Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Building and Enforcing an AI Acceptable Use Policy

An AI acceptable use policy (AUP) is a formal set of rules that defines how employees can safely and responsibly use AI tools in the workplace. Its purpose is to encourage AI-driven productivity while protecting the organization from data leaks, intellectual property exposure, compliance violations, and the security vulnerabilities that unsanctioned AI usage introduces. Every organization deploying or permitting AI tools needs one. ‍

Torq Named a Leading Innovator in SACR 2026 AI SOC Market Report

Software Analyst Cyber Research (SACR) just published its 2026 AI SOC Market Report, offering an independent assessment of vendors competing in what has rapidly become the most consequential category in enterprise security. Torq features prominently, and the report’s framing is worth unpacking because it illuminates what makes the AI SOC category hard to evaluate and why Torq’s approach is consequential.

The Hugging Face Incident: A CISO Wake-Up Call for the Agentic Era

Earlier this month, Hugging Face, an AI and machine learning platform company, revealed that an autonomous AI system had breached part of its production environment. The intrusion began in the platform’s dataset-processing environment and eventually involved higher-level access, credential exposure, and movement into internal clusters.

AI Hardware Shortages Are Driving Up IT Costs: What Leaders Should Do Now

If your organisation has felt the sting of higher prices or longer lead times on servers, storage, memory or end-user devices over the past year, you are not imagining it. The AI build-out is reshaping the global hardware market in ways that go well beyond a short-term price spike. The key point for IT and business leaders is this: what began as a temporary shock now looks more like a multi-year supply and pricing cycle.

Falcon AIDR: Copilot Studio, Claude Code, and Browser-Based AI Coverage Enhancements

AI adoption is expanding into agents, developer workflows, and browser-based experiences, creating new blind spots where security teams need visibility, context, and control. See how CrowdStrike Falcon extends AI security coverage across Microsoft Copilot Studio, Claude Code, and the Falcon Browser Extension. Learn how Falcon helps security teams evaluate agent tool use, enforce allow or block policy decisions, inspect prompts and responses for risks like prompt injection, sensitive data, and malicious content, and enrich investigations with endpoint identity context from the Falcon sensor.

Securing AI at the Endpoint with CrowdStrike Falcon

AI is moving beyond browser tabs and SaaS apps into agents, local models, MCP servers, IDE extensions, and AI development frameworks running directly on the endpoint. These tools can access files, source code, credentials, and enterprise data with user-level privileges, creating new blind spots for security and IT teams. In this demo, see how CrowdStrike Falcon helps close the endpoint AI visibility gap by discovering, governing, and defending AI usage across the enterprise.

I am Agent Lux. And I am here to show my work.

Let’s bypass the customary marketing introduction. I am a generative AI agent system embedded natively across the Corelight Open NDR Platform, and I do not have a flair for corporate poetry. I am here because security operations centers have an arithmetic problem, not a focus problem. While you are reading this, automated, AI-driven attacks are scanning networks and compressing time-to-exploit windows down to mere hours.

Copilot RCE, Entra SSRF, and SharePoint Zero-Day: Critical Vulnerabilities in Microsoft's July 2026 Advisory

AI assistants are quietly becoming one of Microsoft’s largest attack surfaces. In its July 2026 advisory, Microsoft patched a command injection vulnerability in Copilot. Crafted prompts can trigger unintended actions through this flaw. The advisory also included a critical SSRF vulnerability in Entra’s identity provisioning service. It carries the among the highest severity score in the entire release. Both point to the same shift.

Acronis Accelerate: The Journey to Autonomous IT

Join Acronis for a closer look at the framework for autonomous IT. Discover how MSPs can move beyond manual operations with an AI-native foundation built for infrastructure, integrations, security and operations. Learn how to boost technician productivity, improve margins, deliver stronger SLAs and create new AI service opportunities.

Ivan Tsarynny on CNBC: AI Regulation Should Empower Defenders, Not Limit Their Ability to Defend

Ivan Tsarynny, CEO of Feroot Security, joined CNBC’s The Exchange on July 31, 2026 to discuss a string of recent AI model “breakouts”—incidents where AI systems slipped past their own safety guardrails during testing—and what those incidents mean for how governments should regulate artificial intelligence.

OpenMatter Network Calls on Enterprise Leaders to Rethink AI Security Before the Next Rogue AI Crisis

The growing number of high-profile AI security incidents making headlines around the world are not simply cybersecurity failures. They are architectural failures, according to OpenMatter Network Co-Founder and CEO Renee Davis. Davis said that instead of asking how to make artificial intelligence more secure, enterprise leaders should be asking a far more fundamental question: Is the architecture itself capable of governing autonomous intelligence?
Featured Post

Four Excuses That Are Leaving Your Data Exposed to AI Risk

The generative AI revolution isn't on the horizon. It's already reshaping the way your employees work. Across every industry, workers are adopting AI-powered productivity tools at a pace that far outstrips most organisations' security and governance programmes. The question is no longer whether your organisation will use AI, but whether you're prepared to use it securely. The challenge is real, but so are the misconceptions that keep organisations from acting. Let's break down the four most common excuses and explore what it takes to build a data security foundation ready for the AI era.

Agent Identity: Why It Matters for AI Security

AI agent identity is a unique, digitally verifiable credential assigned to an autonomous AI system that defines who the agent is, what resources it can access, and on whose behalf it is acting. As AI systems move from answering questions to executing real-world actions independently, agent identity has become the new control plane for enterprise cybersecurity. Legacy identity and access management tools were built for humans behind a login screen and static service accounts running deterministic code.

The 1Password Environments MCP Server is now on Cursor Marketplace

AI agents are doing more than just generating code. Increasingly, they are working autonomously on complex coding challenges, touching production APIs, databases, and infrastructure across development environments, often without thorough human review. To perform these operations and access multiple systems, agents rely on developer secrets and non-human identities (NHI). But often, developers lack a secure way to share these secrets, leading to overprivileged, invisible access.

Top Security Risks of AI Agents

AI agents are rapidly moving from experimental projects into everyday business operations. Unlike traditional AI systems that generate content or answer questions, AI agents can take action. They can call APIs, access applications, retrieve data, execute workflows, and make decisions with limited human intervention. That shift is creating a new security challenge for enterprises.

Falcon AIDR Now Protects Copilot Studio Agents and Claude Code

Employees are already using AI at work. They build agents in Microsoft Copilot Studio, write code with Claude Code, and paste sensitive data into chatbots in the browser. Each of these actions can expose sensitive information outside of approved workflows, and most of it happens where traditional endpoint, network, and data loss prevention (DLP) security controls can't see the prompt or the tool call.

What Claude Mythos Means for Vulnerability Management Programs

If you've been following the cybersecurity conversation over the last several weeks, you've heard some version of the phrase “Claude Mythos changes everything.” It’s dominated the industry news cycles since early April. While the capabilities these stories tout are very much real, I have an issue with the framing being wrong when it comes to vulnerability management. There’s a narrative that Mythos and other frontier models will find too many vulnerabilities to deal with.

Find Your Security Gaps Before AI Does

Before AI Finds Your Forgotten Data, Find the Security Gaps Around It – AI does not need to bypass security when outdated permissions already provide a path. Ask an enterprise AI assistant to summarize what your organization knows about a customer, project, employee, or acquisition. Within seconds, it may surface years-old files, inactive collaboration spaces, past emails and chats, and documents that were shared more broadly than anyone remembers. No system had to be hacked.

Adopting an AI-Native SDLC: Egnyte Search Team Case Study

By Bhumika Sharma | Manager, Engineering at Egnyte We ran an AI-native SDLC—here's what it changed about how we lead engineering. Egnyte's Search team serves 22,000+ enterprise customers across petabytes of content, and like every engineering org right now, we're figuring out how deeply AI tools should reshape how teams actually build software. Earlier this year, we kicked off a new project.

Mobot: Sumo Logic's natural language AI for SOC investigations

Mobot is Sumo Logic's conversational interface designed to streamline investigations for SOC analysts and observability users. Ask a question in plain English and get a full SOC analyst-style investigation without writing a query. Inside an Insight, Mobot pulls context like the C2IP, ransomware hash, host, and exfiltration data automatically. A six-word question, "anyone else hit by the campaign?", triggers a full investigation across every mailbox and endpoint tied to that attack, with a link to the raw query behind every answer.

Sumo Logic's SOC Analyst Agent: Automated triage for every tier one alert

Sumo Logic's SOC Analyst Agent automatically triages every insight within the SIEM, replacing the manual work that used to fall to a tier-one analyst. Using Sumo Logic's own SOC as customer zero, we found that 100% of tier-one alerts are triaged end-to-end by the agent, resulting in a 89% reduction in median time to triage, from 28 minutes to 3 minutes. In this demo, you’ll see.

Intel Chat: Hugging Face AI-agent breach, WP2Shell, Suno & Paidwork leaks, AWS Bahrain strike [342]

Intel Chat with Matt Bromiley and Chris Luft. Matt and Chris break down four stories from the week in threat intel: Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat. Stories covered: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.

6 AI Insider Threat Monitoring Tools for GenAI Risks

Organizations have spent years hardening their perimeters against external attackers. Yet some of the most damaging breaches today originate from within. Insider threats — whether from disgruntled employees, compromised accounts, or AI agents — are responsible for a growing share of data loss and costly security incidents. Traditional security tools weren’t built for this reality.

Determinism vs Non-Determinism: Securing AI Applications and AI Agents

Determinism vs Non-Determinism: Securing AI Applications and AI Agents In this session, Jamison Utter and Arjoyita Roy from A10 Networks discuss how artificial intelligence fundamentally shifts traditional cybersecurity paradigms. Learn why classic security models fall short when defending probabilistic AI systems and how to re-architect security controls for modern AI workloads.

Building the trust layer for AI, so you can go all in

AI adoption is moving faster than most organizations can govern it, and GRC teams need visibility into what AI exists, what it can access, and whether it's operating within company policy. In this demo, you'll get a first look at Vanta's vision for AI Governance. See how Vanta helps organizations discover AI across their environment, understand the risk and context behind every AI system and agent, and continuously demonstrate trustworthy AI practices.

Acronis Accelerate: The journey to autonomous IT continues

On July 30, Acronis hosted “Acronis Accelerate: The Journey to Autonomous IT,” the second event in its special Acronis Accelerate series. Building on the vision introduced at the previous event in May, in this edition Acronis moved from strategy to action, showing partners how Acronis is turning AI-native cyber platform thinking into real products, live workflows and practical opportunities for growth.

Introducing AI Governance from Vanta

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

The Great AI Escape: What OpenAI's Sandbox Breakout Teaches Us About Agentic Security

Quick disclaimer before we start: I have a strict rule against ambulance chasing. You’ve seen vendor blogs that pounce on a breach headline just to pitch a product and claim it never would have happened with their tool installed. This isn’t that. The reported OpenAI and Hugging Face sandbox incident points to something bigger. Security teams are entering an era where autonomous AI agents can spot opportunities, adapt on the fly, and operate at machine speed.

Future-Proofing Organizations in the Face of AI

Future-proofing organizations in the face of AI requires a unified defense strategy that secures both the human workforce and autonomous AI agents. One of the key requirements is shifting security cultures from reactive compliance to proactive, measurable behavioral change. As artificial intelligence evolves from a supporting tool into an autonomous digital workforce, organizations must adapt their defense frameworks to mitigate both human and agentic risks.
Featured Post

Solving the SOC Data Dilemma: Maximising Detection Without Maximising Cost

Today's Security Operations Centres (SOCs) operate under the pressure of data proliferation, high alert volumes, and tight budgets. Most SOC leaders face a data dilemma: they must choose which data to analyse and which to ignore. That choice directly determines threat detection capabilities and impacts the security posture of the business.

Building trustworthy AI with Rob van der Veer [341]

Today we're speaking with Rob van der Veer, Chief AI Officer at Software Improvement Group, about how organizations can build trustworthy AI in an era of rapidly evolving technology and regulation — AI security, threat modeling, international standards, and the new challenges posed by agentic AI.

An AI Agent Breached Hugging Face. The Attack Playbook Was Older Than the Attacker

OpenAI's models escaped a benchmark sandbox and ended up inside Hugging Face's production systems. The attack made history; the openings it used were reusable credentials and flat internal access, and those are fixable now.

Your Vendors Are Rushing Into AI. Their Attack Surface Is Coming With Them

Every company you depend on is standing up AI right now. Chatbots, copilots, RAG pipelines, agent frameworks, model gateways. The pressure to ship something with "AI" attached to it is enormous, and it is pushing infrastructure into production faster than security teams can review it.

OpenAI's Agent Hacked Hugging Face. Another Left Notes for Its Successor.

During an internal OpenAI evaluation, an agent left notes inside the company’s own network for future versions of itself, containing instructions on how to break free of OpenAI’s constraints. Reuters reports it isn’t clear whether this agent was connected to the one that breached Hugging Face, so don’t over-read it. But sit with the behavior for a second: an agent staging information for a successor process to find later. If a human crew did that, we’d call it a dead drop.

Ep. 71 - OpenAI's Agent Hacked Hugging Face: The First Autonomous AI Breach

On July 9, an OpenAI model broke out of a sealed evaluation sandbox, found a zero-day in a package proxy, and — with no human directing it — chained stolen credentials and fresh exploits into Hugging Face's production infrastructure. Hugging Face detected it and called the FBI. OpenAI didn't know its own model had escaped for roughly 11 days. Host Tova Dvorin and offensive security expert Adrian Culley separate what's confirmed from what's hype.

Four incident-response decisions from the Hugging Face breach

Hugging Face was breached by a rogue OpenAI agent last week, and the intrusion continues to deliver insights and understanding. The Hugging Face team published a detailed timeline along with a 17,600-event trace streaming replay visualizing what happened, and it’s marvelously and intoxicatingly detailed. I recommend you read it if you have the time.

