Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

When AI Agents Run Healthcare Workflows, Business Logic Becomes the New Attack Surface

Healthcare has moved well past pilot projects. AI agents now triage support tickets, draft clinical documentation, manage patient engagement, and coordinate care across systems that were never designed to talk to autonomous software. Autonomous systems can now analyze data, make decisions, trigger actions, and coordinate across clinical systems with minimal human oversight.

Trust Nothing: Tips to Secure AI Tools and Agents

So, you have some AI tools or are thinking about deploying them and want to know a bit about securing them. You are not alone, but there are significant challenges due to the rapidly growing capabilities of AI, and the issues around new types of vulnerabilities we may not be used to thinking of. This is a very challenging area to attempt to secure, but I hope to point you in the right direction and set you up with some resources.

Beyond the Checkbox: How a Proactive Partnership Led to Turnkey Hazing Compliance

When we formed the global steering committee for our KnowBe4 Student Edition, our primary goal was to simply listen. That listening paid off during a pivotal conversation with a private research university in Florida. Their Chief Information Security Officer operates under a holistic mandate: to make the entire university ecosystem safer and more secure.

How to report risk to leadership and the board: A guide for security and GRC executives

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Top 9 AI Penetration Testing Companies for AI/ML/LLMs/MCPs

From inchoate brainstorming sessions in the halls of Dartmouth College to a panoply of funding springs and winters, AI has made its way into the tech stack of not just almost every enterprise but also every household. This, though music to the ears of an AI researcher, rewards a security professional with sweat beads. Even a single AI/ML/LLM or an MCP feature in your product evolves your attack surface, necessitating scouting for the right AI/ML/LLM/MCP penetration testing companies.

Cato CTRL Insights: How One Threat Actor Turned Frontier AI Into an Offensive Platform

A Russian-speaking threat actor known as “Trim” has spent the better part of 2026 systematically dismantling the guardrails on publicly available frontier AI models and rebuilding them as offensive tools. What started in March as a knowledge-sharing post on a Russian cybercrime forum detailing how to break Claude Opus into writing malware, had evolved by June into a fully productized, commercially marketed AI-powered penetration testing platform.

Bringing Claude Enterprise Activity into Cato AI Security

Claude is now a part of many employees’ everyday work. But even as a sanctioned application, it creates a visibility problem for security teams. Sensitive data can move into prompts, files, projects, and conversations, and teams need a practical way to see what happened and whether it violates policy.

How to Discover, Monitor, and Manage Shadow AI Across the Enterprise

Shadow AI is the fastest-growing unmanaged risk surface in most organizations. Employees are adopting AI tools through browser extensions, free-tier SaaS accounts, personal logins, and embedded platform features without involving IT, security, or procurement. The result is an expanding footprint of AI systems that process corporate data, generate business outputs, and create compliance exposure while remaining invisible to the governance program responsible for managing those risks. ‍