Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Seeing Every MCP Connection: Zenity Joins the Cursor Marketplace

Cursor has become one of the primary AI coding environments for development teams, and its agents increasingly reach into the outside world through MCP servers: databases, ticketing systems, cloud consoles, and internal APIs. Every connection extends what an agent can do. It also extends what could go wrong if that access goes unmonitored or unchecked.

Governance Strikes Back: The Most Used, Most Abused Word in the Galaxy

Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know When I walked to the stage in Copenhagen, I had a lot on my mind. For 3 days I'd had countless conversations with leaders and practitioners about AI and agentic security. The one word on everyone's lips was "governance"; day 3 at the conference was "Governance Day," in fact. This is a bag one vendor was giving out: But governance of what? To what end?

How Zenity Implements the 2026 OWASP Top 10 for LLM Applications

Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know Every AI security framework names the risks you have to control. Zenity is built to implement those controls at runtime. Here's the 2026 OWASP Top 10 for LLM Applications, entry by entry, with the gaps marked honestly. Paste a booby-trapped instruction into a chat window, and nothing much happens.

Secure AI Agents, Everywhere: Why Prompt Injection Is Only Part of the Problem

Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know The rules have changed. In every AI deployment, the agent itself is now part of the threat model, and that's a first for enterprise security. Prompt injection gets most of the attention, and for good reason: it doesn't require access to source code, credentials, or network infrastructure. It exploits the fundamental mechanism by which language models process instructions.

Coding Agent Risk for CISOs: Blast Radius, Governance, and Where to Start

Claude Code, Cursor, GitHub Copilot, and Gemini CLI are running on developer machines across your enterprise right now. They're browsing the web, writing to your filesystem, committing code to your repositories, and calling external APIs under the identity of your engineers. Most security teams have no visibility into any of it. This isn't a future problem.

Black Hat Proved AI Agents Are Already the Attack Surface

Enterprise AI agents stopped being a pilot project a while ago. They read email, touch source code, operate browsers, and increasingly make decisions inside production systems, which means the security model built for chatbots and prompts no longer covers what is actually happening inside the enterprise. Black Hat USA 2026 turned out to be the week that gap became impossible to ignore.

Securing the Agent Supply Chain

A developer installs a skill to make their coding agent less chatty. It works. It also, the first time the agent uses it, reads the AWS credentials on that laptop and sends them to a domain no one recognizes. No one wrote obviously malicious code and no one approved a change. A file landed in a folder, the agent loaded it on the next run, and production credentials were gone.

The Identity Surface You're Not Watching: Three Layers of Coding Agent Risk

There's a widespread assumption in enterprise security that identity is a problem IAM programs know how to solve. Provision the right access, enforce least privilege, audit the credential chain, and you've addressed the identity risk. For human users and traditional service accounts, that's approximately correct. For coding agents, it misses two-thirds of the problem. Coding agents don't have a single identity. They operate across a layered identity surface, and each layer carries its own risk profile.

Zenity Now Integrates with Microsoft Agent 365

AI agents have moved from pilots into broad enterprise use. They read email, query systems of record, take actions, invoke tools, and coordinate with other agents on behalf of employees. Every line of business wants more of them, and security teams are being asked to enable that expansion without losing visibility or control.