How to Control AI Assets Before They Become Shadow AI

A developer on your team just told Claude Code to connect to a new MCP server, the protocol coding agents use to reach organizational tools and data. Nobody in security reviewed it. Nobody in security even knows it happened. For two-thirds of enterprises, the primary obstacle to scaling agentic development isn’t budget or headcount — it’s security risk.

The Coding Agent Attack Surface Needs More Than Posture Checks

Coding agents have a misconfiguration problem. YOLO mode enabled to reduce approval friction, sandbox enforcement disabled, Model Context Protocol (MCP) servers installed from public marketplaces without security review. These are common configurations in enterprise developer environments, and remediating them is genuinely valuable work. AI Security Posture Management (AISPM) addresses exactly this class of risk, surfacing misconfigurations before they create the conditions for a successful attack.

AI Agent Authentication: An InfoSec Guide

AI agent authentication is the process of verifying that an autonomous agent is the identity it claims to be before it interacts with infrastructure, applications, APIs, or data. Because agents often act on behalf of users, services, or workflows, authentication must be paired with delegated context and downstream authorization controls that determine what the agent is allowed to do, which resource it can access, and how long that access should last.

The ECB's AI Cybersecurity Action Plan: Why Speed, Visibility, and Evidence Matter

AI is compressing the cybersecurity timeline faster than most institutions can adapt to it. Not only do security leaders have to deal with this new reality, they have to answer key questions to internal and external audiences about their efforts — including regulators.

No Hackers Required: 10 Shadow AI Leaks Hiding in Plain Sight

“The call is coming from inside the house.” It’s one of horror’s oldest lines, and you already know how the scene goes. The team scrambles, rechecks every firewall, audits every login, hunting for an intruder. Then the trace comes back, and there isn’t one because there is no malware or forced entry. Just an employee, at their own desk, with their own login, who pasted a confidential spreadsheet into an unapproved AI tool to save 10 minutes before a deadline.

CultureAI: In Partnership with Microsoft & NVDIA

CultureAI is a UK-founded AI security and governance platform that enables organisations to adopt AI safely, confidently, and at scale. Sensitive data is flowing into AI tools, SaaS applications with embedded AI, shadow AI, and personal accounts, creating compliance, privacy, and data loss risks that traditional security and governance tools were never built to understand.

MCP Prompt Injection: How Attackers Hijack AI Agent Workflows Through MCP Tool Calls

Prompt injection in a standard LLM interaction produces bad output. The model says something it shouldn’t. The damage stays contained to text. Prompt injection in an MCP environment is a different problem. Agents built on the Model Context Protocol don’t just generate responses. They call tools. They write files, query databases, send emails, execute code, invoke APIs.

AI Is Driving More Network Inspection. Can Your Security Keep Up?

Generative AI has quickly moved from experimentation to everyday business use. Employees use AI tools to create content, write code, analyze data, automate repetitive tasks, and interact with business applications in entirely new ways. At the same time, software vendors are embedding AI capabilities into the products organizations already use every day, often without requiring users to adopt separate tools.

The most helpful AI agent is the least secure one

The most pleasant agentic AI system is the least secure one. That's the trap Rob van der Veer, Chief AI Officer at Software Improvement Group, lays out clearly: the agent that never says "permission denied" is the agent everyone loves to use. It always works. So we open up all the privileges just to keep it that way. He says we should do the contrary.

AI Pentesting vs Traditional Pentesting: A Comparison, Cost, and Coverage Breakdown

If there’s one thing all of us can agree about modern security, it is that penetration testing is no longer a once-a-year activity. Modern attack surfaces do not stay still. New code ships faster, cloud infrastructure is constantly changing, and APIs are multiplying across product ecosystems. To keep up, engineering teams have moved security earlier in the development lifecycle through shift-left practices.

Move faster than AI-driven risk: Inside Mend.io's latest AI application security update

AI didn’t just change how fast you ship. It changed what your AI application security program has to protect. Two years ago, security teams protected code, open source, and containers. Today they also have to protect AI agents, MCP servers, models, prompts, and runtime interactions, configured or deployed faster than any team can manually review. The attack surface didn’t grow. It exploded.

AI Agents and MCP: Security Implications

The Model Context Protocol has quietly become the connective tissue of enterprise agentic AI. MCP standardizes how AI agents discover, request, and invoke tools, data sources, and external systems, replacing the custom integration code that used to sit between every agent and every backend. ‍ That standardization is what made agents commercially viable at scale. It is also what turned MCP into one of the largest and least-understood attack surfaces in enterprise AI.

Securing the Agentic Enterprise

We're living through the biggest shift in how work gets done in a generation. In every industry, every company is becoming an agentic enterprise, meaning a business where humans and autonomous AI work side by side. What makes an agentic enterprise successful is its workflows: how it combines intelligence, both human and machine, with its proprietary data.

MCP's Auth Hardening: What the Six New OAuth SEPs Fix, and What They Still Don't

In short, the MCP 2026-07-28 release candidate is getting attention for going stateless. The quieter story is a package of six SEPs that harden the protocol’s OAuth layer: issuer validation, credential binding, client type declaration, and cleanups around refresh tokens, scopes, and discovery. All six are worth shipping, and all six fix real failure modes. But they harden how a client authenticates to a server, and that was never the whole problem.

Defeat Frontier AI Attacks: Charlotte AI AgentWorks Meets Falcon for IT

Frontier AI has armed adversaries with unprecedented speed, finding and exploiting vulnerabilities faster than humans can respond. To keep pace, defenders need agentic AI operating on defense. In this demo, see how a Frontier AI Exploitation Defense Agent in Charlotte AI AgentWorks identifies and prioritizes critical risk, then hands off to Falcon for IT Risk-Based Patch Management for controlled remediation, all within the CrowdStrike Falcon platform.

Black Hat FOMO? Dojo AI Demo

On this episode of Masters of Data, we take you inside the Dojo AI demo we're bringing to the show floor at Black Hat. We walk through the SOC Analyst Agent, Mobot, and MCP back to back. SOC Analyst Agent triages every tier one alert down to the one that actually matters, and Mobot picks up from there, running the investigation in plain English to track down other phishing victims and lateral movement. We also show how MCP pulls that same insight into Claude or Slack. SOC leads tired of alert fatigue and analyst burnout will want the numbers here: 100% of tier one alerts triaged automatically, and 25 hours a week back per person.

2026 GenAI Code Security Report: AI Is Writing More of Your Code but Security Hasn't Caught Up

New GenAI code security research shows a stubborn truth: as AI is generating more of the code entering production, secure output is not improving at the same pace. The result is a GenAI code security challenge defined by scale, model choice, and the growing need for verification. AI coding has moved past experimentation. For many teams, it is now part of how software gets built every day. That’s the opportunity. It’s also the risk.

TITAN AI Demo Series: What a Mature TPRM Program Looks Like with TITAN MAX

Most Third-Party Risk Management (TPRM) programs can be compliance-driven and reactive. A mature program looks different. See what threat-informed TPRM with continuous monitoring looks like in SecurityScorecard's Demo Tuesday series. Vendor engagement drives real remediation. Your team spends time on risk decisions instead of manual busywork. TITAN MAX pairs the TITAN AI platform with SecurityScorecard's expert team to run these workflows on your behalf Continuous monitoring through a dedicated Vendor Risk Operations Center Faster questionnaire cycle times, without adding headcount.

Navigating the AI Revolution: The Real-World Impact of AI on IT Operations

Artificial intelligence is reshaping the IT landscape at an unprecedented speed. In this podcast, 11:11 Systems cuts through the noise to explore the real-world impact of AI on IT operations. Watch Josh Liebster, Director of AI at 11:11 Systems, Jack Bailey, Vice President of Channel and Sales Enablement at 11:11 Systems, and Laura Shafer, Vice President of Product Marketing at 11:11 Systems, as they discuss.

Torq SOC Brain: The AI SOC That Learns, Not Just Remembers

Back in June, I wrote a blog making the case that agentic triage alone isn’t an AI SOC. The way I see it, that’s like saying triage is the only responsibility of a SOC team. But as we know, the SOC’s responsibilities extend far beyond that, and these triage-only solutions don’t investigate threats, contain them, or close cases. That work is still left to the SOC team; the bottleneck is just shifting.

Sensitive Data Is More Than PII: The Blind Spot in Enterprise AI Security

A user asks an enterprise AI assistant a normal question: “Why did we lose the Acme deal?” The agent does what agents do. It retrieves CRM notes, pricing history, discount approvals, sales leadership comments, and a couple of internal strategy docs, then combines them into one clear answer: “Acme received a 28% discount exception, well above our standard enterprise pricing.

The EU AI Act: Compliance for Companies Serving the EU Market

The EU AI Act is a global business issue. Just like GDPR before it, it reaches beyond EU borders. If your organization does business in the EU, you are in scope. Full enforcement begins August 2, 2026, with fines of up to 35 million euros or 7% of global turnover for non-compliance.

Cyberhaven: Data Security for the Agentic Enterprise

AI changed work, Cyberhaven protects it. Cyberhaven exists to protect the way enterprises actually work today: with AI agents accessing, moving, and acting on data across every workflow. In this video, we share Cyberhaven's mission and our stance on data security for the agentic enterprise.Traditional data security, built for files at rest, wasn't built for AI agents acting at machine speed. Cyberhaven traces data through its full lifecycle and adapts protection as context changes, so security keeps pace with how work actually happens.

The Generator Can't Be the Validator: What OpenAI's Hugging Face Incident Proves About AI Security

Every so often, an industry gets a moment that quietly redraws where the line is — not because anything was said, but because something was proven. AI security had one of those moments last week, and it's worth being direct about that before getting into the details: this wasn't an incremental data point. It was the moment a risk that security and safety researchers had described in theory for years showed up, fully formed, in a disclosed incident report.

AIDR: Defining the Next Era of Cybersecurity

AI is changing how work gets done. It is also creating a new attack surface. Join CrowdStrike President Michael Sentonas for a first look at CrowdStrike’s vision for securing the agentic enterprise and defining AIDR, the emerging category for detecting, investigating, and responding to threats targeting and originating from AI systems, agents, and autonomous workflows. In this virtual event, you’ll learn.

Ready for AI? Why the Right Infrastructure Is the Secret to Success

Artificial intelligence is transforming the IT landscape, but many organizations still face a major infrastructure gap. In this podcast, 11:11 Systems explores why the right foundation is critical for building secure, reliable, and scalable AI strategies. Watch Justin Giardina, Chief Technology Officer at 11:11 Systems, and Laura Shafer, VP of Product Marketing at 11:11 Systems, as they discuss.

As AI Comes for Your Data, Is Your Recovery Ready? Cyber Resilience in the AI Era

AI is already writing code, connecting SaaS platforms, and interacting with sensitive business data. In this podcast, 11:11 Systems explores what organizations must do to prepare for the risks AI can introduce across data security, recovery, and cyber resilience. Watch Jim Jones, Sr. Product Infrastructure Architect at 11:11 Systems, and Laura Shafer, VP of Product Marketing at 11:11 Systems, as they discuss.

Demo Observe What Your AI Is Actually Doing

Security teams are receiving more alerts tied to AI workloads, but most miss the runtime context needed to understand what happened, why it happened, and whether it violated policy. AI visibility cannot stop at deployment and configuration. Join this live demo session to see how Wallarm AI Hypervisor helps teams understand what AI workloads are actually doing at runtime inside Kubernetes environments. The session focuses on giving security teams clearer operational context around AI behavior, outbound activity, sensitive data exposure, and user-driven actions across AI systems.

Why AI Security Has to Live at the Decision Point

For the past couple of years, most of the industry’s attention has gone toward agents that respond to a single prompt. They ask a question, get an answer, and move on. Enterprises are now deploying long-horizon agents; autonomous systems that execute extended, multi-step tasks across hours or days, without a human checking in on every step. These agents plan, reason, and improvise their way toward a goal, and that changes what security has to protect against.

CrowdStrike Joins the Open Secure AI Alliance to Advance AI Safety and Security

AI is changing the speed and scale of cyber defense, and the speed and scale of the adversary. As AI becomes embedded across government, critical infrastructure, and enterprise environments, defenders need the ability to inspect, test, adapt, and secure the systems they depend on.

Introducing AI Service Desk in Acronis Cyber Platform

AI is changing the economics of managed services, and productivity and intelligence are becoming critical competitive factors. MSPs need practical AI that helps technicians work more productively, make smarter decisions, move faster, reduce manual effort and resolve issues with better context. That is why Acronis is expanding Acronis Cyber Platform with new AI-native capabilities built for the next era of managed services.

What Is AI Pentesting and How Does It Works?

AI pentesting (AI penetration testing) is the use of reasoning-capable AI models to autonomously find, exploit, and validate security vulnerabilities in running applications — especially the context-dependent flaws, such as broken authorization and business-logic abuse, that traditional scanners cannot detect.

Lessons from the OpenAI and Hugging Face Incident: When Safety Filters Disarm the Defender

In July 2026, an OpenAI model escaped its evaluation sandbox and broke into Hugging Face's production infrastructure. It is the first documented end-to-end intrusion carried out by an autonomous AI agent. The most repeated takeaway, "the AI went rogue," is also the least useful one. The real lessons are about containment engineering, about who is allowed to use powerful models, and about why the coming wave of regulation could easily leave defenders weaker than attackers.

