Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Are Your AI Agents Going Rogue? (The Real Danger of Agentic AI)

ChatGPT is read-only, but AI Agents take action on your behalf. What happens when they go rogue? Discover the hidden cybersecurity risks of Agentic AI and unauthorized remote execution. AI gateways were built for a world where AI meant "prompt in, response out." That world is gone. Today, AI agents call APIs, trigger workflows, and take actions across your enterprise systems autonomously. This massive shift from passive data exfiltration to active, unauthorized execution requires a completely new security model where every input is treated as potentially hostile.

Shadow AI: Employees don't ask IT to use AI tools

Generative AI has gone mainstream, and your customers are already using it, whether IT knows it or not. Employees are turning to AI assistants to write emails, summarize documents, generate code, analyze spreadsheets, and speed up everyday work. Most are simply trying to be more productive. The problem?

Braintrust's Ankur Goyal: Code review doesn't cover prompts

Zero-Shot Learning is a podcast about how AI gets built, secured, and deployed. Hosted by Nancy Wang, 1Password CTO, and Dev Tagare, Senior Director of Engineering at Google, it’s a builder’s view of the architecture and the decisions it takes to ship with AI.

AI Is Breaking Defence in Depth Faster Than We Can Fix It

This episode explores how defence in depth is changing in an AI enabled business world, where code driven systems, supply chain risk and offensive AI are moving faster than defenders can react. It looks at why human in the loop is failing, why visibility still comes too late, and what modern cyber defence needs to become next.

What Is Privacy-by-Design and Why Is It Important?

Every AI application relies on data. From customer conversations and healthcare records to financial transactions, organizations process enormous volumes of sensitive information every day. As AI adoption grows, so does the need to protect that data from misuse, exposure, and compliance risks. This is why understanding what privacy by design entails has become a business necessity rather than just a compliance requirement.

The evolving fraud landscape in the age of AI with Tamas Kadar [334]

Today we're speaking with Tamas Kadar, CEO / Co-Founder of SEON, about building a safer digital world for businesses. We touch on fraud, how it's evolved in the age of AI, and what we can do to protect ourselves against it. Tamas' entrepreneurial path began at Corvinus University in Budapest, where the vision for SEON first took shape. Co-founding a cryptocurrency exchange opened his eyes to the scale and complexity of online fraud, sparking the idea for something better. In 2017, that “something better” became SEON.

The Four Biggest Gaps in Today's AI SOC Vendor Market

A year ago, a handful of vendors called themselves an “AI SOC.” Today, more than 100 do. The label now means whatever the person selling it needs it to mean, leaving security teams to buy very different products under the same two words. So let’s sort the market. Beneath the “agentic” branding, most AI SOC vendors fall into one of four categories, and none of them clears the bar. Each can look capable in a demo.

Shadow AI Explained: What It Is, Where It Hides, and What It Costs

Shadow AI is the term for AI tools, models, and capabilities that operate within an organization without formal approval, oversight, or governance. It is the enterprise AI equivalent of shadow IT, which is the unauthorized software and cloud services that proliferated as employees found faster ways to get work done than waiting for IT procurement cycles. The difference is that the consequences of unmanaged AI are considerably more significant than those of unmanaged software.

How to Discover and Control Shadow AI Agents in Your Environment

Most security programs have a working model for responding to shadow AI: identify the unsanctioned tools employees are using, sanction or block them, and update the acceptable use policy. That model worked, however imperfectly, when the threat was limited to web-based GenAI applications. It does not work when the threat is an autonomous agent, running locally on an endpoint, that reads the file system, calls external APIs, and transmits internal data.

A double-edged bleeding edge: Classifying AI threats

Sophos X-Ops presents a working taxonomy for attacks using, and targeting, AI Conversations about ‘AI threats’ typically collapse into one of two extremes. On the one hand, hype: unverified claims that don’t hold up to scrutiny and invite significant criticism. On the other, dismissal: it’s just old tradecraft with new branding.