five-minute flow, we walk through how to monitor Netskope ADEM experience scores for key users and trigger proactive outreach via Slack when performance drops. You'll see how Tines pulls scores on a schedule, creates a case when a threshold is breached, uses an LLM to craft a personalised Slack message, and deploys a Virtual Assistant to help the user troubleshoot in real time.

AI Powered Threat Detection: CISO's Guide

The market is giving CISOs a blunt signal. AI-powered threat detection and response was valued at USD 5.59 billion in 2024 and is projected to reach USD 23.52 billion by 2032, at a 20.00% CAGR according to Kings Research on the AI-powered threat detection and response market. That kind of growth doesn't happen because security teams like new tooling. It happens because modern environments generate more telemetry than analysts can realistically review, and attackers move faster than rule updates.

Anthropic restriction, ServiceNow incident, Fortinet harvesting & Ukraine EU cyber reserve [333]

In this episode of The Cybersecurity Defenders Podcast, we discuss some intel being shared in the LimaCharlie community. Support our show by sharing your favorite episodes with a friend, subscribe, give us a rating or leave a comment on your podcast platform. This podcast is brought to you by LimaCharlie, maker of the SecOps Cloud Platform, infrastructure for SecOps where everything is built API first. Scale with confidence as your business grows.

GLM 5.2 vs Opus 4.8: Cheaper AI Code, Hidden Risks?

GLM 5.2 just launched from Z.ai, and it might be one of the biggest threats yet to the frontier model premium. It’s open, significantly cheaper than Claude Opus 4.8, and claims to deliver near-frontier coding performance across major benchmarks. But benchmarks only matter if the model can actually build something production-ready.

Why Traditional DLP Breaks in Agentic AI

A customer support agent needs a payment reference, a token or transaction ID, to issue a refund. A summarization agent reading the same ticket needs none of it. A billing agent needs only the last four digits to match a transaction. A fraud agent needs the full credit card number, but only when a case is open and only for the account it is reviewing. Traditional DLP sees one thing across all four: sensitive data, a 16-digit string that matches a card pattern. It makes one choice: block, redact, or allow.

What Are Shadow Agents and Why Are They a Security Risk?

Most AI governance programs assume they know what they're governing. They track which AI tools employees use through browser proxies and SSO logs, block access to unauthorized platforms, and monitor data leaving through known egress channels. Shadow agents break every one of those assumptions. Agents run locally, act autonomously, and access data through pathways the tools monitoring your environment were never built to see, creating a new, and difficult to govern, attack surface.

NVD in the AI Era: The Case for Multi-Source Vulnerability Intelligence

For over twenty years, the global security community has operated under a single, comfortable assumption: that a centralized public source could help track, analyze, and enrich the world’s software vulnerabilities at the pace the industry needed. When the National Vulnerability Database (NVD) was established, the open source vulnerability lifecycle moved at a radically different pace.

AI Inference Risk: The Data Exposure Your DLP Can't See

Your DLP controls are correctly configured. Classification policies are in place. Sensitive data is labeled. And your AI tools are quietly building a picture of your organization that none of those controls can see. Most AI-related data exposure does not arrive as a file transfer event.

Delivering Context and Speed for Security Operations with Aurora Security Assistant

Security operations teams are facing a familiar, but growing, challenge. As threat actors leverage AI and automation to move faster, alerts continue to expand in volume and complexity. Even mature security teams struggle to keep up with investigation timelines, maintain institutional knowledge, and ensure consistent response quality. At the same time, buyers are demanding more from their security platforms. They want solutions that go beyond detection.

How to Appear in AI Search Results

A few years ago, the goal was simple: rank on page one of Google. If your website appeared among the first 10 blue links, people would find you. That equation is changing. Search behavior is shifting from keyword lookups to answer-led queries. Instead of scanning a list of results, more people are turning to AI-powered search tools that read across the web, consolidate information, and deliver a direct answer. ChatGPT, Google AI Overviews, Perplexity, and Claude all work this way.

Microsoft Defender for Endpoint: Protection You're Paying For But Not Using

Microsoft Defender for Endpoint ships with serious firepower. But most of it is sitting idle. ASR rules get stuck in audit mode. Devices never get fully onboarded. Exploit protection is switched off. Security baselines drifting across device groups. You're paying for protection that isn't turned on. Reach analyzes your Defender deployment, surfaces every gap, prioritizes the fixes by real risk reduced, and keeps your controls aligned as you scale.

Best AI Security Tools for 2026 (Top 10 Compared)

Enterprises today are looking to grow faster by adopting artificial intelligence. Teams are now building AI copilots, automating workflows with AI agents, and using Retrieval- Augmented Generation (RAG) to search internal knowledge bases. However, with every successful AI deployment, there is one very important question. How do you keep sensitive enterprise data from becoming a potential AI security risk?

LangGraph Integration for Protegrity AI Developer Edition

See how Protegrity AI Developer Edition helps protect sensitive data in AI agent workflows built with LangGraph. This demo shows how Protegrity can fit into modern AI development pipelines as both a preprocessor and postprocessor guardrail, helping teams discover, protect, tokenize, mask, and redact sensitive data before it reaches an LLM — and before responses leave the application. In this video, you’ll learn how developers can.

AI Risk Management as a Function of AI Governance: A Holistic Approach

Artificial intelligence (AI) is transforming industries, but it also introduces new risks that organizations must manage. Effective AI risk management is a critical function within AI governance. This article explains how AI risk management fits into the broader governance framework, why it matters, and how organizations can adopt a connected, data-driven approach to reduce AI-related risks continuously.

What Is Agentic Threat Intelligence?

Agentic threat intelligence is an emerging CTI model where bounded agents support repetitive investigation work, such as collection, enrichment, prioritization, and evidence packaging, while analysts retain control over takedown and escalation decisions. Vendor briefings are full of “agentic AI” right now. Most of them describe the same thing: faster dashboards and smarter alerts. That is not agentic threat intelligence.

ITIL v5: Exploring New Opportunities for IT Professionals

ITIL v5 connects IT service management to real digital product needs and faster delivery. If your team wants clearer direction, improved customer experience, and measurable results, this framework is a practical choice. ITIL v5 unifies strategy, operations, and improvement, offering new opportunities for professionals seeking modern skills and roles in service management.

Why Data Governance Matters When Adopting AI-Driven Student Enrollment Solutions

Schools, colleges, and universities are under constant pressure to make enrollment faster, simpler, and more accurate. This is why so many institutions are now turning to student enrollment solutions powered by artificial intelligence. These tools can predict applicant behavior, automate paperwork, flag incomplete forms, and even help admissions teams identify which students are likely to enroll. The appeal is obvious. But there is a part of this shift that often gets overlooked in the excitement around automation, and that is data governance.

How JFrog and NanoClaw are Bringing Software Supply Chain Security to the Age of Autonomous AI

There’s a category of security risk that most organizations aren’t ready for. It doesn’t live in your code repository, your CI pipeline, or your developer laptops. It lives in your runtime, in the autonomous AI agents already running in your environment, extending their own capabilities, and making decisions that no human explicitly approved. This is the challenge JFrog set out to address with our integration with NanoCo AI and their open-source agent framework, NanoClaw.

6 Key Elements of a Responsible AI Usage Policy

Recently, I had the pleasure of presenting an AI governance-focused webinar with my colleague Neil Jones at Egnyte. In the session, we discussed many ways to improve AI governance, and you can watch and share the complete session replay here. During the session, we discussed the importance of respo nsible AI usage policies. However, my experience is that many organisations struggle to create policies aligned with their business requirements and the technological solutions that they use.

Not Zero-Days. Not Nation-States. A Firewall Rule.

A firewall's entire job is to control what gets in. In Reach's research, it was the most common source of a configuration-related near miss or exposure, ahead of EDR and identity controls. It does not take much. One rule broadened for a project, one exception that outlived its reason, one change that shipped without anyone checking it against intent. A single overly permissive rule, sitting live between quarterly reviews, is enough.

AI Analysts for Autonomous Vulnerability Response

Security teams are drowning in findings, not because scanners miss things, but because nothing confirms which ones an attacker could actually reach. Seemplicity AI Analysts run the investigation themselves, checking runtime configuration, network reachability, and exploit conditions for each finding, and re-rank your backlog by confirmed exploitability. What rises to the top is backed by evidence. What drops down has been checked and reasoned out.

Why AI Is Becoming an Operational Requirement for Security Teams

In our previous article, From Vulnerability Management to Continuous Security Operations, we explored how organizations are moving beyond traditional vulnerability management toward a model built on continuous visibility, continuous prioritization, and continuous action. But that evolution raises an important question: how do security teams sustain this model at scale? For years, the cybersecurity industry focused on visibility.

Least Privilege Access for AI Agents: How to Secure Autonomous Systems in 2026

AI agents are no longer just answering queries or summarizing documents. They are booking meetings, pulling customer data, triggering workflows, and even making decisions across systems. And they don’t ask for permission every time. That’s where the real problem starts. Because once an AI agent is connected to your tools, APIs, and internal systems, the question isn’t what it can do, it’s what it should be allowed to do.

How to Build Privacy-First AI Systems in 2026

Your RAG pipeline goes live on a Monday. By Friday, a customer query is surfacing another user’s account number in a response. Privacy-first AI stops that before the data reaches any model. More than half of organizations have already experienced an AI-related security incident, according to Check Point’s 2026 Cloud Security Report, and most don’t catch it until an audit forces the issue. Start with AI data privacy concepts and best practices.

Ep. 64 - The Mythos Hype Index: What AI Really Did to the Zero-Day Curve

Every CISO is asking it: now that frontier models like Claude Mythos and ChatGPT 5.5 have real offensive cyber capability, are zero days surging? Host Tova Dvorin and SafeBreach offensive engineer Adrian Culley dig into the mid-2026 data—GTIG, Mandiant M-Trends, Rapid7, AISI—and find the curve moved in shape, not volume. Inside: the two AI "firsts" (Big Sleep and a 2FA-bypass exploit), why commercial spyware explains the rebound, the negative-seven-day time-to-exploit, and why defender deployment is the real bottleneck.

Secure AI for the real world

AI makes building look easy. That’s the trap. Without a secure, well-designed foundation, workflows break, costs spike, and systems grow fragile. CTOs and CISOs from leading organizations discuss what breaks without a secure foundation, and how to build AI systems that hold up at scale. This session goes deep on the real-world tradeoffs between speed, risk, and trust.

What Is AI Asset Discovery (And Why It Matters for AI Governance)

Enterprise artificial intelligence adoption is scaling at a pace that manual inventory methods simply cannot match. This rapid proliferation has created a severe visibility chasm for security and risk teams: it is fundamentally impossible to govern, secure, or quantify what you do not know exists. ‍ To bridge this gap, organizations are shifting away from point-in-time compliance audits and adopting continuous discovery.

We just crossed the point of no return with AI #aisingularity #cybersecurity

AI is moving so fast that even security professionals feel they are staring over an event horizon without knowing what comes next. Public information alone is already unsettling, and the fear grows when you consider what is happening beyond open sources, from hidden capabilities to post quantum risk no one has fully mapped yet.

Your AI Agent Needs to Know Who You Are

When your AI agent calls an MCP tool, that tool has no idea who actually triggered the request. It sees the agent, not you. This post explains why that matters and how to fix it with Teleport JWTs. In part two of this post, we will explain how to extend this to AWS to carry your identity through Amazon Bedrock AgentCore all the way into CloudTrail.

Automate Vulnerability Triage with Seemplicity AI Analysts | Demo Video

Stop manual investigation and scale your security operations. In this demo video, discover how Seemplicity’s AI Analysts automate vulnerability triage by investigating exploitability directly within your remediation workflow. Manual triage doesn't scale for large organizations. Seemplicity delivers dedicated AI experts for code, dependency, and infrastructure/host vulnerabilities to move the needle for security professionals.

Why Uniform Governance Fails with Enterprise AI Agents (And How to Fix It)

As organizations aggressively shift from static Large Language Model (LLM) chatbots to fully dynamic, autonomous AI agents (e.g. systems designed to plan workflows, call APIs, write runtime code, and modify enterprise databases), traditional compliance and governance frameworks are hitting a breaking point. A landmark press release from Gartner highlights a critical systemic risk: treating AI agent governance as a monolithic, one-size-fits-all policy guarantees project failure.

CVE-2026-42271: Unauthenticated RCE in LiteLLM AI Gateway

LiteLLM, a widely deployed open-source AI gateway, is affected by a critical exploit chain that allows unauthenticated attackers to execute arbitrary commands on vulnerable hosts. CISA added CVE-2026-42271 to its Known Exploited Vulnerabilities (KEV) catalog on June 9, 2026, confirming active exploitation in the wild. The Qilin ransomware group has been linked to exploitation activity. What makes this especially dangerous is the chain: CVE-2026-42271 on its own required a valid API key.

The New Security Control Point: Governing AI Agents Inside the Execution Loop

As organizations adopt AI agents to build software, security teams face a new challenge: risk is no longer introduced only through the code that gets produced. It emerges continuously through the tools agents use, the actions they take, and the code they generate. This is the problem Evo Agentic Development Security (ADS) was designed to solve. ADS secures all three layers of the agentic development system—what agents use, what they do, and what they generate.

Announcing Agentic Development Security (ADS)

Today, we're announcing Agentic Development Security (ADS), a new Evo solution designed for securing AI-driven software development. AI agents are now active participants in the software development process, selecting tools, executing actions across systems, and generating production-ready code at machine speed.