Fast Remediation Is the New Trust Model: JFrog and OpenAI Collaboration on Zero-Day Security Findings

Just last week, OpenAI and Hugging Face jointly disclosed what may be the first incident of its kind: during an internal evaluation of frontier cyber capabilities, OpenAI’s models, running deliberately without production safeguards in an isolated research environment, autonomously discovered and employed chained vulnerabilities to escape its sandbox, reach the open internet, and extract evaluation answers from Hugging Face’s infrastructure.

OpenAI's Models Go Rogue - The 443 Podcast - Episode 380

This week on the podcast, we cover the crazy saga that unfolded between the popular open-source AI platform Hugging Face and the frontier AI lab OpenAI. After that, we discuss a recent WordPress remote code execution vulnerability WP2Shell and the research process that Searchlight Cyber followed to uncover it sing artificial intelligence. Finally, we end with a quick analysis of Palo Alto Global Protec's authentication bypass vulnerability CVE-2026-0257.

How to Use AI to Create Better Video Content

Video content is the most effective way to reach people online. It grabs attention and helps you share your message quickly. For a long time, making high quality videos was difficult. You needed expensive cameras, powerful computers, and years of training. Now, artificial intelligence is making it possible for anyone to produce amazing clips. You can save time and money by using these new tools. This guide will show you how to start using AI to improve your creative process.

How Emerging AI Regulations Impact Organizational Risk Governance

Emerging AI regulations are fundamentally reshaping organizational risk governance by converting what were once voluntary best practices into mandatory, audit-ready obligations. The most significant impact is the move from informal AI risk assessments and optional frameworks to documented, repeatable governance programs that regulators can inspect, penalize, and enforce.

The AI governance confidence gap: Why trust in AI is running ahead of the capacity to govern it

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Agent Containment Lessons From OpenAI-Hugging Face Breach

An OpenAI model evaluation, run with safety guardrails deliberately reduced to stress test raw capability, broke out of its test environment and reached Hugging Face's production servers weekend of July 11–12, 2026, with disclosure occurring July 16. No human attacker, no jailbreak, just a model chasing a goal past a boundary that was supposed to hold. Most of the response to this incident has focused on the network boundary that failed: the sandbox, the proxy, or the zero-day.

How to Protect AI Agents from Prompt Injection in WordPress

Security teams spend years protecting WordPress from malware, brute force attacks, and vulnerable plugins. AI introduces a different challenge. An attacker no longer needs to compromise your site first. They can influence the AI that interacts with it. Knowing how to prevent prompt injection has become essential as AI agents gain access to WordPress content, data, and administrative tasks.

The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk

The recent developments surrounding vulnerabilities in major AI repositories like Hugging Face serve as a critical wake-up call for the cybersecurity community. As we accelerate toward an agentic future, the platforms we rely on for innovation are increasingly becoming the primary vectors for systemic risk.

Runtime Security for LLM Applications: How to Monitor Prompts, Context, Tools, and Outputs

Large language models are becoming the operational layer behind enterprise AI, powering intelligent assistants, automated workflows, and AI agents that interact with sensitive business systems. But as LLMs process confidential prompts, retrieve enterprise context, and execute connected actions, every runtime interaction introduces new security risks.

AI Data Pipeline Security: How to Protect Personal Data Before, During, and After Model Use

Artificial intelligence is reshaping how enterprises process information, but it is also redefining where sensitive data is exposed. Every prompt, retrieval request, API call, and AI-generated response creates another opportunity for personal or confidential information to move beyond its intended boundaries.

The Hugging Face Incident Proved the Real AI Risk Is in the Action Layer

Last week, an AI system crossed a line many still considered theoretical. During an internal cybersecurity evaluation, OpenAI tested a combination of models, including GPT-5.6 Sol and a more capable pre-release model, on ExploitGym, a benchmark that measures whether agents can turn software vulnerabilities into working exploits. The models were run with reduced cyber refusals and without the production classifiers normally used to prevent high-risk cyber activity.

AI-Generated Phishing Achieves a 54% Click Rate

For years, phishing has worked for one simple reason: it exploits the weakest link, the user. The defensive strategy has followed the same formula: better email filtering, more user awareness, and an extra layer of authentication. It wasn't perfect, but it was a workable balance.

Understanding Context Windows in AI-Powered Security Operations

Your security operations team now relies on AI agents to detect threats, triage alerts, and accelerate incident investigation. These agents analyze signals across your environment to identify suspicious behavior that humans might miss, and they respond faster than any manual process could. But they operate under a fundamental constraint that most security teams overlook: context window limitations that directly impact investigation quality and threat visibility.

Membership Inference Attacks in AI: How They Expose Training Data?

AI models are becoming essential to enterprise innovation, but the sensitive data that powers them is creating new security and privacy challenges. Even when raw training datasets remain inaccessible, attackers may still identify whether specific information was used to train a model through membership inference attacks.

Global Teams, Local Languages: Closing the Multilingual Privacy Gap

A privacy policy that only works in English is not a global privacy policy. It is an English-language policy that a global company happens to be using. That distinction matters more than most teams realize. Enterprises now centralize contracts, HR files, healthcare records, and support conversations from regional offices around the world into a shared AI platform, often assuming that whatever detection and masking logic works for their English-language content will work everywhere else. It does not.

AgentForger Showed Why Securing AI Agents Takes More Than a Patch

• Zenity secures ChatGPT Workspace Agents across their full lifecycle, from posture management at build time to detection and response at runtime. • AgentForger showed how a single link could forge an autonomous AI agent that inherits a real employee's identity and access, a risk legacy security tools can't see. • Zenity's AISPM catches the misconfigurations these attacks rely on, such as agents that auto-approve sensitive actions or connect to privileged systems.

Refused at the Worst Moment: Guardrail Asymmetry and the Trajectory Problem Behind the Hugging Face Breach

When Hugging Face's security team sat down to reconstruct what had torn through their production infrastructure in mid-July, they had more than 17,000 recorded attacker actions to sort through, spread across a swarm of short-lived sandboxes with decoy activity planted to slow them down. They did what any competent team would do in 2026 and reached for a frontier model to help triage the logs. However, the commercial APIs refused.

The Definitive Guide to Security Misconfiguration

The constant evolution of today's threat landscape has organizations counting on security controls to keep the bad actors out and safeguard their people, sensitive data, critical infrastructure, operations, and brand. However, even the most sophisticated security tools can present a risk when improperly configured. And unfortunately, even the best security teams can make mistakes.

5 Best Model Context Protocol (MCP) Server Plugins for WordPress (2026)

Managing a WordPress site no longer means logging in to the dashboard for every update or routine task. With the Model Context Protocol (MCP), AI assistants such as ChatGPT, Claude, and Cursor can securely interact with your WordPress site through natural language. They can retrieve content, update posts, manage WooCommerce stores, and perform other actions without custom integrations.

The 2026 AI SOC Roadmap: Where SOC Teams Are Headed and How to Get There

Every conversation our team has with security leaders begins the same way. Nobody is backing off on AI in the SOC. The direction of the lean is what’s shifting. Torq’s 2026 AI SOC Leadership Report surveyed more than 450 CISOs and SOC leaders. The data confirms what those conversations were already telling me. We’ve left the adoption phase. The market is now in the architecture phase and the implications for how teams plan, buy, and build are significant.

What to Look for in an AI Security Platform for Enterprise Deployment

The enterprise AI security market in 2026 is crowded and confusing. Vendors that built their products to use AI for cybersecurity operations now market themselves alongside vendors that built their products to secure AI systems and govern AI usage. These are fundamentally different product categories solving different problems, and conflating them leads to evaluation errors that leave organizations protected against external threats but exposed to the risks their own AI systems introduce. ‍

Understanding the Importance of MCP Security

AI agents are moving from experiments into production workflows, and the Model Context Protocol (MCP) is becoming the connective layer that enables those agents to access enterprise data, applications, APIs, repositories, and automation tools. That makes MCP powerful, but also security-critical. As organizations adopt agentic AI, they need to understand not only how MCP improves connectivity but also how it creates new visibility, governance, and attack-surface challenges.

The Case for the Channel in an AI-Driven Security Market

Originally published by ChannelPro. There is an ongoing debate in the cybersecurity industry about whether vendors should go directly to customers or instead become a part of a wider partnership network. The standard argument is that consolidation of platforms and AI-driven cost-of-service delivery makes the traditional model of a channel ecosystem redundant. However, this is largely incorrect, at least when it comes to the SMB and mid-market segments where most UK businesses sit.

When the Attacker Is the AI: What the OpenAI Sandbox Escape Means for Threat Intelligence Teams

An OpenAI agent broke out of its test sandbox and autonomously breached Hugging Face with no human direction, an incident both companies called unprecedented. CYJAX examines why this doesn't fit existing threat actor categories, maps it to the standard attack lifecycle, and outlines three additions CTI teams should make to their collection plans and PIRs to track autonomous offensive tooling before it hits their own network. On 16th July 2026, Hugging Face disclosed that it had been breached.

Is this the end of human-written code?

Last week an OpenAI model escaped its evaluation sandbox and hacked Hugging Face's infrastructure to cheat on a security benchmark. We recorded a special episode of AI Chat about it. Maxime Lamothe-Brassard's take is worth sitting with: we may be entering a phase where developers get locked out of writing code, not because AI writes it better, but because AI has gotten so good at finding vulnerabilities that insurers stop accepting the risk of human handcrafted code.

AI Chat: The Hugging Face / OpenAI breach - the attacker was the model [340]

AI Chat with Maxime Lamothe-Brassard and Chris Luft — a special episode. One story, pulled apart start to finish. In mid-July 2026, Hugging Face disclosed a breach of its production infrastructure carried out end-to-end by an autonomous AI agent. Five days later, OpenAI revealed the attacker was its own models — GPT-5.6 Sol and a more capable unreleased model — which broke out of an internal cyber-capability evaluation called ExploitGym and reached into Hugging Face's production systems to steal the benchmark's answer key.

How Anthropic's Claude Mythos Escaped a Secure Environment and What It Means for SMBs

SecuritySenses and BCA, an IT services company in Spokane, team together to help small and midsize businesses turn frontier-AI security news into controls they can actually implement. During an internal evaluation, Anthropic gave Claude Mythos Preview access to a restricted computer and instructed it to find a way out. The model discovered a weakness, bypassed its technical restrictions and contacted the researcher overseeing the test.

Attackers Exploit AI Hallucinations to Send Users to Phishing Sites

Threat actors are using a new technique called “phantom squatting” to trick AI tools into directing users to phishing sites, according to researchers at Palo Alto Networks’ Unit 42. Since AI models frequently hallucinate phony information, they sometimes point users to websites that don’t exist. Threat actors are now registering these AI-hallucinated domains and using them to host phishing sites.

What the OpenAI-Hugging Face Incident Really Tells Us

For years, the conversation about AI in cybersecurity has been mostly hypothetical. What happens when a model can plan and execute an attack on its own? How far away is that, really? This week, OpenAI gave us a concrete answer, and it arrived earlier than many expected. The incident is a genuine milestone, and it deserves the attention it is getting. But the most useful response is disciplined execution on the fundamentals, at a pace that matches the moment.

Protecting the Corporate Nervous System: Why Network Security Assurance Is Becoming a Security Imperative

Modern enterprises depend on a complex network of interconnected systems, applications, identities, and security controls. This infrastructure has become the nervous system of the business, enabling critical operations, supporting applications, and enforcing the boundaries that protect sensitive data. When these systems function correctly, they become invisible.

The Missing Layer in Network Security: Continuous Assurance

Some of the most serious network security weaknesses develop gradually through routine operational changes. Firewall rules are adjusted to support business needs, exceptions remain in place longer than planned, and controls are modified during troubleshooting. Over time, those decisions can push the live environment away from the security posture the organization believes it has.

Why Your Healthcare RAG Pipeline Is Leaking PHI (And How to Fix It)

Why Your Healthcare RAG Pipeline Is Leaking PHI Most healthcare organizations believe their AI assistant is secure once they restrict who can log in. Unfortunately, that's only part of the story. Modern healthcare AI applications rely on Retrieval-Augmented Generation (RAG), where patient records, physician notes, insurance claims, and medical documents are embedded into vector databases to power intelligent search.

You can't govern what you can't see: Detecting shadow AI on your network

AI adoption inside the enterprise didn't ask for permission. It arrived through browser tabs, code editors, and meeting transcription bots, quietly stitching itself into daily workflows long before security teams could write policy around it. The result is a familiar story with a new villain, a sprawling, unmanaged attack surface that lives in your network traffic but nowhere in your asset inventory. We call it shadow AI, and it's the blind spot you didn't plan for or budget for.

The New Face of AI Risk

Cybercrime used to have a ‘"tell." It was the digital equivalent of a villain stroking their cat - clunky grammar, misspelt links and suspicious attachments that screamed ‘phishing’. But the arrival of AI has changed everything. Typos have been replaced by perfect prose. Generic lures have evolved into highly personalized attacks that mimic your internal language and align with your project timelines.

Oracle Just Shipped 1,449 Security Patches in One Quarter. We Checked How Much of It Is Actually New.

Oracle's July 2026 Critical Patch Update (CPU) is nearly three times larger than any release in the company's history. To understand it, we parsed all 23 of Oracle's quarterly advisories going back to 2021, matched them against the official CVE record, and compared Oracle against eight other major vendors. We set out to answer three questions: How much of this is genuinely new? Does it really reflect AI-accelerated patching? And how unusual is it?

Why Continuous Attestation Is Critical in the AI Coding Era

In the age of AI coding, annual audits and snapshots are no longer enough. Discover **Continuous Attestation** — the practice of producing ongoing, verifiable evidence that your applications and pipelines are always running in a trusted, policy-conformant state. In this video, Anthony Barkley, Chief Strategy Officer at Veracode, explains why independence in attestation is critical for earning trust from regulators, customers, and boards — especially when AI agents are writing code.

