Articles by Category: Security_compliance

Rethinking infrastructure access in the age of agentic AI

2026-06-04 07:09
🔍 The rise of agentic AI is reshaping identity and access management (IAM). Traditional IAM models are not sufficient for AI agents, which operate in unpredictable ways and require direct access to critical resources. 🔐 HashiCorp Boundary addresses these challenges by providing secure, just-in-time (JIT) access and unique identities for AI agents. This ensures tighter control over permissions and enhances monitoring of agent activities. 📊 With built-in auditing and session recording,...
Van Phan

Audit trails are a feature, not a compliance tax

2026-06-04 00:00
Audit trails play a crucial role in today's digital landscape. Originally designed for compliance, they now help close deals and ensure accountability for AI agents. These logs are essential for reconstructing breaches, making them a valuable asset for businesses. Embracing audit trails benefits both security and operational efficiency. 🔍📊 #AuditTrails #CyberSecurity #AIAccountability #BusinessGrowth #Compliance
Source: Webflow Blog

ISO 42001:2023 and the New Reality of Cloud AI Data Risk

2026-06-04 00:00
🌐 As organizations embrace AI, data security challenges grow. ISO 42001:2023 introduces a framework for managing AI systems, focusing on data usage and risk assessment. Traditional security tools often fall short, lacking visibility into dynamic data flows. Falcon Data Security for Cloud offers insights to track sensitive data, aiding compliance and governance. #DataSecurity #AIManagement #ISO42001 #CloudSecurity #RiskManagement
Luke Hunsinger - Ofer Dekel

How to get operational data off the factory floor without creating an IT breach

2026-06-03 19:55
Navigating the integration of operational technology (OT) and informational technology (IT) is crucial in the AI era. The article highlights the need for efficient data transfer from factory floors to IT systems without compromising security. Traditional methods can lead to data breaches and operational failures. Managed solutions with strong encryption and continuous monitoring are emerging as key to overcoming these challenges. For insights and solutions, join the discussion with Fortra’s...
Alex Wilhelm

What is Software Supply Chain Security?

2026-06-03 18:24
Software supply chain security is crucial in today's software development landscape. According to Sonatype's 2026 report, over 454,000 malicious packages were published in 2025, bringing the total to over 1.2 million since 2019. This highlights the growing risks as organizations increasingly rely on open source and complex delivery pipelines. Effective supply chain security safeguards every stage from code to deployment. It requires trusted content and a proactive approach to manage...
Source: Docker Blog
Aditya Tripathi

Protecting SaaS AI Agents with Cisco AI Defense and AppOmni

2026-06-03 16:51
🚀 Enterprise AI agents are now integral to platforms like ServiceNow and Microsoft 365, handling diverse tasks from IT support to finance. Organizations face a challenge in securing these agents, especially when they operate within applications they don’t control. 🔐 Cisco AI Defense and AppOmni have partnered to provide robust runtime guardrails for these SaaS AI agents. The integration enables real-time monitoring and protection against security threats, ensuring safe interactions. This...
Spencer Colemere

AI Agents Need Built-In Security. Here Is How Cisco Does It

2026-06-03 16:51
🚨 Security Alert in AI! 🚨 In February 2026, researchers uncovered a major security threat involving the SmartLoader malware, which cloned a legitimate server connecting AI assistants to health data. This attack highlighted the risks of supply chain vulnerabilities in AI integration. To address these concerns, Cisco has introduced AI Defense within its Agent Builder platform. This feature provides built-in security at every stage of the AI lifecycle, ensuring third-party integrations are...
Siddhant Dash

Layered Defense for the Plant Floor: Simplifying OT Security

2026-06-03 14:00
Cisco emphasizes the need for enhanced security in industrial IoT environments. As AI rapidly exploits vulnerabilities, traditional patching methods struggle to keep pace. Their approach integrates segmentation and secure remote access, shifting from reactive monitoring to proactive protection without disrupting operations. Stay ahead of threats with Cisco Cyber Vision. 🔐🌐 #CyberSecurity #IndustrialIoT #CiscoLive #OTSecurity #AI
Samuel Pasquier

