Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Salt Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection

Your WAF is doing its job. It's blocking SQLi, XSS, and the usual suspects. But here's the problem: it wasn't built for APIs, and it definitely wasn't built for AI agents. APIs now power nearly every digital experience. And AI agents — the automated systems that access your APIs at machine speed, at machine scale — are the fastest-growing source of that traffic.

How CFOs can manage AI costs and prove business value

Earlier this year, a bill arrived from one of 1Password’s AI vendors for 5x the value of the original contract. The initial agreement came in below a certain threshold, so it never reached the right approvers for review. By the time it did, we had a much clearer understanding of how quickly AI costs can add up.

Patch Reliability Score: Make patch deployment decisions with confidence

Every Patch Tuesday starts the same way: New patches become available, and administrators begin answering the question, Is this patch safe to deploy? That answer rarely comes from a single place. Most administrators read the vendor's knowledge base article, look for known issues, monitor community discussions, and wait for early deployment feedback before rolling the patch out across the organization.
Featured Post

The first short-lifespan TLS renewal wave is closer than it looks

If your organization runs anything on the public internet, a mandate that changes how often you renew TLS certificates is already in effect. In March 2026, the maximum validity of public TLS certificates dropped from 398 days to 200. What fewer teams have worked out is that the first certificates issued under the 200-day cap start expiring at the end of September. That makes this autumn the first real test of whether your renewal workflows are ready for what the next three years will ask of them.

CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates

The CrowdStrike 2026 Threat Hunting Report illustrates the next evolution in trust abuse. Adversaries are targeting trusted users and tools across identity systems, cloud environments, SaaS applications, AI services, software supply chains, and developer workflows to blend into legitimate business activity and reach critical assets before defenders can detect them. Our frontline intelligence in this year’s report underscores this shift.

Best Practices for Managing the Identity Lifecycle

Every employee, contractor, and partner who touches your systems creates a paper trail of accounts, permissions, and access rights that has to be managed from the day they join to long after they leave. Identity lifecycle management is the process of creating, updating, and retiring a user's digital identity and access rights across that entire span — from onboarding through role changes to offboarding.

Next Gen SIEM: Modern Security Ops Guide

Monday starts the same way in too many SOCs. The queue is already full, the overnight team has left behind a stack of alerts nobody had time to finish, and the first hour goes to deciding which notifications are real and which ones are just noise. That's the point where next gen SIEM stops being a product category and becomes an operational decision, because the wrong platform turns your analysts into log clerks while the right one helps them work threats in real time.