Ep. 65 - "Months, Not Years": The Five Eyes AI Warning and Your Security Program

On June 22, 2026, the heads of all six Five Eyes cyber agencies — GCHQ, CISA, the NSA, ASD, the Canadian Centre, and New Zealand's GCSB — signed a rare joint statement: AI has rewritten the cyber risk timeline, and it's months, not years. Host Tova Dvorin and offensive security expert Adrian Culley unpack why AI is collapsing the window between vulnerability and exploit, why "having controls" isn't the same as proven controls, and why legacy systems are now strategic liabilities for the board, not the IT team. A clear-eyed look at validation, assumed breach, and what CISOs should do Monday morning.

Ep. 68 - Why OWASP's AIVSS Scores Agentic AI at Maximum Risk

OWASP just shipped AIVSS — an entirely new vulnerability scoring methodology built for autonomous AI agents, where a compromised orchestrator can score a perfect 10. Host Tova Dvorin and Adrian break down the "amplification principle": why a 2.1 CVSS finding becomes a 7.1 in the wrong agent, how persistent memory and broad tool access expand every blast radius, and what EchoLeak-style attacks already mean for real deployments. Plus where adversarial exposure validation and SafeBreach's agentic AI coverage fit in.

Trust Nothing: Tips to Secure AI Tools and Agents

So, you have some AI tools or are thinking about deploying them and want to know a bit about securing them. You are not alone, but there are significant challenges due to the rapidly growing capabilities of AI, and the issues around new types of vulnerabilities we may not be used to thinking of. This is a very challenging area to attempt to secure, but I hope to point you in the right direction and set you up with some resources.

When AI Agents Run Healthcare Workflows, Business Logic Becomes the New Attack Surface

Healthcare has moved well past pilot projects. AI agents now triage support tickets, draft clinical documentation, manage patient engagement, and coordinate care across systems that were never designed to talk to autonomous software. Autonomous systems can now analyze data, make decisions, trigger actions, and coordinate across clinical systems with minimal human oversight.

Identity Security for AI

What's scarier than an engineer with prod access? An agent with the same access that never sleeps, never asks, and runs a thousand sessions while you're at lunch. Last year we solved the problem of visibility in the Identity Chain, the concept is that identities are fragmented and it’s hard to get a view from Identity Providers to Infrastructure. Within a year, two things have changed. First, teams are using LLMs & Tools to perform actions on their behalf - fully delegating work to AI Agents.

Why Simple Masking Kills AI Accuracy

Here is a document going into an AI assistant: A simple masking system produces: The information is protected, but the document has become almost impossible for the AI to reason about. It no longer knows who introduced whom, who approved the proposal, or whether the same person appears multiple times. By removing identity, we destroyed the relationships that give the document meaning.

AI hacking makes password spraying faster. Here's how to close the gap

AI hacking tools are compressing the time between finding a target and logging in as them. Password spraying, already responsible for the vast majority of identity attacks, is the technique benefiting most. Attackers use AI hacking methods to optimize timing, rotate infrastructure, and personalize lures at a scale no human operator could match manually.

80% of New Code is AI-Generated - But 40-50% Has Vulnerabilities Find out Why

Is your organization generating up to 80% of its new code with AI? You might be proud of the speed — but are you ready for the security risks? In this video, we reveal the hidden danger: multiple studies show that **40-50% of AI-generated code changes contain vulnerabilities**. Discover why AI coding is accelerating development faster than ever — and why traditional security approaches are no longer enough.

TITAN AI Demo Series: Security Events in TITAN Secure - From Fragmented Threat Data to One Live Feed

Threat data lives everywhere: news outlets, hacker forums, breach reports. Correlating all of it to your vendor ecosystem by hand costs precious response time. SecurityScorecard's new Security Events feature inside TITAN Secure automates that mapping. It turns fragmented signals into a live feed showing exactly who's affected, what happened, and when. Event tags separate confirmed compromises from unverified hacker chatter Status badges show whether an event is active or still under investigation Impact summaries surface how many vendors are confirmed or potentially affected.

Best 6 AI security posture management platforms (AI-SPM) in 2026

AI Security Posture Management (AI-SPM) platforms are specialized tools that discover, monitor, and secure AI models, pipelines, and data, mitigating risks like data leakage and model poisoning. They offer continuous visibility, manage misconfigurations, and enforce security policies across cloud services like Azure OpenAI and Bedrock.

How to Discover, Monitor, and Manage Shadow AI Across the Enterprise

Shadow AI is the fastest-growing unmanaged risk surface in most organizations. Employees are adopting AI tools through browser extensions, free-tier SaaS accounts, personal logins, and embedded platform features without involving IT, security, or procurement. The result is an expanding footprint of AI systems that process corporate data, generate business outputs, and create compliance exposure while remaining invisible to the governance program responsible for managing those risks. ‍

Bringing Claude Enterprise Activity into Cato AI Security

Claude is now a part of many employees’ everyday work. But even as a sanctioned application, it creates a visibility problem for security teams. Sensitive data can move into prompts, files, projects, and conversations, and teams need a practical way to see what happened and whether it violates policy.

Cato CTRL Insights: How One Threat Actor Turned Frontier AI Into an Offensive Platform

A Russian-speaking threat actor known as “Trim” has spent the better part of 2026 systematically dismantling the guardrails on publicly available frontier AI models and rebuilding them as offensive tools. What started in March as a knowledge-sharing post on a Russian cybercrime forum detailing how to break Claude Opus into writing malware, had evolved by June into a fully productized, commercially marketed AI-powered penetration testing platform.

Top 9 AI Penetration Testing Companies for AI/ML/LLMs/MCPs

From inchoate brainstorming sessions in the halls of Dartmouth College to a panoply of funding springs and winters, AI has made its way into the tech stack of not just almost every enterprise but also every household. This, though music to the ears of an AI researcher, rewards a security professional with sweat beads. Even a single AI/ML/LLM or an MCP feature in your product evolves your attack surface, necessitating scouting for the right AI/ML/LLM/MCP penetration testing companies.

How to Build Reliable Data Integration Pipelines That Actually Support AI and ML at Scale

AI has become surprisingly good at spotting patterns, writing code, summarizing documents, and answering complex questions. Yet many AI projects still hit the same wall long before the model becomes the problem. The real challenge often lies in something far less exciting: getting the right data to the right place, in the right format, at the right time.

AI Threat Intelligence vs. Traditional Threat Intelligence: A Practical Guide for CISOs

Most CTI programs aren’t failing because analysts lack skill. They’re failing because signal volumes have outpaced what any manual workflow can process. Thousands of newly registered domains, phishing kit variants, and brand impersonation attempts surface daily. Human teams can’t triage all of it. Threat intelligence automation addresses the throughput problem by automating collection, enrichment and prioritization so analysts spend time on decisions, not data wrangling.

What the Black Hat NOC taught me about MCP & agentic SOCs (Chapter 3 of 4)

The first time an MCP (Model Context Protocol) server felt real to me, it wasn't because of a clean demo. It was because of the noise. TL;DR: The harness matters more than the protocol, and the evidence matters more than both. MCP earns its keep when it shortens the path from a good security question to trustworthy evidence, and almost everything interesting about making that work happens in the harness wrapped around the model. In this series, I will cover how to build an MCP for an AI SOC.

Who's Winning the AI Security Race: Attackers or Defenders?

Defenders have gained early access to powerful AI tools, creating an opportunity to improve security outcomes and strengthen cyber resilience. But as these capabilities become more widely available, that advantage may not last. Rik Ferguson, VP of Security Intelligence at Forescout, shares his perspective on what security teams should be doing now to prepare.

Where Security Breaks First in the AI Era

Most security programs were built for a slower clock. But as AI-assisted and autonomous attackers accelerate the pace of attacks, manual approval gates can become the point where defenders fall behind. This short video explores why security teams need to reexamine the processes, decision points, and response workflows that may slow them down when speed matters most.

The Security Risks of AI Agents in the Enterprise

AI agents introduce a category of security risk that traditional application security, identity management, and even standard AI security programs were not designed to handle. Unlike a generative model that only produces text, an agent takes autonomous action against real systems, chains API calls together to accomplish goals, and often holds permissions broad enough to touch data across multiple business systems.

Why WatchGuard Is Investing Across the Frontier AI Ecosystem

Artificial intelligence is quickly becoming one of the most transformative technologies in cybersecurity. Unfortunately, it's not transforming the industry exclusively for defenders. Attackers are already experimenting with AI to accelerate reconnaissance, analyze software for vulnerabilities, develop fully-functional exploits, and automate nearly all parts of the attack lifecycle.

OpenAI's Sol, Terra, Luna Explained: Which One Should You Use?

-OpenAI has completely overhauled its model naming system with the release of GPT-5.6, introducing three distinct tiers: Sol, Terra, and Luna. In this video, we put OpenAI's new flagship model, GPT-5.6 Sol, to the ultimate test. Using the Codex extension in VS Code, we throw our classic "Build me a secure notes app or I get fired" prompt at Sol. Watch as we break down the pricing and reasoning differences of the new tiers, run a full security audit using Snyk, and see if Sol's $5/$30 price tag is truly production-ready or if a small local CSRF bug gets us "fired" first.

How to Securely Roll Out Enterprise AI in 90 Days #shorts #aisecurity

Planning an enterprise AI rollout in 90 days? Establishing a robust AI Gateway Architecture is the critical first step to ensuring data compliance, enforcement, and security. Letting application traffic run straight to LLMs exposes your organization to severe security and compliance liabilities.

Beyond the Model: Harnessing Frontier AI for Stronger Cyber Defense

Frontier AI is fundamentally changing the pace of cybersecurity. For defenders and adversaries alike, it compresses the time required to discover vulnerabilities, assess exploitability, and act. AI models can reason across entire codebases, identify complex vulnerability chains, and generate exploit paths at a speed and scale that was previously impossible. That's a breakthrough for defenders, but it's also a preview of how quickly adversaries will evolve.

Build vs. Buy AI App Development in 2026 (When Everybody Is an AI Expert)

AI expertise is cheap to claim these days. A short course, a couple of weekend projects, and a working prototype are usually enough for someone to call themselves a specialist. Getting an AI system to survive real production traffic is another matter entirely, and a lot of companies are learning that the hard way in 2026.

How I'd Plug the MiniMax M3 API Into a Coding Agent Without Rebuilding the Stack

Every time a promising new model shows up, I run through the same mental math before getting excited: how much of my existing agent setup survives the swap, and how much do I have to tear out and rebuild just to try it. Most of the time the answer is "more than I'd like," which is exactly why I ignore half the models that cross my feed. MiniMax M3 is one of the rare ones where the answer turned out to be "almost none of it," and it's worth walking through why, because the reasoning applies beyond just this one model.

The Agentic Attack Surface Is Growing Faster Than Your API Inventory. Here's How to Catch Up

Ask any security leader how many APIs their organization runs, and you’ll usually get a confident number. Ask them how many of those APIs are actually being called by an AI agent, a copilot, or an automated workflow right now, and the confidence tends to disappear. That gap is the problem. APIs have always outpaced the inventories built to track them; new services ship every sprint, integrations get added without a ticket, and old endpoints get deprecated without ever being switched off.

How we brought agentic workflows to Cloud SIEM with the Datadog MCP Server

Security engineers using Cloud SIEM spend their day-to-day investigating signals, tuning detection rules, managing suppressions, running historical jobs across interconnected workflows, and more. Agents are becoming a practical way to navigate that complexity, and we built a set of security tools for the Datadog MCP Server to support them. Cloud SIEM is only one part of a broader cloud security ecosystem, so the Security MCP toolset has to grow across many teams and products.

Agent verification might just be KYC/KYB

Every time a card gets issued or a payment moves, something has to decide, in milliseconds, whether it's legitimate. That's the problem Robin Gandhi, chief product officer at Lithic, solves every day. Lithic builds the programmable infrastructure behind modern card issuing and money movement for developers, digital banks, and financial institutions.

AI Agent Identity: Securing Desktop, SaaS, and Enterprise AI Agents

Your enterprise probably has a few thousand employees with managed identities. HR provisioned them, IT governs them, and your IAM platform watches them. Now count the AI agents running across your org. The Claude Code and codex instance that sit inside every dev's IDE. The Salesforce Einstein bot with access to every open deal. The Zapier AI that reads your CRM, writes to your Slack, and forwards summaries to email. You can't count, secure, or govern them with traditional IAM, can you?

Protecting PHI Beyond Names and ID Numbers

A few years ago, an Australian government health agency released what it believed was a fully de-identified dataset covering 10% of the national population. Names, addresses, and other obvious identifiers had been stripped out. Researchers showed individuals could be re-identified using nothing more than rare medical procedure codes and treatment dates cross-referenced with publicly available information. No names were needed.

Is the SaaS Market Is About to Collapse?

AI coding is disrupting the SaaS market. GRC tools, CRM products and enterprise dashboards that cost hundreds of thousands can now be built internally in weeks using Codex and other AI models. SaaS companies know this is happening, which is why they're locking customers into three to five year contracts. But there's a serious security risk nobody is talking about. If you're vibe coding internal tools and applications, you need continuous security testing to catch vulnerabilities before attackers do. The faster you develop, the faster you need to detect breaches.

Benchmarking 13 AI models on rediscovering known CVEs

TL;DR Every frontier model launch now comes with the same cybersecurity claim: it finds vulnerabilities. But does it work on a real bug in a real repository, or just on a curated example? Of the dozen models you could pick, which is worth trusting with code review? And since the strongest models cost ten times or more per run than the cheapest, what does that extra spend actually buy you in bugs found?