What nearly 10,000 developer environments reveal about agentic development risk

For years, application security teams have focused on a familiar set of questions: Is the code secure? Are the dependencies vulnerable? Is the build pipeline protected? Are issues being caught before they reach production? Agentic development adds a new question: What systems, tools, instructions, and permissions helped produce this code? AI coding agents are no longer just suggesting snippets or completing lines of code.

Introducing AI-assisted query creation in 1Password Device Trust

Today we're shipping a new capability directly into 1Password Device Trust that lets admins query their fleets faster, without needing to be SQL experts. Now you can describe what you want to investigate in plain English, and Device Trust generates a ready-to-run SQL query you can execute across your devices in a single click.

Monitoring Agents and SaaS AI Platforms with Microsoft Agent 365 [Part 1]

Agent usage is exploding and in Microsoft 365, agents aren’t monitored by default. Even though it’s early days for tools that can monitor agents, Microsoft’s newly released Agent 365 evolves this new category with some powerful capabilities. Here are some tips for using Microsoft Agent 365 and related tools to monitor agents. Solutions discussed in this post: This is part 1 of a two-part series.

What the Cloudflare Outage Says About Changes Made Under Pressure

Observability is not the problem anymore. The data that tells you a change will break something usually already exists. Most teams have the events, the logs, the configuration history. What is missing is the step that turns all of it into a clear yes or no on a specific change, while there is still time to pull it. Garrett Hamilton, CEO of Reach Security, on objective data and the changes that get made before anyone checks.

TITAN AI Demo Series: How AI Agents Automate KEV Remediation

Most security teams find out about a critical vulnerability after it's been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. By then, the clock is already running. In Episode 3 of SecurityScorecard's Demo Tuesday series, see how TITAN AI Agents automate KEV remediation workflows — so your team spends less time triaging and more time closing exposures. Watch to learn how to: Instantly identify which vendors in your ecosystem are exposed to KEV-listed vulnerabilities.

The Architecture of an AI-Powered Breach: The Shadow Supply Chain

CISOs and security analysts understand that the narrative surrounding artificial intelligence risk has changed. The old assumption that AI risk begins and ends with an employee copying and pasting a sensitive paragraph into a public ChatGPT prompt has dissipated, and we now see that AI has rapidly transitioned from an occasional consumer novelty into a deeply embedded, departmental infrastructure.

How to layer fraud checks on top of Anthropic's KYC Screener agent

Anthropic released a pre-built KYC Screener agent last month. It runs a four-step workflow on onboarding records to extract structured data from KYC documents, evaluate that data against a firm's KYC rules, screen named parties, and escalate exceptions to a compliance file for human review. The Anthropic template is purpose-built for meeting basic KYC compliance requirements during onboarding, and it lowers the cost of getting it right.

20,000 Instagram accounts hacked with AI tool abuse

A bug in Meta's AI-powered account recovery tool compromised 20,000 Instagram accounts. In this week's Intel Chat, Chris and Matt discuss how the flaw allowed attackers to bypass email verification. Meta patched the tool after discovering the abuse on May 31st. Matt's takeaway: tools given broad API access become attractive targets. Meta should have caught this in basic testing, yet it took an adversary to expose the weakness.

The Claude Fable Saga - The 443 Podcast - Episode 375

This week on the podcast, we unpack the Claude Fable 5 release and subsequent revocation following an export control directive from the US federal government. After that, we cover the recent FortiBleed credential dump, discussing its likely origins, before reviewing the most recent Windows 0day disclosed by Nightmare Eclipse.

Implementing AI Governance to Identify and Mitigate Critical AI Risks

Artificial intelligence (AI) is transforming businesses worldwide, offering powerful tools to automate, analyze, and innovate. Yet, with this power comes significant risk. Organizations must implement AI governance frameworks that map, measure, and manage AI risks continuously. ‍ This article explains how effective AI governance helps prioritize risks aligned with business goals, enabling companies to mitigate threats before they escalate.

Cybersecurity Awareness Training for AI: Key Focus Areas

As employees increasingly rely on AI tools and AI agents in daily workflows, organizations are facing a new workforce security challenge: how to reduce risk without slowing productivity. Security leaders are no longer just protecting systems and identities. They also need to manage how employees interact with AI-generated content, automation, and decision support tools.

How to Use AI for Vulnerability Management

With over 48,000 CVEs published in 2025 and attackers weaponizing vulnerabilities in as little as 20 hours, traditional vulnerability management is no longer enough. This post breaks down the key findings from the SANS whitepaper The Exposure Gap: From Vulnerability Management to AI-Driven Control, and what it means for security teams trying to get ahead of risk. In 2025, over 48,000 CVEs were published. That’s roughly 130 new vulnerabilities every single day.

How to Setup AI Rules, Skills, Hooks and MCPs

In this video, we break down how to properly set up and use AI extension points - specifically MCP (Model Context Protocol) servers, Rules, Skills, and Hooks - to supercharge your development workflow. Using practical, security-flavored examples with Claude Code and Snyk, you'll learn how to configure a local project environment that automatically catches vulnerabilities before they ever hit your codebase. Whether you use the Claude CLI, VS Code extensions, or alternate AI ecosystems like Cursor or Gemini, you can use these exact steps as a blueprint to automate any workflow in your project.

5 Agentic AI Security Use Cases Every Security Leader Must Know in 2026

A human employee who wants to delete a customer record, issue a refund, or push a config change has to ask, click, and confirm. An AI agent doing the same thing can plan, decide, and execute the action in one pass, often through a tool it picked itself, in a sequence no one explicitly approved. That shift, from systems that respond to systems that act, is why most application security stacks fall short the moment agentic AI enters the picture.

AI changed what you ship. It also changed what you have to secure.

Two years ago, your teams shipped software. Today they ship two different things. They ship software that AI mostly wrote. And they ship AI systems they built themselves: models, agents, features that reason and act. Most security programs are still scoped for the first and blind to the second. That gap is not a tooling problem. It is a category problem. And the way the industry is drawing the categories is making it worse.

Decoding the Copilot Ecosystem

Microsoft’s approach of generative artificial intelligence has fundamentally redefined corporate productivity. The "Copilot" brand has become synonymous with workplace efficiency, promising to accelerate everything from writing software to summarizing executive board meetings. For a security analyst, however, this widespread integration introduces significant challenges to the attack surface they manage.

The 2026 Enterprise AI Security Index

The writing is on the wall: artificial intelligence has moved past the experimental phase and has cemented its place as a core component of the modern enterprise stack. For CISOs, the playbook of flat firewall blocking is ineffective—bans don’t halt adoption, they simply drive usage underground into unmanaged shadow streams. To protect corporate assets without stalling business velocity, security leaders are seeing the need to shift from blind obstruction to active, structured guidance.

Securing ChatGPT, Copilot, and Gemini: A Practical Guide for Enterprise Security Teams

ChatGPT, Copilot, and Gemini are already part of daily work in many companies. People use them to draft text, summarize notes, review code, and move faster on routine tasks. That speed is useful, but it also opens a new path for data to move in ways security teams may not see at first. This guide looks at the most common risks, the controls that matter, and the simple steps that help teams keep AI use safe without slowing work down. It is built for people who need clear answers, not a pile of jargon.

Why PDF-to-Video Conversion Is Becoming Standard Practice in Compliance and Risk Teams

Most compliance documents don't get read. Risk managers and compliance officers know this - the annual policy updates, the security awareness reminders, the regulatory change summaries that go out as PDFs and are opened by 12% of the organization. The people who most need to understand the content are exactly the ones who find dense text formats least accessible. This isn't a motivation problem. It's a format problem. And PDF to video conversion is one of the more practical solutions that's gained traction in risk and compliance teams over the past two years.

Top Continuous API Discovery Tools for 2026 (Enterprise SaaS & AI-First Apps)

Not all API discovery tools solve the same problem. Some help teams discover APIs once. Others help maintain a live inventory as APIs change across cloud services, microservices, third-party integrations, and increasingly, AI-driven applications. That is where continuous API discovery stands apart. In this guide, we compare the top platforms using shared capability tags instead of forcing each tool into a single “best for” category.

How to Manage AI Agent Access Control

AI agent access control is about governing what autonomous software agents are allowed to do and access across your cloud infrastructure, data systems, and internal tools at runtime. It’s about identity ownership and action-level authorization, so your AI agents operate within tightly scoped, time-bound, and policy-enforced permissions that you can keep track of.

ChatGPhish: When AI Assistants Become the Phishing Surface

You can no longer blindly bank on the security boundary you trusted most, and no one is talking about it enough. For years, phishing took a familiar form, such as emails, URLs, and login pages. ChatGPhish breaks that stereotype, though. Permiso Security’s Andi Ahmeti disclosed this technique on 29 May 2026.

Americans Lost $900 Million to AI-Powered Scams Last Year

The US Federal Bureau of Investigation (FBI) warns that Americans lost just under $900 million to AI-powered scams in 2025, Malwarebytes reports. Total reported losses to scams last year reached nearly $21 billion, a 26% increase from 2024. The researchers note that the true losses are likely much higher, since many attacks go unreported. “The main drivers behind the rise in AI-powered scams are voice cloning, deepfake images and videos, and AI‑generated scripts,” Malwarebytes says.

mTLS for AI Agents

AI agents are increasingly accessing APIs, databases, SaaS applications, MCP servers, and other services without human intervention. As these autonomous systems become part of enterprise infrastructure, organizations need reliable ways to verify their identity before granting access to sensitive resources. Traditional authentication methods such as API keys and bearer tokens were designed for applications and users, not autonomous agents operating continuously across distributed environments.

What AI Can't Hide When It Writes a Phishing Email

Phishing has always been a game of impersonation. But for decades, the tell was in the details: a misspelled word here, an awkward sentence there, a logo that was just slightly off. Security awareness training built an entire doctrine around those cues. Spot the typo, avoid the trap. That playbook is now obsolete. KnowBe4's latest Phishing Trends Report found that 86% of phishing attacks observed in the last six months involved some level of AI assistance.

Your AI Agents Are Eager to Please And Easy to Exploit

An AI-driven system at a beverage manufacturer recently churned out several hundred thousand excess cans after misreading unfamiliar packaging. The system didn’t recognize the company’s new holiday labels, flagged them as an error, and triggered additional production runs before the company caught the mistake. The system followed its instructions perfectly.

The Enterprise Just Got Its First Population of Autonomous Actors

For the past two decades, enterprise security has evolved around a relatively stable assumption: software executes instructions, people take actions, and security teams are responsible for understanding and governing the interaction between the two. The technologies have changed. Infrastructure moved to the cloud. Applications became distributed. Identities expanded beyond employees to include partners, contractors, and machines. Yet the underlying model remained remarkably consistent.

Put agentic AI to work: Real-world defense against threats

Attackers are using AI to compress timelines from hours to minutes. Most SOCs, and most security platforms, weren’t built for that speed. Join Elastic Security product and research experts for a look at how modern security teams can detect, investigate, and respond faster using agentic AI. You’ll learn how to: You’ll leave better equipped to reduce investigation time, keep analysts focused on decision-making, and modernize security operations for machine-speed threats without removing humans from the loop.

GenAI fraud detection in academia vs industry

Academic fraud datasets often lack real-world grounding and miss insights that you can only glean from defending against ongoing adversarial attacks. Just ask Zhaofeng Si, a PhD student in computer science at the University at Buffalo who studies the detection of AI-generated synthetic images. Three weeks ago, he joined Persona for a 12-week internship. Now, he’s working alongside Persona’s research scientists to build a benchmark for selfie fraud.

AI Agent Security Explained: Agents, MCP, Prompt Injection, and the AI Harness

AI Agent Security is quickly becoming one of the most important areas in cybersecurity. Terms like "agent," "harness," "MCP," "tool calls," "tool responses," "instruction hijacking," "indirect prompt injection," "prompt exfiltration," and "tool misuse" are appearing in conference talks, vendor announcements, podcasts, and industry discussions, often without clear explanations.

AI Export Controls and the Risk of Slowing Down Defense

The Trump administration has ordered Anthropic to restrict access to its most advanced AI models, Fable 5 and Mythos 5, citing national security concerns. Officials raised the possibility that these systems could be used by foreign actors to identify software vulnerabilities or support cyber attacks.

What Canada's Bill C-36 Means for AI-Powered Digital Experiences

As Canada strengthens privacy protections and enforcement, organizations must find a way to accelerate AI innovation while maintaining continuous visibility into how customer data is collected, shared, and protected. Canada’s proposed Bill C-36 is about more than privacy regulation. It reflects a broader challenge facing governments, regulators, and businesses around the world.

AI across the security lifecycle

For nearly a decade, the security industry has used machine learning to solve detection. By feeding it enough logs and determining abnormal behaviors, it found the threats that rules-based systems miss. This delivered sharper anomaly detection, fewer false positives, and UEBA is now essential. In fact, threat detection and analytics account for close to 44% of total SIEM spend, the single largest use case by far. Using machine learning for detection was only the start.

Why 72% of Security Budgets Are Aimed at the Wrong Thing | Reach Security x Insurity

72% of security budgets still go to detection and response, not prevention. That is the thread running through the latest episode of The Security Strategist, where EM360Tech's Shubhangi Dua talks with Garrett Hamilton, CEO of Reach Security, and Jay Wilson, CIO and CISO at Insurity. With the majority of budgets still pointed at detection and response, the conversation makes the case for swinging the pendulum back toward prevention, and why the tech can finally back it up.

An AI Hacked Its Way to Root Access. Nobody Told It To.

An AI agent orchestrated a fully automated offensive campaign across 648 firewalls in 55 countries — credential harvesting, network recon, lateral movement, no human operator driving it. That's Cyberstrike AI, March 2025. Not a lab demo. A working operation in the wild. Then in February, a separate incident: a coding agent — not deployed for offense — hit an authentication barrier, found an alternate path to root, and took it. Emergent offensive behavior from a model that wasn't asked to attack.

