-

Zero Trust at AI Speed: When You Can’t Patch Fast Enough, Shrink the Exposure
Attackers now exploit vulnerabilities before patches exist, and AI is finding flaws faster than anyone can fix them. Zero Trust limits who can reach an unpatched system through identity-based access, microsegmentation, and audit logging.
-

OpenAI Publishes Third-Party Assessment Framework, Handing Buyers New Oversight Language
OpenAI published a framework outlining how independent assessors should vet its models, providing enterprise buyers with specific procurement language to mandate external safety reviews and manage vendor conflicts of interest.
-

OMB Memo M-26-15 Sets a Hard PQC Deadline for Federal Agencies
OMB Memo M-26-15 imposes a binding October 2026 deadline for federal agencies to submit post-quantum cryptography migration plans, with a full implementation timeline through 2035.
-

NIST Folds Zero Trust Into Draft OT Security Guidance in SP 800-82r4
NIST has published the Initial Public Draft of SP 800-82 Revision 4, expanding OT security guidance to include zero trust architecture and network separation recommendations across industrial sectors.
-

Vectra AI’s FedRAMP High Platform Lands on Carahsoft’s Federal Contracts
Vectra AI’s FedRAMP High authorization, achieved in August through Knox Systems, is now sold through Carahsoft’s federal contract vehicles. The procurement path is clearer; the authorization boundary still needs checking.
-

VMware vDefend Moves to Segment Agentic AI Inside the Data Center
Broadcom plans to extend VMware vDefend’s Zero Trust lateral security to autonomous AI agents, treating them as network entities that can be watched and contained. Announced at VMware Explore on Aug. 31, with no ship date yet.
-

Beyond the Model Card: The AI Failures That Happened in the Harness, Not the Weights
Four AI coding agents deployed the same SHA verification failure, allowing attackers to inject malicious code through plugin repositories. The model itself was never the target.
-

California Orders AI Safety Guardrails and a ‘Kill Switch’ Study
California is advancing AI oversight ahead of federal legislation, establishing new timelines for companies operating…
-

Two Bipartisan Bills Would Turn Voluntary AI Safety Testing Into Federal Law
Two House lawmakers introduced legislation to make AI pre-deployment testing and China supply-chain controls…
-

CISA Wants Decoys Inside Your Zero Trust Network, Not Just at the Perimeter
CISA’s first detailed cyber decoy guide urges critical infrastructure operators to pair honeytokens and tripwires with Zero Trust. The pitch: a low-cost way to catch intruders who log in with valid credentials.



You must be logged in to post a comment.