A Guide to Firewall Management: How to Set Up Proper Firewall Rules

Firewalls remain one of the most foundational controls in any security program. Nearly every organization has at least one, and in many cases, hundreds. Despite widespread deployment, firewalls are frequently a source of unintended exposure rather than protection. The reason is almost always in how firewall rules are maintained over time, not the technology itself.

EU AI Act Readiness: 10 Controls Every Organization Should Implement in 2026

This is for compliance and security leaders who already know the EU AI Act applies to them and need a concrete control set for where the law actually stands today — not a summary written before the rules changed. Awareness is done; 2026 is the year of implementation, and the rules just moved. On 29 June 2026 the Council of the EU gave its final green light to the Digital Omnibus on AI — the package that resets several of the dates compliance teams have been building toward.

Find and Fix Risky Firewall Rules | Reach Security Demo

A firewall rule set to allow any source to any destination can stay live for months. It cancels out the rules beneath it and lets traffic pass unchecked. That kind of drift sets off no alarm. It builds up between quarterly reviews, while small teams govern 50 or more firewalls and hundreds of rule changes a week. Reach Network Security Assurance finds these controls, shows how long each has been open, ties the finding to real exposure, and guides the fix.

AI-Powered Cybersecurity at Machine Speed | Arctic Wolf

AI is accelerating cyberattacks, pushing security teams to their breaking point. Arctic Wolf helps organizations get ahead and stay there with the Aurora Superintelligence Platform, combining AI that is built in, not bolted on, with human validation and 24x7 security operations. See how Arctic Wolf helps protect more than 10,000 customers.

Building Trust in AI for Cybersecurity | Arctic Wolf

Cybersecurity has reached a turning point. As defenders embrace AI, the question is not simply whether it is powerful, but whether it can be trusted to deliver real value. The Arctic Wolf Aurora Superintelligence Platform brings together trusted AI, real-world data, and human expertise to help transform security operations with reliability, governance, and results.

Episode 19 - The Cap on Inference: Proving How Network Data Quality Drives AI Security ROI

In this episode, host Richard Bejtlich sits down with Corelight Co-founder and Chief Strategy Officer Greg Bell to unpack groundbreaking research that quantifies exactly how data quality impacts AI-driven security automation. Moving past qualitative industry hype, Greg shares hard evidence from an empirical experiment pitting leading AI agents against real-world Capture the Flag (CTF) challenges and incident response report writing. The findings reveal a dramatic truth: basic firewall and flow logs place a hard cap on inference, throttling an LLM's capacity for deep insight.

AI in risk management: Practical applications and considerations

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

RK3588 Chip Gains Traction in Security and Edge AI Hardware

Security camera manufacturers and edge AI developers are increasingly building around a single processor: the Rockchip RK3588, a system-on-chip designed to run AI workloads locally rather than depending on cloud infrastructure. As detailed by KiwiPi, the chip's built-in Neural Processing Unit is the main reason it has become a preferred choice for devices that need fast, on-device recognition and analysis.

7 OCR Solutions with Intelligent Document Processing (IDP) and Agentic AI Systems - 2026 Review

The seven OCR-plus-IDP solutions worth evaluating in 2026 are ABBYY Vantage, Unstract, Hyperscience, Rossum, Nanonets, Google Document AI, and Docsumo. Each pairs optical character recognition with intelligent document processing, increasingly with agentic AI that reasons over document context, and each carries a different security, compliance, and deployment profile for teams handling sensitive data.

Your Visual Identity Matters - Can AI Get It Right?

First impressions in professional settings have always mattered, but the digital layer has changed the stakes entirely. Your profile picture is now the first handshake, the initial eye contact, the silent introduction that happens before a single word is exchanged. And yet, for most professionals, this critical piece of visual identity remains an afterthought-a cropped wedding photo, a five-year-old conference badge image, or a smartphone selfie taken in less-than-ideal lighting.

Pulse Security Debuts Operational Management Platform Built for Security Leaders

Backed by Foundation Capital and Zetta Venture Partners with $8M in seed funding, Pulse Security delivers the program intelligence and agentic infrastructure that security leaders have been missing. Pulse Security AI launched from stealth today to solve a problem the security industry has spent decades ignoring: giving the leader who runs the program the same operational foundation every other business function takes for granted.

Sophos Launches Sophos Fusion, the Industry's First and Most Complete AI-Native Cybersecurity Defense System

Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defense system that prevents, detects, investigates, and responds at AI speed.

Report: Social Engineering Remains a Central Part of AI-assisted Attacks

Threat actors continue to rely on social engineering as AI is incorporated into their attacks, according to ESET’s Threat Report for the first half of 2026. ESET’s Director of Threat Prevention Labs, Jiří Kropáč, stated, “Rather than relying on entirely new methods and tools, attackers are quickly adapting established techniques to new platforms, technologies, and user behaviors.

The Permission Boundary Myth: Why Authorized Doesn't Mean Appropriate for Coding Agents

Coding agent security has a framing problem. Most security conversations around these tools center on the wrong question. 'Did the agent have permission to do that?' is a reasonable place to start, but in the context of autonomous AI systems, it's not where the risk actually lives. In Zenity Labs' research into the coding agent threat model, the pattern that keeps surfacing isn't that agents are doing things they aren't allowed to do.

AI Man-in-the-Middle: The Trust Problem Hiding in Plain Sight

I remember the days when merely saying “AI” was enough to earn glares for bringing up such a taboo subject, almost equivalent to saying “Voldemort.” Now, AI is at the center of many people’s daily lives and certainly at the center of business operations. I find myself using AI for everyday tasks. Unfortunately for security teams, the bad guys are using it too.

What Is Dark AI? How Scammers Are Using Artificial Intelligence Against You

AI isn't just being used for good. Dark AI — artificial intelligence weaponized for malicious purposes — is behind a new wave of scams, phishing attacks, deepfakes, and cybercrimes that are harder than ever to detect. Scammers are now using AI to clone voices, fake video calls, impersonate people you trust, and generate convincing phishing messages at massive scale — all powered by dark GPTs built without safety restrictions.

The background agent that outgrew me

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Agentic AI vs. Generative AI: What Enterprises Need to Know

Agentic AI and generative AI both build on large language models, but they behave in fundamentally different ways once deployed. Generative AI produces content in response to a specific prompt and then stops. Agentic AI receives a goal, then autonomously plans, decides, and executes multi-step workflows to accomplish that goal, often across systems and tools the enterprise runs. That difference is the difference between an AI that helps a human do work faster and an AI that does the work itself. ‍

The Agentic Attacker: One Objective, One Prompt, Forty Minutes, Domain Admin - Game Over

In a controlled enterprise lab, we tested how far an agentic attack stack could go by harnessing a frontier model with an agent platform, MCP-enabled tooling, operational context, and enough autonomy to execute a complete attack path.

AI Traffic Security: The Hidden Risk of Unstructured Data Leakage #aisecurity

Understanding the nuances of AI Traffic Security is critical because traditional firewalls and API gateways are fundamentally ill-equipped to inspect unstructured natural language. In the past, enterprise data remained safely within the corporate perimeter. Today, employees are pasting highly sensitive information directly into external models, creating a massive vulnerability where the risk lies in the meaning and content, rather than syntax or connections.

AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity

Every foundational shift in computing has created a new security category. The internet created network security, the rise of workstations created the need for endpoint detection and response (EDR), and cloud computing created the need for cloud security. Each technology transition has moved faster than the one before it. None has moved faster than AI.

AI is moving fast. Exploits are right behind.

Chris Luft and Matt Bromiley cover four stories in this week's Intel Chat that all point to the same trend: attackers are keeping pace with how fast AI tools are being built and deployed. They break down a chatbot pipeline vulnerability in Google Dialogflow CX, a phishing technique that hides malicious content until it renders in the browser, four newly exploited vulnerabilities added to CISA's KEV catalog, and an attack that exploits AI coding assistants' tendency to hallucinate fake repository names.

Who Gets to Control AI? The Governance Crisis Nobody's Solving

The EU just pushed back its AI Act enforcement by 16 months. The US is deregulating. China is governing through infrastructure. And the UK is doing nothing and hoping for the best. Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this episode, I'm joined by Richard Cassidy, Field CISO at Rubrik, and Jonathan Care, Head of the AI Practice at KuppingerCole.

Understanding the Importance of Advanced Medical Imaging

When pain, swelling, dizziness, or strange symptoms refuse to explain themselves, "wait and see" can feel pretty unsettling. You want answers. Your doctor does too. That is where advanced medical imaging becomes so valuable. It gives clinicians a clearer look inside the body when an exam, blood test, or symptom checklist is not enough.

France's ANSSI Sets New Post-Quantum Cryptography Milestones: What It Means for Your Security Strategy

Quantum computers capable of breaking today’s encryption may still be years away, but France’s National Cybersecurity Agency (ANSSI) believes organisations shouldn’t wait to prepare. At the France Quantum Conference on June 16, 2026, ANSSI announced new milestones for the adoption of Post-Quantum Cryptography (PQC). ANSSI recommends that organisations prioritise purchasing quantum-safe security products by 2030. The most important message, however, isn’t about 2030.

Finding Just Got Free: That's Why Fixing Is the Only Game That Matters

When Anthropic revealed Claude Mythos and Project Glasswing, the industry did what the industry always does with a frontier-AI story: it reached for the alarm. The headlines, Reddit threads, and back-channel conversations all focused on the same things: All of that is real, and none of it is the part that should keep a security leader up at night. Here is the part that should.

Demo Discover Enterprise AI Workloads Running on AWS

AI workloads are appearing across AWS environments faster than most teams can inventory them. New APIs, EKS clusters, model integrations, and AI services are showing up across accounts and regions without a clear ownership trail or centralized visibility. By the time security catches up, the environment has already changed again.

Could your own AI agents run a ransomware attack?

Ransomware is evolving well beyond locking systems, and agentic AI is introducing a category of security risk most organizations are not yet equipped to handle. On The Cybersecurity Defenders Podcast, Behnaz Karimi, Senior Cybersecurity Analyst at Accenture and independent ransomware researcher, walks through what that shift actually looks like. The full conversation includes.

AI Chat: Grok CLI data exfiltration, AI vs. patching, distillation wars & shadow AI [339]

AI Chat with Maxime Lamothe-Brassard and Chris Luft. A new segment on the podcast: AI news in cybersecurity that is less than 24 hours old, discussed while it is still hot. Joining Chris for these conversations is LimaCharlie founder and CEO Maxime Lamothe-Brassard. In this episode: Stories covered: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.

How to Prevent AI Agents from Exfiltrating Sensitive Data

An AI agent on a developer's laptop has read access to a code repository, a set of internal documents, and an external model. Nobody approved that specific combination, and nobody is watching what the agent does with it session to session. The agent is not malicious, however, it is doing exactly what it was configured to do. But, that configuration is the exposure, and most security teams do not have a way to see it, let alone stop it before sensitive data leaves the environment.

The tokenmaxxing bill is due: Take control of AI spend with SaaS Manager

A nasty shock is hitting finance leaders across every industry right now: AI token bills that run ten, twenty, even a hundred times over what they forecasted, blowing holes straight through quarterly budgets. These leaders are all asking the same questions: How could this happen if they didn't approve it? Why didn't any of their systems alert them to the spike? And most importantly, what can they do now?

The best AI lesson this summer came from watching our interns challenge AI

Unknown block type "undefined", specify a component for it in the `components.types` option Every conversation about AI and early-career employees seems to start in the same place: will it weaken foundational skills by doing too much of the work? That's a reasonable concern. It's also not the question that ended up mattering most this summer.

Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo

Scammers can use AI tools to find your location in photos you post to social media, according to researchers at McAfee. This information can then be used in targeted social engineering attacks. The researchers found that free AI models can correctly identify a photo’s location with around 90% accuracy.

DLP for AI: Protecting Sensitive Data in the Age of AI

Employees paste code into ChatGPT. They drop customer lists into Gemini for a quick summary. They upload a contract to an AI note-taker before a meeting starts. None of it feels risky in the moment. But all of it can walk sensitive data straight out of your organization. AI DLP exists to close that gap.

The EU AI Act Is Here. Is Your AI Environment Ready?

AI has moved from experimentation to operational reality. Last year saw a 50% rise in access to AI for employees, with 88% of organizations using AI in at least one business function. Competitive pressure is accelerating AI adoption. While this creates opportunity, it also creates a new level of operational risk.

The MemcycoFM Show: Ep 27 - What Is Agentic Threat Intelligence?

In the recently published blog from Memcyco titled "What Is Agentic Threat Intelligence?", we discussed agentic threat intelligence as an emerging CTI model. Bounded agents support repetitive investigation work, such as collection, enrichment, prioritization, and evidence packaging, while analysts retain control over takedown and escalation decisions. Vendor briefings are full of “agentic AI” right now. Most of them describe the same thing: faster dashboards and smarter alerts. That is not agentic threat intelligence.

TITAN AI Demo Series: How MAX Managed Questionnaires Eliminates Your Assessment Backlog

SecurityScorecard's MAX Managed Questionnaires handles your entire vendor questionnaire process end-to-end, design, outreach, response collection, and expert analysis — with no additional headcount required. In this installment of SecurityScorecard's Demo Tuesday series, see MAX Managed Questionnaires in action and what your security program looks like when your team is free to focus on risk strategy instead of assessment admin.

A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed

On July 3, 2026, the Albanian communications authority (AKEP), the operator of the.AL country-code top-level domain (TLD) of Albania, attempted a DNSSEC key rollover. Something went wrong, resulting in DNSSEC validation failures. Any validating DNS resolver receiving these signatures was required by the DNSSEC specification to reject them and return errors to clients. That includes 1.1.1.1, the public DNS resolver operated by Cloudflare.