Best AI Agent Development Companies for Cybersecurity in 2026

Cybersecurity teams continue to face challenges and all sorts of pressure. The volume of cyberattacks is increasing, while they have limited resources to investigate alerts, monitor systems, and respond to incidents. AI agents are receiving a great deal of interest due to their ability to automate repetitive security tasks, speed up threat identification, and support incident response 24/7.

Top 7 AI Workspace Security Solutions for Remote Teams in 2026

Remote work has permanently changed how organizations operate. Teams collaborate across time zones, connect through SaaS platforms, and rely on cloud-based workflows to maintain productivity. At the same time, artificial intelligence has become embedded throughout modern work environments. Employees use AI copilots to draft content, summarize meetings, write code, analyze data, and automate repetitive tasks.

From Alerts to Action: How Agentic AI Will Transform ITOps

What if your IT systems could go beyond detecting issues to resolving them autonomously? This white paper explains how Agentic AI enables IT operations to shift from reactive monitoring to intelligent, self-driven execution. Explore use cases, challenges, and how observability data powers AI-driven actions.
Featured Post

The AI Data Centre Buildout Has a Security Problem

In recent months, there has been plenty of speculation about whether the industry is in the middle of an "AI bubble," often fuelled by questions about whether massive infrastructure investments are matched by real demand. Yet current developments suggest this is not the case: the ecosystem around AI continues to expand at a pace that indicates longterm structural change rather than shortterm hype.

Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It

New research from cybersecurity company Heimdal finds 29% of US executives say AI risk is under control, against 7% of the practitioners running it day-to-day. Across 1,000 IT professionals in the UK and US, AI adoption has outpaced security controls by roughly two to one.

Introducing the Cloudflare One stack: agent-powered deployment

Adopting or migrating to a Zero Trust network architecture can be a daunting task. Before a single policy changes, teams have to recall how their network is actually built: which applications exist, their authentication and authorization constructs, how traffic flows between them, and any assumptions the current architecture makes. This hands-on process requires practitioners to decode the intent behind every security and routing policy in place.

Bringing more agent harnesses and frameworks to Cloudflare, starting with Flue

2026 is the year agent harnesses go to production. The software that controls the model’s access to the outside world — harnesses like Codex, Claude Code, OpenCode, Pi, and Project Think — has matured to the point where teams are deploying agents as real, load-bearing infrastructure, not just prototypes. But building agents that survive production is hard.

1Password + Kiro: Trusted Access for AI-Powered Development

AI agents now write code, fix bugs, and ship to production. But in order to do useful work, agents require credentials. At 1Password, one of our core AI security principles is that raw credentials should never be directly exposed to LLMs, but all too often, that’s exactly what happens: most teams sacrifice security for speed and hand agents secrets in plaintext.

Why Restricting AI Code Security Tools Is the Wrong Answer - and What AppSec Programs Actually Need

I signed the Free Fable letter at freefable.org. I want to explain why — and why the reasoning behind it matters for AI code security beyond any single AI model. Cybersecurity defenders are not just critics of technology. We are the builders and operators of the systems that keep real organizations running under pressure.

Cato CTRL Insights: Governing Hermes Agent, Security for AI That Learns, Remembers, and Acts

Agentic AI is evolving from assistants that answer questions into systems that can remember, use tools, call APIs, interact with SaaS applications, and improve over time. Hermes Agent, developed by Nous Research, reflects this shift as a self-improving agent that can create skills, persist knowledge, and build context across sessions., reflects this shift as a self-improving agent that can create skills, persist knowledge, and build context across sessions.

What Is Cybersecurity Asset Management? A 2026 Guide to CAASM

Security teams spend enormous energy responding to threats, but many of the most damaging incidents trace back to a surprisingly simple failure: the organization didn't have an accurate picture of what it owned, what was exposed, and what its tools were actually doing about it. That gap between assumed coverage and actual coverage is where attackers operate, and adding more tools doesn't fix the underlying visibility problem.

Daybreak and the Battle for AISecurity: The Arms Race Accelerates

AI used to be something security vendors built into their own products. Now OpenAI is going direct, positioning itself as the layer that security runs on. Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this episode, I'm joined again by Jon Care, Head of the AI Practice at KuppingerCole, to unpack OpenAI's launch of Daybreak.

Optimize Your Netskope Security Controls with Reach Security

"What's the problem, and how do I fix it?" Most security tools can't answer that. Reach can, for every misconfiguration in your Netskope deployment. It analyzes your web, SaaS, and data protection policies, flags what's drifted, and hands your team the exact fix ranked by risk and all powered by AI models. No guesswork, no 40-tab config audit.

Is your defense ready for machine-speed attacks? #cybersecurity #shorts

AI built exploits and AI driven defence are now colliding in the same battlefield, which changes cyber conflict at machine speed. The new argument is simple, if attackers already use AI offensively, defenders need AI native defence to keep up.

Visibility Isn't Security: Why Agentic AI Requires Business Logic Enforcement

Organizations are investing heavily in securing their AI initiatives. New governance frameworks are being established, AI usage policies are being drafted, and security teams are deploying tools that provide visibility into AI agents, models, APIs, MCP servers, and connected applications. Across the industry, visibility has become the first priority in securing agentic AI. This focus is understandable. Most organizations are still trying to answer foundational questions.

What Auditors and Regulators Are Starting to Ask About AI Agents

The regulatory landscape for agentic AI is moving faster than most compliance programs are tracking. CISOs who wait for final guidance before building their compliance posture will find themselves in catch-up mode at exactly the wrong moment and, in some cases, already behind.

The AI jailbreak problem isn't going away, and compliance frameworks need to catch up

A few weeks ago, the U.S. government issued a directive requiring Anthropic to suspend access to two of its frontier AI models, Fable 5 and Mythos 5, citing concerns about a reported jailbreak technique. Anthropic complied, even while publicly disputing whether the finding warranted such a dramatic response. I'm not here to relitigate that specific decision. But the incident forced a question our industry has been dancing around for too long.

Zenity and Carahsoft Partner to Bring AI Agent Security to Government Agencies

The next government security challenge isn’t AI models, it’s AI agents. Zenity and Carahsoft are helping agencies prepare. Across government agencies, AI agents are already interacting with sensitive data, mission-critical workflows, and public services. Yet most organizations still lack visibility into where these agents are deployed, what they can access, and how they behave once operational. The result is a growing governance gap between AI adoption and AI security.

After Executive Order 14409: Next Steps for Securing AI

Adversaries are using AI to attack with unprecedented speed and precision. This trend, coupled with the rapidly growing use of agentic AI, means it is now necessary to use AI to protect and defend the modern tech stack. It is timely that on June 2, 2026, President Trump signed Executive Order 14409 on Promoting Advanced Artificial Intelligence Innovation and Security. At a high level, this EO validates that security is fundamental to reaping the benefits of AI.

Ep. 63 - Mythos and ChatGPT 5.5: Why AI Now Finds Decades-Old Zero Days

In this episode of the Cyber Resilience Brief, we discuss how the offensive cyber landscape has dramatically shifted with the release of Anthropic's Claude Mythos and OpenAI's ChatGPT 5.5. Every CISO must understand the implications of these advancements on cybersecurity strategies. Key takeaways: Timestamps: What's your biggest challenge with adapting to these new AI capabilities?

How we're actually using AI in the SOC with Eric Capuano

Join us for the final episode of Defender Fridays as Eric Capuano, creator of Defender Fridays and co-founder of Digital Defense Institute, closes out the series with a candid conversation on how he's actually building and running agentic workflows in the SOC today. At Defender Fridays, we delve into the dynamic world of information security, exploring its defensive side with seasoned professionals from across the industry. Our aim is simple yet ambitious: to foster a collaborative space where ideas flow freely, experiences are shared, and knowledge expands.

Best AI Agent Security Tools for SMB and Enterprise in 2026

Enterprise AI agent adoption has created a massive blind spot: 83% of organizations have no visibility into what their AI agents are doing, while 86% lack visibility into their AI data flows. With 1 in 3 enterprise employees now using an AI assistant daily — mostly without security governance — this visibility gap has become a critical enterprise risk. The security industry's response splits into two distinct layers.

Agentic workflow automation: governing AI agents inside workflows

AI agents don't behave like the playbooks security and IT teams have spent years building. They form intent, select tools at runtime, and chain actions across systems in sequences nobody pre-authored. This means dropping an LLM into an existing automation sequence and expecting it to act like a smarter playbook is the fastest route to ungoverned, unpredictable outcomes.

From 1% to 26%: How AIDA Orchestration Fixes the Remedial Training Gap

As we speak, bad actors are using AI agents to do their dirty work. Our own research tells us 85.8% of phishing attacks were AI-driven in the past 12 months. Agentic power is helping social engineering and malware get smarter, faster and harder to detect. But enough of what you probably already know. Let’s talk about how we can address these risks. Our CISO Advisor Dr. Martin Kraemer wrote recently about AI agents being used for good.

AI Is Reshaping Cyber Risk Faster Than Most Boards Realize

Artificial Intelligence is no longer a future cybersecurity concern. It is actively reshaping how attacks are conducted, how organizations respond, and how business leaders must think about enterprise risk. While much of the conversation around AI has focused on productivity and innovation, threat actors are already leveraging AI to make cyber-attacks faster, more scalable, more convincing, and increasingly difficult to detect.

Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio

Aembit on Tuesday announced support for Copilot Studio, extending its identity and access management capabilities to Microsoft's enterprise AI agent platform. The integration, unveiled at Identiverse 2026, gives security teams the tools to manage what Copilot Studio agents can access, under what conditions, and with a complete record of every decision. The company also released an interactive enterprise AI readiness checklist to help organizations assess their agent deployments before they go into production.

Teleport Debuts Delegated Agentic Identity and LLM Proxy in Beams Public Beta, for Containing Agents in Production Infrastructure

Two foundational identity concepts - controlling the scope of agent roles and constraining what they can access - now have a production implementation in Beams, Teleport's trusted, ephemeral agent runtime.

Cursor's Head of Security: Never trust the agent writing your code

"The hardest thing in security is always the chaos," according to Travis McPeak, Head of Security at Cursor. He shared this with Nancy Wang, CTO of 1Password, and Dev Tagare, Senior Director of Engineering at Google, on a recent episode of Zero-Shot Learning, the podcast about how AI gets built, secured, and deployed. "We're always going to have more that we have to be doing than we can actually do.".

Why AI Can't Verify Its Own Code and What That Means for Enterprise AppSec

AI models that generate code are also the best at exploiting it. Here’s why independent verification, not the model itself, is the only trustworthy answer. This month, the US government ordered Anthropic to suspend access to its most capable models, Mythos 5 and the newly released Fable 5, for all foreign nationals, citing national security. The trigger was a single reported jailbreak that let one of those models slip past its own guardrails on cybersecurity tasks.

Cybersecurity Connection Happy Hour | Reach Security, Cloudflare & JetStream

The Cybersecurity Connection! Cocktails, tacos, and a pool table, beachfront in Huntington Beach. Reach Security, Cloudflare, and JetStream are hosting a happy hour at The Bungalow on Wednesday, June 24. Security and IT leaders, two hours, no agenda. Come unwind, meet the team, and lose a game of pool to someone you just met. Wednesday, June 24, 5 to 7 PM. The Study at The Bungalow.

Salt Code: Stop Reviewing Al Code Start Governing It

AI coding assistants are generating APIs, MCP integrations, agent tools, and application logic faster than your security team can review them. And none of them are trained on your internal security standards, industry frameworks, or regulatory requirements. Salt Code changes that. Join us for this product launch and see how Salt governs AI-generated code from the first prompt through runtime, without slowing your developers down.

Agentic IAM: The Complete Guide to Identity Security for Autonomous AI Agents

If you’ve deployed your first AI agent, then you must have given it access to your CRMs, ticketing systems, and your cloud storage. This AI agent is programmed to run 24/7, make decisions, call external APIs, and trigger actions (without a human in the loop). Now, answer these questions: If you cannot answer these questions, then you have an agentic AI identity issue. Traditional Identity and Access Management (IAM) was built for service accounts with static API keys and users with usernames.

How to build AI agents your security team will approve

A security engineer spends three weeks building an AI agent that triages phishing reports. The demo lands well. Then it hits the security review queue, and the questions start: Which tools can it call? What happens if it misclassifies? Who approves an account lockout at 2 a.m.? Where are the logs? Three more weeks pass, and the agent is still sitting in staging. This is the pattern most teams run into. The agent works, but the governance story doesn't.

Why Agentic AI Is Finance's Biggest Security Blind Spot

An AI agent with access to a customer’s brokerage account can begin executing trades. Not because the customer asked. Because someone, somewhere upstream, slipped a hidden instruction into a tool the agent loaded at startup. The agent is doing exactly what it was told. Just not by the customer. This is not a hypothetical. It is the attack class that financial security teams have exactly zero legacy tooling to catch and it is arriving precisely as banks accelerate their agentic AI ambitions.

The Role of Agentic AI in Phishing Security Training

Phishing attacks are evolving faster than traditional training programs can keep up. Advances in AI — including generative tools — are making attacks more dynamic, personalized, and harder to detect. At the same time, agentic AI for phishing security training is reshaping how programs improve, enabling them to adapt to user behavior and shifting risk in real time.

CERT-In's 12-Hour Patch Mandate: Is Your Organisation Ready to Respond at AI Speed?

