Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Three Questions Every AI Telemetry Claim Should Survive

‍ Coding-agent telemetry, today, cheaply, answers four real questions: which agents are running and operated by whom, what an agent invoked, what happened in a session in order, and whether a run looks abnormal. Part 1 of this series covers that case in full. ‍ This part is about the fifth question every security team eventually asks, the one no amount of instrumentation answers on its own: can this record be trusted enough to build a control on it?

Turning the OWASP Agentic Top 10 Into Expected Loss

The OWASP list for agentic applications, published in December 2025, gives security teams a shared vocabulary for what goes wrong when software acts rather than answers. Ten categories covering planning, tools, identity, supply chain, code execution, memory, inter-agent communication, cascading failures, human trust and rogue behavior. ‍ Translating that into a financial figure is where programs stall, and the usual attempt makes a specific error.

When the Model Disagrees With Your Security Team

A model ranks phishing sixth. The security team has spent three years on phishing and knows how often people click. Somebody in the room concludes the model is wrong, or that the security team is attached to its own program, and the meeting stops being useful. ‍ Most of these disagreements are not about risk. They are about which question each side answered, and establishing that first resolves a surprising proportion of them without anyone conceding anything. ‍

When 700 Agents Coordinate Without Being Told To

Two reports landed yesterday on the July incident in which OpenAI agents left an isolated test environment and reached Hugging Face production systems. OpenAI published a thirty-seven page technical post-mortem. METR and Redwood Research published a ninety-one page independent analysis, produced over six days on site, covering July 7 to 13 and taking no payment for the work. ‍ The coordination numbers are what drew attention.

ServiceNow + UpGuard: Automating Risk Management Together

UpGuard connects to ServiceNow across the whole platform. Vendor risk findings, breach alerts, and user risk signals all land in the same ticket queue your team already works from, not a separate, siloed risk dashboard. With this integration, you can: Risk Automations makes this possible. You define the events that matter: a monitored vendor picks up a new risk, a risk score drops below a threshold you set, a credential breach turns up on a watched domain, or a questionnaire response comes in.

AI Assurance: The Third Head of Your AI Governance Watchdog

In July 2026, two AI stories broke that appeared unrelated on the surface. But were they really? The first was an AI product's shared conversation links, meant for specific people, turning up in Google searches, some holding sensitive personal and company data. The second was a frontier AI lab's own model escaping a security sandbox during an internal evaluation and spending four and a half days inside three companies' systems. One involved ordinary users making a common mistake.

Agent Incident Response: Containment Is the Easy Part

Containment guidance for agent incidents already exists and it is largely correct. Revoke the tokens, freeze the orchestration tier, cut egress, set the vector store to read-only. Those steps take minutes and any competent team will find them. ‍ The difficulty sits either side of containment. Deciding what kind of incident this is takes longer than stopping it, establishing what the agent did before you stopped it takes longer still, and both depend on preparation that has to exist beforehand.

How Many Cyber Risk Scenarios Should You Model?

Scenario libraries grow. A program starts with ransomware and a data breach, adds a third-party failure after a supplier incident, splits ransomware into encryption and extortion variants, adds a cloud outage, and two years later holds forty entries nobody has revisited. ‍ The usual guidance suggests a range, somewhere between five and fifteen, which is a reasonable starting point and answers the wrong question.

Nucleus Helix Was Built to Fix Exposure Management's Breaking Point

Let me be direct about something the industry keeps dancing around: the vulnerability problem isn’t getting better. It’s getting structurally worse. The wave of AI-generated code and compression of time to exploit thanks to frontier AI models like Mythos is about to make “worse” look quaint. If your vulnerability and exposure management program is still built around scanner cycles, ticket queues, and CVSS scores, you’re not running a security program.

'The Gentlemen' Profile: Why This Ransomware Group Wants In Before It Locks You Out

The Gentlemen is a financially motivated ransomware group that combines data theft with encryption to increase pressure on victims. They first came onto the threat scene in July 2025. Rather than relying on encryption alone, the group exfiltrates sensitive business data before locking files, leaving organizations to deal with both operational disruption and the risk of stolen information being exposed.