Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Sophos Launches Sophos Fusion, the Industry's First and Most Complete AI-Native Cybersecurity Defense System

Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defense system that prevents, detects, investigates, and responds at AI speed.

Pulse Security Debuts Operational Management Platform Built for Security Leaders

Backed by Foundation Capital and Zetta Venture Partners with $8M in seed funding, Pulse Security delivers the program intelligence and agentic infrastructure that security leaders have been missing. Pulse Security AI launched from stealth today to solve a problem the security industry has spent decades ignoring: giving the leader who runs the program the same operational foundation every other business function takes for granted.

AI is moving fast. Exploits are right behind.

Chris Luft and Matt Bromiley cover four stories in this week's Intel Chat that all point to the same trend: attackers are keeping pace with how fast AI tools are being built and deployed. They break down a chatbot pipeline vulnerability in Google Dialogflow CX, a phishing technique that hides malicious content until it renders in the browser, four newly exploited vulnerabilities added to CISA's KEV catalog, and an attack that exploits AI coding assistants' tendency to hallucinate fake repository names.

AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity

Every foundational shift in computing has created a new security category. The internet created network security, the rise of workstations created the need for endpoint detection and response (EDR), and cloud computing created the need for cloud security. Each technology transition has moved faster than the one before it. None has moved faster than AI.

AI Traffic Security: The Hidden Risk of Unstructured Data Leakage #aisecurity

Understanding the nuances of AI Traffic Security is critical because traditional firewalls and API gateways are fundamentally ill-equipped to inspect unstructured natural language. In the past, enterprise data remained safely within the corporate perimeter. Today, employees are pasting highly sensitive information directly into external models, creating a massive vulnerability where the risk lies in the meaning and content, rather than syntax or connections.

ISO 27001 vs ISO 42001 Do You Need Both

Already certified to ISO 27001 but wondering if your organization also needs ISO 42001? In this video, we explain the difference between ISO 27001 (Information Security Management) and ISO 42001 (AI Management Systems). If your organization uses AI tools like ChatGPT, Microsoft Copilot, Gemini, or develops AI-powered products, understanding AI governance is becoming increasingly important. Learn when ISO 42001 complements ISO 27001 and how both standards help organizations strengthen security, governance, and compliance.

The value of adding Microsoft administration and governance to your IGA environment

Most identity governance and administration (IGA) programs do a good job answering one question: who should have access to what. The platform provisions accounts, runs certifications, enforces segregation of duties and feeds compliance reporting. After the request has been approved and the account exists in Active Directory, the IGA tool typically stops looking. What happens inside the directory after that is somebody else’s problem.

The Agentic Attacker: One Objective, One Prompt, Forty Minutes, Domain Admin - Game Over

In a controlled enterprise lab, we tested how far an agentic attack stack could go by harnessing a frontier model with an agent platform, MCP-enabled tooling, operational context, and enough autonomy to execute a complete attack path.

Cyber Risk Intelligence Brief: Supply Chain Trust Erosion and Ransomware Velocity Require Preventive Control Discipline

This CISO Executive Cyber Risk Intelligence Briefing covers the Past Week (July 8–14, 2026) and the Past Month (June 15–July 14, 2026). Analysis draws exclusively from verified incident disclosures, CISA KEV activity, threat intelligence platforms, and platform telemetry. Focus remains on material risk to AppSec posture, software supply chain integrity, cloud/IaC, identity fabrics, and business enablement.