Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

EU Cyber Resilience Act: Europe Just Put Your AI Agents on a 24-Hour Clock

In short, the EU Cyber Resilience Act (CRA) puts binding cybersecurity requirements on any software sold as a product in the EU, and it does not carve out AI agents. Since 11th September 2026, any company that sells software with digital elements into the EU has 24 hours from learning that a vulnerability is being exploited to file an early warning with a national CSIRT and ENISA, 72 hours to describe it, and 14 days to report what it did about it.

New in Falcon Cloud Security: Third-Party App Insights and AI-Enhanced Remediation

Two forces are reshaping modern cloud posture management: context and AI. Context gives security teams the business insight to understand risk. AI helps them turn that insight into faster, more informed action. CrowdStrike Falcon Cloud Security is advancing both. New third-party application insights map the external services cloud-native applications depend on, helping customers assess the risk those dependencies introduce.

Falcon Data Security for SaaS Secures Sensitive Data in Microsoft 365

For many organizations, Microsoft 365 environments are essential to data security strategy. Their strategic plans live in SharePoint; their employee records and customer data are stored in OneDrive. Teams use these tools to collaborate on projects every day, and increasingly, AI tools like Microsoft Copilot can access the information they rely on.

How Essential Eight impacts government contracting in Australia

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Process and route critical security logs to Exabeam with Observability Pipelines

Enterprise security teams use Exabeam as a security information and event management (SIEM) platform with user and entity behavior analytics (UEBA) to detect insider threats, lateral movement, privilege escalation, credential compromise, and data exfiltration.

September 2026 Product Updates

September was the month Nightfall's control layer reached inside the model call. Five releases shipped: Claude Inference Hooks, MCP Gateway, expanded endpoint exfiltration controls, personal file classifiers, and PII coverage across 30 countries. Together they close the gap between what security teams can control when a person moves data and what they can control when an AI agent does.

Meta Muse in the Enterprise: Data Security for Personal Autonomous Agents

The deployment of personal AI agents like Meta's Muse represents a structural shift in enterprise data loss prevention. Unlike conversational web chatbots where data movement is limited to manual user prompts, autonomous personal agents operate in cloud virtual machines, run continuous background tasks, and connect directly to enterprise SaaS platforms through OAuth integrations.

State of Application Security

Our View from the Front Lines of Technical Assessments Kroll analyzed five years of penetration testing data. Of the trends that emerged, we focus on three in this report: the static application security testing (SAST)/software composition analysis (SCA) plateau, the need for more attention around authentication and authorization, and the security health divergence, which shows that regulation is not a reliable predictor of attack surface health.

Beyond Renew or Replatform: A Fourth Option for VMware Customers

A customer tells you they want off VMware. They have seen the headlines, looked at the latest renewal, and decided it is time to evaluate Nutanix, Proxmox, public cloud, or another virtualization platform. The opportunity appears straightforward: help them select an alternative and build the migration plan. But what if leaving VMware isn’t actually the best answer? A platform move is risky, time-consuming, and expensive.

Step-Up Authentication: How It Works, Use Cases and Benefits

A user signs in to an application and gets access to the dashboard. Later, the same user tries to change account settings or approve a high-value transaction. Suddenly, another verification step appears. Why? The risk has changed. Routine access and sensitive actions do not need the same level of protection. Step-up authentication lets organizations add stronger verification when users cross a higher-risk threshold, while keeping everyday access simple.