Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

July Release Rollup: Bulk Extraction, Enhanced AI Assistant UI, and More

July's release makes AI more useful across the Egnyte platform, with major enhancements to AI Assistant that make it easier to build agents, create documents, have more natural conversations, and securely connect AI tools through Egnyte MCP Server.

AI's Hidden Identity Risk for MSPs

Organizations are rapidly integrating AI into everyday business operations. Teams are using Microsoft Copilot and Gemini to summarize meetings, developers are accelerating software delivery with coding copilots and customer service teams are deploying AI-powered chatbots to improve response times. While these initiatives are viewed through the lens of productivity and innovation, they are also reshaping organizations’ identity environments in ways that frequently go unnoticed.

AI Governance vs AI Compliance: What's the Difference?

The main difference between AI governance and AI compliance is that AI governance is the internal framework an organization develops to manage AI responsibly, while AI compliance is how organizations demonstrate to external regulators that they’re adhering to applicable laws and regulations. These two terms get used interchangeably, but they solve different problems. With compliance alone, an organization can satisfy regulators without meaningfully controlling how its AI behaves.

How CFOs can manage AI costs and prove business value

Earlier this year, a bill arrived from one of 1Password’s AI vendors for 5x the value of the original contract. The initial agreement came in below a certain threshold, so it never reached the right approvers for review. By the time it did, we had a much clearer understanding of how quickly AI costs can add up.

Zenity Now Integrates with Microsoft Agent 365

AI agents have moved from pilots into broad enterprise use. They read email, query systems of record, take actions, invoke tools, and coordinate with other agents on behalf of employees. Every line of business wants more of them, and security teams are being asked to enable that expansion without losing visibility or control.

Salt Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection

Your WAF is doing its job. It's blocking SQLi, XSS, and the usual suspects. But here's the problem: it wasn't built for APIs, and it definitely wasn't built for AI agents. APIs now power nearly every digital experience. And AI agents — the automated systems that access your APIs at machine speed, at machine scale — are the fastest-growing source of that traffic.

Automate your GRC program with the Vanta Agent

Your compliance program never sits still. Controls drift, tests fail, policies go out of date. The Vanta Agent keeps up. It has full context on your program through Vanta's Trust Graph, so it never hits a dead end. It always recommends the next step. The Trust Graph is Vanta's data and intelligence layer, powered by 400+ integrations that map your risks, controls, policies, and vendors. Add continuous monitoring, risk scoring, automated testing, and framework mapping, and the Agent works with the full picture.

The Control Gap: Why Cyber Defenses Are Falling Behind AI-Powered Threats

Cybersecurity teams have faced major shifts before—from advanced persistent threats to ransomware. Now, Frontier AI is accelerating vulnerability discovery and creating new challenges for defenders. In this episode of Let's Talk Security, Forescout CEO Barry Mainz sits down with cybersecurity evangelist and former practitioner Karsten Abata to discuss the concept of the "Control Gap"—the time between identifying a risk and having the controls in place to effectively contain it.

The AI agent working for you probably has more access than you do

Say a sales rep uses an AI assistant to help manage their pipeline. The rep has role-based access to Salesforce, scoped to their territory and their accounts. The assistant, wired in through an API integration, often doesn't have that same scoping. It authenticates as a service account with broad read and write access across the org, because that was faster to set up than a permission model that matches what the actual user is allowed to see.