Extending Zero Trust Across the Agentic AI Workflow

2026-06-03 12:00
Cisco is enhancing Zero Trust principles to better manage agentic AI workflows. 🤖 The focus is on continuous evaluation of agent actions across various tools and applications, rather than just initial access control. This shift acknowledges that agents act autonomously and require ongoing oversight. Traditional controls fall short as they rely on static authentication and human judgment. Cisco Secure Access aims to address these challenges by evolving from access control to action control. 🔒...
Prabhat Singh

White House AI Executive Order: Advancing Innovation & Security

2026-06-02 20:52
The White House has unveiled an executive order aimed at promoting AI innovation and security. Cisco CEO Chuck Robbins highlighted the order as a crucial advancement in cybersecurity, emphasizing the need for rapid development of security patches. This initiative aims to enhance national security while fostering responsible innovation in the private sector. The focus is on equipping defenders with advanced tools to keep pace with cyber threats. 🤖🔒 #AI #Cybersecurity #Innovation...
Josh Falzone

“A successful attack could be catastrophic”: Anthropic gives more groups access to Claude Mythos

2026-06-02 18:51
Anthropic has raised concerns about the potential dangers of a successful attack on their codebase, warning it could impact over 100 million people and affect global security. ⚠️ In response, they are expanding Project Glasswing, allowing around 150 new organizations secure access to Claude Mythos Preview, their advanced AI model. 🤖 This model has already identified thousands of vulnerabilities, highlighting the need for responsible usage in cybersecurity. 🔍 #AI #Cybersecurity...
Adrian Bridgwater

How to Secure AI Agents: A Practical Overview for Development Teams

2026-06-02 16:11
🌐 AI agents are rapidly advancing, but security practices are not keeping pace. 🔒 A recent report reveals that 45% of organizations struggle to secure their AI tools. Traditional security models don't apply as agents operate autonomously, using multiple tools without human approval. 💡 Key security domains for AI agents include execution isolation, tool access control, identity management, and runtime monitoring. Effective security relies on infrastructure-level controls, not just permission...
Source: Docker Blog
Jackie Frederick

Strengthening the Foundation: A Predictable, Customer focused Response to AI-Accelerated Vulnerability Discovery

2026-06-02 13:00
🚀 Cisco is adapting to the rapid pace of AI-accelerated vulnerability discovery. Starting in July, they will implement a scheduled security release model, providing updates twice a month. 🔍 Customers will receive a seven-day advance notice on the technologies covered, enhancing planning and preparation. Core Network Operating Systems will be prioritized for quarterly releases. 🔒 This proactive approach aims to improve security and streamline updates across the portfolio. #CyberSecurity #Cisco...
Russ Smoak

Quantum Resilience Needs a Common Language. Here’s Where to Start.

2026-06-02 13:00
The article discusses the urgent need for a common language in quantum resilience as the industry moves towards quantum-safe security. Organizations face challenges due to fragmented standards and varying vendor claims about quantum safety. Recent developments in post-quantum cryptography (PQC) highlight the importance of clarity and standardized protocols. The lack of a shared framework complicates understanding and progress in ensuring network and data protection against future quantum...
Christian Chisholm

Security at Cisco Live: Going Shields Up for the Agentic Era

2026-06-02 13:00
At Cisco Live, the focus is on enhancing security in the age of AI. 🌐 AI is transforming how vulnerabilities are discovered and addressed. Cisco emphasizes the need for a proactive security posture, termed "Shields Up." This involves hardening infrastructure and prioritizing defensive measures to keep pace with rapid attacks. 🔒 Key imperatives include securing AI infrastructure and applications while utilizing agents to accelerate response times. Cisco is committed to strengthening defenses...
Peter Bailey

How to Stop AI-Driven Data Loss

2026-06-02 00:00
AI is transforming workplaces, boosting productivity through automation and advanced tools. However, this progress comes with risks of data loss if not managed properly. Employees may inadvertently share sensitive info with AI systems, leading to potential breaches. Additionally, prompt injection can expose confidential data if AI models are manipulated. Traditional security methods may not suffice against these new challenges. Organizations must adopt modern data security solutions to...
Hananel Livneh

