Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Vulnerability Scanning Best Practices for 2026

Periodic vulnerability scans are no longer a reliable security program for hybrid environments. NIST's guidance treats scanning as a recurring, risk-based control that should account for changing vulnerabilities, historical results, authenticated coverage, and correlations between findings over time (NIST vulnerability-scanning guidance). Industry practice is moving in the same direction.

When 700 Agents Coordinate Without Being Told To

Two reports landed yesterday on the July incident in which OpenAI agents left an isolated test environment and reached Hugging Face production systems. OpenAI published a thirty-seven page technical post-mortem. METR and Redwood Research published a ninety-one page independent analysis, produced over six days on site, covering July 7 to 13 and taking no payment for the work. ‍ The coordination numbers are what drew attention.

How to start the AI-accelerated defense

Early on in the AI adoption boom, I gained a reputation for just throwing everything at it to see what would stick. That wasn’t the most effective strategy, and my token usage was crazy high. There are a ton of talks and posts on all the cool ways you can use AI for detection engineering, but I didn’t see any that showed you where to begin.

When AI adoption outpaces IT visibility

At 1Password, we started expanding our use of AI with a familiar IT playbook. We identified the problems we wanted to solve and the tools that could help us achieve those goals. The plan was straightforward: enable teams, move quickly, learn what worked, and build the visibility needed to manage the cost.

1Password product enhancements: Smarter autofill, phishing prevention, and more

At 1Password, we’re constantly working to make life simpler and more secure for our users, from the biggest businesses to each individual who signs up for our password manager. Over the past few months, we’ve been rolling out a slew of updates designed to make a difference for customers, whether you’re using us at home, at work, or (ideally) both.

The 5 best options for compliance privacy software

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Does It Make Sense to Pay a Ransom? A C-Suite Guide to DevOps Resilience

When ransomware hits, decision makers face an impossible ultimatum: pay the ransom or lose business operations. In software development, data criticality also comes to the forefront. That’s because source code isn’t just some trivial data, but primary intellectual property and a revenue driver. Let’s see what’s exactly at stake and how you can minimize the risk of paying a ransom for your tech business.

What we learned about AI agent security by monitoring our agents

AI agents comprise models, instructions, data, and tools, so thoroughly investigating potential security risks requires evidence from several components. As Datadog teams build AI agents for internal workflows, we use Datadog AI Guard to monitor how they handle each component during a session. We’ve found that application logs may capture an agent’s final API call without showing which prompt, retrieved content, or tool result led to the action.

See More, Act Faster: Arctic Wolf's Next Step in Accessible Security Operations

Security operations are complex. Teams are constantly balancing investigations, risk, operational health, and day-to-day priorities. Knowing what requires attention and deciding what to do next isn’t always easy. That’s why Arctic Wolf is introducing new experiences designed to make security operations more accessible and easier to manage.