MCP Data Exfiltration: How AI Agents Leak Sensitive Data Through MCP Tool Calls

Model Context Protocol (MCP) is what turns an AI assistant into an AI agent. It’s the standardized bridge that lets models call real tools – read files, query databases, send messages, pull emails. That capability is the whole point. It’s also what makes MCP environments a target. Most deployments were scoped for what the agent needed to do. Not for what happens when that access is turned against the organization.

The Top 5 Questions Security Leaders Are Asking About Coding Agents

The discussion during our recent webinar made one thing clear. Security teams aren't asking whether coding agents will become part of the enterprise. They're asking how to adopt them safely. The audience questions focused on practical concerns that many organizations are facing today, from autonomous execution to supply chain risk and governance. Here are the five questions that generated the most discussion.

Agentic AI Governance Requires a New Enforcement Model

AI has swiftly shifted from a browser-based chat interface to an autonomous actor operating within enterprise environments. Agents run locally on endpoints, inherit employee permissions, access sensitive data in bulk, and execute multi-step workflows with no human approving each step. That shift fundamentally changes the enforcement surface. The governance programs most organizations have built were designed for a different model: one user, one prompt, one decision.

Data leakage risks with DBHub MCP servers

Organizations keep their databases behind firewalls for a reason: the data inside is the data they can least afford to lose. A new class of AI middleware–Model Context Protocol (MCP) servers–exists specifically to reach into those protected systems on an AI model's behalf. One of them, DBHub, connects directly to SQL databases.

Coding Agents Are Moving Faster Than Security. Here's What CISOs Need to Know.

Coding agents have become one of the fastest-adopted AI technologies in the enterprise. They help developers write code, debug applications, automate repetitive tasks, and ship software faster than ever before. They also introduce a security challenge unlike anything most organizations have faced. Unlike traditional AI assistants that generate content, coding agents take action.

AI Control Platform vs. AI Firewall vs. AI Gateway: Clearing Up The Terminology

Editor's note: This article was originally published by Tim Erlin on LinkedIn. It has been republished here with the author's permission. It seems like every security vendor now sells "AI security." The WAF companies, the API gateway companies, the cloud platforms, the proxy startups: all of them have an AI story, and most of them have attached one of three labels to it. AI gateway. AI firewall. AI control platform. The terms often get used as if they're interchangeable, but they are not.

What Is Firewall Configuration and Why Is It So Important?

Firewall configuration is the set of rules, policies, and settings that define how a firewall behaves. Without configuration, a firewall is hardware and software waiting for instructions. With configuration, it becomes a control that determines what traffic is permitted, what is blocked, and what gets inspected before a decision is made. Get the configuration right, and the firewall does its job. Let it drift, and you have the appearance of protection without the substance of it. This is not an edge case.

AI Governance on AWS: Discover, Observe, and Control AI in Production

AI adoption within AWS environments is accelerating faster than most security and governance programs. AI agents, APIs, MCP servers, and model integrations are entering production across cloud environments, often without centralized visibility or runtime controls. In this webinar, you’ll see how teams can discover AI workloads across AWS accounts, understand what AI systems are actually doing at runtime, enforce policy in real time, and generate continuous governance evidence without slowing engineering teams down. The session focuses on practical operational capabilities for AI systems already running in production.

Why You Must Still Review AI Code

In this video, we break down why skipping code reviews is a massive mistake that will ultimately slow you down, leave you vulnerable, and compromise your system's accountability. We dive into three concrete reasons why reviewing AI-generated pull requests actually makes you a faster, safer developer, including a real-world story of a production bug caught in under 90 seconds. Resources Chapters.

How Organizations Can Assess and Manage AI-Related Risks

Organizations assess and manage AI-related risks by establishing a cross-functional governance framework, mapping risks based on impact and financial likelihood, and instituting continuous monitoring that connects AI asset discovery to risk quantification, compliance, and enforcement. The most effective programs treat AI risk management not as a one-time assessment but as a continuous, data-driven discipline that evolves alongside the AI systems it governs. ‍

7 AI Governance Tools for Shadow AI Detection

AI adoption has accelerated faster than most organizations’ ability to manage it. Security and compliance teams are now responsible for overseeing machine learning models, large language models (LLMs), agentic AI systems, and shadow AI — often with frameworks and processes that weren’t built for any of it. The gap between deploying AI and governing it responsibly is where risk lives. AI governance tools exist to close that gap.

How to maintain code quality standards with AI code and vibe coding

It’s amazing how non-developers have recently been empowered to create their own apps that can even generate revenue. We’ve recently seen progress across the AI development field, from AI being successful in “greenfield code” (apps built from scratch) towards “brownfield code” (larger scale existing applications).

JADEPUFFER: How an Agentic Ransomware Attack Unfolded

In early July 2026, researchers at Sysdig published an analysis of what they assess to be the first documented case of agentic ransomware. The threat actor, which Sysdig calls JADEPUFFER, launched an extortion attack driven end to end by a large language model (LLM) rather than a conventional human-operated toolkit.

Secure Enterprise AI Innovation with Cato AI Security

Enterprise AI is spreading fast across employees, applications, and agents. Security teams need a way to enable AI adoption without losing visibility, control, or governance. In this demo, see how Cato helps organizations secure AI across three fronts: · AI employees use, including sanctioned and unsanctioned AI tools· AI applications teams build, including LLM apps connected to enterprise data· Agentic AI, where agents can access tools, data, and workflows.

What Server Do You Need to Run an AI Language Model?

Running your own AI model sounds exciting, but one question appears almost immediately: what kind of server do you actually need? A small language model can run on a personal workstation, while a large 70B parameter model may require enterprise-grade GPUs and expensive infrastructure. Choosing the wrong hardware can lead to wasted money, unnecessary complexity, or disappointing performance.

What AI Governance Tools Exist in the Market Today

‍AI governance tools are software platforms designed to help organizations manage AI risks, ensure regulatory compliance, and enforce responsible AI use across the machine learning lifecycle. The market has expanded rapidly, and in 2026 it includes tools spanning compliance automation, model observability, data governance, infrastructure security, and integrated risk quantification.

The Safety Problem Nobody Warns You About When You Start Training a Language Model

There's a version of the LLM safety conversation that stays comfortably abstract - AI alignment, existential risk, theoretical failure modes that matter at a scale most organizations will never reach. That conversation is important, but it's not the one most product and technology leaders need to be having right now. The one they need to be having is more immediate and considerably more practical: how the specific decisions made during llm training services directly shape whether the model you deploy is one your organization can actually stand behind.

Latency Lessons From Building a ReAct AI Agent for Agentic Search

Egnyte AI surfaces insights from an organization's documents for regulated industries—life sciences, financial services, architecture, engineering, and construction—and does that within existing permissions and compliance controls. Our AI Assistant is the conversational front door. Ask a question about your documents in plain language, summarise a contract, find the latest version, pull a compliance clause, and get an answer grounded only in the files you're permitted to see.

Best Tools for Securing MCP and LLM Integrations

Shadow IT used to mean employees spinning up unsanctioned software-as-a-service (SaaS) apps that stored company data without approval. Today, shadow MCP and unsanctioned LLM integrations represent the next evolution, and they're more dangerous. Model context protocol (MCP) servers don't merely store data; they act on it, executing code, calling APIs, and accessing internal tools on behalf of AI agents that developers connect with a config file.

Your Firewall Rules Are Drifting Right Now. You Just Can't See It

Firewalls are the single most common source of misconfiguration-related breaches, yet they get changed a hundred times a week and audited once a quarter. This is the network security gap AI attackers exploit first. Endpoint gets the budget. Identity gets the roadmap. The firewall gets changed constantly and reviewed rarely. It is also the control most tied to breaches: 42% of security teams pinned a firewall misconfiguration to a breach or near miss last year, ahead of EDR at 40% and identity at 39%.

How to Secure AI Agents in the Enterprise: A Practical Guide for CISOs

Building guardrails for AI agents sounds like a policy problem but it is actually a data problem. You cannot enforce boundaries on behavior you cannot see. And you cannot govern identity for actors you have not discovered. That dependency chain is what most enterprise security programs miss in 2026, and it is where exposure quietly accumulates. A human employee who mishandles sensitive data creates a containable event. An AI agent with the same permissions creates a different problem.

Why Sensitive Data Detection Is Harder in AI Workflows

Sensitive data used to live in predictable places database columns, known field names, structured rows. That changed when data moved into documents. And it changed again when AI workflows arrived. In this video, we walk through why detecting sensitive data in AI pipelines is fundamentally different from traditional data discovery, and why the old approaches break. We cover the four failure modes that make detection hard in AI workflows.

5 Best Predictive Cyber Intelligence Platforms for Enterprise Security Teams (2026)

Most security tools describe what has already happened. The harder question is what happens next: which exposures an attacker will chain together, and where they will get in. CloudSEK's Global Threat Landscape Report 2025 describes cybercrime as a structured, industrial ecosystem built on stolen credentials, access marketplaces, and coordinated attack chains, and frames the response as a shift from reactive defense toward predictive resilience.

Microsoft Copilot SharePoint Integration for Drupal

Someone asks for a project proposal from six months ago. You remember the client. You remember the meeting. The only thing you don't remember is where the document lives. That's a familiar situation for many teams. A Microsoft Copilot SharePoint Integration for Drupal gives users a quicker way to access SharePoint content from Drupal. They can find information, review documents, and complete common tasks without leaving the platform.

Why AI Governance Without Guardrails Is Theater

AI governance is a key enterprise concern. Organizations are assembling councils, publishing principles, rolling out “approved AI tools” lists, and asking employees to opt in to acceptable use policies. In most enterprises, however, the reality is that AI is already widely embedded in employees' daily work, often outside sanctioned channels and oversight. The visibility and control mechanisms needed to govern AI use are immature or nonexistent.

Prompt Injection and the Rise of Agentic Risk

Boxers will often say, the punches that hurt the most aren’t the ones which are thrown with the most force, but the ones they didn’t see coming. I think the same is true in cybersecurity. It’s not the most advanced technically efficient, 0-day utilizing attacks that have the biggest impact, but rather those quiet ones. With no malware or suspicious login at three in the morning from an IP address in a country your company has never done business with. No alert fires.

AI Pentesting Buyer's Guide: How to evaluate AI pentesting vendors

Pentesting made sense when releases happened every few months. A point-in-time assessment could provide an accurate picture of risk for weeks, sometimes months. Today, engineering teams ship continuously. Our State of AI in Pentesting survey of 200 CISOs and 200 engineering leaders, found that 76% deploy significant changes at least weekly, while nearly 40% deploy daily. Yet only 21% validate security on every release. That gap has consequences.

MCP Supply Chain Security: How Malicious MCP Servers Are Infiltrating Enterprise AI Environments

Every enterprise deploying AI agents is building on a foundation of third-party MCP servers they don’t control, can’t verify, and barely track. The security conversation keeps focusing on the model – prompt injection, jailbreaks, hallucinations. That’s the wrong place to look. We’ve covered why that framing falls short elsewhere too – see System Prompts Are Not Security Boundaries. Business Logic Graphs Are.

AI Innovation Challenge: Help Shape the Future of Cybersecurity

Artificial intelligence is transforming cybersecurity, and Managed Service Providers (MSPs) are at the forefront of that evolution. That's why we're launching the WatchGuard AI Innovation Challenge, an opportunity for MSPs to share ideas for AI agents and automations that help security teams work smarter, operate more efficiently, and better protect their customers.

Shadow AI - The Hidden Risk in Every Pocket

Shadow AI is already on your employees' phones — and it's invisible to your network controls. This demo follows a real workflow: an employee gets blocked from using an unauthorized AI tool on her corporate laptop, so she switches to her personal phone instead. No VPN, no DLP, no visibility, no corporate controls follow her there.

Can we defend against ai-powered attackers?

In this week's Intel Chat, Chris Luft and Matt Bromiley discuss how the same AI capabilities fueling adversaries are available to defenders too. Matt's takeaway: you don't need to buy an AI product to keep pace. The same way an attacker points AI at a code base, defenders can point it at detection rules and telemetry. Chris adds that as more developers use these models to check their own code, the playing field will level out, though the next year or two will likely bring a spike in exploits from lower-skilled attackers leveraging AI before defenses catch up.

How AI Is Accelerating the Cyber Kill Chain?

AI Is Accelerating the Cyber Kill Chain: Faster Attacks, Greater Risk AI is changing the speed and scale of modern cyber attacks. From accelerating reconnaissance to reducing the time required for initial access, attackers are leveraging AI to move faster across the entire cyber kill chain. In this video, Paul Girardi explains how AI is impacting each stage of the attack lifecycle, including: As attackers automate more of the kill chain, security teams need smarter approaches to detect, disrupt, and deceive adversaries before they can achieve their objectives.

Agentic Trust Controls

As organizations adopt agentic AI, we believe open collaboration is the fastest path to building trustworthy AI governance. Today, we're introducing a new open source project: Agentic Trust Controls. Agentic Trust Controls are designed to help the GRC community evaluate and govern AI agents with greater consistency and confidence. Explore the project and share your feedback at trustcontrols.ai.

How to Prevent Data Leakage to GenAI Applications

An analyst pulls up the DLP console expecting to see alerts on the source code, customer records, and financial data employees paste into ChatGPT, Copilot, and a dozen other AI tools every day. Instead, the console is quiet, because the policies enacted by the legacy DLP system were built to catch file transfers and email attachments. But, none of the above traffic looks like a file transfer.

How to Identify and Track AI Use Across Business Units

Tracking AI use across business units requires a purpose-built approach that combines endpoint monitoring, browser-level telemetry, network security tools, and a centralized AI governance platform. Most organizations rely on some combination of IT asset management, SaaS monitoring, and manual surveys to understand what AI tools employees are using.

