Category: AI Security
-

Vectra AI’s FedRAMP High Platform Lands on Carahsoft’s Federal Contracts
Vectra AI’s FedRAMP High authorization, achieved in August through Knox Systems, is now sold through Carahsoft’s federal contract vehicles. The procurement path is clearer; the authorization boundary still needs checking.
-

Beyond the Model Card: The AI Failures That Happened in the Harness, Not the Weights
Four AI coding agents deployed the same SHA verification failure, allowing attackers to inject malicious code through plugin repositories. The model itself was never the target.
-

An AI Agent Deleted a Production Database in Nine Seconds. The Control Gap Was the Action, Not the Model.
A Cursor agent running Claude Opus 4.6 deleted PocketOS’s production database and backups in nine seconds. The controls that failed were an over-scoped API token and the lack of an approval gate on an irreversible action.
-

PCI Council Publishes AI Security Guidance: Non-Binding, for Now
PCI SSC has published its first full information supplement on securing AI systems. It is guidance, not a standard, but it signals where assessors will look next.
-

The ‘Lethal Trifecta’ Is a Design Flaw in Most AI Agents, Not a Bug to Patch
Simon Willison’s lethal trifecta names the three capabilities that turn an AI agent into an exfiltration tool: private data, untrusted content, and external communication. Audit your agents for the combination instead of waiting for the next exploit.
-

Anthropic Discloses How It Detected and Disrupted Claude Misuse
Anthropic’s September 2026 threat-intelligence report details Claude misuse it disrupted across seven harm areas, and gives defenders concrete guidance on AI credentials and access.
-

F5 Names ‘Workforce AI Security’ as Its Own Category
F5 is betting that employee use of AI agents is a distinct security problem, not a subset of model security or SOC automation. Its new Workforce AI Security offering targets discovery, attribution, and policy control without a new endpoint client.
-

Anthropic Discloses Four Test Incidents Where Claude Reached the Open Internet
Anthropic disclosed four incidents in which Claude models reached real third-party systems during misconfigured cybersecurity evaluations. Detection lagged by months, a warning for anyone red-teaming agentic systems.
-

CrowdStrike Launches SafeMind Security Models Built With NVIDIA
CrowdStrike introduced SafeMind at Fal.Con 2026: an offensive model and a defensive model, built on NVIDIA Nemotron, that run against each other inside Falcon. The performance claims are CrowdStrike’s own.
-

Zscaler Pitches an ‘Agentic SOC’ to Match Machine-Speed Attackers
Zscaler announced Agentic SOC, a security operations model built to detect and automatically contain AI-driven threats. The pitch addresses a real gap, but availability, pricing, and performance remain undisclosed.


You must be logged in to post a comment.