Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Automate Inactive User Suspension with JumpCloud Workflows

Say goodbye to manual offboarding checks and dormant account risks! Join Derek Johnson as he demonstrates how to leverage JumpCloud’s user inactivity rules and Directory Insights (DI) trigger events to instantly automate account suspensions, group isolations, and admin notifications. We walk through configuring inactivity thresholds, mapping JSON parameters, and executing a live test run so you can streamline your IT operations today.

Avoid Azure secret rotation with secretless authentication

Many observability platforms authenticate to Microsoft Azure by using client secrets. Teams must create, store, and periodically rotate these secrets to keep receiving the telemetry data that they need. This recurring maintenance adds operational overhead and increases the risk of ingestion outages that occur when secrets expire.

The Agent Baseline: 35 controls, but where should you start?

Two weeks ago, we published the Agent Baseline alongside Docker and Keycard. In it, we describe six security outcomes, 35 controls, and an open reference architecture for running AI agents at the enterprise level. Last week, we stress-tested it: we took it to a panel at Black Hat and spent about one hour being asked hard questions about it. Play Video: Snyk x Docker x Keycard | Agent Baseline Panel @ Black Hat 2026 The most useful question came from someone who had actually already read it.

Reflections from Black Hat: Speed Is Table Stakes. Resilience Is the Win.

Black Hat 2026 came just weeks after the Five Eyes cybersecurity agencies — CISA, the UK’s NCSC, Australia’s ACSC, Canada’s CCCS, and New Zealand’s NCSC-NZ — issued a joint statement to boards and executives with the blunt message that AI is rewriting the rules of cyber risk, the window between vulnerability and exploitation is shrinking, and organizations have a matter of months to adapt.

Microsoft Defender Patch Bypass: High Severity Zero-Day Privilege Escalation (CVE-2026-50656/RoguePlanet, ShieldBreak)

A critical zero-day vulnerability (CVE-2026-50656/“RoguePlanet”) in Microsoft Defender’s Malware Protection Engine (mpengine.dll) enables local users, including standard, low-privilege accounts, to escalate privileges to NT AUTHORITY\SYSTEM using a race condition and improper link resolution. Microsoft initially issued a patch (Engine v1.1.26060.3008) in July 2026.

The Industrialized Fraud Hiding in Plain Sight

To read more on this story and the significance of Business Email Compromise (BEC), visit The Wall Street Journal where Dave Burg was interviewed (subscription required). A few months ago, scammers hijacked a routine infrastructure project in Surfside Beach, South Carolina, costing the small town $545,000. The scheme stemmed from a single spoofed email sent from a lookalike domain, instructing the town to switch payment from check to ACH.

Black Hat Proved AI Agents Are Already the Attack Surface

Enterprise AI agents stopped being a pilot project a while ago. They read email, touch source code, operate browsers, and increasingly make decisions inside production systems, which means the security model built for chatbots and prompts no longer covers what is actually happening inside the enterprise. Black Hat USA 2026 turned out to be the week that gap became impossible to ignore.

Coding Agent Risk for CISOs: Blast Radius, Governance, and Where to Start

Claude Code, Cursor, GitHub Copilot, and Gemini CLI are running on developer machines across your enterprise right now. They're browsing the web, writing to your filesystem, committing code to your repositories, and calling external APIs under the identity of your engineers. Most security teams have no visibility into any of it. This isn't a future problem.