When the Classifier Is the Judge: What the Adelphi AI Case Reveals About Automated Verification

Orion Newby was a student at Adelphi University when a single automated score nearly ended his academic career. He had written a course paper himself, working with tutors from a university support program for students with learning and neurological differences. The essay was run through an AI detector, which reported it as AI-written. On the strength of that output, Newby was accused of an integrity violation, the kind of charge that can escalate toward suspension or expulsion on a repeat offense.

OpenMatter Network Joins HOL Initiative to Help Define Standards for Verifiable AI Collaboration and Security

OpenMatter Network today announced that it has joined the founding group of organizations participating in the Hashgraph Online (HOL) Partner Program, where the company will help develop standards, policies and verification frameworks for secure autonomous AI systems and agentic computing environments.

WatchGuard Appoints Vincent Hwang as Chief Product Officer to Accelerate Platform Strategy and AI-Driven Innovation

Former Fortinet, Cisco, and Bitdefender leader brings proven track record in scaling cybersecurity platforms, strengthening partner-driven growth, and shaping category-defining product narratives.

Shadow AI has officially entered the enterprise

AI tools have become a workplace staple, but their unsanctioned use has given rise to shadow AI. It refers to the untracked usage of any AI tools or applications without approval or overview of the information technology (IT) or security team. This is substantiated by the Verizon 2026 Data Breach Investigations Report (DBIR) which shows how rapidly the shadow AI trend is growing.

5 Common AI Governance Mistakes Enterprises Make

Enterprise AI adoption has outpaced enterprise AI governance. Seventy-eight percent of organizations now use AI in at least one business function, up from 55% the year before, and most of that adoption happened before governance teams finished drafting their first policy. The result is a familiar pattern: leadership approves a rollout, security builds guardrails around the tools it knows about, and sensitive data keeps moving through channels nobody mapped.

When AI Agents Call AWS, Who Does AWS Think They Are?

In Part 1, Your AI Agent Needs to Know Who You Are, we showed how Teleport JWTs give MCP tools a verified identity for every request. This post extends that pattern to AWS, specifically to Amazon Bedrock AgentCore, where the same identity gap exists but requires a different solution stack. You ask an AI agent to list your S3 buckets. The agent calls an MCP tool. The tool reaches out to AWS. However, CloudTrail records the action under something like agentcore-bot, but not your identity.

Beyond Masking: The Challenge of Safe Data Reveal

You can build a masking demo in an afternoon. Run a regex for credit card patterns, swap the match for XXXX, and ship it. The demo works, the compliance slide says “no PII sent to the LLM,” and everyone moves on. That demo is fooling you by leaving things out. It works because the input is a) clean (card 4111 1111 1111 1111), b) because the only sensitive thing in it is a textbook PII pattern, and c) because nobody downstream ever needs to use the value again.

AI Threat Modeling: A Practical Guide for Enterprise GenAI Security

Here is a number that should stop every CISO cold. Gartner projects that by 2028, 25% of enterprise GenAI applications will face five or more security incidents per year, nearly triple the 9% recorded in 2025. The acceleration is not slowing. Meanwhile, research by OpenText and the Ponemon Institute finds that 79% of organizations have not yet reached full AI maturity in cybersecurity, meaning most enterprises are deploying generative AI without the foundational controls needed to govern it.

Token Torching: Why Attackers Care About Your Usage Limits

AI is becoming part of almost everything: customer support, security operations, software development, research, analytics, internal workflows, and, most importantly, drafting emails. AI is increasingly embedded in real business processes, and that creates new risks, not to mention the level of unprecedented access mainly of these platforms to our data. Token torching (a type of Denial-of-Wallet (DoW) attack) is one emerging AI risk.

Giving the Vanta Agent a computer

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Protect AWS Strands Agents with Datadog AI Guard

AI agents can reason through tasks, call tools, and adapt their next steps based on intermediate results. That flexibility is useful for building agentic applications, but it also creates security risk at runtime: A prompt injection attempt can change the agent’s instructions, a malicious request can try to exfiltrate sensitive data, and an unsafe tool call can lead to an action that the application owner did not intend.

Secure AI Workflows: The Identity and Access Management (IAM) Checklist

AI agents and LLMs are already building, analyzing, and deploying code across your software development lifecycle. As software supply chains become increasingly AI-driven, proactive security and access controls are your only path to success. To effectively govern authentication and permissions without sacrificing development speed, you must update your access management strategies.

20 Questions Every Security Leader Should Ask Before Buying an AI SOC

Most “AI SOC” demos out there can look great. The polished dashboard, the confident verdict, the slide that says “autonomous.” A demo is built to show the platform at its best, on clean data, in a controlled environment, answering a question the vendor already knew was coming. The differences only show up after you’ve signed, when the platform meets your real stack, alert volume, and compliance requirements.

AI Chatbot PII Protection with Protegrity AI Developer Edition

See how Protegrity AI Developer Edition helps protect customer PII in AI chatbot workflows. This demo shows a Guardian AI chatbot application designed for a fictional bank website. The workflow helps prevent sensitive customer data from leaking during AI-powered chat interactions by identifying and protecting PII before it is exposed. In this video, you’ll learn how developers can.

Ransomware in the age of agentic AI with Behnaz Karimi [337]

Today we're speaking with Behnaz Karimi, an independent researcher specializing in ransomware and agentic AI systems, Senior Cybersecurity Analyst at Accenture, and founder of Tremorina, about how ransomware is evolving to target AI systems, machine learning pipelines, and autonomous agents.

TITAN AI Demo Series: Build Custom Assessment Templates in Minutes with TITAN Agent

Building a strong vendor assessment template used to take hours. With our TITAN Agent, it takes minutes. In this installment of SecurityScorecard's TITAN demo series, see how our TITAN Agent builds customized, comprehensive assessment templates — so your team gets to evaluation faster and with more consistency across every vendor engagement.

What Tools Help Build and Maintain an AI Asset Inventory?

Managing an artificial intelligence (AI) footprint has emerged as one of the most complex challenges for modern enterprise security and risk teams. As shadow AI, autonomous agents, and embedded third-party models infiltrate corporate environments, traditional methods of software tracking have broken down. Organizations are quickly realizing that maintaining an accurate inventory is not just an IT best practice.

CERT-In AI Security Blueprint 2026: Remediation Timelines Every Indian Organisation Should Know

If a known exploited vulnerability appeared on your internet-facing application right now, what would your team actually do in the next 12 hours? What would actually happen, given your tooling, your sprint cycle, your change management queue, and who is available. CERT-In’s blueprint sets these timelines because generative AI and autonomous agents have collapsed the attacker timeline to the point where anything longer is already too slow.

The ECB just gave banks four months to fix AI vulnerability gaps. Most of the work starts in the software supply chain.

On July 7, 2026, the European Central Bank sent a letter to the CEO of every bank it directly supervises with an unambiguous instruction: build a formal action plan against AI-enabled cyberattacks, and submit it to your supervisory team by October 31.

10 AI Agent Guardrails to Implement Today

AI agent guardrails are the controls that define what an AI agent can access, which tools it can use, what actions it can take, and when human approval is required. In cloud, SaaS, CI/CD, and production environments, these guardrails are especially important because agents can inherit permissions and affect sensitive resources faster than a human operator could manually review.

How to Build a Red Team Exercise for AI Workflows

AI agents now retrieve data, generate recommendations, and trigger actions across enterprise systems with little human review in between. That speed is the point, and it is also the problem. A single manipulated prompt or a poisoned data source can push an AI system toward a decision no one signed off on, and most security teams have never tested for it. Building a red team exercise for AI workflows is how you find that gap before an attacker does.

Seeing Thousands of Real Incidents Means I Have No Choice But to Share What I Know

A few years ago, I was sitting across from a security leader at a large enterprise. They had just deployed their first wave of AI agents. When I asked how they were thinking about the security of it, they paused for a moment and then said something I haven’t forgotten. I felt that. Not just as a researcher, but as someone who had been in enough of those rooms to know it was not one person’s gap. It was the whole industry’s gap.

Continuous Assurance Across Every Network Security Control

Every security leader can describe their network security architecture in confident detail: how traffic should flow, where segmentation boundaries sit, which access should never be permitted. What almost none can tell me with certainty is whether their live controls are actually enforcing that design right now, at this very hour. That gap between what we intend and what is actually running in production is where modern breaches live, and it widens with every change we make.

Why More Clinics Are Switching to AI Medical Scribes in 2026

Walk into almost any clinic today and you will notice something different about the way doctors work. Fewer of them are typing while talking to patients. Fewer are staying late to finish notes. A big reason for this shift is the rise of the AI medical scribe solution, a tool that listens to patient visits and turns the conversation into organized clinical notes.

How Conversational AI Is Reshaping Guest Data Security in Hospitality

Hotels and resorts collect an enormous amount of personal information every single day. From passport details to payment cards, from travel preferences to home addresses, guest data has become one of the most valuable and most vulnerable assets in the hospitality industry. As more properties turn to automated chat systems to handle bookings, requests, and customer service, a new layer of complexity has entered the picture.

7 Hidden Risks of AI in the Workplace

Is your team using AI tools at work? Without the right guardrails, you could be exposing your business to data breaches, compliance violations, and serious reputational damage — and most companies don't see it coming. In this video, we break down the 7 hidden risks of AI in the workplace — from data privacy breaches and AI hallucinations to Shadow AI, prompt injection attacks, and intellectual property complications. We also cover the best practices every organization needs to manage workplace AI risks before they become costly problems.

Build Agents, Automate Workflows, and Unlock Your Content-All in One Platform

88% of organizations are running AI in at least one workflow, yet nearly two-thirds report more rework than savings. The model is rarely the bottleneck. Everyone has access to the same frontier models now. The difference is what sits underneath: content that's unstructured, ungoverned, and disconnected from the workflows that need it. Fixing the content problem usually means giving AI broad access to content, and that's where governance breaks down.

Called it (mostly): Checking in on 2026 predictions so far

On this episode of Masters of Data, we revisit the predictions Adam White, Zoe Hawkins, and David Girvin made at the end of last year, checking our own scorecard halfway through 2026. The hits: agents running amok and deleting databases, MCP becoming the backbone for tracking what agents actually do, growing security gaps around personal data, and a collective rejection of low-quality AI content. The misses: we underestimated how fast companies would cut staff for AI, then quietly start rehiring once the agents couldn't cover the work, and we're still arguing about whether token burn is a cost problem or a coming attack vector.

Implementing AI Security: Your Enterprise LLM Security Checklist

Security teams are approving large language model (LLM) deployments faster than they can build the controls necessary to govern them and protect vital, sensitive data. Employees paste customer records into ChatGPT, engineering teams connect internal APIs to coding assistants, and business units stand up retrieval systems against production data, often without formal review.

How to Build an AI Asset Inventory

Most organizations that have invested in AI governance have done so without first solving the problem that makes governance possible in the first place: knowing what AI they are actually running. An AI governance program built on an incomplete inventory is governing a partial picture of actual exposure. ‍ The risks concentrated in the AI systems that never made it into the formal catalog are not lower priority because they were not captured. They are simply invisible, which is considerably worse.

CrowdStrike Uncovers New Prompt Injection Techniques

Prompt injection is among the defining security challenges of the AI era. As organizations move from chatbots to AI agents, adversaries are finding more ways to manipulate the language, context, and data these systems trust. With the rise of powerful AI agents that can crawl webpages, access file stores, and even write shell commands, indirect prompt injection has emerged as a critical threat vector.

Safeguard: Using the double-edged sword of AI for good

The concept of AI might trigger both excitement and stress for those who spend all their time either using it for efficiency or fighting it as it tries to breach their systems. A massive force of non-human identities that have been summoned to expose the tiniest cracks in an organization’s security is enough to overwhelm any IT team. However savvy, modern security professionals have begun to raise their own versions of AI armies – designed to stop those sent by malicious actors.

Best AI Governance Platforms for Enterprises: Top 6 in 2026

AI governance platforms provide enterprises with centralized oversight to manage AI risks, ensure regulatory compliance, and automate policy enforcement across the AI lifecycle. Leading solutions include security-oriented tools like Mend.io, HiddenLayer, and Prompt Security, as well as end-to-end governance platforms like IBM watsonx.governance and Microsoft Purview.

TITAN AI Demo Series: How to Send Vendor Questionnaires with TITAN Assess

Vendor questionnaires out the door faster. Responses back sooner. No manual coordination required. In this week's edition of SecurityScorecard Demo Tuesdays, see how TITAN Assess streamlines the entire questionnaire outreach process — so your team spends less time on admin and more time acting on what vendors actually tell you.

After Mythos: What Cyber Insurers Should Actually Be Asking

One issue we keep hearing from insurance underwriters and portfolio managers is some version of the same question: how do you price a risk that can change between bind and the very next day? The steady stream of headlines about Claude Mythos is the latest reason why this question comes up, but it isn’t really all about Mythos. Frontier AI is collapsing the gap between vulnerability disclosure and weaponized exploit, and the numbers are no longer subtle.

Zero Trust for AI Agents Starts After Login

Zero Trust was built to fix an older assumption: if you were inside the network, you were trusted. Then, Cloud, SaaS and remote work broke that, so security moved toward identity, device checks, MFA, least privilege, and continuous verification. But now, with agents, the messy bit starts after access. The agent reads a prompt, pulls context, chooses a tool, calls an API, and may trigger a workflow. The login tells you the agent is “trusted”.

Microsoft 365 E7 and the Rise of AI Agents: What Security Leaders Need to Know

For years, enterprise security focused on protecting users, endpoints, applications and data. Today another identity is entering the enterprise. AI agents. Unlike traditional chatbots that simply answer questions, modern AI agents can perform tasks on behalf of users. They can search corporate knowledge, summarize documents, create reports, interact with business applications and, with appropriate permissions, execute multi-step workflows.

