Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The New Face of AI Risk

Cybercrime used to have a ‘"tell." It was the digital equivalent of a villain stroking their cat - clunky grammar, misspelt links and suspicious attachments that screamed ‘phishing’. But the arrival of AI has changed everything. Typos have been replaced by perfect prose. Generic lures have evolved into highly personalized attacks that mimic your internal language and align with your project timelines.

Oracle Just Shipped 1,449 Security Patches in One Quarter. We Checked How Much of It Is Actually New.

Oracle's July 2026 Critical Patch Update (CPU) is nearly three times larger than any release in the company's history. To understand it, we parsed all 23 of Oracle's quarterly advisories going back to 2021, matched them against the official CVE record, and compared Oracle against eight other major vendors. We set out to answer three questions: How much of this is genuinely new? Does it really reflect AI-accelerated patching? And how unusual is it?

Why Continuous Attestation Is Critical in the AI Coding Era

In the age of AI coding, annual audits and snapshots are no longer enough. Discover **Continuous Attestation** — the practice of producing ongoing, verifiable evidence that your applications and pipelines are always running in a trusted, policy-conformant state. In this video, Anthony Barkley, Chief Strategy Officer at Veracode, explains why independence in attestation is critical for earning trust from regulators, customers, and boards — especially when AI agents are writing code.

Ep. 65 - "Months, Not Years": The Five Eyes AI Warning and Your Security Program

On June 22, 2026, the heads of all six Five Eyes cyber agencies — GCHQ, CISA, the NSA, ASD, the Canadian Centre, and New Zealand's GCSB — signed a rare joint statement: AI has rewritten the cyber risk timeline, and it's months, not years. Host Tova Dvorin and offensive security expert Adrian Culley unpack why AI is collapsing the window between vulnerability and exploit, why "having controls" isn't the same as proven controls, and why legacy systems are now strategic liabilities for the board, not the IT team. A clear-eyed look at validation, assumed breach, and what CISOs should do Monday morning.

Ep. 68 - Why OWASP's AIVSS Scores Agentic AI at Maximum Risk

OWASP just shipped AIVSS — an entirely new vulnerability scoring methodology built for autonomous AI agents, where a compromised orchestrator can score a perfect 10. Host Tova Dvorin and Adrian break down the "amplification principle": why a 2.1 CVSS finding becomes a 7.1 in the wrong agent, how persistent memory and broad tool access expand every blast radius, and what EchoLeak-style attacks already mean for real deployments. Plus where adversarial exposure validation and SafeBreach's agentic AI coverage fit in.

Attackers Exploit AI Hallucinations to Send Users to Phishing Sites

Threat actors are using a new technique called “phantom squatting” to trick AI tools into directing users to phishing sites, according to researchers at Palo Alto Networks’ Unit 42. Since AI models frequently hallucinate phony information, they sometimes point users to websites that don’t exist. Threat actors are now registering these AI-hallucinated domains and using them to host phishing sites.

What the OpenAI-Hugging Face Incident Really Tells Us

For years, the conversation about AI in cybersecurity has been mostly hypothetical. What happens when a model can plan and execute an attack on its own? How far away is that, really? This week, OpenAI gave us a concrete answer, and it arrived earlier than many expected. The incident is a genuine milestone, and it deserves the attention it is getting. But the most useful response is disciplined execution on the fundamentals, at a pace that matches the moment.

Identity Security for AI

What's scarier than an engineer with prod access? An agent with the same access that never sleeps, never asks, and runs a thousand sessions while you're at lunch. Last year we solved the problem of visibility in the Identity Chain, the concept is that identities are fragmented and it’s hard to get a view from Identity Providers to Infrastructure. Within a year, two things have changed. First, teams are using LLMs & Tools to perform actions on their behalf - fully delegating work to AI Agents.