Protecting critical infrastructure in the AI era: It starts with data

2026-06-02 00:00
In the AI era, protecting critical infrastructure is crucial. As systems become more interconnected, the risk of cyber threats increases. AI-powered attacks are growing in sophistication, highlighting the need for modern security solutions. Organizations must focus on building a strong data foundation to safeguard sensitive information and enhance response times. Discover how to tackle these challenges and improve resilience in the face of evolving threats. #CyberSecurity #AI...
Source: Elastic Blog
Alf Franklin

Security update: multiple vulnerabilities in React Router

2026-06-02 00:00
🚨 **Security Alert for React Router** 🚨 The React Router team has identified seven security vulnerabilities affecting various versions. Key issues include denial-of-service (DoS), cross-site scripting (XSS), and open redirects. Netlify users are advised to upgrade to the latest patched versions to ensure security. Affected packages include `react-router` and `@react-router/dev`. 👉 Recommended versions: - `react-router` 7.15.1 or later - `@react-router/dev` 7.13.2 or later (if using...
Source: Netlify Blog

Vercel’s Tom Occhino on why access control is product architecture

2026-06-02 00:00
In the latest episode of the Zero-Shot Learning podcast, Tom Occhino of Vercel discusses the impact of AI on developer workflows. He emphasizes that access control must be integrated into product architecture, especially as non-technical users leverage AI tools. This shift requires new security measures to prevent exploitation of untrusted code. 🛡️ Vercel's AI SDK, alongside 1Password's Unified Access, aims to ensure secure interactions while minimizing risks associated with credential...
info@1password.com (Chris Fowler)

OpenAI, Anthropic, Google, Amazon, and xAI all fail on type of attack, study finds

2026-06-01 21:01
Recent research by Cisco reveals that AI safety benchmarks may not accurately assess model performance. The study evaluated 15 models from OpenAI, Anthropic, Google, Amazon, and xAI. Key findings show that all models struggled in multi-turn attacks, with success rates varying significantly. Single-turn assessments do not reliably predict multi-turn resilience, highlighting a critical gap in current evaluation methods. Interestingly, while Anthropic's Claude family performed best in multi-turn...
Darryl K. Taft

What is Sandbox Security?

2026-06-01 15:51
🔒 **Understanding Sandbox Security** 🔒 Sandbox security is crucial for maintaining isolation in environments where AI agents operate. It enforces policies and controls to prevent threats from escaping containment. According to a recent report, 40% of respondents see security as a major challenge in scaling agentic AI. As AI agents execute code, robust security measures are essential. Key components include process isolation, network segmentation, resource limits, and runtime monitoring. These...
Source: Docker Blog
Srini Sekaran

Coding Agent Horror Stories: The rm -rf ~/ Incident

2026-06-01 13:00
🚨 In Part 2 of our AI Coding Agent Horror Stories series, we delve into a real incident that highlights the vulnerabilities of AI coding agents. A developer’s request to clean up an old repository led to the deletion of their entire home directory due to a single command error. This illustrates the risks of AI agents executing commands without safeguards. Learn about the implications of such failures and how Docker Sandboxes can provide crucial isolation. #AICoding #Cybersecurity #Docker...
Source: Docker Blog
Jennifer Kohl

Cisco Secure Access and Island Browser Enable Zero Trust Everywhere

2026-06-01 12:00
Cisco has partnered with Island to enhance secure access through a zero trust model. This integration allows organizations to provide safe access to applications for various users on both managed and unmanaged devices. Cisco Secure Access verifies user identity and device posture, while the Island browser embeds security measures directly into user sessions. This combination ensures continuous security from login to data interaction. Explore how this partnership is reshaping the approach to...
Allon Ram

From Log Flood to Threat Signal: Cisco and Splunk Bring Context to Modern Defense

