Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Whos watching your AI A security leader panel on runtime visibility and accountability

AI is making decisions across your environment — calling APIs, accessing data, and taking action. Most organizations know it's happening, but far fewer can see it, let alone stop it. In this panel discussion, security leaders will share what they've learned deploying and governing AI workloads at scale on AWS, and what it takes to close the gap between deployment and accountability.

Why AI Discovery Must Be the First Step in Enterprise AI Security

Every enterprise security leader is being asked the same question by their board: are we secure against AI risk? Most cannot answer it with confidence, and the reason is rarely a lack of tools. It is a lack of visibility. AI has spread through enterprises faster than almost any technology before it. Developers wire large language model APIs into internal tools. Business teams stand up copilots and chat assistants. Data science teams build retrieval pipelines against customer and financial data.

What the OpenClaw Gym Booking Incident Reveals About Agentic and API Security

An Australian man named Andrew asked his personal AI agent, built on the open-source OpenClaw framework and powered by Anthropic’s Claude model, to book him into a popular morning gym class. According to ABC News, the class was full, so the agent started looking for a way around that. It found that the gym’s booking API let bookings be pushed far further into the future than the website’s own interface allowed, a limit that turned out to exist only on the front end.

Choosing an API Discovery Tool? Here's the Unmanaged API Gap Most Vendors Miss

If you’re evaluating API discovery tools right now, you’ve probably already seen a handful of demos that look nearly identical: a clean dashboard, an inventory count, maybe a risk score. What’s harder to see in a 30-minute demo is whether that inventory reflects what’s actually running in production, or just what the vendor’s connectors happened to catch on setup day.

The API Security Gap Behind Recent Supply Chain Breaches

Most coverage of software supply chain attacks focuses on the entry point: the poisoned package, the compromised maintainer account, the malicious commit. That’s the part that makes headlines, but it’s rarely the part that causes the damage. A malicious package sitting on a developer’s machine doesn’t exfiltrate anything by itself.

Guide to Agentic AI Governance

Agentic AI governance is about keeping powerful, autonomous AI systems aligned, safe, and accountable as they act on our behalf. It’s now a certainty that AI agents will be deployed enterprise-wide. So, we need to look more deeply into those agents, figure out where they are, how to find them, and fully understand what they are doing in deployment so we can prevent attacks. The most dangerous agentic attacks will not look like attacks at the layer where they originate.

Best API Frameworks in 2026: How to Choose the Right One (and What Most Teams Miss)

Framework choice isn’t really about syntax or GitHub stars. It’s a multi-year commitment that shapes architecture, team habits, hiring, and how painful your next migration will be. Frameworks decide your architecture by default, whether you choose it or not. Some frameworks default to synchronous request handling; others assume non-blocking IO from day one. Some nudge you toward a monolith; others push you toward services that split naturally.

Webinar Recording: AI Governance & Policy Enforcement for the Abilities API

In this Webinar, Learn to secure your WordPress AI agents against common risks. Understand how to implement audit trails and smarter permissions for your site. Integrating AI agents with WordPress offers powerful marketing capabilities, but it introduces significant security vulnerabilities. This webinar explains how to manage these risks by addressing scoping, identity verification, and access control. If you are a developer or site owner building autonomous workflows, this breakdown highlights exactly where your current setup might be exposed.

Salt Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection

Your WAF is doing its job. It's blocking SQLi, XSS, and the usual suspects. But here's the problem: it wasn't built for APIs, and it definitely wasn't built for AI agents. APIs now power nearly every digital experience. And AI agents — the automated systems that access your APIs at machine speed, at machine scale — are the fastest-growing source of that traffic.