Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cybersecurity Skills Shortage or Capabilities Gap? Why the Difference Matters

For years, cybersecurity has faced a persistent talent shortage. Yet the real challenge for many organizations isn't simply finding more people; it's having the specialized capabilities needed to investigate and respond to today's increasingly sophisticated threats.

In AI, No One Can Hear the Sandbox Scream

Aaron Beardslee, Security Researcher, Securonix Threat Labs As many of you have heard, OpenAI was running a cyber-capability evaluation against advanced models, including GPT-5.6 Sol and a more capable pre-release model with reduced cyber refusals. The environment was meant to be constrained and the model still brute forced through it.

AI Agent Governance: How Enterprises Should Approach It

Governing AI agents at enterprise scale requires a fundamental change in how security, risk, and compliance teams think about AI oversight. The generative AI era focused governance on output quality: what the model says, what it produces, and whether the content meets policy standards. ‍ The agentic era demands governance of action and delegated authority: what the AI is allowed to do, what systems it can touch, and how its decisions trace back to human accountability.

AI Agent Sprawl and How Enterprises Are Controlling It

AI agent sprawl is the uncontrolled proliferation of AI agents, autonomous assistants, and LLM-powered tools across an organization without centralized tracking or governance. It mirrors historical IT challenges like SaaS sprawl and shadow IT, and it emerges when decentralized business units build or deploy agents independently, without coordinated oversight from security, IT, or risk teams. ‍ The difference is that these agents are active software actors.

How to Quantify Cyber Risk Effectively: A Practical Enterprise Guide

Effective cyber risk quantification means moving past subjective heatmaps and translating technical vulnerabilities into dollar-denominated loss exposure and probability distributions that the CFO, board, and cyber insurance underwriter can act on. It is the discipline that turns cyber from a technical cost center into a strategic risk portfolio managed alongside every other category of enterprise exposure.

How to Transform Cybersecurity Data Into Risk Metrics

Enterprise security teams sit on enormous volumes of operational data. Vulnerability scanners produce thousands of findings weekly. Endpoint agents generate millions of events daily. SIEM platforms ingest logs from every system in the environment. Threat intelligence feeds fire off indicators by the hour. All of this data is useful for operational security work.

The Vendor Assurance Confidence Gap: Why It's Widest With Your Most Critical Vendors

Vendor assurance efforts are increasing, but risk leaders don’t trust the results of that effort. In KPMG’s Global Third-Party Risk Management (TPRM) Survey, only 15% of risk leaders said they have high confidence in the data that underpins their TPRM program. Only 17% rate their data quality as excellent. Security teams are running more assessments and sending more questionnaires than ever, but fewer than one in five leaders trust what any of that produces.

The Illusion of AI Containment: Why AI Guardrails Won't Save Your Supply Chain

AI is quickly becoming one of the most useful tools available to security researchers. Its ability to analyze enormous volumes of data, identify vulnerabilities, reconstruct attacks, connect seemingly unrelated signals, and help defenders respond faster than humans could alone is incredibly beneficial.

A First Look at Evo Agentic AppSec: Agentic Remediation and Malicious Code Defense

The Remediation Agent and Malicious Code Defense are the first two pieces of Evo Agentic AppSec: security that not only surfaces risk, but resolves it and prevents the next ones. This morning, we announced the broadest expansion of the Snyk AI Security Platform to date: discover, remediate, validate, and prevent. A loop with a missing segment is not a loop; it is a gap that an autonomous attacker will occupy. Evo Continuous Offensive Security closes validation and shipped today.

AI Model Risk Intelligence Know Which Models You Can Trust Before You Deploy

When we started thinking about how to surface AI model risk inside Evo, the obvious answer was to borrow from how we score everything else: find the issue, assign a severity, surface it. Done. The core of the new approach is a real risk score, built the way security teams already reason about risk: Likelihood × Impact. Likelihood comes from Attack Success Rate (ASR), the share of real adversarial attacks that succeed against a model. Impact is how much damage the attacker's goal does when it lands.