GeneralAI Agents Can Now Run in Sandboxes
Microsoft has introduced Microsoft Execution Containers (MXC), a policy-driven execution layer that runs AI agents in isolated environments on Windows and WSL. If your team is deploying autonomous age
Expert perspectives on application security, compliance, and emerging threats
GeneralMicrosoft has introduced Microsoft Execution Containers (MXC), a policy-driven execution layer that runs AI agents in isolated environments on Windows and WSL. If your team is deploying autonomous age
GeneralSecurity teams often treat AI agents like advanced APIs, but they re not. The recent Zscaler research revealing indirect prompt injection vulnerabilities in four models highlights a critical issue: yo
ResearchYour AI coding agent just installed a new skill from the marketplace. The static scanner gave it a clean bill of health. Three days later, you re investigating why production data is leaving your netw
IncidentA development team deployed a customer dashboard that let authenticated users view any account by changing a URL parameter. The vulnerability sat in production for three months before a penetration te
Get weekly security insights and compliance updates delivered to your inbox.
GeneralIn application security, the belief is that more detection equals better security. Scan everything, flag everything, track everything. If your SAST tool finds 10,000 issues, you need to see all 10,000
GeneralScope This guide explains how to manage AI security tools as supply chain dependencies requiring formal risk management. It covers: Identifying critical AI dependencies in your security workflow Build
ResearchThe Problem: Why This Matters Now Your developers are using AI coding assistants, connecting them to databases, APIs, and internal systems. They re loading third-party skills that execute code in thei
GeneralA 2026 Dataiku survey found that 85 percent of CIOs had seen AI projects delayed or blocked due to privacy concerns. Your compliance team s response? Deploy a privacy proxy and call it solved. Not qui
IncidentWhat Happened A financial services company with 2,800 employees spent 18 months feeding vulnerability data into their exposure management platform. Their dashboard showed 847 critical findings. The se
GeneralBetween 2024 and 2026, three major attack patterns targeted Retrieval-Augmented Generation (RAG) pipelines in enterprise SaaS environments. The EchoLeak vulnerability in Microsoft 365 Copilot enabled
GeneralYou can t audit what you can t define. When your LLM returns a user profile, incident report, or configuration change, you need to know exactly what fields you re getting, what types they are, and whe
IncidentWhat Happened Capital One s AI Foundations group developed a reinforcement learning system to identify effective jailbreak techniques against large language models. They tested it using the WildJailbr
IncidentWhat Happened The Linux kernel security mailing list has become almost entirely unmanageable, according to Linus Torvalds, due to a surge of AI-generated vulnerability reports. Multiple open source pr
GeneralAI spending is projected to reach $2.5 trillion by 2026, with 40% of enterprise applications embedding task-specific AI agents by the end of that year. However, many organizations grant these agents m
ResearchYour compliance team is hearing the same message from every business unit: deploy AI faster. But when you ask about security controls, threat models, or data governance, you get blank stares. This gap
GeneralYou ve probably seen the demos: type a single command, watch an AI agent probe your infrastructure, generate exploits, and produce a vulnerability report. Lyrie, the open-source autonomous pentesting