Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Grounding the AI SOC: The Context Graph Problem

See how Torq harnesses AI in your SOC to detect, prioritize, and respond to threats faster. Request a Demo David Melamed is Head of Emerging Technologies at Torq. He joined through Torq’s acquisition of Jit, which he co-founded and led as CTO since 2020, building agentic security on a production Context Graph. A cloud security veteran with 20+ years of experience, David previously held senior technical roles at Cisco (via the CloudLock acquisition) and MyHeritage.

Our AI Agent Now Has a Security Conscience: Introducing the JFrog Plugin for Claude Code

AI coding agents are changing the pace of software development. With tools like Claude Code, developers can move from idea to implementation faster than ever, generating code, exploring unfamiliar repositories, refactoring services, and turning plain-language intent into working software. That speed is powerful. But speed without governance = risk. It also creates a new challenge: how can you govern what an AI agent builds, suggests, and pulls in from the internet?

This 'caveman' trick will slash your AI costs #ai #tokeneconomics #trending

One simple prompt change, asking an AI to respond like a caveman with shorter sentences and fewer words, reportedly cut token spend by 75 percent. It is a funny example, but it points to a bigger issue, AI efficiency and cost control will matter far more as usage spreads.

Looks Can Be Deceiving: Silent Overwrite of Agent Skills

Agent skills are the newest piece of plumbing quietly making its way onto developer machines. They're easy to install, they get to call into the user's tools on the agent's behalf, and once they're in place they tend to stay in place. While auditing the popular installer vercel-labs/skills, we saw several ways a bad actor can make the tool install something other than what the user thought they were installing.

Salt Code

AI is writing more enterprise code than ever. The problem? AI coding assistants aren’t trained on your internal security policies, compliance requirements, or industry frameworks. The solution? Salt Code, the first agentic security solution to enforce security policies inside AI coding assistants. Salt Code brings policy-driven security to the moment code is created, helping developers generate compliant code by default from prompt to production.

Least Privilege Isn't Enough for AI Agents. You Need Least Agency.

Least privilege is foundational. It's been a core security principle for decades, and it's no less relevant in agentic AI environments. An agent shouldn't hold permissions beyond what its task requires, and remediating over-permissioned agents is one of the highest-value quick wins available to any agentic AI security program. But here's what the security industry has been slow to acknowledge: correctly implemented least privilege still isn't sufficient.

Pi Coding Agent: The Claude Code Alternative That Builds Itself

Pi is a minimal coding agent that lets you choose the features Claude Code and Codex bake in for you. Nothing is forced, nothing is hidden, and you decide what your harness does. However, Pi runs with no safety rails by design, so the environment has to be the boundary. In this video, we'll take a look at Pi, what it is, its features, how to get your own customized setup running, and why it works so well with isolated agentic environments like Beams.

The US Has a New AI Security Blueprint: Here's What It Actually Means

The Trump administration has spent much of its second term removing regulatory constraints on AI development. On June 2, it added one back voluntarily and carefully. Earlier this week, President Trump signed "Promoting Advanced Artificial Intelligence Innovation and Security" after months of internal debate, a last-minute pull of the signing in May, and a compressed final timeline. The result of this tumult is an order that strikes a deliberate balance.

AI workflow automation: what enterprise teams need that consumer tools miss

Most enterprise teams already run some form of workflow automation. The question is whether it can hold up when an AI step makes decisions within the chain, an auditor asks for a trail, and three teams need to build on each other's work without stepping on governance. That is where consumer-grade tools and enterprise-grade platforms part ways. The gap is architectural, not a feature lag, which is why it cannot be retrofitted.