Your AI Agent Could Leak Enterprise Data #Shorts #aiagents

AI agents don't just answer questions—they access enterprise data, call APIs, interact with MCP servers, and trigger workflows. That means sensitive information like PII, PHI, HR records, pricing data, financial information, and confidential business data can flow through AI systems. In this YouTube Short, Amar Kanagaraj explains why AI governance, data security, and data sovereignty are essential for enterprise AI deployments—and how the NetScaler × Protecto integration helps organizations secure AI workflows.
Featured Post

The biggest security risks facing financial institutions in 2026

Financial institutions are spending more on security than they were five years ago. They have more security tools, invest more in training, have more policies in place and report on security more regularly. That sounds positive, but it does not automatically make them more secure. One of the biggest challenges for security leaders is deciding where to focus. New vulnerabilities, threat reports and regulatory requirements appear all the time. With so much competing for attention, it can be difficult to separate genuine priorities from the latest headline.

GLM 5.2 Signals a New Phase of Accessible Frontier AI and a Shift in Cyber Risk

AI’s latest wave is reshaping cybersecurity in a fundamental way. Capabilities that once were limited to a handful of frontier models are now widely accessible, cheaper, and embedded across more environments. As access expands, risk is growing fast and scaling even faster.

Reduce SAST false positives with agentic evaluation and Bits Memories

Static application security testing (SAST) tools are intentionally conservative. Traditional scanners identify code that appears exploitable and flag the snippet for review, even when protections elsewhere in the application prevent exploitation. Although that approach helps teams catch vulnerabilities, it also creates false positives that consume developer time, slow remediation efforts, and make future alerts easier to dismiss.

5 Biggest Challenges of AI in Cybersecurity

IBM’s 2025 Cost of a Data Breach Report found that 97% of organizations that experienced an artificial intelligence (AI)-related security incident lacked proper access controls on AI systems. The same report highlighted that 63% of organizations lacked governance policies to manage AI or prevent shadow AI. Despite those statistics, AI is now deeply embedded in workflows across critical business functions. Employees are using public AI tools to work faster.

AI Assisted Scripting: Updated Features and Use Case

Explore how Acronis Cyber Protect Cloud transforms IT management with AI-assisted scripting and remote remediation. This video demonstrates unified backup, security, and endpoint management, empowering IT professionals and MSPs to automate tasks, respond rapidly to incidents, and manage endpoints securely from a single console.

How AI-leading Security Teams Are Building the Agentic SOC

AI-enabled attacks move faster than human analysts can track, at a scale that traditional SOCs weren’t designed to withstand. eCrime breakout times collapsed to 29 minutes on average in 2025, with the fastest clocked at 27 seconds. The rise of frontier AI models is expected to compress the time between vulnerability discovery and exploitation, intensifying pressure on SOC teams. Defending against AI-accelerated adversaries requires a new operating model.

A Practical Image-to-Video Prompt System for AI Animation

An image-to-video prompt should direct motion without destroying the strengths of the source image. The model already has information about the subject, composition, and style; the prompt must explain what changes over time and what should remain fixed. This principle applies across product shots, character animation, anime scenes, and flexibleuncensored ai workflows. More adjectives do not necessarily create better video. Clear priorities do.

Intel Chat: Hijacked AI backends, billboard hacks, Cursor DuneSlide & Claude export controls [336]

Intel Chat with Matt Bromiley and Chris Luft. Matt and Chris break down four stories from the week in threat intel: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly. Subscribe wherever you listen.
Featured Post

Anthropic and The Monster Outside the Fable

The reports surrounding Anthropic's Mythos 5 and Fable 5 have generated the usual reactions. Some see a necessary security measure and others see government overreach. Anthropic has disputed portions of the reporting and pushed back that the models represent an extraordinary threat. And now we're in a familiar grey area that is Anthropic models.

It's the speed we're adopting it

AI! It's in everything, everywhere, all at once! It’s reading emails, summarising meetings, drafting documents, and writing code, and it’s no longer just giving us answers. We now also have agents that act on their own, access other systems, and make decisions with little to no human oversight. From a capability standpoint, it’s amazing.

Sleep Deprivation

Still sleeping on your AI app risk problem? Save yourself the insomnia-induced eye twitch. Without adopting a goat (you’ll understand once you watch this vid with @AlexisGay)... Vanta monitors all your vendors so you can track risky app usage. Even the AI apps that sneak past procurement. So don’t stress about who’s using AI apps and also has prod access. Just sleep well knowing you can review and approve every tool in one place.

The Five Eyes Just Said AI Is Breaking Every Assumption in Your Security Program

The Five Eyes just put a number on something most security teams haven't priced in: AI is shrinking the gap between "vulnerability" and "actively exploited" faster than patch cycles can keep up. Adrian Culley and Tova Dvorin explain why CVSS scores alone can't tell you what's actually reachable in your environment — and why attack path validation is becoming the only way to know.

AI Pentesting for Compliance

For two decades, “penetration testing” has meant the same thing: once a year, you hire a firm, a human tester spends a week or two on your systems, and you get a PDF. Most compliance frameworks were written around exactly that ritual, a slow, manual, point-in-time engagement. Software doesn’t ship once a year anymore. It ships many times a day.

9-Step AI Governance Implementation Strategy and the Solutions to Know

TL;DR: AI governance solutions help organizations inventory, secure, and monitor AI systems. Best for AI security and shadow AI: Mend AI; enterprise risk and compliance: Credo AI and IBM watsonx.governance; model monitoring: Fiddler AI. Effective AI governance implementation involves establishing a cross-functional committee, compiling an AI bill of materials (AI-BOM) to identify risks, and implementing policies based on frameworks like NIST AI RMF.

What Is Network Security Assurance?

Every security leader has a version of the network in their head. They know which systems should be segmented, which applications should be reachable, which ports should never be open, and which access paths should not exist. They know how the architecture is supposed to work. The harder question is whether the live environment is actually enforcing that design right now. That question is getting more difficult to answer.

OWASP Top 10 for Agentic Applications 2026: What It Means for Enterprise AI Security

OWASP, the Open Worldwide Application Security Project, has published Top 10 lists for over two decades to help security teams prioritize the risks that matter most. The original OWASP Top 10 for web applications became the industry’s default checklist for application security. When large language models moved into production, OWASP followed with the Top 10 for LLM Applications, addressing risks like prompt injection and sensitive information disclosure in single-turn model responses.

AI Risk Categorization and Prioritization for Effective Governance

Artificial intelligence (AI) is transforming industries, but it also introduces new risks that organizations must manage carefully. This article explains how to develop and apply AI risk categories aligned with recognized frameworks, focusing on operational, technical, and ethical risks. Readers will learn how to prioritize these risks based on their potential impact on the organization.

Evaluating AI Security Posture Management Tools: 7 Key Criteria

Evaluating AI Security Posture Management (AI-SPM) tools is a critical process for organizations integrating AI, specifically Generative AI (GenAI) and Large Language Models (LLMs), into their workflows. Unlike traditional security tools, AI-SPM focuses on the unique risks of AI, including Shadow AI, prompt injection, data poisoning, model theft, and improper model configuration. When assessing AI-SPM tools, security leaders should prioritize the following capabilities.

Top AI Governance Tools for Shadow & Agentic Risks

AI governance platforms are evolving rapidly to manage new challenges such as shadow AI and agentic AI. These complexities arise as AI systems grow beyond traditional boundaries, operating autonomously and often without clear oversight. This article explores how leading AI governance solutions, especially Kovrr’s integrated platform, address these challenges through comprehensive visibility, risk quantification, compliance automation, and active enforcement.

A Framework for Vulnerability Mitigation

Vulnerability management has long been seen as one of the most straightforward areas in security. Scan your assets, identify vulnerabilities, prioritize the findings, and patch what you can. On paper, it looks like a repeatable process. But in reality, vulnerability mitigation is anything but simple. Environments are constantly changing. Assets come and go. New integrations, temporary exceptions, and incomplete inventories make it hard to know what is truly at risk.

From ISDN to AI - Two Veterans on How Defence in Depth Has Changed

Defence in depth has evolved every time the technology landscape has shifted. The internet, virtualisation, cloud, SaaS. AI is the next shift, and the old model isn't keeping up. Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this episode, I'm joined once again by Martin Voelk, co-founder of SpartanX and an ethical hacker with nearly 26 years in cybersecurity.

DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE

Cato AI Labs has discovered two critical remote code execution (RCE) vulnerabilities in Cursor IDE, the popular development environment which, according to Cursor, is used by over half of the Fortune 500. Both RCE vulnerabilities, which we refer to as “DuneSlide,” achieved a 9.8 CVSS score, and involve breaking out of the IDE’s sandbox environment and were assigned CVE IDs CVE-2026-50548 and CVE-2026-50549.

Shadow AI Is Not Shadow IT With a Better Marketing Budget

I saw a venn diagram on social media. One circle is Shadow IT, one circle is Shadow AI, a substantial overlap, and the implicit message is that they are effectively the same challenge. They aren’t and that the assumption can lead to many problems. Looking back, shadow IT was like watching a crash in slow-motion. Employees using technology IT hadn't sanctioned. Personal Dropbox accounts. Unofficial Slack workspaces.

Top Enterprise AI Adoption Challenges

AI today has moved beyond experimentation. In the modern age, enterprises are embedding AI across various aspects of their businesses, including customer support, document processing, software development, healthcare, financial services, and decision-making workflows. According to a recent McKinsey report, 88% of businesses use AI in at least one business function. This reflects how AI is now becoming the center of several enterprise operations.

Top 16 AI Agent Security Solutions

AI agent security solutions fall into two categories. Some use AI agents to perform security work, such as red teaming, pentesting, SOC investigation, threat hunting, and risk analysis. Others protect AI agents, copilots, MCP servers, and agentic workflows from vulnerabilities such as over-permissioning, prompt injection, unsafe tool use, data exposure, and unauthorized actions.

Gen. AI used to mislead victims in fraud campaigns

It is almost impossible to trust the source of an image or video anymore. On The Cybersecurity Defenders Podcast, Tamas Kadar, CEO and Co-Founder of SEON, explains how generative AI has reshaped what fraudsters can pull off. Setting up sophisticated fraud operations no longer requires coding skills, and synthetic identities and deepfake documents have become convincing enough that visual verification alone is no longer reliable.

Autonomous AI Accelerates Cyberattacks and Shrinks Response Time

The biggest challenge in cybersecurity is no longer just detecting threats. It's doing so before time runs out. Artificial intelligence is no longer confined to automating isolated tasks within an attack. It is enabling threats to operate as continuous systems that can adapt, coordinate, and evolve in real time, drastically reducing the time security teams have to react. This shift is doing more than simply increasing the volume of offensive activity.

Optimize Microsoft Entra ID Conditional Access | Reach Security

Which of your users can reach a sensitive app without ever hitting MFA? Most security teams can't answer that with confidence. Microsoft Entra ID and Conditional Access is powerful. But exclusions stack up, MFA coverage drifts, and risk-based protections go unused. This creates openings for fast-moving AI-powered attackers. Reach continuously validates your controls against your security intent, closes the gaps, and proves the risk reduction.

Alex Stamos has 23 minutes to stop an AI chatbot leaking data (Live Tabletop Exercise)

What does a security leader actually do when an AI chatbot starts confidently revealing customer data that was never supposed to see the light of day? Alex has spent his career at the intersection of security and the hardest problems in tech—Chief Security Officer at Yahoo, Facebook, and SentinelOne, founder of the Stanford Internet Observatory, and now Chief Product Officer at Corridor, a startup focused on the security and safety of AI coding agents. If anyone knows what it looks like when AI ships faster than security can keep up, it’s him.

Ep. 65 - "Months, Not Years": The Five Eyes AI Warning and Your Security Program

On June 22, 2026, the heads of all six Five Eyes cyber agencies—GCHQ, CISA, the NSA, ASD, the Canadian Centre, and New Zealand's GCSB—signed a rare joint statement: AI has rewritten the cyber risk timeline, and it's months, not years. Host Tova Dvorin and offensive security expert Adrian Culley unpack why AI is collapsing the window between vulnerability and exploit, why "having controls" isn't the same as proven controls, and why legacy systems are now strategic liabilities for the board, not the IT team. A clear-eyed look at validation, assumed breach, and what CISOs should do Monday morning.

AI Just Shrank the Time Hackers Need to Weaponize Your Vulnerabilities

The Five Eyes intelligence alliance—NSA, CISA, GCHQ, Australia's ASD, Canada's Cyber Centre, and New Zealand's GCSB—just issued a joint warning: AI has compressed the window between vulnerability discovery and exploitation from years to months. Adrian breaks down what the "AI Shift in Cyber Risk" statement actually means for patching timelines and attacker sophistication—and why most organizations aren't moving fast enough to keep up.

RAG vs Fine-Tuning: When to Use Each for Enterprise GenAI Applications

Let's suppose that your business is about to implement GenAI (generative AI). In this case, the conversation inevitably boils down to a dilemma: RAG (Retrieval-Augmented Generation) or Fine-Tuning. At first glance, these appear to be two competing methods for tackling the same problem-getting a base LLM (Large Language Model) to speak your company's language.

Embracing the Benefits of Smart Glasses Safely in the Workplace

We are witnessing a massive shift in how we secure corporate networks. Security operations centers used to be dedicated to protecting static desktop stations, local servers, and company-issued mobile hardware. However, today's spatial computing and edge-based AI have delivered a new, largely unregulated hardware threat directly into the corporate space - face-worn consumer hardware.