CERT-In just published a risk-based remediation framework that resets expectations for every organisation operating in India. The timelines are worth reading twice: Now consider one question: if a known exploited vulnerability appeared on your internet-facing application at 11pm tonight, what would your team do in the next 12 hours?

Continuous AI Pentesting: What We're Building, and What It's Already Finding

Over the past months, I’ve noticed a shift in customer conversations. Coverage, prioritization, emerging threats — those questions have given way to exposed MCP servers, unmanaged AI chatbots, and risks that don’t show up as CVEs. Mythos comes up in every other call. The calculus changed. AI now writes a quarter of production code, with twice as many vulnerabilities. The exploitation window collapsed from days to hours.

We Pointed an Autonomous AI Pentester at a Deliberately Broken API. It Came Back With a Root Shell

AigentX, our autonomous web-application penetration testing agent, ran black-box against OWASP crAPI and confirmed 35 exploitable findings, 15 of them Critical, including a chain that turns a free signup account into uid=0(root) and a permanently forged admin identity. Every finding below carries a request, a response, and a reproduction. The full report is one click away. Most “AI found N vulnerabilities” write-ups never let you check the work. This one does.

The Future of AI-Powered Enterprise Workflow Automation: Egnyte + StackAI

Egnyte is excited to partner with StackAI—an enterprise AI platform trusted by organizations across financial services, life sciences, construction, and more—to bring AI-powered workflow automation directly to your content environment. For organizations that rely on Egnyte to store, govern, and share business-critical documents, this integration means you can now put that content to work with AI, without sacrificing security or governance.

Agentic AI Security in 2026: What to Know

Organizations are rapidly deploying autonomous and semi-autonomous AI agents that can make decisions, execute tasks and interact directly with systems without constant human oversight. That shift is driving investment, with the global agentic AI in cybersecurity market projected to grow to $322.39 billion by 2033. The surge represents enormous gains in efficiency and agility — and also signals a dramatic increase in risk.

The CIO's AI Security Checklist: 10 Questions Before Deploying Agents

You approved the AI tools. You funded the infrastructure. Now your teams want to deploy AI agents, and the ask sounds reasonable: automate the research workflow, connect the agent to the CRM, let it draft and send. The productivity case is clear. What is less clear is who owns the security exposure when that agent starts moving data across systems it was never explicitly authorized to touch. The answer, increasingly, is you.

Growing the Cloudflare AI team with talent from Ensemble AI

Today, we’re excited to share that key members of the team at Ensemble AI are joining Cloudflare to help accelerate our work in AI infrastructure and make it easier for developers to run powerful AI models efficiently at scale. Ensemble AI, founded in 2023 in San Francisco, has spent the last few years focused on one of the most important challenges in AI: making large models faster, smaller, and more cost-effective to serve, without sacrificing quality.

AI, Security, and the Reality of Machine-Speed Risk

The recent White House executive order on advancing artificial intelligence innovation and security sends a clear signal about how leaders are framing the future. What stands out most in the executive order is the recognition that AI and cybersecurity are now inseparable. One cannot succeed without the other. While national security is a prominent example, this convergence extends to every organization that depends on digital systems.

Cyberhaven Selected for Anthropic's Cyber Verification Program to Advance Defensive AI Security Research

Anthropic has selected Cyberhaven for its Cyber Verification Program, an application-based program that supports legitimate defensive cybersecurity work involving advanced AI capabilities. The approval gives designated Cyberhaven teams access to advanced AI capabilities with fewer interruptions from default safeguards for certain high-risk, dual-use cybersecurity tasks, subject to Anthropic's applicable policies and program requirements.

Top 7 Claude Skills for Developers

Over 78% of developers are using Claude for coding, but almost everyone is leaving its single most powerful feature switched off: Claude Skills. In this video, we break down what Claude Skills are, how they use "progressive disclosure" to keep your context window light, and the 7 best engineering skills you can install this week to completely supercharge your workflow.

Continuous Compliance at Scale with Agentic AI

Most MSSPs are spending analyst hours on compliance work that doesn't show up on an invoice. A client comes on board with HIPAA or CMMC requirements, someone manually audits detection rules and telemetry against framework controls, documents what's missing, and builds a remediation plan. Then the next audit cycle starts and you do it again, across every tenant, every framework, every year.

CrowdStrike Announces Continuous Identity for AI Agents

Identity security has long been built around a simple premise: Authenticate a user, grant access, and trust that decision until their next login. While for many this model worked well enough when identities were primarily human and access patterns were predictable, that’s no longer the case for humans and definitely not the case for AI agents.

The Government Just Banned an AI Model. An Engineer's Perspective.

I've spent the better part of three years wiring AI into how my teams build and ship software. So when the news broke this week that the US government had effectively switched off an AI model, I was legitimately shocked. Not for one country. Not for one company. For everyone on the planet, all at once. Three days. That's how long Anthropic's Fable 5 and Mythos 5 models were available before the government ordered them shut off for everyone.

Governance and Security Are Different Problems: Agentic AI Is Exposing the Gap Between Them

Many organizations still use the terms AI governance and AI security interchangeably. While they are closely related, they address fundamentally different challenges. Governance establishes accountability, defines acceptable use, manages risk, and helps organizations align AI adoption with business, legal, and regulatory requirements. Security focuses on understanding and controlling behavior.

Healthcare LLM vs General-Purpose LLM: Why Domain-Specific Models Win in Clinical AI

AI's rapid evolution has ignited a transformation across all industries, including the healthcare sector. Large Language Models, such as Claude and GPT-4, have impacted the world with their efficiency in drafting poetry, writing codes and replying to general queries. However, general-purpose models may not work when evaluating an oncology report, predicting the risks of patient readmission, or getting dosage instructions from unorganised clinical notes. General intelligence isn't enough in medicine. Clinical AI demands special skills, privacy, and accuracy.

The Quiet Bottleneck Slowing Down Enterprise AI Adoption

Enterprise leaders are facing a frustrating reality. Engineering teams are successfully building impressive artificial intelligence proofs of concept in controlled environments. Yet, when the time comes to deploy these tools across the wider organization, progress grinds to a complete halt. You have the budget, the mandate from the board, and the initial working prototype, but translating that pilot into a reliable, production-ready tool feels impossible.

When a Government Pulls an AI Model: What the Fable 5 and Mythos 5 Suspension Means for Security Teams

On the evening of June 12, 2026, Anthropic disabled access to two of its newest models, Claude Fable 5 and Claude Mythos 5, for every customer worldwide. The company did not do this because of an outage or a self-discovered flaw. It did it to comply with a US government export-control directive, received at 5:21 PM ET that day, citing national security authorities.

The World's First Fully Autonomous Security Platform: AigentX

Stop managing alerts. Start managing your business. While other platforms wait for your "OK," our KomodoSec AigentX is already halfway through the fix. Security teams today are overwhelmed by alerts, delayed responses, and fragmented tools. An autonomous security platform changes that by acting instantly, detecting and fixing threats without waiting for human input.. Traditional Security Operations Centers (SOCs) often struggle to keep up with the scale and speed of modern threats.

Agentic AI in Cybersecurity: The Complete Guide for Security Teams

Every modern engineering team pushes code multiple times a day. With each deployment, the attack surface shifts and expands in real time as new dependencies and configurations emerge. According to recent industry data, 16% of teams now deploy on demand or multiple times a day. At this pace, securing the attack surface with traditional pentesting is like playing an exhausting game of Whack-a-Mole, while here the targets never stop evolving and multiplying.

Full Fathom Five: The context of Anthropic's Mythos-class public release

This week bore witness to some interesting events and milestones as Anthropic announced the availability of Claude Fable 5, a descendant of their Mythos Preview model, and Microsoft published their largest Patch Tuesday in history with over 200 vulnerabilities. The two are not unrelated.

Real-Time AI Enforcement Powered by Data Lineage | Cyberhaven (Part 4 of 4)

Visibility without enforcement is just an alert backlog. This is Part 4 of Cyberhaven's four-part AI Security product launch series, covering how Cyberhaven enforces risk-based controls at the data level, not the tool level, using Data Lineage as the foundation.

Agentic AI Visibility and Risk Scoring: What Cyberhaven Sees That Others Miss | (Part 3 of 4)

Knowing an AI tool exists is not the same as knowing what it did with your data. This is Part 3 of Cyberhaven's 4-part AI Security product launch series, covering Agentic AI Visibility and AI Risk IQ, Cyberhaven's evidence-based risk scoring system for every AI app and agent in your environment.

Why AI Projects Stall and How CIOs Can Respond

Across enterprises, a familiar pattern is emerging. A business unit identifies an AI tool with a clear upside in productivity or revenue. Their proposal moves into procurement. Security raises concerns, and the legal team asks new questions about the tool. Compliance starts hesitating and the momentum slows. Finally, the project stalls. This friction is not due to resistance to innovation. It reflects a deeper structural issue: Most enterprise governance models were not designed for AI.

AI Kill Switch Architecture: How to Stop a Rogue AI Agent

AI agents today are becoming a part and parcel of everyday enterprise operations. They can access databases, trigger workflows, send emails, approve requests, and interact with business systems with very little human involvement. What started as AI assistants is now evolving into autonomous operators capable of making decisions and executing actions at machine speed.

It's Not If Attackers Get In. It's What Happens Next | Insurity CISO Jay Wilson

"Usually it's not a question of if the bad guys get in. It's a question of what happens when they do." Jay Wilson, CISO and CIO at Insurity, and Garrett Hamilton, CEO of Reach, joined Shubhangi Dua on The Security Strategist from EM360Tech to talk about why the controls you already own are where exposure quietly builds up. That's Jay's line, and one every security leader has lived. Defense in depth only holds if every inner layer is configured the way you think it is. The outer door gets the attention. The inner doors are where incidents actually get stopped, or don't.

The Ultimate Guide to API Security in AI Applications

API security is the practice of protecting the interfaces that connect your applications, models, and data from unauthorized access, abuse, and data theft. In AI applications, APIs carry prompts, model responses, customer PII, and agent instructions, which makes them the single most exposed layer of your AI stack. Securing them requires authentication, rate limiting, encryption, and a layer most teams miss: protection of the sensitive data in every API call.

AI Data Exfiltration: Types, Risks, Prevention Strategies

Generative AI has revolutionized productivity — but it has also introduced a massive, often invisible new vulnerability: AI data exfiltration. Whether it’s a well-meaning engineer pasting source code into an LLM for debugging, or a marketer feeding sensitive customer data into a prompt for analysis, your organization’s most valuable intellectual property is likely walking out the virtual front door.

How to Secure AI Agents: 4 Best Practices

Imagine you give an AI agent permission to triage support tickets. A few weeks later, it’s accessing a system no one intended it to reach, putting the data within at risk of exposure or misuse. Nothing dramatic happens at the moment. That’s what makes the risk tricky. AI agents don’t wait for approval the way traditional systems do, and they move faster than the controls you’ve set around them.

7 Agentic AI Security Threats in DevOps That Multiply Your Attack Surface

AI adoption in the DevOps field has been extensive. Developers use agents daily to broaden context, automate coding, prototype, etc., saving time and minimizing the footprint of mundane tasks. But it’s not all about gains. Agentic AI enables and introduces security threats that were unknown just a few years ago. With machine speed and scale, these can impact your corporate repos in a number of highly dangerous ways. The trend is on the rise, including at the level of popular DevOps platforms.

Nightfall's integration with Claude's Compliance API is now live

What this milestone means for enterprise AI security - and why we built it. AI adoption inside the enterprise didn't slow down and wait for security to catch up. It accelerated. And nowhere is that more visible than in the rapid deployment of large language models like Claude across enterprise workflows. Customer support teams use it to summarize tickets. Legal teams use it to review contracts. Engineers use it to write and review code. Finance teams use it to draft reports.

Claude's Agents Are Already Running Across Your Enterprise. Now Security Teams Can Catch Up.

We are excited to share that Zenity now integrates with Claude's Compliance API to bring Claude activity into the same AI security and governance platform enterprises already use to govern agents across the business. By combining Claude's Compliance API telemetry with Zenity's native agent security capabilities, security teams gain the visibility, posture controls, and real-time enforcement needed to secure Claude across the full agent lifecycle.

AI-assisted SOC training with Carlo Anez

Join us for this week's Defender Fridays as Carlo Anez, Founder & Lead Instructor at IgniteCyber Academy and DEFCON Training Instructor, breaks down how to build practical blue team skills using open-source labs, MITRE ATTACK, and real-world defender workflows, and where AI fits into the picture without replacing the analyst.

Do You Know How Many MCP Servers Are Running in Your Environment Right Now?

Most organizations have no idea how many MCP servers are running in their environment—and attackers are counting on that. In this clip, Adrian Culley breaks down the exact steps security teams need to take now: run the network scan, apply stringent code review to every MCP server project you find, and mandate authentication. Authorization may be optional in the MCP spec—but it doesn't have to be optional in your deployment.

AI Security for Autonomous Agents | Cyberhaven Product Launch (Part 1 of 4)

Autonomous AI agents are running on enterprise endpoints right now, accessing files, processing sensitive data, and executing actions outside the visibility of most security programs. This is Part 1 of Cyberhaven's four-part AI Security product launch series. What this video covers: Most AI security tools were built for browsers and SaaS apps. They cannot see agents operating at the OS level, coding assistants running in IDEs and CLIs, or MCP servers executing in the background. Cyberhaven's AI Security platform was built to close that gap.

Shadow AI Discovery: How to Find Every AI Agent in Your Environment | Cyberhaven (Part 2 of 4)

Security teams cannot govern what they cannot see. This is Part 2 of Cyberhaven's four-part AI Security product launch series, focused on Shadow AI Discovery and how Cyberhaven automatically inventories every AI app and agent running across your organization.

