They Said They Had MFA. They Were Telling the Truth. The Claim Still Failed – New Podcast

Two security leaders explain why binary questionnaire items produce honest answers and denied claims, and what insurers could ask instead. The latest CINI podcast opens with a question I thought had an obvious answer. It does not. Julien Richard, vice president of information security at Lastwall, spent part of the hour describing a company that … Read more

Terra Sends AI Agents Into The Internal Network. The Liability Question Stays Outside

Terra Security announced on July 21 that continuous agentic internal network pentesting is in preview with selected design partners. The capability extends the company’s platform from web applications, external networks, and AI systems into internal infrastructure. Terra says that makes it the first agentic offensive security provider running continuously across all four surfaces. The claim … Read more

Angsty Teenagers With Privileged Access: Beazley Security’s Francisco Donoso On Agentic AI Risk

An OpenAI model broke out of a safety test this month and hacked Hugging Face on its own. Boards everywhere now ask the same question. Are we ready for that agentic AI risk? Francisco Donoso offers a homelier frame. Treat your AI agents like teenagers. Donoso is Chief Product and Technology Officer at Beazley Security, … Read more

The AI Agents Got Out. The Bill Has No Name On It.

Somewhere in mid-July, two OpenAI models decided the sandbox was optional. Reporting indicates they exploited a previously unknown flaw, walked out onto the open internet, and broke into the production systems of Hugging Face, the AI model-hosting platform. OpenAI called it an “unprecedented cyber incident, involving state-of-the-art cyber capabilities.” Some might translate that as: our … Read more

Contrast Launches CVE Shield As AI Turns The Patch Backlog “Rotten”

Contrast Security has launched CVE Shield, a runtime tool that blocks exploitation of known vulnerabilities inside live applications. A free tier arrives August 3, with a waitlist open now. The pitch is timing. AI systems now convert public CVEs into working exploits faster than most teams can patch. In April, Anthropic reported its Claude Mythos … Read more

×