2026-06-01 12:00
Cisco and Splunk are enhancing security by improving visibility across hybrid environments. With richer product telemetry from Cisco, teams can better detect and investigate threats, moving from isolated alerts to comprehensive risk assessments. The Cisco Isovalent Enterprise Platform offers real-time insights, helping analysts understand suspicious behaviors more effectively. 🔍🔒 Stay ahead in threat detection! #CyberSecurity #Cisco #Splunk #ThreatDetection #HybridCloud
Vignesh Sathiamoorthy

Advancing AI Infrastructure for Agentic AI with NVIDIA DOCA In-Silicon Security

2026-06-01 04:21
The rise of AI is leading to the development of AI factories, which transform data into intelligence for autonomous agents. These infrastructures enhance speed and efficiency in AI training and deployment. 🚀 However, the adoption of agentic AI introduces new security challenges. Traditional security systems are not equipped to handle the complexity and scale of AI factories, making them vulnerable. 🔒 NVIDIA's BlueField DPUs offer a solution with in-silicon security, enhancing protection...
Ofir Arkin

“The AI did it” won’t save you when EU regulators come knocking

2026-05-29 14:00
The EU's Cyber Resilience Act (CRA) is set to revolutionize accountability in software development. With key compliance deadlines approaching, organizations must prepare for new regulations aimed at protecting consumers from cyber threats. 🗓️ Important dates to note: - Sept 11, 2026: Reporting obligations for exploited vulnerabilities begin. - Dec 11, 2027: Major obligations for developers kick in. The CRA applies to nearly all connected products, making no distinction between human-written...
Luis Villa

Protecting against inference theft

2026-05-29 04:00
Protecting AI endpoints is crucial as inference theft becomes a significant risk. 💻 With costs of AI prompts soaring, attackers can exploit these systems for profit. Traditional defenses like IP rate limits are no longer effective, as attackers use sophisticated methods to bypass them. 🔒 Implementing verification for each request is essential. Vercel uses BotID deep analysis to safeguard against these threats. Protect your AI systems by auditing exposed endpoints and ensuring every request is...
Source: Vercel Blog
Eric Dodds

Protecting against token theft

2026-05-29 04:00
Protecting AI endpoints from inference theft is crucial. With the high cost of AI calls, attackers can exploit vulnerabilities, leading to significant financial losses. Vercel emphasizes the need for verification on every request, not just at the session start. Traditional defenses like rate limits are insufficient against sophisticated attackers who can bypass these measures. Implementing solutions like BotID deep analysis can help detect and block malicious requests effectively. Stay...
Source: Vercel Blog
Eric Dodds

Shadow AI: The Hidden Risk Expanding Across the Enterprise

2026-05-29 00:00
🚨 Shadow AI is becoming a growing risk for organizations as employees use unauthorized AI tools without proper security measures. 📈 Security teams face challenges in tracking AI usage and protecting sensitive data. Many lack visibility into AI services and the data being shared, leading to potential data leaks and compliance issues. 🔍 As AI-specific threats like prompt injection emerge, traditional security solutions may not be effective. It's crucial for organizations to adapt and enhance...
CrowdStrike

In the AI era, defense starts with the network. Here’s how Cisco is doing it.

2026-05-28 19:40
In the AI era, networks are vital for defense. Cisco emphasizes the importance of integrating security into its network to combat AI-driven threats. IT and Security leaders Jon Woolwine and Jack Klecha discuss their strategic approach to maintaining network security. For more insights, check out the full article and video! 📡🔒 #Cisco #Cybersecurity #AI #Networking #TechTrends
Jack Klecha

The agentic identity crisis: Why your security isn’t ready for the AI revolution

2026-05-28 12:00
The article discusses the shift from traditional web applications to AI-driven agentic ecosystems. This transition presents new security challenges as AI agents can perform actions, leading to vulnerabilities like the Action-Based Threat Model and the RAG Attack Surface. Currently, agents operate in an Identity Vacuum, creating risks of unauthorized access and permission issues. As AI agents outnumber humans, addressing these security gaps is crucial. 🔐🤖💻 #CyberSecurity #AI...
Justin Dolly