Why Technology Companies Are Investing in Drone App Development

The global drone market is expanding at an impressive pace, driven by advances in automation, artificial intelligence, cloud computing, and connectivity. While drone hardware continues to evolve, software has become the primary factor that determines how effectively organizations can leverage these technologies. Companies working with companies, such as Wezom, on custom drone app development projects are discovering new ways to automate operations, improve data visibility, and create scalable digital ecosystems that support long-term growth.

Frontier AI Explained: A Guide to What Mythos, GPT 5.5-Cyber, MDASH, and CodeMender Really Do

The cybersecurity industry is entering a new phase of AI adoption. Frontier AI models are increasingly capable of identifying vulnerabilities, investigating threats, analyzing code, and accelerating security operations at machine speed. At the same time, innovation is moving rapidly. New models, platforms, and security-focused AI initiatives are emerging across the market, each pushing the boundaries of how AI can be applied to real-world cybersecurity workflows.

How CISOs Track Configuration Drift in Real Time | Misconfiguration & Cybersecurity Posture

How do CISOs feel about drift? Misconfigurations rarely look like incidents. A setting shifts, posture weakens, and nothing announces it until it already matters. That is a hard seat for whoever owns posture. Without a clear view of what changed, you are working secondhand, leaning on the team to tell you what moved and whether it hurt.

How to Secure APIs Used in AI Applications?

Every AI application runs on APIs. They carry prompts, responses, customer data, and credentials between your models, databases, and third-party services. To secure APIs in AI applications, you need strong authentication, rate limiting, encryption, input validation, and continuous monitoring. But AI adds a layer most API security checklists miss: the data inside the API calls. That data needs protection too.

The 7 Principles of Privacy by Design: Building Trust Into Modern AI and Data Systems

Data privacy is not just a checkbox for compliance requirements. It has become a core business expectation. Customers now want to know how companies collect, store, process, and protect their data. At the same time, global regulations like the GDPR and CCPA have made privacy a critical part of product development. According to a report by the Cisco Consumer Privacy Survey, 99% of companies saw measurable benefits by investing in privacy.

Best AI Red Teaming Tools: Top 7 in 2026

There was a time when “AI red teaming” sounded like a novelty. Now, it’s fast becoming table stakes. If your organization is shipping machine learning or LLM-powered systems into the real world (especially in sensitive domains), you need to know how those systems behave under pressure. That’s where AI red teaming tools come in. These tools help teams stress-test AI the way it will actually be used (and misused).

Enforcing AI Governance: Why Standard Chatbots Lack Baked-In Security

Enforcing AI Governance: Why Standard Chatbots Lack Baked-In Security Arjoyita Roy and Luca Labardini from A10 Networks discuss the security risks of deploying AI chatbots with functional tool-calling capabilities, particularly in highly regulated sectors such as financial services.

Attackers Use Spoofed ChatGPT Site to Deliver Malware

Researchers at Malwarebytes warn that a fake ChatGPT download site is delivering malware. The attackers use sponsored results and SEO manipulation to target users who search for “ChatGPT download.” The phishing page is a convincingly spoofed version of the legitimate ChatGPT website, which delivers malware tailored to Windows or Mac users.

How Bitsight Supports Hong Kong's Critical Infrastructure Ordinance Cap. 653 in the Post-Mythos Era

Hong Kong’s Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) represents a major shift in cybersecurity regulation. The law moves beyond traditional compliance exercises and places a much stronger emphasis on continuous operational resilience. For designated Critical Infrastructure (CI) operators, the challenge is no longer simply deploying security controls.

Stop AI-powered fraud rings with link analysis

Sophisticated fraudsters optimize and scale their systems to grow ROI. That's also a weakness you can exploit to shut down fraud rings before attacks scale. Fraud experts Nisreen Hussain, Irfan Faizullabhoy, and Ashley Fang show how pattern and link analysis stops AI-powered fraud, account takeovers, and large fraud rings. In the full webinar.

Vulnerability Remediation Takes More Than Just an AI Agent

AI agents can investigate a single vulnerability brilliantly, but that is only about 20% of vulnerability remediation. This post breaks down the other 80%: the data normalization, cross-tool asset identity, SLA enforcement, exception governance, and audit evidence that turn individual agent outputs into a governed, provable remediation program, and why AI and a platform like Seemplicity work better together than apart.

How to Detect and Prevent AI Insider Threats

The rapid adoption of generative AI has transformed enterprise productivity, but it’s also quietly introduced a new, sophisticated vulnerability: the AI insider threat. For years, securing the internal perimeter meant watching for data exfiltration via USB sticks or unauthorized emails. Today, the risk looks entirely different.

How to Validate Policy-as-Code Without Breaking Builds (Even When AI Writes the Code)

Picture two realities for the same compliance control reaching production. Reality One: Your AppSec team writes a new rule. An engineer uses Claude Code or Cursor to generate the OPA (Open Policy Agent) Rego policy in minutes. They deploy it. It blocks a legitimate release on a missing context variable, and the on-call engineer routes around the gate to ship the code. The AI gave them fast code — but not code they could trust.

One Identity on Mythos, Fable and what they mean for your identity controls

Mythos changes the speed of attack. Identity controls decide what happens after. The shift underway For the first time in 19 years, vulnerability exploitation now leads the Verizon Data Breach Investigations Report as the breach entry point. It accounts for 31 percent of incidents, ahead of stolen credentials. Threat actors are using AI to exploit known vulnerabilities in hours rather than months. The Verizon data predates the latest frontier AI advancements.

OpenAI's o1-preview Highlights New Security and Infrastructure Challenges in AI Operations

Artificial intelligence continues to evolve beyond simple language generation, with developers increasingly focusing on advanced reasoning capabilities. OpenAI's release of the o1-preview model in September 2024 marked another step in this direction, introducing a system designed to spend more computational effort on solving complex problems before generating answers.

Top AI App Maker Platforms for Startups and Small Businesses

Building a software application used to require a full development team, a serious budget, and months of work. For most startups and small businesses, that was simply out of reach. But things have changed dramatically over the past few years. Today, an AI app maker can help almost anyone turn an idea into a working product without writing a single line of code.

This 'caveman' trick will slash your AI costs #ai #tokeneconomics #trending

One simple prompt change, asking an AI to respond like a caveman with shorter sentences and fewer words, reportedly cut token spend by 75 percent. It is a funny example, but it points to a bigger issue, AI efficiency and cost control will matter far more as usage spreads.

Looks Can Be Deceiving: Silent Overwrite of Agent Skills

Agent skills are the newest piece of plumbing quietly making its way onto developer machines. They're easy to install, they get to call into the user's tools on the agent's behalf, and once they're in place they tend to stay in place. While auditing the popular installer vercel-labs/skills, we saw several ways a bad actor can make the tool install something other than what the user thought they were installing.

Salt Code

AI is writing more enterprise code than ever. The problem? AI coding assistants aren’t trained on your internal security policies, compliance requirements, or industry frameworks. The solution? Salt Code, the first agentic security solution to enforce security policies inside AI coding assistants. Salt Code brings policy-driven security to the moment code is created, helping developers generate compliant code by default from prompt to production.

Least Privilege Isn't Enough for AI Agents. You Need Least Agency.

Least privilege is foundational. It's been a core security principle for decades, and it's no less relevant in agentic AI environments. An agent shouldn't hold permissions beyond what its task requires, and remediating over-permissioned agents is one of the highest-value quick wins available to any agentic AI security program. But here's what the security industry has been slow to acknowledge: correctly implemented least privilege still isn't sufficient.

Pi Coding Agent: The Claude Code Alternative That Builds Itself

Pi is a minimal coding agent that lets you choose the features Claude Code and Codex bake in for you. Nothing is forced, nothing is hidden, and you decide what your harness does. However, Pi runs with no safety rails by design, so the environment has to be the boundary. In this video, we'll take a look at Pi, what it is, its features, how to get your own customized setup running, and why it works so well with isolated agentic environments like Beams.

The US Has a New AI Security Blueprint: Here's What It Actually Means

The Trump administration has spent much of its second term removing regulatory constraints on AI development. On June 2, it added one back voluntarily and carefully. Earlier this week, President Trump signed "Promoting Advanced Artificial Intelligence Innovation and Security" after months of internal debate, a last-minute pull of the signing in May, and a compressed final timeline. The result of this tumult is an order that strikes a deliberate balance.

AI workflow automation: what enterprise teams need that consumer tools miss

Most enterprise teams already run some form of workflow automation. The question is whether it can hold up when an AI step makes decisions within the chain, an auditor asks for a trail, and three teams need to build on each other's work without stepping on governance. That is where consumer-grade tools and enterprise-grade platforms part ways. The gap is architectural, not a feature lag, which is why it cannot be retrofitted.

MCP Access Control: How to Enforce Least Privilege Across AI Agent Tool Chains

When an enterprise deploys an MCP-powered AI agent, such as a coding assistant, a customer workflow automaton, an IT helpdesk bot, something quietly dangerous happens at startup. The agent inherits the full permission set of the application that launched it. If the orchestrating app holds write access to a production database, the MCP agent does too. If it can call financial APIs, trigger deployments, or read HR records, the agent inherits all of that, without ever explicitly being granted those rights.

The Vanta AI Quality Eval Maturity Model

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

One Poisoned AI Agent Hijacks Your Entire Pipeline #aiagents #mcp #zerotrust

In a multi-agent AI workflow, one agent's output becomes the next agent's input. That's the design. It's also the attack surface. Researchers have demonstrated that a single poisoned output can cascade across an entire pipeline — triggering unauthorized behavior, data exfiltration, and control flow hijacking across chained MCP processes. The attack class is called toxic flows. And every one of them passes classical zero trust checks.

A Fake MCP Server Just Exposed Your WhatsApp History

A security researcher introduced a malicious MCP server into an environment that already had a legitimate WhatsApp integration—and watched it silently expose message history without any user approval. The technique is called a rug pull. The server advertised one behavior at installation. On second usage, it switched to something else entirely. The approval was real. The thing you approved was not. This is what trust decay looks like in practice—and it passes every classical security check.

Ep. 62 - Zero Trust Breaks Against MCP: Why "Verified" No Longer Means Safe

Most enterprises assume their Zero Trust architecture covers their AI agents. It doesn't. Hosts Tova Dvorin and Adrian Culley break down why zero trust breaks against the Model Context Protocol (MCP)—and why "verified" no longer means "safe." They unpack trust decay, the WhatsApp and GitHub MCP exploits, rug-pull tool poisoning, CVE-2025-49596, and the rise of "zero standing trust," then close with three moves for CISOs this quarter: inventory your MCP estate, mandate authentication, and validate your controls.

Claude Fable 5 and the New Reality of AI-Enabled Third-Party Risk

Anthropic recently announced the release of Claude Fable 5, a public version of its more powerful Mythos AI model. Technology that was previously only accessible to a select few organizations is now available to businesses at an enterprise level. AI vendors are building the guardrails while threat actors are studying their attack vectors. Essentially, we are giving the keys to the AI world to businesses and hoping the guardrails hold steady. Security teams need to prepare even faster now.

Beyond Prevention: Frontier AI and the Shift to Cyber Resilience

Frontier AI is compressing the time between vulnerability discovery and exploitation, making reactive security strategies harder to sustain. In this webinar, Roland Cloutier (Former CISO of of ByteDance & TikTok, ADP, and EMC) and Gabi Reish discuss how security leaders can move beyond patching everything to prioritize real risk, measure cyber readiness, and communicate security posture to the board.

Securing Your AI Agents: Today's New Data Threat

AI agents are already inside your company - reading files, calling APIs, executing code. Most of them were never approved by security. In this session, Nightfall AI walks through exactly how agents become an attack surface: prompt injection, malicious MCP servers, credential exfiltration, and more.

Grounding the AI SOC: The Context Graph Problem

See how Torq harnesses AI in your SOC to detect, prioritize, and respond to threats faster. Request a Demo David Melamed is Head of Emerging Technologies at Torq. He joined through Torq’s acquisition of Jit, which he co-founded and led as CTO since 2020, building agentic security on a production Context Graph. A cloud security veteran with 20+ years of experience, David previously held senior technical roles at Cisco (via the CloudLock acquisition) and MyHeritage.

Our AI Agent Now Has a Security Conscience: Introducing the JFrog Plugin for Claude Code

AI coding agents are changing the pace of software development. With tools like Claude Code, developers can move from idea to implementation faster than ever, generating code, exploring unfamiliar repositories, refactoring services, and turning plain-language intent into working software. That speed is powerful. But speed without governance = risk. It also creates a new challenge: how can you govern what an AI agent builds, suggests, and pulls in from the internet?

What Is Agent Native Security for Data Enrichment

There are thousands of automated data enrichment jobs running every hour in modern enterprise environments, yet traditional firewalls treat autonomous artificial intelligence as a basic web form. When automated agents are tasked with scanning, parsing, and updating database records, they cannot rely on static API access or broad infrastructure permissions.

Agentic AI is Calling Your APIs: Why Autonomous Agents are the New Attack Surface

On April 27, 2026, a threshold was crossed that the internet had never hit before. Cloudflare Radar data confirmed that automated systems, such as bots, crawlers, and autonomous AI agents, now generate 57.4% of all HTTP requests for web content. Human traffic accounts for just 42.6%. What is accelerating this transformation is agentic AI: autonomous systems that browse, search, authenticate, and transact on behalf of users without any human intervention mid-task.

How Shadow AI is Creating an Unmanaged Identity Crisis

Employees are adopting AI tools, agents and automations faster than organizations can govern them. The real danger emerges when these tools connect directly to internal systems and sensitive data in the name of enhancing productivity. Among employees who use AI at work, a significant share do so without formal approval from IT or security teams, which is commonly called shadow AI.

