'Recall' Was Enough for Firewalls. AI Needs a Stricter Scorecard

For much of security history, one metric dominated: recall. Recall means: of all the sensitive data that exists, how much did you catch? If there are 100 pieces of PII in a document and your system finds 95, your recall is 95 percent. This made sense in the old security world. If a firewall missed a real threat, the company had a serious problem. If it blocked something safe, someone could investigate and fix it.

AI Security for Healthcare: How to Protect PHI When Employees Use GenAI Tools

Clinicians are pasting patient summaries into ChatGPT to draft discharge instructions. Billing staff are uploading claim data to AI writing tools to speed up appeals letters. Nurses are using consumer AI assistants to look up drug interactions between patient visits. None of this was approved by the security team, and most of it would surprise the compliance officer.

9 AI Usage Control Tools for Monitoring AI in the Workplace

AI adoption in business has moved at a staggering pace. According to a major survey from The Conversation, 58% of global employees are intentionally using AI at work. That same study revealed an alarming trend: 66% of global employees have used unapproved AI tools, while only 34% say their company has put in place rules to govern AI usage. This use — and potential misuse — of AI systems is the latest and most complex threat facing businesses today.

How to Stop AI-Driven Data Loss

AI is reshaping the modern workplace. From automating tasks to generating in-depth research in seconds, AI tools are enhancing productivity at a lightning pace. GenAI assistants, agentic browsers, and automation platforms are everyday tools that employees are interweaving into their daily workflows. However, with this powerful new capability comes the serious risk of data loss.

17 Best Cloud WAAP & WAF Software in 2026

A web application firewall is a security software that observes and filters HTTP/HTTPS traffic between a web application and the internet. While this has been available for decades, with the evolution of the threat landscape, WAFs have also added additional capabilities to protect not only web apps but also APIs against a range of attacks, including DDoS and bot attacks. So, the category has evolved and is currently called Web Application and API Protection (WAAP).

From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services

In our previous post, Token Bingo: Don’t Let Your Code Be the Winner, we documented Kali365, a phishing-as-a-service (PhaaS) kit abusing Microsoft’s OAuth 2.0 device authorization flow to steal Entra ID tokens. In this follow-up report, we track the same operator into new territory as they expand their operation and infrastructure.

Why Rabobank made the switch to Identity Manager

Danny van Onna, senior product owner of IAM at Rabobank, and his team made the switch to Identity Manager by One Identity, and they’re not looking back. Hear him walk through what’s worked, what’s impressed and why they’re excited for the Identity Manager 10.0 update.

Corelight Brings Network Data to Cisco Cloud Control | Corelight

Corelight, a leader in fueling the AI SOC, today announced that it is providing industry-leading data to power AI investigations of emerging threats through an integration of Corelight Open NDR into Cloud Control Studio. Cloud Control Studio is the design space within Cisco Cloud Control, Cisco’s unified platform for agentic IT operations, where customers can build AI agents and connect them to non-Cisco tools.

AI Guardrails in 2026: Types, Challenges, and Impact of Agentic AI

AI guardrails are safety, security, and governance frameworks designed to ensure Large Language Models (LLMs) and generative AI applications produce trustworthy, accurate, and appropriate content. They function as filters for inputs and outputs to prevent harmful or biased outputs and proprietary data leakage, enforcing compliance with safety policies and regulatory standards.