For years, Microsoft 365 storage for universities was unlimited and free. That changed this year. Microsoft capped Education tenants at 100 terabytes plus 50 to 100 gigabytes per licensed user, and turned on overage pricing worth roughly $360,000 per...
Picture a Java developer shipping an AI agent into production. The agent gets a prompt and starts working through a task, 50 steps, each one a call to a model like OpenAI or Anthropic, a database write, maybe a few dollars of compute. At step 49 of ...
A busy week across tooling, supply chain security, and governance. Two stories have immediate action items attached. Here's what mattered.
GitHub Copilot bets on model choice, not model loyalty
GitHub's latest Copilot update, covering the week of ...
Every few years, a major cloud provider makes a play for the next generation of developers. AWS tried it before with AWS Educate, a dedicated academic program that eventually shut down. This week, the company is trying again, with more money and a di...
A DH2i customer in Germany couldn't move its SQL Server infrastructure off Windows. Not because the technology wasn't ready. Because the team running it wasn't. "They basically said we had to wait for guys to retire before we could look at moving to ...
Ask most AI SOC vendors what their agent does, and you'll hear some version of "faster investigations, fewer alerts." Ask Monzy Merza, and he'll walk you through a blast radius map instead — because for Crogl's customers, the real problem was never s...
Application security has operated on human timelines for as long as it's existed: a scanner flags something, a ticket gets filed, developers and security argue over priority, and a fix ships weeks or months later, if it ships at all. Rahul Sood, GM o...
Security teams already know the real problem isn't a lack of tools. It's the time it takes to move between them. A detection fires in one product, the context lives in three others, and by the time someone's pieced together what actually happened, th...
A Caribbean retailer had one developer keeping a core system running. He understood it well enough to operate and change it safely. No one else did. So the company kept pushing his retirement back, year after year, because losing him meant losing the...
Ask Rickard Carlsson, co-founder and CEO of Detectify, whether AI is handing attackers new capabilities, and he'll correct the premise. It's not new vulnerabilities. It's not new techniques. It's the same attacks, running on a clock that used to be m...
Coming off Black Hat, the theme continues: the tools developers use every day are becoming part of the threat model. This week had two concrete examples of that — and a major shift in how one of the most widely used AI coding agents handles permissio...
In 2010, Mike Wiacek was helping lead Google's response to Operation Aurora, the nation-state attack that hit Google and dozens of other companies. At the time, threat intelligence wasn't even a real job category yet. Wiacek says Google wouldn't let ...
Two months after closing a ten million dollar seed round led by a16z Speedrun, ZeroDrift is opening its compliance enforcement platform to developers directly. The company just launched Command, a self-service console where developers can get an API ...
A CISO told Mimecast Chief Product and Technology Officer Rob Juncker a story last week at Black Hat that sums up where agentic AI security actually stands right now.
One of the company's enterprise account reps had an automation set up to read inco...
LTX, the Jerusalem-based generative AI company spun out of Lightricks, is releasing LTX-2.5, the newest version of its open-weights world model. The company is positioning the release less as a video-generation upgrade and more as an infrastructure d...
Cursor's command-line coding agent has a workspace trust feature. It's supposed to stop the agent from acting on a project until you've told it you trust that project. Security researcher Francisco Rosales at Manifold Security found a way around it, ...
Black Hat USA 2026 was this week in Las Vegas. I covered 13 sessions, briefings, and demos across four days. The theme that ran through almost every conversation: agent identity and access governance is no longer a future problem. It's happening righ...
At a joint media roundtable at Black Hat, Accenture's global cyber intelligence lead Ryan Whelan and Google Threat Intelligence's John Hultquist described an incident that's become a kind of Rorschach test for the security industry this summer: a coo...
Brett Johnson opens most rooms the same way: by telling them exactly who he used to be. The U.S. Secret Service once called him the "original Internet Godfather," a title he earned the hard way. He built and ran Shadow Crew, an early organized cyberc...
Sean Murphy spent nearly a decade as an F5 customer, running security at BECU and, before that, Premera Blue Cross, both in Seattle, before joining F5 itself this year as Field CISO. That vantage point shapes how he talks about the shift AI has force...