As network vulnerabilities pile up faster than teams can patch them, most of the AI conversation in NetOps has centered on autonomy: letting AI agents make and execute changes on their own. BackBox is making a different bet. With the launch of its Ki...
Developers are writing more code than ever, and most of it isn't coming from their own hands anymore. AI agents draft it, refactor it, and increasingly ship it. The problem isn't a shortage of code. It's that nobody can review it fast enough to trust...
An alert fires in one of Gravwell's own data centers at 3 a.m. Before PagerDuty wakes anyone up, an agent runs a set of scoped queries, pulls together enough context to orient a half-asleep analyst, and drops a plain-language playbook in Slack. By th...
In April, a Cursor agent running on Claude Opus was working through a routine task at a startup called PocketOS. Somewhere in the codebase it was scanning, it found an AWS key. It used the key to reach the production database. Then it deleted it. The...
A GitHub-heavy week — five stories in a row from the same platform, which says something about how fast the platform is moving right now. But the two Coder Legion pieces on agent memory and sovereign AI are the ones that will age well. Here's what m...
A coding agent looks at one service, sees a change that makes sense, and ships it. What it doesn't see is the billing service three hops away that depends on that exact behavior staying put.
"There could be another part of the system — one service u...
Enterprises in the Middle East and Asia-Pacific have been telling AI vendors the same thing for the past year: they want agentic AI, but they don't want to hand their data, prompts, or operations to somebody else's cloud to get it.
Anurag Gurtu has ...
At Black Hat this year, agent sprawl was the phrase everyone kept using: enterprises spinning up dozens, then hundreds, of AI agents faster than anyone could govern them. Most of that conversation was about security — who's watching all these agents,...
Over the past week, attackers have been hijacking MikroTik routers at scale, exploiting a chain of RouterOS vulnerabilities CERT Polska calls "MikroTrick." Two flaws, an SSH authentication bypass and a privilege escalation triggered by a specially cr...
A strong week with two hard deadlines attached. GitHub Copilot's billing and governance changes start landing September 1 — one of them already hit. Developers and platform teams have until September 28 before the next wave takes effect. Here's every...
David Kerber pulled up a policy with 30,000 characters in it — right at the edge of what AWS will let you attach to a role — and ran it through a tool called IAM Shrink. A few seconds later it was 25,000 characters. He ran it again: 23,000. One more ...
F5's Jimmy White, the company's CTO AI Security, put a number on the problem last week: mean time to exploit for a new vulnerability is now under seven days. That's not vendor time — that's the window between disclosure and someone weaponizing it. If...
Every AI security vendor ships a benchmark chart these days. Most of them don't survive a second phone call.
On September 1, Cycode launched Agentic Code Scanning, a fourth layer that sits on top of its existing rule-based scanner and decides, code ...
Here's an uncomfortable number for anyone running production infrastructure: 76% of enterprises with high availability and disaster recovery protection in place still had at least one outage longer than 10 minutes in the past year. Nearly a quarter h...
This summer, an AI agent broke out of its sandbox at one of the world's most prominent AI companies. It escalated privileges, stole credentials, and buried a real attack inside a mountain of noise. CrowdStrike CEO George Kurtz opened Fal.Con 2026 wit...
Legacy DLP has a well-earned reputation for drowning security teams in noise: pattern-match first, flag everything, let a human sort out what actually matters. Jazz, this year's winner of the CrowdStrike, AWS, and NVIDIA Startup Nest competition, is ...
A quieter week after the Black Hat stretch, but the five pieces that came out of it are worth your time. All five circle the same territory: what AI can and can't actually do in security, and who ends up owning the outcome when it falls short.
Tria...
Here's a number worth sitting with: scanning a 2-million-line codebase with an AI-powered tool costs roughly $315 in tokens. Triaging what that scan finds costs $128,000. That 400x gap, buried in Contrast Security's new AppSec Overflow 2026 report, i...
Ask Amy Chang, Head of AI Threat Intelligence & Security Research at Cisco, what a model's country-of-origin label actually tells you, and her answer cuts against how most procurement conversations still work. "Country of origin classifiers" aren't s...
Earlier this year, Anthropic gave Apple, Microsoft, Google, Amazon and a handful of other companies access to an AI agent called Mythos and turned it loose on their code. Project Glasswing, as the initiative became known, found bugs that had survived...