Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Generator Can't Be the Validator: What OpenAI's Hugging Face Incident Proves About AI Security

Every so often, an industry gets a moment that quietly redraws where the line is — not because anything was said, but because something was proven. AI security had one of those moments last week, and it's worth being direct about that before getting into the details: this wasn't an incremental data point. It was the moment a risk that security and safety researchers had described in theory for years showed up, fully formed, in a disclosed incident report.

Best API Discovery Tools for Lineage Mapping

API discovery has become a foundational capability for modern enterprises as API ecosystems expand across cloud-native applications, microservices, SaaS integrations, partner APIs, and AI-powered workflows. By 2027, 78% of applications are expected to use APIs, and with that growth comes an urgent need for visibility that goes far beyond simply listing endpoints.

America's New Security Doctrine: Hardening Digital and Supply Chain Borders

In the span of six weeks this summer, the United States government issued three separate security directives that, on the surface, appear to address completely different problems. One tightens how federal agencies patch software vulnerabilities. Another creates a government-industry clearinghouse to triage AI-discovered bugs. The third restructures how defense contractors source the raw materials that go into missiles, aircraft, and military electronics. Different agencies. Different languages.

UK vs Europe: comparing the physical threat landscape facing the rail sector

Rail networks sit at the intersection of critical national infrastructure and daily public life, making them a persistent target for protest, industrial action, infrastructure crime and, in parts of Europe, suspected sabotage tied to geopolitical tensions. This analysis from CYJAX sets out the physical threat picture in the UK alongside that of the wider continent.

Torq SOC Brain: The AI SOC That Learns, Not Just Remembers

Back in June, I wrote a blog making the case that agentic triage alone isn’t an AI SOC. The way I see it, that’s like saying triage is the only responsibility of a SOC team. But as we know, the SOC’s responsibilities extend far beyond that, and these triage-only solutions don’t investigate threats, contain them, or close cases. That work is still left to the SOC team; the bottleneck is just shifting.

MCP's Auth Hardening: What the Six New OAuth SEPs Fix, and What They Still Don't

In short, the MCP 2026-07-28 release candidate is getting attention for going stateless. The quieter story is a package of six SEPs that harden the protocol’s OAuth layer: issuer validation, credential binding, client type declaration, and cleanups around refresh tokens, scopes, and discovery. All six are worth shipping, and all six fix real failure modes. But they harden how a client authenticates to a server, and that was never the whole problem.

1Password Credential Broker is now in public preview

Every security team has tried to trace a credential access event back to a specific workload, and received nothing but a "service account." That service account probably had access to an entire vault, and its audit trail doesn’t tell you which repo triggered the request, which specific credential was accessed, or whether the workflow still has access. When an auditor asks, or an incident occurs, that's not a good place to be.

Compliance Automation Software: A Practical Guide for 2026

You're staring at a spreadsheet full of screenshots, exported CSVs, and half-finished owner assignments, while the auditor wants one clean answer to a simple question, can you prove the control worked when it mattered? That's the gap compliance automation software is built to close in security programs that can't afford guesswork, especially when logs, cloud settings, identity events, and policy evidence all live in different places.