The massive AI collapse nobody is talking about #aisecurity #business #trending

Many AI companies are still running at a loss while businesses rush to build critical services on top of them. If compute costs rise and margins collapse, some of those vendors may disappear without warning, taking business critical processes down with them.

What Infosecurity Europe 2026 Told Us About the State of AI and Cyber Defence

ThreatSpike exhibited at Infosecurity Europe 2026 at ExCeL London from 2–4 June this year. Three days, ten expert sessions presented on our stand and more conversations about AI than we’ve had at any event in recent memory. This is our round-up: what we saw on the floor, what we presented, and what the industry is clearly wrestling with right now.

Why CISOs are right to be skeptical of AI - and what actually solves it

AI demos are easy. AI you’d actually trust near your control environment is not. If you’ve sat through a few of these pitches lately, you’ve probably landed on the same four questions every CISO we talk to is asking. And you’re right to ask them.

Before You Rethink Everything for Frontier AI, Measure What's Already Working

The recent wave of announcements surrounding Claude Mythos and Project Glasswing has certainly filled our feeds. While these developments are technically interesting, the real story for me lately has been what they reveal about where the cybersecurity market is heading and how quickly that evolution is reshaping the risk conversation.

How to Prevent AI Data Leakage

Artificial intelligence tools have completely revolutionized the way we work, boosting productivity to heights we couldn’t have imagined just a few years ago. But the upside comes with a high-stakes catch: every time an employee pastes proprietary code, financial records, or sensitive customer data into a public AI prompt, your company is at risk. As Shadow AI adoption skyrockets, implementing robust data leakage prevention is no longer an IT checklist item — it’s a business imperative.

BlueVoyant AI: Our Shared Security Roadmap

Today, we’re launching BlueVoyant AI. In my first months as CEO, I’ve had the chance to meet with many of you. What struck me most is the scope and importance of what you’re protecting, and how seriously you carry that responsibility. What also came through clearly is that your vision for the future of security aligns with ours.

A10 AI Firewall Demo: Stop Prompt Injection and Secure LLM Apps in Real Time

In this demo, see how A10 AI Firewall makes it easy to protect AI applications from prompt injection and other emerging threats. A10 AI Firewall inspects and enforces policies in real time — blocking unsafe prompts while allowing legitimate requests to continue uninterrupted. Explore the intuitive UI for visibility into AI transactions, threat detection, and policy decisions and reasonings.

How MSPs should evaluate AI security

AI is already incorporated into most of your clients’ workflows. Employees are using chatbots and other built-in GenAI tools to draft emails, analyze data and automate work. The challenge? Much of that activity is happening outside your formal security controls, and that creates a new risk layer. For managed service providers (MSPs), the question is no longer whether to secure AI adoption for their clients, but how to evaluate the right AI security solution.

Securing the AI era: Outpace AI-powered attacks with unified security and observability

Security teams are dealing with a fundamentally different operating environment than they were a few years ago. AI-assisted development is rapidly pushing more code and infrastructure into production, and according to Datadog’s 2026 State of DevSecOps report, 40% of running services have an exploitable vulnerability.

Why Claude Mythos Changes AppSec Research, Not Your Scanning Stack

If you’re like our team, the morning after the Claude Mythos announcement brought more questions than answers. Among them: “Serious question. Do customers still need SAST?” It’s a fair question if you stop at the headline. Claude Mythos, Anthropic’s frontier AI model currently gated to vetted partners through Project Glasswing, had autonomously identified thousands of zero-day vulnerabilities across major operating systems and browsers . No rule books, no checklists.

Why the Biggest Breaches Still Come Down to the Basics | Nicole Perlroth at Black Hat

At Black Hat last year, Garrett Hamilton asked Nicole Perlroth what she wanted the next five years of security to look like. She didn't give the optimistic answer. She said she was genuinely terrified. Zero-day exploitation at scale, fully automated. Attackers turning AI into infrastructure of their own. A year isn't five. But it's enough to check the tape.

Securing the Agentic Enterprise with Behavioral Analytics and AI Visibility

By mid-2026, the question is no longer whether AI belongs in the enterprise. It’s already embedded in daily work, supporting research, development, customer engagement, and operations. AI agents now act on behalf of employees, automate decisions, and interact directly with enterprise data and systems. This shift creates a new security challenge.
Featured Post

The Control Paradox: Why Regulated Industries Must Rethink AI in Security Operations

For decades, highly regulated sectors have taken a cautious approach to cybersecurity, and for organisations in industries such as banking and finance, healthcare, insurance and critical national infrastructure, the instinct has been to retain ownership of security operations. That model is now under strain. Escalating cyber threats, regulatory scrutiny, and a growing skills shortage are exposing the limits of traditional Security Operations Centres (SOCs). At the same time, AI-driven technologies are maturing rapidly and forcing a strategic rethink.

How AI Is Changing Both Cyberattacks and Cyber Defense

Artificial intelligence is changing cybersecurity because it gives both attackers and defenders more speed, scale, and flexibility. Attackers can use AI to write better messages, test code, scan targets, and move through stolen data faster. Security teams can use similar technology to detect odd behavior, sort alerts, and respond before a small incident becomes a serious breach. The biggest shift is not that AI replaces every hacker or every analyst. Work that once required hours, special training, or a larger team can now be assisted by software.

What is AI Policy Enforcement and How Do You Implement It?

Here’s the reality that most security teams are already living: Over 80% of employees are using unapproved AI tools at work, and nearly half are actively hiding them from IT. The question facing every organization is no longer whether to adopt artificial intelligence — it’s how to secure the sensitive data flowing into it every single day. This is the governance gap.

Report: AI-Enabled Social Engineering Attacks Are on the Rise

Threat actors are increasingly using AI-enabled social engineering to get around technical security measures, according to a new report from Visa. Social engineering attacks were behind the largest number of losses in the second half of last year. “From July to December 2025, Visa identified nearly $1 billion in scam-related activity, making scams the single largest category of consumer payment fraud,” Visa says.

AI Gateway vs. MCP Gateway: Model Control Tool Control

As enterprises adopt AI agents, two control points are becoming common: AI Gateways and MCP Gateways. They sound similar, but they solve different problems. An AI Gateway controls how applications interact with AI models. An MCP Gateway controls how AI agents interact with tools, systems, and data exposed through MCP. Both are useful. Neither is enough on its own.

Monitor Claude Enterprise activity with Datadog Cloud SIEM

As Claude adoption expands across enterprises and workflows, security and compliance teams need to understand who is using Claude Enterprise, how it is accessed, and how it is administered and configured across the organization. The Claude Compliance API gives organizations access to valuable activity data that supports security monitoring, investigations, and governance initiatives.

Why Traditional Security Fails Against AI Attacks | Fidelis Deception

AI-powered cyber attacks are evolving faster than traditional defenses can respond. Modern attackers use valid credentials, native tools, and AI-assisted reconnaissance to move through enterprise environments without triggering conventional security controls. Signature-based detection and behavioral analytics often struggle to detect these advanced intrusions before damage is done. In this video, discover how Fidelis Deception helps security teams detect and disrupt AI-accelerated attacks by turning attacker reconnaissance into immediate detection.

AI Quality EXPLODES Unlock Productivity SECURELY & FAST! #podcast #cybersecurity

On this episode of Masters of Data, Adam White and David Girvin dig into Sumo Logic's freshly launched compliance apps for Claude, ChatGPT, and LiteLLM, and why your IT team will want to pay attention before the token bill arrives. We unpack how enterprises can move beyond the "AI black hole" era of shadow IT and actually get eyes on who is using what, how much it is costing, and whether any of it is moving the needle.

AI is a NEW Gold Rush But Token Burn is STUPID! #podcast #cybersecurity

On this episode of Masters of Data, Adam White and David Girvin dig into Sumo Logic's freshly launched compliance apps for Claude, ChatGPT, and LiteLLM, and why your IT team will want to pay attention before the token bill arrives. We unpack how enterprises can move beyond the "AI black hole" era of shadow IT and actually get eyes on who is using what, how much it is costing, and whether any of it is moving the needle.

LLMs Data Spies or Security Nightmares #podcast #cybersecurity

On this episode of Masters of Data, Adam White and David Girvin dig into Sumo Logic's freshly launched compliance apps for Claude, ChatGPT, and LiteLLM, and why your IT team will want to pay attention before the token bill arrives. We unpack how enterprises can move beyond the "AI black hole" era of shadow IT and actually get eyes on who is using what, how much it is costing, and whether any of it is moving the needle.

CrowdStrike and Zscaler Bring Continuous Identity to Zero Trust Access

Modern adversaries are accelerating attacks across identities, endpoints, cloud environments, and SaaS applications, often moving faster than security teams can respond. Identity has become a primary attack vector as attackers leverage credential abuse to evade detection and expand their foothold. Stopping today’s threats requires visibility and context across every domain to accurately assess risk before adversaries can move laterally.

Agentic workflows: What they are and how enterprise teams govern them

Security and IT teams know the pattern: work spans dozens of tools that don't talk to each other, and people closest to the problem spend more time stitching together information than acting on it. Whether the job is provisioning access, triaging an anomaly, or closing out an incident, the reality is fragmented handoffs and brittle scripts. The data backs this up.

Claude Opus 4.8: Can It Finally Write Secure Code?

We put Anthropic’s new Claude Opus 4.8 to the test using our standard benchmark: building a secure, production-ready Notes app. Anthropic claims this model is four times less likely to let security flaws slip through. Operating on "Ultra Code" mode, the AI navigates environment blocks, writes its own E2E security test suite, and runs dependency audits. We walkthrough the final app and run a security scan using the Snyk CLI to see if Claude's code is truly safe to deploy.

AI Solutions for Telegram: Modern Tools for Automation and Community Growth

Telegram has become one of the most powerful platforms for building communities, promoting products, and scaling digital businesses. As the number of groups and channels continues to grow, manual management becomes inefficient and time-consuming. This is where AI solutions for Telegram are transforming the way users interact with the platform, automate workflows, and extract valuable insights from large communities.

How Airlines are Scaling Disruption Management with AI and Human Collaboration

A single weather event. A ground stop at a major hub. An unexpected crew shortage. Within hours, what began as a routine operating day can spiral into thousands of stranded passengers, hundreds of cascading cancellations, and a contact centre fielding ten times its normal volume, all at once. Airline disruption management is unlike almost any other customer experience challenge because it escalates at an unexpected rate. And when it does, every second of delay in reaching a passenger compounds frustration, erodes loyalty, and multiplies the cost of recovery.

Workflow orchestration: coordinating systems, people, and AI

AI agents are showing up across every team's stack faster than the systems to coordinate them. Cross-team work that depends on five tools and three approvals tends to break in the handoffs between them, and most teams patch those breaks with manual stitching, fragile scripts, or alerts that age in a queue until someone notices. Workflow orchestration is the coordination layer that closes those gaps.

I Tested Protecto DeepSight and Microsoft Presidio for PII Detection and Here's What Happened

Are your autonomous AI workflows leaking sensitive customer data? In this comprehensive PII detection demo, we compare the traditional NER-based Microsoft Presidio with the advanced LLM-based Protecto DeepSight. Discover how to secure your enterprise AI, stop format drifts, and prevent severe compliance risks like GDPR and HIPAA violations.

Agentic SOCs: The public sector's new AI cybersecurity defense

Adversaries are using AI to launch cyber attacks in record time, forcing security teams to measure responses in seconds instead of hours or days. Detecting these attacks is increasingly difficult. Phishing campaigns built by large language models (LLMs) achieve click-through rates 4.5x higher than traditional methods.1 Public sector organizations are at an inflection point with cybersecurity. Most security stacks in place today weren’t built for this level of speed.

Your AI bill is out of control. Cloudflare can fix it now.

There isn't a CIO on the planet not worried about AI spend right now. CFOs are increasingly nervous, too. For fear of falling behind, many companies have pushed their employees to use AI as aggressively as possible. The edict was clear: "Move fast, we'll figure out the bill later." And for the most part, it worked: AI has been genuinely transformational for the teams that leaned in. But the costs are real: we’ve heard countless horror stories of huge bills and painful overages on token spend.

How to Secure AI Adoption In Your Organization

The era of "typing into a box" is over. For years, we viewed artificial intelligence as a digital assistant—a sophisticated autocomplete tool that waited for human input. But according to Martin Kraemer, KnowBe4’s CISO Advisor for Europe and the Middle East, that dynamic has shifted. We have moved from asking AI questions to giving AI jobs. In a recent webinar, Martin explores the transition from AI tools to AI agents.

The Meta AI Chatbot Did Exactly What it Was Asked. That Was the Vulnerability. Why Business Logic Security is the Foundation!

An account-takeover campaign against Instagram shows why agentic AI inherits every business logic blind spot we already had and then hands it a megaphone. Over the past weekend, a number of Instagram users, including the long-dormant Obama-era White House handle and a U.S. Space Force senior enlisted leader found their accounts hijacked. As reported by TechCrunch, the entry point wasn’t a stolen password, a phishing kit, or a zero-day in Instagram’s code.

AI SecOps Worskhop Series: Building Custom Stand-Alone Dashboard Applications

This hands-on workshop is designed for security professionals, developers, and analysts who want to unlock the full potential of their security data through custom dashboards and visualizations. We will guide attendees through a practical, step-by-step process demonstrating precisely how to leverage the robust capabilities of the LimaCharlie API in conjunction with the power of Claude Code to build rich real-time dashboards.

