Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Inside the AI-Accelerated Cyber Underground

Cyberattacks take shape long before a breach through exposed systems, vulnerable software, stolen credentials, underground tools, and attacker experimentation. In this webinar, Emma Stevens, Threat Intelligence Researcher at Bitsight, and Qionglu Lei, Senior Product Marketing Manager at Bitsight, explore what Bitsight research reveals about AI-enabled attacker behavior and the changing cyber underground.

What's New in Vanta: August 2026

What's new this month in Vanta? Agentic onboarding—Upload your controls, policies, and custom framework docs. The agent builds your framework and suggests policies and evidence (nothing writes without your approval). Dark mode—Now available, and follows your OS or browser setting automatically. C5:2026—Germany's leading cloud security attestation standard is now a supported framework. Customer Commitments—A contract can carry 50+ commitments. The Vanta Agent checks each against your live program and ranks them by the risk they carry.

Inside SECNAP: An Agentic MDR Platform Built on LimaCharlie

Joshua Strickland from SECNAP shows how his team built a full agentic MDR platform on top of LimaCharlie. SECNAP layers its own customer portal and SOC workflows directly on LimaCharlie's API, giving AI agents the same access to telemetry and response actions as a human analyst. Joshua will walk you through the customer portal, the SOC dashboard, and a live attack simulation on a sandboxed machine, including how AI agents handle tier one and tier two triage with Sonnet and Opus, and how a human analyst reviews and approves response actions before anything ships.

Secure AI Agents, Everywhere: Why Prompt Injection Is Only Part of the Problem

Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know The rules have changed. In every AI deployment, the agent itself is now part of the threat model, and that's a first for enterprise security. Prompt injection gets most of the attention, and for good reason: it doesn't require access to source code, credentials, or network infrastructure. It exploits the fundamental mechanism by which language models process instructions.

How Cato handled record-breaking traffic after Japan's return from the Obon holiday

On Monday, August 17, 2026, Cato recorded record-breaking post-Obon traffic across its Japan Points of Presence (PoPs) as employees returned to work together. At one of Cato’s Tokyo PoPs, traffic rose to more than 15 times its typical level for the same morning period on normal business days.

More Tools Never Fixed the SOC: The Bottleneck Was Never Visibility

Odysseus left Troy with a fleet and reached Ithaca with nothing, having lost every ship to the sea. While the war was won by force, the journey home was won by wits, and ultimately the fleet barely mattered. Most security operations centers are still running their SecOps voyage the way Odysseus ran the war: more tools, more force, more signal. It is the wrong instinct, because the SOC bottleneck was never how much you can see. It is how fast you can decide.

Open Source Security Tools: A 2026 Guide

A mid-sized SOC can have endpoint telemetry in one platform, cloud logs in another, vulnerability findings in a third, and identity alerts somewhere else entirely. Analysts switch consoles, normalize the same event repeatedly, and still miss the incident that required context from several systems. The problem usually isn't a lack of detection technology. It's the absence of a shared data model, disciplined correlation, and evidence that security and compliance teams can use together.

Why Your AI Application Is Exposed

Imagine getting three separate security reports back for your new enterprise AI assistant: On paper, the application looks ready for production, but in reality, a threat actor bypasses your guardrails in minutes. How? By using the AI model as an intermediary. The attacker steers the LLM to invoke the internal utility tool, thereby bridging an untrusted prompt directly to the backend execution sink.

'The Gentlemen' Profile: Why This Ransomware Group Wants In Before It Locks You Out

The Gentlemen is a financially motivated ransomware group that combines data theft with encryption to increase pressure on victims. They first came onto the threat scene in July 2025. Rather than relying on encryption alone, the group exfiltrates sensitive business data before locking files, leaving organizations to deal with both operational disruption and the risk of stolen information being exposed.