Tel-Aviv, Israel
2021
  |  By Ben Hanson
Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know When I walked to the stage in Copenhagen, I had a lot on my mind. For 3 days I'd had countless conversations with leaders and practitioners about AI and agentic security. The one word on everyone's lips was "governance"; day 3 at the conference was "Governance Day," in fact. This is a bag one vendor was giving out: But governance of what? To what end?
  |  By Rock Lambros
Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know Every AI security framework names the risks you have to control. Zenity is built to implement those controls at runtime. Here's the 2026 OWASP Top 10 for LLM Applications, entry by entry, with the gaps marked honestly. Paste a booby-trapped instruction into a chat window, and nothing much happens.
  |  By Emily Wise
Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know The rules have changed. In every AI deployment, the agent itself is now part of the threat model, and that's a first for enterprise security. Prompt injection gets most of the attention, and for good reason: it doesn't require access to source code, credentials, or network infrastructure. It exploits the fundamental mechanism by which language models process instructions.
  |  By Dina Durutlic
Claude Code, Cursor, GitHub Copilot, and Gemini CLI are running on developer machines across your enterprise right now. They're browsing the web, writing to your filesystem, committing code to your repositories, and calling external APIs under the identity of your engineers. Most security teams have no visibility into any of it. This isn't a future problem.
  |  By Anna Schibli
Enterprise AI agents stopped being a pilot project a while ago. They read email, touch source code, operate browsers, and increasingly make decisions inside production systems, which means the security model built for chatbots and prompts no longer covers what is actually happening inside the enterprise. Black Hat USA 2026 turned out to be the week that gap became impossible to ignore.
  |  By Taylor Roberts
Between April and August 2026, at least six distinct AI-security efforts launched across North America, Europe, and Asia, several in the same week as one another and some for contradictory reasons. This piece maps 18 of them: what each says it's trying to achieve, who founded and backs it, and what it has actually shipped versus only announced.
  |  By Refael (Rafa) Lachmish
A developer installs a skill to make their coding agent less chatty. It works. It also, the first time the agent uses it, reads the AWS credentials on that laptop and sends them to a domain no one recognizes. No one wrote obviously malicious code and no one approved a change. A file landed in a folder, the agent loaded it on the next run, and production credentials were gone.
  |  By Cinthia Portugal
There's a widespread assumption in enterprise security that identity is a problem IAM programs know how to solve. Provision the right access, enforce least privilege, audit the credential chain, and you've addressed the identity risk. For human users and traditional service accounts, that's approximately correct. For coding agents, it misses two-thirds of the problem. Coding agents don't have a single identity. They operate across a layered identity surface, and each layer carries its own risk profile.
  |  By Joseph Geiser
AI agents have moved from pilots into broad enterprise use. They read email, query systems of record, take actions, invoke tools, and coordinate with other agents on behalf of employees. Every line of business wants more of them, and security teams are being asked to enable that expansion without losing visibility or control.
  |  By Ben Kliger
A few years ago, when Michael and I started Zenity, most of the industry was not ready to hear what we believed. Software itself was changing. AI would let millions of people, not just engineers, build and automate real work. And securing that world would take a completely new approach, because we would no longer be protecting software. We would be protecting systems that think, decide, and act on their own.
  |  By Zenity
Zenity's low-code security research team is exposed to real world low-code applications on a daily basis, and we're glad to share our knowledge in this domain in order to help you to design and develop secure low-code applications.

Continuously protecting all low-code/no-code applications and components! Design and implement governance policies, identify security risks, detect emerging threats and drive automatic mitigation and response.

Low-code/no-code development and automation platforms are the wave of the future. The largest companies in the world are already adopting low-code/no-code development for their core business units. But with all their benefits, low-code/no-code development brings with it a host of governance challenges and risks that are unaddressed by existing InfoSec and AppSec solutions.

Zenity, the first and only governance and security platform for low-code/no-code applications, creates a win-win environment where IT and information security can give business and pro developers the freedom and independence they want in order to continue pushing their business forward while retaining full visibility and control.

Our Platform:

  • Discover: Identify shadow-IT business applications across your low-code/no-code fleet and track sensitive and business data movement.
  • Mitigate: Identify insecure, vulnerable and risky configurations. Drive mitigation and remediation immediately.
  • Govern: Design policies and implement automatic enforcement. Eliminate risks without disrupting business.
  • Protect: Detect suspicious and malicious activity, such as supply-chain attacks, malware obfuscation and data leakage.

Governance and Security for Low-Code/No-Code Applications.