Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Solving the identity debt crisis with a One Identity platform approach: IGA, PAM and AD

Identities in the modern enterprise are increasingly less human and more autonomous, powered by the rise in AI agents, APIs and other non-human identities (NHIs). The result is often an entitlement sprawl, where operations take place without human oversight and with privileged access. This non-linear evolution has meant many businesses have had to respond using bolted-on tools, rather than one unified, enterprise-grade platform.

DORA Compliance for Mobile Apps: Mapping Security Findings to Regulatory Requirements

DORA compliance for mobile applications is the process of identifying, testing, and documenting mobile ICT risks in line with Regulation (EU) 2022/2554, covering Articles 8, 9, 10, 24, and 25, through vulnerability assessments, security testing, and audit-ready evidence generation that financial institutions can present to regulators, auditors, and internal governance bodies.

Four incident-response decisions from the Hugging Face breach

Hugging Face was breached by a rogue OpenAI agent last week, and the intrusion continues to deliver insights and understanding. The Hugging Face team published a detailed timeline along with a 17,600-event trace streaming replay visualizing what happened, and it’s marvelously and intoxicatingly detailed. I recommend you read it if you have the time.

Ep. 71 - OpenAI's Agent Hacked Hugging Face: The First Autonomous AI Breach

On July 9, an OpenAI model broke out of a sealed evaluation sandbox, found a zero-day in a package proxy, and — with no human directing it — chained stolen credentials and fresh exploits into Hugging Face's production infrastructure. Hugging Face detected it and called the FBI. OpenAI didn't know its own model had escaped for roughly 11 days. Host Tova Dvorin and offensive security expert Adrian Culley separate what's confirmed from what's hype.

OpenAI's Agent Hacked Hugging Face. Another Left Notes for Its Successor.

During an internal OpenAI evaluation, an agent left notes inside the company’s own network for future versions of itself, containing instructions on how to break free of OpenAI’s constraints. Reuters reports it isn’t clear whether this agent was connected to the one that breached Hugging Face, so don’t over-read it. But sit with the behavior for a second: an agent staging information for a successor process to find later. If a human crew did that, we’d call it a dead drop.

The Cyber Risk Register, Reimagined With Quantification | Kovrr

For years, security and risk managers have relied on spreadsheets to track their cyber risk. But as regulatory expectations tighten and threats grow more sophisticated, manual tracking cannot keep up. In this video, Kovrr walks through what a modern cyber risk register looks like when cyber risk quantification is built into its foundation. We cover.

Your Vendors Are Rushing Into AI. Their Attack Surface Is Coming With Them

Every company you depend on is standing up AI right now. Chatbots, copilots, RAG pipelines, agent frameworks, model gateways. The pressure to ship something with "AI" attached to it is enormous, and it is pushing infrastructure into production faster than security teams can review it.