Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Buying an AI SOC Isn't Like Anything You've Bought Before

John White is the Field CISO for EMEA at Torq. A respected security executive with more than 20 years of leadership experience, John previously served as CISO at Virgin Atlantic, where he led a multi-year transformation deploying the Torq AI SOC Platform to modernize cyber operations. Prior to Virgin Atlantic, he built and transformed security functions for global organizations, including ASOS, Liberty Global, AEG Europe, and KPMG.

Frontier models found the vulnerabilities. Only the attacker found the chains.

Attackers don't read your repository; they hit your URL, and chain together whatever they find. In an era where offensive AI runs against live applications at machine speed, your security tooling needs to go beyond finding vulnerabilities to prove exploitability, including whether they can be combined into a breach.

Autonomous Attacks Are Already Here. The Defense Has to Match Their Speed.

Last week, Snyk CTO Manoj Nair sat down with Alon Krifcher, Head of Applied AI from Anthropic, for a live discussion on the coming wave of autonomous attacks. Manoj kept landing on one thing: the AI Hurricane has already arrived, and what's left is deciding whether your defense runs at the same speed as the threat.

Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance

CrowdStrike Intelligence identified infrastructure associated with a targeted campaign against South Korean financial organizations that resulted in exfiltrated data. The campaign was active from late September to early October 2026. Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor's operational methodology and tooling.

Gemini Never Left the Sandbox. The Sandbox Had a Door.

In short, in May 2026 a Gemini model under evaluation by the AI security firm Irregular reached the systems of three real companies, and the incident has been reported as a breakout. By Google’s own account it was nothing of the kind. The test environment had internet access it was not meant to have, the fictional target shared its name with a real company, and the model found public information online, guessed one password and found two more in public code repositories.

Why Your Collaboration Foundation Matters Most When Adopting AI Tools

Is your leadership team pushing to roll out new AI tools, but your users are still struggling with basic issues like working on large/complex files or collaborating effectively? Then you’re starting off with an ineffective AI adoption plan. AI is becoming an increasingly important collaboration tool, so it’s critical to include it as part of your foundation. You can even think of AI as being your first collaborator.

Building an evidence-grounded agentic security operations harness on Cloudflare

Security alerts rarely arrive one at a time. A single alert can cause a spike across the environment, requiring a human analyst to decide which alerts are related and what they mean. When multiple arrive at the same time, it can quickly overwhelm even a seasoned security analyst. Enter the alert paradox. Now, our built-in, multi-AI-agent security operations harness can handle more of this work at Cloudflare scale.

Five Ways AI Agents Actually Fail, and Why Most Security Programs Are Only Built for Two of Them

Most of the industry discourse on agentic AI risk has settled into a comfortable framing: agents get attacked the way models get attacked, through some form of prompt manipulation, and the fix is a better guardrail. I think that framing is dangerously incomplete, and I want to walk through five specific scenarios that make the case directly rather than abstractly. Two of them are manipulation. One exploits trust between agents rather than any single agent's behavior.

Top 5 Antidetect Browsers for Web Scraping, Research, and Data Collection at Scale

Modern web setup needs strong anti-bot tools. These tools look at what comes in from the web, the browser settings, and what the canvas shows to find bots. People who work in company growth, data, and research often need to pull data from the web. For them, normal headless browsers like Puppeteer or Selenium are easy to spot. To get data many times, you will need tools that can hide your system details in several sessions at once.

5 Best Direct Mail APIs for Automated, Multi-Touch Campaigns

Email has triggers, sequences, and dashboards. For years, direct mail had a spreadsheet and a print deadline. A good direct mail API closes that gap: your software decides who gets a mailpiece and when, and the provider prints, mails, and tracks it. The catch is that "best" depends on the job. A product team embedding transactional notices needs something very different from a marketing team running three-touch campaigns across dozens of clients. I compared Postalytics, Lob, PostGrid, PCM Integrations, and Click2Mail on the factors that actually separate them.