Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Grounding the AI SOC: The Context Graph Problem

See how Torq harnesses AI in your SOC to detect, prioritize, and respond to threats faster. Request a Demo David Melamed is Head of Emerging Technologies at Torq. He joined through Torq’s acquisition of Jit, which he co-founded and led as CTO since 2020, building agentic security on a production Context Graph. A cloud security veteran with 20+ years of experience, David previously held senior technical roles at Cisco (via the CloudLock acquisition) and MyHeritage.

The Governance Gap: What IDC's 2026 Data Reveals About AI and the Software Supply Chain

In a landscape where executive teams demand immediate AI integration, engineering and security leaders find themselves navigating a complex operational balancing act. To explore how organizations can accelerate delivery pipelines without introducing fatal security risks, JFrog recently hosted a virtual panel discussion titled “Agentic Software Delivery in 2026.

Our AI Agent Now Has a Security Conscience: Introducing the JFrog Plugin for Claude Code

AI coding agents are changing the pace of software development. With tools like Claude Code, developers can move from idea to implementation faster than ever, generating code, exploring unfamiliar repositories, refactoring services, and turning plain-language intent into working software. That speed is powerful. But speed without governance = risk. It also creates a new challenge: how can you govern what an AI agent builds, suggests, and pulls in from the internet?

How DSPM Detects Insider Threats Using Data Lineage

Most insider risk programs stall at the same place: they can see what data exists, but not what users are doing with it. Data security posture management (DSPM) tools catalog sensitive files, flag misconfigured permissions, and surface overexposed repositories. What they often cannot communicate is whether that overexposed file was accessed, copied, renamed, and uploaded to a personal cloud account by an employee who put in their resignation last week.

Should penetration testing be performed in staging or production?

One of the most common questions organisations ask when planning a security assessment is whether penetration testing should be performed against a staging environment or a live production system. At first glance, staging appears to be the safer option. It provides an environment where testing can be conducted without affecting real users, customer data, or operational services.

Why Ongoing Cybersecurity Monitoring Is Essential for Medical Device Compliance

Healthcare organizations today rely heavily on connected medical devices to improve patient outcomes, streamline clinical workflows, and support real-time decision-making. From infusion pumps and imaging systems to wearable monitoring technologies, these devices have become a critical part of modern healthcare delivery. However, as connectivity increases, so does exposure to cybersecurity risks that can affect device functionality, patient safety, and regulatory compliance.

What Integrated Lab Management Teaches Us About Systematic Risk Reduction

Risk in laboratory environments doesn't usually announce itself. It accumulates in the gaps - between process steps, between systems that don't communicate, between the way a procedure is documented and the way it's actually being performed on a busy Tuesday afternoon. Individual failures are often small enough to be invisible until they combine with other small failures to produce an outcome that prompts a formal investigation.

What Is Agent Native Security for Data Enrichment

There are thousands of automated data enrichment jobs running every hour in modern enterprise environments, yet traditional firewalls treat autonomous artificial intelligence as a basic web form. When automated agents are tasked with scanning, parsing, and updating database records, they cannot rely on static API access or broad infrastructure permissions.

How Advanced Training Protocols Define Elite Security Teams

When businesses and event organizers evaluate security partners, one factor consistently separates elite providers from the rest: the depth and rigor of their team's training. In an industry where split-second decisions can determine outcomes, advanced tactical preparation isn't optional-it's essential.

3-2-1-1-0 backup rule: Strengthening data protection against ransomware

Data loss is no longer a rare event—it is an inevitability. From ransomware attacks to accidental deletions, organizations must be prepared not just to prevent incidents, but to recover from them quickly and reliably. Modern threats increasingly target backup environments, making recovery readiness a critical component of any data protection strategy.