Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Hugging Face Incident Proved the Real AI Risk Is in the Action Layer

Last week, an AI system crossed a line many still considered theoretical. During an internal cybersecurity evaluation, OpenAI tested a combination of models, including GPT-5.6 Sol and a more capable pre-release model, on ExploitGym, a benchmark that measures whether agents can turn software vulnerabilities into working exploits. The models were run with reduced cyber refusals and without the production classifiers normally used to prevent high-risk cyber activity.

Understanding the Importance of MCP Security

AI agents are moving from experiments into production workflows, and the Model Context Protocol (MCP) is becoming the connective layer that enables those agents to access enterprise data, applications, APIs, repositories, and automation tools. That makes MCP powerful, but also security-critical. As organizations adopt agentic AI, they need to understand not only how MCP improves connectivity but also how it creates new visibility, governance, and attack-surface challenges.

From prompt to action: Al Security with Salt Security and CrowdStrike

As enterprises accelerate adoption of Generative AI, the security perimeter is rapidly expanding. This creates a new, largely unprotected attack surface: the Agentic Action Layer. In this on-demand webinar, @CrowdStrike and Salt Security introduce an AI-native security architecture that spans the full chain of intent-to-action. Learn how CrowdStrike Falcon AIDR protects the model runtime, prompts, inference, and LLM behavior, while Salt Security governs and defends the APIs, MCPs, and services where AI actions actually occur.

We Trained Cybersecurity Startups to Win POVs, Not Solve Problems

Cybersecurity has a strange problem. Everyone says they want to reduce risk. But too often, the way we evaluate products rewards something narrower: how quickly a vendor can show value in a POV. Can it deploy fast? Can it work agentless? Can it produce a clean report? Can it map to OWASP, NIST, the EU AI Act, or the latest framework? Can it check enough boxes in the RFP?

Salt Code: Stop Reviewing Al Code Start Governing It

AI coding assistants are generating APIs, MCP integrations, agent tools, and application logic faster than your security team can review them. And none of them are trained on your internal security standards, industry frameworks, or regulatory requirements. Salt Code changes that. Join us for this product launch and see how Salt governs AI-generated code from the first prompt through runtime, without slowing your developers down.

Deconstructing the Agentic Stack: Why API Visibility Is the Ultimate Defense for AI Agents

AI agents do not create risk only when they hallucinate or produce an inaccurate answer. They create risk when they take the wrong action. A single user prompt can move through an application, reach an agent runtime, call a tool, trigger an MCP server, and touch a downstream API. By the time the action happens, the original request may be several layers away from the system that actually changes data, sends information, or executes a workflow. That is the problem security teams now face.

Salt Code

AI is writing more enterprise code than ever. The problem? AI coding assistants aren’t trained on your internal security policies, compliance requirements, or industry frameworks. The solution? Salt Code, the first agentic security solution to enforce security policies inside AI coding assistants. Salt Code brings policy-driven security to the moment code is created, helping developers generate compliant code by default from prompt to production.

Everyone Is Buying AI Guardrails. But Agents Have the Keys to the Car.

The first wave of AI security looked a lot like a WAF for LLMs: inspect the prompt, filter the output, block the obvious bad patterns. That was useful. It still is. But it was built for systems that mostly talked. Agents are different. They use tools, call APIs, access data, and change things. The confusion I keep seeing is simple: many teams think securing the model means securing the agent. It does not.