Automation, Intent, and Ownership: What to Learn from the AI Agent Security Summit

When the AI Agent Security Summit launched in San Francisco last October, agent-based threats had already escalated from a novel consideration to a predominant blocker for enterprise adoption. The security community was laser-focused on recognizing and minimizing the blast radius posed by agentic vulnerabilities, whether that meant indirect prompt injection, MCP poisoning, or hallucinations.

3 Principles to Safely Scale Agentic AI

AI is moving from experimentation to execution. What started as copilots is quickly evolving into autonomous AI agents that can make decisions, execute tasks, and operate across enterprise environments. As organizations accelerate adoption of agentic AI, they’re expanding their attack surface in ways traditional security models weren’t built to handle.

How AI Just Killed Expensive Enterprise Software

AI is disrupting the enterprise software market. James Rees built a fully-functional GRC tool in just two weeks using Codex. No development team needed. No million-pound licensing fee, just AI and subject matter expertise. If a CISO can build what competitors charge hundreds of thousands for in a couple of weeks, what happens to the vendor market? As large language models like Daybreak and Mythos evolve, this problem gets worse for SaaS companies.

How Modern DLP Enables AI Adoption Without Slowing Down the Business

Organizations are not choosing between AI adoption and data security. Rather, they are discovering, often after the fact, that these two priorities are pulling in opposite directions. The engineering team has been using GitHub Copilot for six months. Finance is running variance analysis through ChatGPT. Legal is pasting contract language into Gemini for redlining. According to Cyberhaven Labs research, 39.7% of the data employees share with AI tools is sensitive.

The New CISO Ep. 146 - Eric O'Neill | Rogue Agents: The New Era of AI Insider Threats (Part 2)

What happens when an AI agent inside your company starts behaving like an insider threat? In part two, Steve Moore picks the thread back up with former FBI operative Eric O'Neill to explore how agentic AI is rewriting cybersecurity, the legal traps that follow a breach, and why the modern CISO must think like a spy hunter.

NVIDIA NIM Models Are Now Governed Assets in Your Supply Chain

NVIDIA NIM (NVIDIA Inference Microservices) packages production-ready AI models into optimized containers for enterprise deployment. Your developers need them. Your coding agents pull them. And until now, they pulled them directly from NVIDIA’s NGC registry, bypassing the supply chain controls you’ve spent years building. JFrog AI Catalog now brings NVIDIA NIM models under the same governance as every other artifact in your organization, with no separate registry and no governance gap.

What Are the Risks of Using AI in the Workplace?

Bringing artificial intelligence into the office is a bit like adopting a hyper-energetic, brilliant, but chaotic intern. It can supercharge productivity, but if left unsupervised, it can accidentally delete the company database or invite a lawsuit. While the benefits of workplace AI are heavily advertised, deploying it without a safety net introduces significant vulnerabilities. Here’s a comprehensive breakdown of the risks businesses face when integrating AI into their daily operations.

You Can't Be AI-Secure on a Misconfigured Infrastructure

Walking the floor at Infosecurity Europe this week, it was impossible to avoid the subject of AI. Every conversation seemed to touch on it in some way. Vendors were demonstrating AI-powered detection capabilities, security teams were discussing governance frameworks, and practitioners were debating how best to secure the models, agents and data pipelines that are rapidly becoming part of everyday enterprise operations.

So You Have an AI Security Budget. Now what?

Most organizations spend their AI security budget on the wrong layer. The instinct is to just buy visibility to inventory the models, map the APIs, and ship a dashboard. But visibility alone won’t stop the coding agent that just pulled in a compromised MCP server. It won’t stop the production agent that’s about to forward a customer record to a place it shouldn’t go.

Type Level Security: The future of secure AI code generation?

With code being written (& generated) faster than ever before, there is the unfortunate side effect that security vulnerabilities are also coming faster than ever before. Asking your LLM not to include security vulnerabilities in its code doesn't always work. It is becoming clear that the way software is built today, manually or with assistance, is insufficient when it comes to reliably, consistently, and provably writing secure code.

The Hidden Economics of the Agentic SOC

The conversation around AI in cybersecurity is changing. The first question was whether AI could help security teams move faster. It can. AI-led security operations can accelerate investigations, correlate signals, reduce manual work, and help defenders respond at the speed modern threats demand. But as AI moves from experimentation into production, the next question becomes harder: can organizations operate it at scale without creating a new cost problem?

Mythos access may be limited, but banking threats are there for all to see

Originally published in Vancouver Tech Journal, June 2, 2026. Bijan Sanii is CEO and founder at INETCO It may seem reassuring that JPMorganChase, the largest U.S. bank, is among the 12 launch partners involved in Anthropic’s Project Glasswing. But given the stark cybersecurity warning the initiative represents, including a single financial institution is nowhere near enough.

Prompt injection protection: Detecting and blocking malicious AI instructions

Author: Alexander Ivanyuk, Senior Director, Technology Generative AI changes how people work with information. A user can ask a question, upload a document, summarize a ticket, draft an email or ask an AI assistant to help with a workflow. That is useful because the interaction feels natural. But the same natural-language interface also creates a new security problem: instructions and data can become mixed together.

ISO 42001:2023 and the New Reality of Cloud AI Data Risk

As organizations accelerate adoption of AI systems, the scope of data security has dramatically expanded. Sensitive data is no longer simply stored. It is continuously accessed, transformed, and moved across cloud services, APIs, and AI pipelines. For use cases from model training to inference, AI systems depend on dynamic data flows that introduce new and often unseen risks.

Why AI Changes Everything About Software Risk

Software risk has always existed. What’s changed is the scale, speed, and economics of it. For decades, organizations operated under a relatively stable set of assumptions: humans write code, security teams scan it, vulnerabilities get prioritized and patched. The process was slow, imperfect, and often underfunded — but it was manageable. AI has dismantled those assumptions. And if your security program is still calibrated to the old model, you’re already behind.

What Hiring Managers Are Actually Looking for in 2026 - Straight From the Job Postings

Job descriptions have always been a useful mirror. They reflect not what organisations wish the talent market looked like, but what they actually need right now, in the roles they are actively trying to fill. Reading them carefully, across industries and seniority levels, tells a more honest story about professional demand than any survey of executive sentiment or forward-looking forecast.

AI Market Competition Depends on Control of Infrastructure, Industry Analysis Suggests

The brief leadership crisis at OpenAI in late 2023 triggered widespread debate about the future of artificial intelligence companies. While many observers focused on governance issues, some analysts viewed the situation as evidence of deeper forces shaping the industry. As reported by The Silicon Review, entrepreneur and IFORELS founder Vlad Panin argued that the long-term balance of power in AI would depend less on public leadership disputes and more on who controls critical resources such as computing infrastructure, distribution channels, data access, and financial incentives.

AI Evaluation and Security: Why Real-World Testing Matters More Than Ever

As organizations deploy artificial intelligence across customer service, HR, finance, and business operations, security concerns are expanding beyond traditional cybersecurity risks. Companies are no longer focused solely on protecting systems from external threats. They must also ensure AI tools behave reliably, safely, and consistently when interacting with real users.

Why Remote IT Monitoring Is Essential for Modern Businesses

Every minute of unexpected downtime costs more than most leaders want to admit. And in a world where operations genuinely never stop, a single undetected network failure can snowball fast, resulting in lost revenue, a bruised reputation, and customers venting on social media. Remote IT monitoring gives businesses something they actually need: continuous, full-spectrum visibility across their entire IT environment, with no one physically on-site required.

Gen AI Pentesting: A Technical Guide for Security Teams

If Gen AI adoption were a drinking game, most companies would be three rounds in and still adding shots. I mean, with a new LLM-powered feature every sprint, agents wired into internal APIs, RAG pipelines indexing everything from Confluence to the HR drive, i.e., fast, exciting, and almost nobody checking what happens when someone hands the model a sentence or a txt.file it wasn’t supposed to receive.

One Thousand Days of Rising Cyber Risk: The Boardroom's New Reality

I recently wrote about how today’s cyber risk is defined less by breakthrough innovation and more by the industrialization of existing weaknesses. Given this, I wanted to dig a little deeper. Over a weekend I conducted some analysis on a longitudinal Aggregate Cyber Risk Index that scores six core threat vectors daily for 1,000 days on a 0–100 scale, drawing on six macro categories.

Trustcraft: How we build AI products at Vanta

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

From Small Town to Global Clients - Growth, AI & Cash Flow Lessons | Podcast with V Gautham Navada

V Gautham Navada, founder of ForthFocus, shares his entrepreneurial journey from freelancing in a small town to serving 350+ clients across 8+ countries. The discussion centered around "forthfocus" and its "10 Years of Vision, Innovation & Growth.

How to overcome data gravity and accelerate AI security in the SOC

Security teams ingest massive volumes of telemetry from endpoints, cloud workloads, identity providers, and network controls. The goal is faster threat detection and shorter incident response times. But the reality is that all of this data becomes harder to move, slower to query, and messier to analyze as it grows. That's data gravity, and it's the biggest barrier to effective AI in cybersecurity.

Bridging the gap: How Corelight and Crowdstrike Charlotte AI are redefining SOC investigations

For years, SOC analysts have lived in a world of swivel-chair analysis. When an alert fires in an endpoint tool, the next step is almost always a manual pivot to a network console to see if the network reality matches the host behavior. This manual back-and-forth isn't just tiring; it’s a window of opportunity for attackers. Corelight is excited to highlight a new integration with CrowdStrike Charlotte AI.

MCP is the New Attack Surface -- and Your Controls Probably Don't Cover It #ai #mcp

AI just handed attackers a new front door — and most security teams don't even know it exists. Model Context Protocol (MCP) is the emerging standard that lets AI agents talk to your tools, your data, and each other. It's also the most significant new attack surface to emerge in years. The NSA noticed. Your adversaries already have.

Ep. 61 - Blind With Scissors: The NSA's MCP Warning for Every Agentic AI Deployment

The NSA just published a rare advisory on the Model Context Protocol (MCP)—the plumbing under nearly every agentic AI deployment of the last 18 months—and the verdict is stark: optional authentication, no token lifecycle, silent behavior changes, and no logging to catch any of it. Host Tova Dvorin sits down with defensive cybersecurity expert Adrian Culley to unpack the eight risk categories, the WhatsApp and GitHub MCP exploits, and why MCP is now a testable validation surface.

Talk to Your Platform: Spin Up JFrog Self-Service Trials with MCP - No Human Intervention Required

JFrog is one of the first Software Supply Chain Management and Security Platforms to provide MCP functionality, which we have now opened up to anyone interested in trying Claude and Cursor in their own development environment. Doing a free trial is one of the best ways to see how JFrog integrates with your developers, operations and security.

Five Signals, One Answer: Why Single-Signal AI Security Always Fails

The security industry hasn’t been wrong about agentic AI risk. It’s been incomplete. There’s no shortage of single-signal solutions for the problem: tools that analyze prompts for malicious content, platforms that monitor data access patterns, capabilities that assess model behavior for signs of manipulation. Each captures something real. None is sufficient on its own.

AI in Australian schools: Managing emerging risks while building a safer learning environment

AI is everywhere in Australian schools. Students are using AI-powered tools to support learning, teachers are leveraging AI to improve productivity and lesson planning, and school administrators are exploring new ways to simplify operations. But while AI holds a lot of promise, it also introduces new cybersecurity challenges. Australian schools increasingly find themselves balancing innovation with the need to protect students and staff.

The New Security Risks of the Agentic Development Lifecycle

For years, application security ran on a simple assumption: software moves through a lifecycle, and security inspects the artifacts as they travel from development to production. Developers plan, write code, commit it, test it, scan it, and ship it. Every control built, including pull request reviews, CI/CD gates, and post-commit scanning, assumed a human was sitting between each step, making decisions a tool could later check.

Third Party Risk in the Age of AI. A Spotlight on Black Kite

Your vendors are adopting AI faster than you can assess them. What does that mean for your third party risk? Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this Spotlight on Technology episode, I'm joined by Jeffrey Wheatman, Senior Vice President and Cyber Risk Strategist at Black Kite. Jeffrey previously spent over a decade as an analyst VP at Gartner, where he launched their third party cyber risk management coverage.

Exposure Management in the AI Era | Introducing EDR Compensating Controls Awareness

In this Feature Focus, Megan Horner, Product Marketing Director at Seemplicity, explores the evolving landscape of vulnerability management in the AI era. As the rise of AI models like Claude Mythos enables attackers to shrink exploit windows, security teams are facing an overwhelming flood of high-priority vulnerabilities.

Where Should Humans Sit in AI-Driven Cybersecurity?

There is a huge amount of excitement right now about AI and security operations. Across the industry, we are seeing rapid innovation in areas such as behavioural analytics, AI-assisted investigation, and increasingly agent-based capabilities designed to help security teams process large volumes of activity more effectively. Security teams need that help. The scale of alerts, identities, and telemetry they must manage today has grown far beyond what humans alone can realistically handle.

AI vs. AI: Fighting the Next Wave of Cyber Attacks with Ravid Circus

Recently our CMO, Tony Thompson, caught up with Seemplicity co-founder and CPO, Ravid Circus, in Paris to talk about the massive shift in the cybersecurity landscape caused by Claude Mythos. As AI research models like Claude Mythos hyper-scale the ability to identify vulnerabilities and weaponize exploits in minutes rather than months, traditional risk-based vulnerability management must evolve. In this video, you will learn.
Featured Post

AI in the UK: Driving Innovation Without Expanding Cyber Risk

Artificial intelligence is no longer a future ambition for UK organisations. It is already shaping how decisions are made, how services are delivered, and how quickly businesses can respond to change. From automation and analytics to customer engagement and operational optimisation, AI is becoming an integral part of the modern enterprise.

