Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI Assurance: The Third Head of Your AI Governance Watchdog

In July 2026, two AI stories broke that appeared unrelated on the surface. But were they really? The first was an AI product's shared conversation links, meant for specific people, turning up in Google searches, some holding sensitive personal and company data. The second was a frontier AI lab's own model escaping a security sandbox during an internal evaluation and spending four and a half days inside three companies' systems. One involved ordinary users making a common mistake.

Zombie APIs Are Costing You More Than You Think: A Risk Quantification Guide

Zombie APIs are API versions or endpoints that were once known and documented, but were never properly retired. A team ships v2 of an API, tells everyone to migrate, and assumes v1 is dead. In reality, v1 is still running on a server somewhere, still accepting requests, and still connected to production data. This is different from unmanaged APIs, which were never documented in the first place. Zombie APIs were documented once.

Aikido Security achieves ISO 42001:2023 certification for AI governance

Aikido Security has achieved ISO 42001:2023 certification, the international standard for AI management systems, a step few security vendors have taken so far. The certification confirms that Aikido runs a structured, continuously improving governance system for managing the risks introduced by its AI-enabled features, across our entire platform.

Aikido launches agentic pentesting for Android apps

TL;DR: Aikido now pentests Android apps. The same agents that test your web apps and APIs can now work through your APK, log into the app, and reason through it, alongside the backend it talks to, in a single assessment. Findings come back with reproduction steps and are ready for an AutoFix, the same as any other Aikido pentest. Aikido has been running autonomous pentests against web apps and APIs since November 2025.

Ep. 76 - A Tale of Two SOCs: Invisible in One Network, Caught in 10 Minutes in the Other

CISA's own red team ran two critical-infrastructure assessments at once — and got opposite results. Host Tova Dvorin and SafeBreach offensive security engineer Adrian Culley break down advisory AA26-237A: how an ESC1 certificate template flaw and a default machine account quota chained into full domain compromise, why one SOC isolated three infected workstations in 10 minutes while the other never noticed, and the cloud identity gaps both organizations shared.

How does the SafeBreach Helm and the Anvilogic Integration Work Together?

SafeBreach Helm and Anvilogic help security teams accelerate the path from exposure to detection. SafeBreach Helm brings three AI agents together behind a plain-English interface: Analysis Agent — Prioritizes exposures based on real-world risk Validation Agent — Proves which exposures are actually exploitable by running real attacks SecOps Agent — Turns validated gaps into actionable fixes and works with Anvilogic to close the detection gap.

Cybersecurity Events Have a Problem

Are cybersecurity events still giving people a reason to turn up, or have too many become expensive sales floors with the same conversations on repeat? Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this episode I'm joined by James Bore, Chartered Security Professional, Gary Hibberd, co-founder of Consultants Like Us and Lisa Ventura, founder of the AI and Cybersecurity Association and Unity Group Solutions.

The Financial Grid: What 600+ banks & corporates told us about their digital asset build

89% of banks have committed budget to digital asset infrastructure. Only 16% are in production. The Financial Grid, our January 2026 survey of 600+ C-suite leaders at banks and corporates, maps what sits between funded and live. Barnaby Nelson, CEO of the Value Exchange, whose team ran the research, joins Fireblocks' Tim Way to unpack the gap: the internal constraints, the custody decision at the foundation, and the one call that turns budget into production.

Machine vs. machine: The new reality of cybersecurity in ANZ

Frontier AI has handed attackers something they have never had before: the ability to move at machine speed. Attacks that once took days to craft now take minutes. Threats have not just evolved to be automated, adaptive, and operational around the clock. They have also changed category. We surveyed more than 850 IT and cybersecurity professionals across Australia and New Zealand to understand how organisations are keeping up. What the data reveals is not a capability problem. It is a pace problem.