Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

What Is Prompt Injection, Really? Why the Textbook Answer Cannot Tell You If You Have an Incident

Prompt injection is three things happening at once. The definition written in 2022 described a model that followed an instruction hidden in the text it was asked to translate. The definition needed in 2026 describes an agent that read a support ticket and then queried a customer table it had never touched, using a service account nobody had revoked. Those are the same attack.

How To Control Which WordPress Abilities an MCP Client/AI Agent Can Use

Connecting ChatGPT, Claude, or another AI agent to WordPress can turn simple instructions into real website actions. An agent can create posts, update pages, upload media, manage orders, and handle other tasks when the right MCP tools are available. The interesting part starts when you decide how much access to give it. A content management agent may need posts and media, while a WooCommerce support agent may need orders and customer information.

The Truth About Insider Threats: AI, Paranoia & Hybrid Work | MSP Series

Every organization thinks insider threat is someone else's problem — until it isn't. Join host Alex Courson as she sits down with two leading experts who have spent their careers on the front lines of insider risk: Shawnee Delaney (former CIA-trained DIA case officer and CEO of Vaillance Group) and Peter Hadjigeorgiou (Field CISO at Teramind). Whether you run a business, work in IT, or manage people in a remote, hybrid, or in-office environment, this conversation is for you. We dive deep into AI in the workplace, workplace paranoia, and how organizations need to evolve to drive real change.

Hot Take: Over-permissioned agents will be the next big breach.

The next big breach won't be a hacker. It'll be an over-permissioned agent. Someone approved an agent action at some point, for a reason that made sense at the time. But access persisted long after a task was performed. Stale permissions without human intervention could turn into exposure. Listen to perspectives from people who see this problem from different roles.

Introducing Adaptive Intelligence: Undermining the economics of every bot attack

Modern bot threats are increasingly driven by determined, sophisticated attackers. Often it is not even one person, but a group trading techniques with each other or a commercial service sold to anyone willing to pay. For many of them, getting past bot detection is a full-time job they genuinely enjoy. Block them and they get to work, finding a workaround. AI has simplified this further, making it even easier to set up complex configurations for attackers, lowering the overhead of an attack.

How Zenity Implements the 2026 OWASP Top 10 for LLM Applications

Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know Every AI security framework names the risks you have to control. Zenity is built to implement those controls at runtime. Here's the 2026 OWASP Top 10 for LLM Applications, entry by entry, with the gaps marked honestly. Paste a booby-trapped instruction into a chat window, and nothing much happens.

The Trillion-Dollar AI Bet Needs a Security Strategy

AI agents have now proven, in the real world, that autonomy without a security model is a liability. At Arctic Wolf, we’ve spent years watching that same lesson play out with cloud migrations, remote work, and every other rush of new technology, and this is that pattern showing up again, just faster.

Secure What Agents Do, Not Just What They Say

Salt Security and CrowdStrike give joint customers visibility across the full agentic path, from the model to the system where the action lands An employee at a bank asks an AI assistant a routine question. How much money is in my savings account? The assistant answers correctly. The prompt was legitimate. The response was accurate. A model-layer security control inspects both and finds nothing wrong, because nothing is wrong with either. Now look at what happened in between.

Has security taken a back seat to productivity?

We told everyone to adopt AI, and they did. Almost anyone can now produce polished, professional work in seconds. The newest shortcut behind that speed is skills: small files that hand an AI agent a new ability. Skills are also where the risk now sits. One file can hold dozens of instructions and actions, so anything buried inside travels with it, and the agent follows all of it without asking. Most of those agents run unwatched, so the speed you gained is now exposure nobody in the business is measuring.