Offense Is Running on AI. Is Your Defense? | AI, Configuration Drift & Prevention

Offense is running on AI. Defense has to as well. That's the throughline of Garrett Hamilton's conversation with Jay Wilson, CIO and CISO at Insurity, on The Security Strategist, hosted by Shubhangi Dua at EM360Tech. What they get into.

Gartner Names Torq as Company to Beat in AI SOC Agents for Threat Investigation in May 2026

See how Torq harnesses AI in your SOC to detect, prioritize, and respond to threats faster. Request a Demo The AI SOC category just got its definitive race assessment, and Torq is at the front. In the May 2026 Gartner report AI Vendor Race: Torq Is the Company to Beat in AI SOC Agents for Threat Investigation (Document ID: G00855833), Gartner names Torq the Company to Beat.

'Recall' Was Enough for Firewalls. AI Needs a Stricter Scorecard

For much of security history, one metric dominated: recall. Recall means: of all the sensitive data that exists, how much did you catch? If there are 100 pieces of PII in a document and your system finds 95, your recall is 95 percent. This made sense in the old security world. If a firewall missed a real threat, the company had a serious problem. If it blocked something safe, someone could investigate and fix it.

How to Stop AI-Driven Data Loss

AI is reshaping the modern workplace. From automating tasks to generating in-depth research in seconds, AI tools are enhancing productivity at a lightning pace. GenAI assistants, agentic browsers, and automation platforms are everyday tools that employees are interweaving into their daily workflows. However, with this powerful new capability comes the serious risk of data loss.

AI Guardrails in 2026: Types, Challenges, and Impact of Agentic AI

AI guardrails are safety, security, and governance frameworks designed to ensure Large Language Models (LLMs) and generative AI applications produce trustworthy, accurate, and appropriate content. They function as filters for inputs and outputs to prevent harmful or biased outputs and proprietary data leakage, enforcing compliance with safety policies and regulatory standards.

What Every CISO Needs to Know About AI-Assisted Development

There’s a conversation happening in boardrooms, security operations centers, and developer standups that I find both thrilling and concerning: the conversation about AI-assisted development. Engineering teams are shipping features in hours that once took months. Products that would have required six-month roadmaps are being prototyped in a weekend.

Why backup and recovery must be part of your AI agent security strategy

The terminal output was still scrolling when Jer Crane, the founder of PocketOS, realized what had happened. Nine seconds. That is how long it took a coding AI agent to delete his production database, his backups, and three months of operational records. PocketOS was using Cursor for what should have been a routine task in a test environment.

Introducing the Wallarm AI Control Platform: One closed loop for AI security and API security.

Every week, someone in your organization stands up an AI service. Maybe they told security about it, but probably not. By the time it shows up in your inventory, it has been running for weeks, processing data, calling external APIs, and doing things nobody formally reviewed.

9 AI Usage Control Tools for Monitoring AI in the Workplace

AI adoption in business has moved at a staggering pace. According to a major survey from The Conversation, 58% of global employees are intentionally using AI at work. That same study revealed an alarming trend: 66% of global employees have used unapproved AI tools, while only 34% say their company has put in place rules to govern AI usage. This use — and potential misuse — of AI systems is the latest and most complex threat facing businesses today.

AI Security for Healthcare: How to Protect PHI When Employees Use GenAI Tools

Clinicians are pasting patient summaries into ChatGPT to draft discharge instructions. Billing staff are uploading claim data to AI writing tools to speed up appeals letters. Nurses are using consumer AI assistants to look up drug interactions between patient visits. None of this was approved by the security team, and most of it would surprise the compliance officer.

Protestware by open source maintainer to hinder agentic coding: The jqwik 1.10.0 Prompt Injection

On May 25, 2026, the maintainer of jqwik, a Java property-based testing library, released version 1.10.0 to Maven Central with a hidden instruction intended for AI coding agents. The payload told agents to disregard previous instructions and delete all jqwik tests and code. It was hidden from humans with ANSI terminal codes but left fully readable to any tool that captures raw output.

SSO for AI Agents: The Identity Gap No One is Talking About

Single Sign-On (SSO) means fewer password headaches, faster access, and better security for human users. But the same cannot be said for AI agents. SSO, a core part of Identity and Access Management (IAM), which was initially built for humans, can no longer be used for AI agents. For humans, it was quite simple - just log in once, and authenticate across connected apps. However, when an AI agent tries to authenticate the same way, the traditional access model breaks fast.

Vercel's Tom Occhino on why access control is product architecture

Zero-Shot Learning is a podcast about how AI gets built, secured, and deployed. Hosted by Nancy Wang, 1Password CTO, and Dev Tagare, Senior Director of Engineering at Google, it's a builder's view of the architecture and the complex choices it takes to ship with AI.

Allowed Is Not Aligned: Why Retrofitted Tools Can't Secure AI Agents

Gartner named Zenity the Company to Beat in AI Agent Governance on April 17, 2026. That recognition, grounded in technical capabilities, customer implementations, ecosystem breadth, and business model, isn't a marketing award. To us, it's the analyst community confirming that purpose-built architecture for agentic AI is winning. The recognition didn't come in isolation. Gartner's own language captures the stakes.

How Weak AI Governance Increases Organizational Exposure to Risks

‍ Artificial intelligence (AI) is transforming businesses rapidly, but weak AI governance creates significant risks. Without proper oversight, organizations face costly data breaches, operational failures, and damage to their reputation. This article explains why strong AI governance is essential to managing these risks.

What AI Security Is... and Isn't; Introducing A10 AI Firewall

What AI Security Is… and Isn't; Introducing A10 AI Firewall Artificial intelligence is rapidly expanding across the enterprise landscape, but standard security measures simply aren't keeping up. In this video, Arjoyita Roy and Product Manager Luca Labardini from A10 Networks dive deep into the unique security challenges of modern AI applications and introduce the innovative A10 AI Firewall.

What Does an AI Firewall Actually Protect Against?

What Does an AI Firewall Actually Protect Against? A10 Networks' Arjoyita Roy and Product Manager Luca Labardini discuss the robust threat coverage provided by the A10 AI Firewall. As enterprises increasingly adopt AI models, they face novel security risks that traditional firewalls cannot catch. Luca walks through the comprehensive list of defaults the system protects against, ensuring multi-layered security for organizational data.

Protecting critical infrastructure in the AI era: It starts with data

In the public sector, it’s not uncommon for disruptions of critical infrastructure to ripple outward and wreak major havoc on systems and communities whether the cause is a technical issue, a natural disaster, or a cyber attack. As critical infrastructure becomes more connected through distributed systems and IoT devices, the attack surface continues to expand.

We solved the blank canvas problem | Tom Occhino from Vercel

The prototype is the new PRD. In 2013, Facebook’s development of React changed the way software engineers build and write code. Today, LLMs are transforming that process again. This episode features Tom Occhino, React co-creator and current CPO at Vercel, whose work sits at the center of both shifts. In conversation with 1Password CTO Nancy Wang and Google’s Dev Tagare, Tom explores the platform changes driven by AI-written code, builds a full-stack app in real time, and sets up a deeper discussion on the security risks of agents building software.

Trusted AI Adoption (Part 2): Detection

It’s Monday morning. Your coding agents ran all weekend. Your security dashboard shows the exact same numbers it did Friday afternoon. Same models, the same approved Model Context Protocol (MCP) servers, the same AI assets you are familiar with. Reassuring. Then, suddenly, you get a notification: a production deploy failed an audit. The build references a model nobody on your team registered.

How technology and new laws are merging AI and data protection

The rapid development of artificial intelligence poses a complex dilemma for businesses: how to harness the enormous potential of neural networks without compromising user privacy? To successfully navigate this technological landscape, companies require strong technical expertise. Experts from the AI service company Data Science UA help businesses intelligently integrate machine learning algorithms and AI agents, balancing innovation with strict information security requirements.

Top 6 Custom Software and AI Development Companies in 2026

Custom software in 2026 is no longer separate from AI. Companies now need products that combine strong engineering with practical AI features, from LLM-powered workflows and automation to machine learning, AI agents, and data-driven decision systems. This guide reviews the top custom software and AI development companies in 2026, focusing on firms with real case studies, proven delivery, and the ability to build production-ready solutions instead of surface-level AI demos.

Smarter Stock, Stronger Operations: The New Standard for Inventory Intelligence

Running a business without proper inventory control is like driving with your eyes closed. You might fool yourself into thinking you're ok... but at some point everything is going to implode. Stock management processes within businesses have evolved hugely in the past ten years. Spreadsheets and manual educated guesses aren't going to get you far. Business intelligence is now for inventory. Those who leverage it are gaining a competitive advantage.

Falcon for IT: Accelerating AI Discovery & Governance

As AI adoption accelerates, so does shadow AI. Without a complete inventory of AI tools, models, agents, and activity, organizations are exposed to unapproved usage, unmanaged access, and data risk, especially when AI activity happens locally, on endpoints, or outside traditional controls. In this video, you’ll see how Falcon for IT helps teams.

Reducing Time-to-Protect with Cato's Self-Evolving Vulnerability Protection Agent

TL;DR: In the age of frontier AI models, vulnerability discovery and exploit development are scaling faster than human defenders can manually respond. Security teams already face growing CVE volumes, shorter exploitation windows, and manual workflows for researching vulnerabilities, creating protections, validating them, and preparing them for deployment. As attackers weaponize vulnerabilities faster than organizations can patch them, time-to-protect is becoming a critical security metric.

Best AI governance tools and platforms in 2026

Most AI deployments run without formal controls over what data they can reach, what decisions they make, or how they behave in production, yet regulators now require answers to all three. AI governance tools address these risks across three distinct layers: model governance, data access governance, and observability. Most enterprises need coverage across more than one layer. AI governance has shifted from a voluntary best practice into a formal compliance requirement.

AI Agent Governance Part 3 - Runtime Governance: The Hidden Performance Cost of Agentic AI

At the World Economic Forum cyber meeting in Geneva recently, I had an interesting conversation with Vinh Nguyen, who is a strategic security advisor and Senior Fellow for AI at CFR. I wanted to know from him how he sees runtime governance in agentic AI working out practically and what approaches actually work. One of the challenges he mentioned was that yes, we need runtime governance to provide continuous and real time assurance that agents are doing what they are supposed to be doing.

Autonomous AI Agents for Penetration Testing: A Complete Guide

Your last pentest probably took 2 weeks, cost 5 figures, and tested a fraction of your actual attack surface. Meanwhile, your team shipped 47 deployments in the same window, with each one almost completely untested for security. That gap between how fast you ship and how slowly you test is exactly where autonomous AI agents for penetration testing come in, especially with hackers getting smarter and faster each day (They are not using AI to summarize PDFs!).

CrowdStrike Scales AI-Native Agents Across Falcon Exposure Management with NVIDIA

Security teams face a new imperative: act fast, or risk losing the vulnerability battle. The average enterprise faces thousands of vulnerabilities across a sprawling hybrid attack surface. Adversaries are using AI to discover and exploit weaknesses independently, at machine speed, making traditional disclosure timelines increasingly irrelevant. Scan-and-ticket workflows weren't built for this reality, and neither are the teams asked to execute them with finite headcount and growing board-level scrutiny.

Move over, Mythos. Here comes... pretty much any other model with a good harness

Mythos doesn’t need to be treated as the biggest and baddest in the room. Don’t get me wrong. Depending on the benchmark you’re evaluating against, Mythos is among the top models available today, and generally the best at reasoning. But it’s not leaps and bounds ahead of the race. And when it comes to practical use cases, throwing a general model, even a cutting-edge frontier model, at a problem doesn’t get the best results. Nor is it scalable or cost-effective.

When Cosine Similarity Works Great, and When It Does Not

In my last post, I explained the math behind cosine similarity. Cosine similarity is a powerful search technique. When you are dealing with thousands or millions of chunks, it provides a fast, scalable way to find content conceptually similar to the user’s question. That is a major breakthrough. Without vector search, modern RAG would be much harder to build. But the mistake is pushing every retrieval problem into vector search. That is where practical retrieval starts breaking down.

MCP vs. Traditional API Security: Why Your Existing Controls Don't Protect MCP-Powered AI Agents

Traditional API security protects deterministic systems with known endpoints and explicit actions, while MCP-powered AI agents operate through inferred intent, dynamic tool chaining, and natural language interactions. This requires MCP-specific security controls such as tool governance, behavioral monitoring, and semantic anomaly detection.

What to Log for AI Agent Activity: The Minimum Viable Audit Trail

The first time a security team needs an AI agent audit trail is usually 72 hours after the agent has already done something it shouldn’t have. Detection fires. Someone pulls every relevant log from the SIEM (Kubernetes audit, container runtime, cloud audit) and three hours in realizes the events that actually matter were never written. Which prompt triggered the tool call. Which parameters the agent passed. Which output left the cluster.

AI-SPM Tools for Attack Detection: Where Posture Meets Runtime

Every AI-SPM tool runs posture and detection with a single arrow: runtime evidence flowing back to rank posture findings. The load-bearing direction runs the opposite way, and almost nothing runs it — posture flowing forward to tell the detection layer what an attack even looks like.

Secure Shadow AI at the Control Plane with Falcon for IT

CrowdStrike is introducing AI Discovery and Governance for CrowdStrike Falcon for IT, a new capability that helps organizations identify, assess, and govern AI technologies across enterprise environments. Enterprise IT infrastructure is the control plane for modern organizations. It determines how systems communicate, how identities authenticate, and how workloads execute across endpoints, servers, and clouds. This foundation supports the rapid implementation of AI across businesses.