Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

What Is Agentic AI Security? The 3 Layers and Their Owners

Two of the three layers of agentic AI security already have an owner in your organization, and the third has none. Identity falls to IAM and interaction falls to AppSec, because the controls at both layers extend products those teams already run. The behaviour layer covers what the agent does on the infrastructure once it is running, and it sits between a platform team with no security mandate and a SOC with no sense of what normal looks like for an agent. That gap is where a coerced agent works.

AI Agent Identity Security: Where an Agent's Baseline Lives

Identity governance cannot tell you which AI agent did something. It records which identity is allowed what. In a cluster, one service account often serves several workloads, and every pod is replaced at the next rollout. As a result, the permission record and the behavior record point at different objects. Detection and investigation need a unit of attribution. The Deployment is the right one. It stays stable across restarts and replicas and changes only when someone ships a rollout.

Cyber Loss When the Product Is a Clinical Trial

A cyber loss model for a research organization counts subject records and applies a per-record cost. Personal health information, a notification exercise, a regulatory penalty. ‍ The mechanism that matters in a trial is integrity rather than confidentiality, and it produces a loss that occurs even where nothing was altered. What gets destroyed is the ability to demonstrate that nothing was. ‍

What Data Should You Prepare Before Migrating to NetSuite?

Moving to NetSuite is a major step for a growing business. It can bring finance, operations, inventory, sales, and reporting into one system. But before the migration starts, you need to prepare your data. Poor data can create delays, errors, and extra work during implementation. Clean and organized data makes the move much smoother. It also helps your team get more value from NetSuite after go-live.

Keep your Qualys vulnerability scanner: Fix what it finds with Patch Manager Plus

Most organizations that run a vulnerability scanner have already made a significant investment. They chose Qualys, Tenable, Rapid7, or CrowdStrike based on their detection needs, their compliance requirements, and the way their security team works. That scanner is embedded in their workflows, audit processes, and reporting chain. Then they look at their vulnerability remediation times and realize the problem is not on the scanning side.

Salmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Systems

Archipelo today announced Salmon, Execution Verification Infrastructure (EVI) for AI agents and autonomous systems, powered by a cryptographic protocol designed to make execution history verifiable. Salmon establishes verifiable execution history and state lineage across humans, AI agents, and automation.

Managed EDR pricing and MDR costs: what to expect in 2026

A low endpoint rate means little if your technicians still cover nights, investigate alerts and coordinate recovery. For MSP owners, CFOs and IT directors, the useful comparison is not the headline rate but what the service covers and what work stays in-house. Every dollar figure below is a hypothetical U.S.-dollar assumption or calculation, not a published price or market benchmark.

AI Governance When the Data Subject Is a Minor

The assumption about AI systems affecting children is that the consent structure carries the difficulty. The subject cannot consent, so a parent consents instead, and the governance problem is collecting and tracking that permission. ‍ The assumption is backwards. Consent is usually the wrong lawful basis for these deployments, so the parental consent machinery is not required at all. What differs is something else entirely. ‍

Kiteworks recommends server shutdown pending possible attack

On September 25, 2026, reports emerged that Kiteworks (formerly Acellion) emailed customers that law enforcement alerted them about an “imminent” cyberattack on Kiteworks systems, possibly caused by exploitation of a zero-day vulnerability. Kiteworks reportedly advised customers to shut down servers between 02:00 and 08:00 UTC on September 26, if not sooner, as a “precautionary” measure.

Falcon for IT: Collapse the Gap - From Exposure to Remediation

Adversaries are moving faster than ever, exploiting vulnerabilities soon after they’re discovered. As frontier AI accelerates reconnaissance and exploit development, Security and IT teams need to identify endpoint risk and act before exposure becomes compromise. Meet Falcon for IT, a solution that helps teams uncover emerging risk, establish operational control, and accelerate targeted remediation across the endpoint fleet.