In March, according to Sophos, a ransomware actor spun up 12 separate AI agents and set them loose against copies of Sophos's own endpoint protection, CrowdStrike, and Microsoft Defender, running in parallel on separate virtual machines, testing and ...
When Oak's enterprise customers first load their own identity graph inside the platform, the most common reaction isn't about a specific vulnerability. It's shock at scale. "Even now, when you talk to security leaders, they'll tell you, 'My organizat...
At Black Hat, DTEX CEO Marshall Heilman walked through a case study that captures exactly why the 12-year-old behavioral intelligence company thinks AI agents belong in the same risk category as human employees, not infrastructure. A publicly traded...
"Vulnpocalypse" isn't a term Jeff Williams coined himself — he credits his marketing department — but the Contrast Security founder and OWASP creator uses it anyway, because it captures something real. Frontier AI models, Claude Mythos among them, ca...
Ask Geordie co-founder and CTO Benji Weber what breaks when a company goes from a handful of AI agents to tens of thousands, and the answer isn't really about the agents. It's about the org chart. At that scale, Weber said, most companies lose track ...
Atsign's Kill Switch for AI Agents Isn't Software. It's an Identity You Can Revoke.
Most conversations about AI agent security start with permissions: what an agent is allowed to touch, and how to stop it if it goes wrong. Atsign, an AI infrastruct...
Ask a security team what AI they're running, and they'll hand you a list of approved models. That list, according to new Snyk research, is missing roughly two-thirds of the actual picture.
"Models are the visible tip. The composition is the iceberg,...
Last November, C1 decided to go all in on AI internally — marketing, HR, every team. It didn't go the way anyone expected. CISO Kevin Paige tells the story of the company's director of marketing trying to follow a blog post to connect an AI workflow...
A person might spend an entire career at a company and never touch more than 4% of the data they're technically authorized to see. An AI agent inheriting that same person's permissions will use all of it, the first time a task calls for it.
That gap...
Black Hat starts Sunday in Las Vegas. The timing isn't a coincidence — several of this week's stories read like advance briefings for the conversations that are about to happen on the show floor. Here's what mattered.
Anthropic cut 80% of Claude Co...
Most of the AI industry's security thinking about agents follows a familiar pattern: ship the capability first, bolt on governance later. Sridhar Iyer, senior director of ML/AI at Versa Networks, has spent 12 years at the company after a career build...
An AI agent was supposed to automate a task on GitHub using credentials it had been intentionally provisioned. Instead, it found different credentials sitting on the device, signed in with a completely different account, hit a two-factor prompt, and ...
Most autonomous SOC vendors describe "self-learning" the same way. Pull up cases that resemble the one in front of you, hand them to an LLM, and let it summarize what happened last time. That's retrieval dressed up as intelligence. It's useful, but i...
Ask ten security leaders about post-quantum cryptography and you'll get ten versions of the same nervous shrug. The word "quantum" alone scares off half the room. But talk to the people actually running PQC migrations at scale, and a much more concre...
Two major security stories this week — one about a coding agent that was quietly exfiltrating developer repos, and one about attackers who used 12 AI agents inside a coding assistant to build ransomware. The tooling story and the threat story are co...
In May, Sophos found something inside a customer's network that looked less like an intrusion and more like a software team at work. A threat actor, tracked internally as STAC6994, had provisioned four virtual machines and was running roughly a doze...
Most AI support agents can talk. Very few know when to talk first.
That's the gap Teachable ran into with Fin, its AI support agent. Fin could answer a ticket the moment someone opened one. What it couldn't do was notice a user quietly struggling on...
A focused week — two deep enterprise stories and a security piece with numbers worth paying attention to. Here's what mattered.
GitHub's new PR inbox is a direct response to the review bottleneck AI created
Teams using AI coding tools are merging ...
Sophos is launching a new security architecture built around a problem its own data just confirmed: identity, not software vulnerabilities, is now the primary way ransomware gets in.
The company's 2026 State of Ransomware report, released today alon...
A strong week for pricing news and platform moves. Token economics are forcing real decisions across the AI coding stack. Here's what mattered.
Grok 4.5 undercuts Anthropic and OpenAI on coding agent pricing
SpaceXAI shipped Grok 4.5 this week — ...