Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Latest posts

Elastic: Closing the AI control gap: Governing autonomous agents on Microsoft Azure

Autonomous agents are showing up in production faster than most IT teams can govern them. Who approved an agent's last action? Can you trace a bad outcome back to the prompt that caused it? For enterprise IT, that's the new control gap. Join the Elastic team to see how to get end-to-end telemetry, from prompt input to infrastructure metrics across Microsoft Foundry and Azure workloads, built on Elastic Agent's new native OpenTelemetry Collector foundation.

Financial Firm Stops Identity Attack in Under 2 Hours

Developing the full picture of an incident is essential for SOC teams responding to complex threats. A financial firm faced this challenge when attackers created legitimate accounts within their Google Workspace environment. While native alerts flagged the activity, investigators needed deeper context to determine scope and exposure. With Corelight, the team gained the network evidence and chronological activity timeline needed to scope the incident and restore full visibility.

AI Model Governance: Framework, Roles, Controls and Implementation Checklist

AI models rarely become a governance problem because of the model alone. The real risk often emerges from what surrounds it: the data it receives, the decisions it influences, the systems it can access, and the people accountable for its outcomes. That makes AI model governance a lifecycle discipline, not simply a model approval process. Even NIST’s AI Risk Management Framework treats governance as a function that cuts across the entire AI lifecycle.

Prompt Injection Examples: 10 Real Attacks, and Which Ones Would Work on Your Agent

Prompt injection has not changed since 2022. What the model can do has. The instruction that hijacked a translation bot four years ago and the one that opened a homeowner’s windows last year are the same request: do something you are already allowed to do. The first system could only talk. The second could operate devices. Same sentence, different consequence. Here are ten real attacks, in order, and for each one the thing the system was allowed to do that made it work.

What Is Prompt Injection, Really? Why the Textbook Answer Cannot Tell You If You Have an Incident

Prompt injection is three things happening at once. The definition written in 2022 described a model that followed an instruction hidden in the text it was asked to translate. The definition needed in 2026 describes an agent that read a support ticket and then queried a customer table it had never touched, using a service account nobody had revoked. Those are the same attack.