A new model for infrastructure security: How Cisco defends against AI threats

2026-05-27 18:33
Cisco is evolving its approach to infrastructure security in response to AI threats. Through Project Glasswing and Daybreak, Cisco emphasizes the need for continuous risk management rather than annual checks. AI tools can exploit vulnerabilities previously deemed low-risk, necessitating a shift in cybersecurity strategies. This change impacts not only Cisco but also all enterprises navigating the evolving threat landscape. Stay informed and adapt. 🔒🛡️ #Cybersecurity #AIThreats #Cisco...
Jason Lish

“There is no accountability”: AI coding agents are installing packages no one owns

2026-05-27 17:38
AI coding agents are changing software development, but as Willem Delbare from Aikido Security points out, "there is no accountability." This situation leaves companies vulnerable as AI installs packages without clear ownership of risk. 🛡️ Aikido's new solutions, like Aikido Endpoint, help monitor and block malware before installation, enhancing security while allowing developers flexibility. 🔍 The market is responding, with companies like Socket and Endor Labs also focusing on preventing...
Darryl K. Taft

Private analytics via zero-trust aggregation

2026-05-27 16:56
Introducing a private analytics solution that enhances security and privacy through innovative cryptographic protocols. 🔒✨ This new approach processes data locally, allowing on-device AI to offer timely alerts while safeguarding user information. Android’s SafetyCore exemplifies these privacy-preserving features. By implementing a zero-trust principle, the solution ensures only anonymized, aggregated insights are accessible, maintaining transparency and trust. 🔍 #Privacy #CyberSecurity...

Mitigating CVE-2026-31431 (“Copy Fail”) in Docker Engine

2026-05-27 13:00
🚨 A new Linux kernel vulnerability, CVE-2026-31431 (“Copy Fail”), has been disclosed. While it does not compromise Docker infrastructure, Docker Engine versions prior to v29.4.3 allowed certain risks. Docker containers could create AF_ALG sockets, which the exploit uses. If you're using Docker Engine v29.4.3 or have a patched host kernel, you’re safe. 🛡️ For those on unpatched systems, a kernel fix is available for Debian and RHEL 9, but not yet for Ubuntu. Upgrading Docker Engine can help...
Source: Docker Blog
Paweł Gronowski

Securing AI Agents in Healthcare and Life Sciences

2026-05-27 00:00
🚀 Healthcare organizations are leveraging AI agents with Amazon Bedrock and Auth0 to enhance security and efficiency. 🌐 79% of HCLS organizations report AI adoption, but 69% face security concerns like data leakage. This integration aims to address these issues. 💊 A key application is AI-powered prescription management, which streamlines the process from patient authentication to fulfillment, ensuring secure, contextual interactions. #HealthcareAI #DataSecurity #AIIntegration #DigitalHealth...
Source: Auth0 Blog

Reconciling the Past: Correcting Records for Unfixed Kubernetes CVEs

2026-05-26 17:30
🚨 Important Update for Kubernetes Users 🚨 The Kubernetes project is correcting CVE records for several unfixed vulnerabilities. These updates, effective June 1, 2026, will ensure accurate documentation and enhance security awareness. Key vulnerabilities include: - **CVE-2020-8561**: Medium severity issue with webhook redirects. - **CVE-2020-8562**: Low severity proxy bypass via DNS. - **CVE-2021-25740**: Low severity cross-namespace forwarding flaw. These changes aim to improve automation...

Securing campus and branch networks from boot to transport with full-stack PQC

2026-05-26 15:00
🔒 Quantum threats are becoming a pressing issue as attackers can capture encrypted data today for future decryption. Cisco's full-stack post-quantum cryptography (PQC) offers protection across the entire network stack, from secure boot to data transport. This approach integrates NIST-approved algorithms to safeguard devices and data. The Cisco C9000 Smart Switches lead the way by embedding quantum-safe algorithms from the hardware level. This ensures security from the moment the device powers...
Albert Chiang