Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Agent Risk Manager Moves into Early Access

When we first introduced Agent Risk Manager, the response was clear: many security teams are actively looking for a way to secure the AI agents already running in their environment and how they can confidently adopt AI across their organization. AI agents now operate inside organizations with real access to email, files and business systems, often with little visibility for the teams responsible for securing them. That’s exactly the problem Agent Risk Manager was built to solve.

4 Questions every CISO needs to answer about AI

If your board asked today how you are governing AI, how would you respond? Not just the policy you wrote, but what is actually happening across the business. Could you answer with evidence? Many CISOs cannot answer with certainty. AI has entered the business faster than anyone could write policy for it, and securing it across all areas now seems to be the CISO’s responsibility.

Salt Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection

Your WAF is doing its job. It's blocking SQLi, XSS, and the usual suspects. But here's the problem: it wasn't built for APIs, and it definitely wasn't built for AI agents. APIs now power nearly every digital experience. And AI agents — the automated systems that access your APIs at machine speed, at machine scale — are the fastest-growing source of that traffic.

How CFOs can manage AI costs and prove business value

Earlier this year, a bill arrived from one of 1Password’s AI vendors for 5x the value of the original contract. The initial agreement came in below a certain threshold, so it never reached the right approvers for review. By the time it did, we had a much clearer understanding of how quickly AI costs can add up.

Patch Reliability Score: Make patch deployment decisions with confidence

Every Patch Tuesday starts the same way: New patches become available, and administrators begin answering the question, Is this patch safe to deploy? That answer rarely comes from a single place. Most administrators read the vendor's knowledge base article, look for known issues, monitor community discussions, and wait for early deployment feedback before rolling the patch out across the organization.
Featured Post

The first short-lifespan TLS renewal wave is closer than it looks

If your organization runs anything on the public internet, a mandate that changes how often you renew TLS certificates is already in effect. In March 2026, the maximum validity of public TLS certificates dropped from 398 days to 200. What fewer teams have worked out is that the first certificates issued under the 200-day cap start expiring at the end of September. That makes this autumn the first real test of whether your renewal workflows are ready for what the next three years will ask of them.

CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates

The CrowdStrike 2026 Threat Hunting Report illustrates the next evolution in trust abuse. Adversaries are targeting trusted users and tools across identity systems, cloud environments, SaaS applications, AI services, software supply chains, and developer workflows to blend into legitimate business activity and reach critical assets before defenders can detect them. Our frontline intelligence in this year’s report underscores this shift.

Best Practices for Managing the Identity Lifecycle

Every employee, contractor, and partner who touches your systems creates a paper trail of accounts, permissions, and access rights that has to be managed from the day they join to long after they leave. Identity lifecycle management is the process of creating, updating, and retiring a user's digital identity and access rights across that entire span — from onboarding through role changes to offboarding.