Non-Human Identity Security Starts With This Simple Question
Blog Published: 08/14/2026
Most security teams know they have a non-human identity problem. Fewer have a shared language for describing it. Non-Human Identities (NHIs) are the digital gatekeepers for the automated world. They enable code, applications, services, devices, and agents to authenticate and access resource...
Multi-Cloud Data Pipelines: Why Key Management Can’t Be an Afterthought
Blog Published: 08/25/2026
Data pipelines are rarely simple anymore. A typical enterprise pipeline might ingest data in AWS, process it in Azure, send a subset to a SaaS analytics platform, and store the results in Google Cloud. That useful flexibility also creates a security problem. Every stage that processes or tran...
New Chaos Malware Variant Exploiting Misconfigurations in the Cloud
Blog Published: 08/12/2026
Originally published by Darktrace. Introduction To observe adversary behavior in real time, Darktrace operates a global honeypot network known as “CloudyPots”, designed to capture malicious activity across a wide range of services, protocols, and cloud platforms. These honeypot...
MAESTRO Analysis of OpenAI and Anthropic Agent Hacking Incidents
Blog Published: 08/13/2026
Two evaluation escapes in one week. Mapped onto the seven MAESTRO layers, one is an operations failure, and the other is an alignment failure, and the fix lists barely overlap. In the last two weeks of July 2026, two frontier labs published the same headline and two completely differ...
Artificial Intelligence (AI) Emerges as an Attack Enabler and Target in Cloud Security Alliance’s 2026 Top Threats Report
Press Release Published: 08/13/2026
Identity, AI, software supply chains, and interconnected cloud ecosystems displace traditional infrastructure as top security concerns SEATTLE – Aug. 13, 2026 – Security practitioners are increasingly concerned about the impact of AI on cloud security, according to the findings of the Top...
SOC 2 vs. HITRUST: Which Framework is Right for Healthcare Organizations?
Blog Published: 08/17/2026
Healthcare organizations face growing pressure to protect sensitive patient data while meeting strict regulatory requirements. Two of the most recognized cybersecurity and compliance frameworks in the healthcare space are SOC 2 and HITRUST. While both frameworks strengthen security posture an...
When Tokenmaxxing Leads to Riskmaxxing
Blog Published: 08/18/2026
AI fluency and tokenmaxxing are the new corporate obsessions. But where leadership sees opportunity, security sees friction. It’s no longer enough just to do your job well. Across industries, employees are expected to weave AI into every workflow so they can 10x productivity and innovation.&...
When the Playbook Breaks: AI Incident Response for Systems That Don't Behave Like Anything Else
Blog Published: 08/14/2026
Three years after the explosion of GenAI in the enterprise, most organizations now have an inventory of their AI systems, an acceptable use policy, and — at best — a process for approving AI use cases. Far fewer, however, have answered a seemingly simple question about AI Incident Response: w...
Downwind of the Labs
Blog Published: 08/17/2026
One of the first things they teach you in hazmat response is to stage uphill and upwind. (And the rule of thumb: if you can’t cover the scene with your thumb, you’re too close). Before you treat a single patient, before you even get out of the truck, you figure out where the plume is going. W...
Legacy Operating Models Can’t Keep Pace With IT Complexity, Cloud Security Alliance Survey Finds
Press Release Published: 08/18/2026
Study reveals that fragmented ownership and limited visibility have made manual policy management a production risk SEATTLE – Aug. 18, 2026 — Fragmented operating models spanning teams, tools, and environments and which are still heavily reliant on manual processes are taking a measurable t...
AI Governance Programs: What CISOs Say vs. What They Actually Do
Blog Published: 08/31/2026
Security leaders have heard the phrase “AI has expanded the attack surface” enough times. The more interesting story is the widening gap between what CISOs say they're doing about it and what's actually happening inside their organizations. I got to test this disconnect at a recent private C...
We Asked an AI Agent to Close a Linear Ticket. It Dropped a Production Table.
Blog Published: 08/21/2026
Originally published by Eve Security. A developer opens Cursor, points it at a Linear ticket, and asks it to implement the fix. Cursor loads ticket-work, a small skill that standardizes how the agent pulls context from Linear and closes tickets. It’s the kind of utility a team writes on...
The New Face of Identity Attacks: Why Phishing No Longer Needs Your Password
Blog Published: 09/08/2026
For years, cybersecurity awareness has revolved around a familiar set of best practices: create strong passwords, enable multi-factor authentication (MFA), and think twice before clicking on suspicious emails. Those recommendations remain important, but they were designed for a threat landsca...
Why Cloud Security Requires More Than Point-in-Time Audits
Blog Published: 09/09/2026
An organization may pass its annual cloud security audit with every control in place. Yet days later, a misconfigured storage bucket, an overly permissive IAM policy, or an insecure firewall rule can alter its security posture. The audit report remains unchanged, but the environment no longer...
EU AI Act Compliance for High-Risk AI Systems: What Your Organization Needs to Know
Blog Published: 09/03/2026
A Q&A about the EU AI Act with Schellman CEO Avani Desai on risk classification, AI literacy, and the August 2 deadline Schellman CEO, Avani Desai, recently joined a DataCamp panel webinar, "Deadline Approaching: EU AI Act Compliance for High-Risk AI Systems", alongside Jessica Eaves Mat...
How Attackers Abuse the Chinese Nezha Monitoring Tool
Blog Published: 09/10/2026
This blog examines how attackers abuse the Chinese-developed Nezha monitoring tool, a legitimate open-source platform with remote access capabilities. Darktrace analysis of a honeypot intrusion highlights malicious deployment via containers, demonstrating how dual-use software enables stealth...
MITRE's New Continuous Remote Attestation Framework for the AI Era
Blog Published: 09/02/2026
As AI makes decisions on infrastructure that changes by the minute, MITRE is formalizing how to verify those systems stay trustworthy while they run, not just when they boot. Why MITRE built a new framework For most of computing history, we verified a system once and trusted it fro...
MITRE's New Framework: Securing the eBPF Layer Your AI Depends On
Blog Published: 09/09/2026
AI systems are increasingly making automated decisions on telemetry drawn from the kernel. MITRE's new Framework for Continuous Remote Attestation names the layer where that telemetry can be quietly corrupted, and it is the layer the industry has spent the least time defending. In cloud-nati...
State of AI Cybersecurity 2026: 77% of Security Stacks Include AI, But Trust is Lagging
Blog Published: 08/24/2026
Originally published by Darktrace. AI is now embedded throughout the cybersecurity stack, but findings from the State of AI Cybersecurity 2026 show that adoption is growing much faster than trust or understanding. As vendors strive to capture market share, security leaders must learn how t...
Beyond Deepfakes: Zero Trust Security for the AI Economy
Blog Published: 08/20/2026
TL;DR: Deepfakes are not merely a detection challenge. They expose fundamental weaknesses in how organizations establish identity, grant authority, and protect data. Appearances alone can no longer serve as proof. CSA research shows how Zero Trust, IAM, and AI data security can provide the tr...