Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Is your AI system secure enough? MITRE ATLAS Is Now Law.

For the first time anywhere, the MITRE ATLAS framework and the OWASP Top 10 for LLM applications are written into binding law. Article 15 names data poisoning, model poisoning, adversarial examples, model evasion and confidentiality attacks as threat classes you must have technical measures against—and must be able to evidence to a regulator. The question is no longer whether you have thought about AI security. It is whether you can prove your AI system holds.

Ep. 73 - EU AI Act-What Actually Lands on August 2nd, and What Slipped to 2027

The EU AI Act's August 2nd, 2026 deadline just changed shape. Host Tova Dvorin and offensive security engineer Adrian Cully separate what actually lands—Article 50 transparency duties and GPAI enforcement powers—from the high-risk obligations that slipped to December 2027. Inside: Article 15 writes MITRE ATLAS and the OWASP LLM Top 10 into binding law, the DORA / NIS2 / AI Act overlap that makes one incident reportable three times, penalties up to 7% of global turnover, and the five things a CISO should do this week. Part 1 of 2.

AI Security Posture Management: What It Covers and What It Misses

AI Security Posture Management arrived as a term before it arrived as a definition. Vendors announced products under the label through 2025 and in volume at RSA Conference 2026, each describing a somewhat different scope, and buyers now evaluate a category whose boundaries depend on who is selling. The lineage is evident, since AI-SPM follows cloud and data security posture management, and the inherited assumptions are where the difficulty starts.

What the OpenClaw Gym Booking Incident Reveals About Agentic and API Security

An Australian man named Andrew asked his personal AI agent, built on the open-source OpenClaw framework and powered by Anthropic’s Claude model, to book him into a popular morning gym class. According to ABC News, the class was full, so the agent started looking for a way around that. It found that the gym’s booking API let bookings be pushed far further into the future than the website’s own interface allowed, a limit that turned out to exist only on the front end.

AI Can't Do CTEM Alone (And Neither Can You)

AI can meaningfully power Continuous Threat Exposure Management (CTEM), but only for specific stages of the cycle: prioritization, validation, and remediation routing. AI can’t replace the underlying data integration work, and it can’t turn CTEM into a single product, because Gartner defines CTEM as a continuous five-stage program (scoping, discovery, prioritization, validation, mobilization), not a tool you install.

The Cloud Controls Matrix (CCM): Manual vs. AI-Assisted Vendor Assessment

Most teams that assess cloud vendors already have a general idea of the Consensus Assessment Initiative Questionnaire (CAIQ) and Cloud Controls Matrix (CCM). However, you may not have a good answer for what it takes to run that assessment. Turning a vendor's trust center page, SOC 2 report, and security policy into a structured, defensible view of CCM control coverage is a different problem entirely.

Why Securing AI Agents Is More Critical Than Ever

AI agents offer unprecedented capabilities, speed, automation, deep context, and hyper-personalization, that will transform how we work. However, these same capabilities make AI agents significantly more dangerous than traditional software when hijacked by cybercriminals. You simply cannot rely on yesterday's risk management playbooks to handle today's AI-driven threats.

How Can Scrum Masters Integrate AI Tools Effectively Into Daily Work?

Scrum Masters help teams optimize workflow and improve product value. But with frequent business demands, priority shifts, and the rapid adoption of AI by companies, Scrum professionals need to integrate AI tools into their daily work to help enhance their team's productivity to the maximum. When you start your SSM certification journey with organizations like Simpliaxis, you can learn how to incorporate AI into the Scaled Agile Framework and lead Agile teams by becoming a certified SAFe Scrum Master licensed under Scaled Agile.

Smart Home Security Is Only Half the Job: Physical Weak Spots Homeowners Often Miss

Smart locks, video doorbells, motion sensors, and connected cameras have changed what home security looks like. You can check the front porch from another state, lock a door from your phone, or get an alert when someone walks into the backyard. Useful? Absolutely. Complete protection? Not quite. A smart home still depends on ordinary doors, windows, garages, exterior walls, and a network of devices that need attention. Some weak spots are digital. Others are surprisingly low-tech. A better approach is to look at the house as a series of security layers and check what could fail in each one.

Top 10 AI Agents for Legal Research in 2026 (Case Law, Statutes and Drafting)

Legal research rewards the tool that shows its sources, not the one that sounds most confident. The right pick turns less on brand than on whether your priority is model choice, case-law depth, or deployment security. The wrong platform hands you a fabricated citation, a confidential contract fed to a model that trains on it, or a bill for the wrong vendor's LLM. This guide ranks the ten agents US legal teams are shortlisting in 2026.