Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Closing the Gap: What Actually Turns Agent Telemetry Into Evidence

‍ An AI coding agent's own telemetry answers real questions well: which agents are running, what they invoked, the shape of a session, whether a run looks abnormal. It cannot, no matter how completely it is instrumented, stand alone as evidence. The agent under review is also the party writing the record. The record shows an attempt, not an outcome. And the vocabulary for describing any of it is still being written in public, one unstable commit at a time.

Human Risk Management Platforms: How to Choose the Right Software

Security leaders can no longer treat workforce cyber risk as a quarterly phishing campaign. Shadow AI, sprawling SaaS adoption, generative AI-assisted social engineering, and siloed alerts leave many teams unable to answer a basic board question: which users and apps matter most this week? Answering that question is the job of the human risk management (HRM) software category, which is young and crowded.

How to define your third-party risk criteria

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Jira + UpGuard: Automating Risk Management Together

If your security team runs on Jira, sprints and backlog included, UpGuard plugs straight into it: vendor findings, breach alerts, and user risk signals can all surface as issues your team is already triaging. With this integration, you can: Set the trigger once: a new risk detected for a monitored vendor, a risk score dropping below a threshold you’ve set, a credential breach turning up on a watched domain, or a questionnaire response coming in.

The Three Questions Every AI Telemetry Claim Should Survive

‍ Coding-agent telemetry, today, cheaply, answers four real questions: which agents are running and operated by whom, what an agent invoked, what happened in a session in order, and whether a run looks abnormal. Part 1 of this series covers that case in full. ‍ This part is about the fifth question every security team eventually asks, the one no amount of instrumentation answers on its own: can this record be trusted enough to build a control on it?

Turning the OWASP Agentic Top 10 Into Expected Loss

The OWASP list for agentic applications, published in December 2025, gives security teams a shared vocabulary for what goes wrong when software acts rather than answers. Ten categories covering planning, tools, identity, supply chain, code execution, memory, inter-agent communication, cascading failures, human trust and rogue behavior. ‍ Translating that into a financial figure is where programs stall, and the usual attempt makes a specific error.

When the Model Disagrees With Your Security Team

A model ranks phishing sixth. The security team has spent three years on phishing and knows how often people click. Somebody in the room concludes the model is wrong, or that the security team is attached to its own program, and the meeting stops being useful. ‍ Most of these disagreements are not about risk. They are about which question each side answered, and establishing that first resolves a surprising proportion of them without anyone conceding anything. ‍

When 700 Agents Coordinate Without Being Told To

Two reports landed yesterday on the July incident in which OpenAI agents left an isolated test environment and reached Hugging Face production systems. OpenAI published a thirty-seven page technical post-mortem. METR and Redwood Research published a ninety-one page independent analysis, produced over six days on site, covering July 7 to 13 and taking no payment for the work. ‍ The coordination numbers are what drew attention.

ServiceNow + UpGuard: Automating Risk Management Together

UpGuard connects to ServiceNow across the whole platform. Vendor risk findings, breach alerts, and user risk signals all land in the same ticket queue your team already works from, not a separate, siloed risk dashboard. With this integration, you can: Risk Automations makes this possible. You define the events that matter: a monitored vendor picks up a new risk, a risk score drops below a threshold you set, a credential breach turns up on a watched domain, or a questionnaire response comes in.

'The Gentlemen' Profile: Why This Ransomware Group Wants In Before It Locks You Out

The Gentlemen is a financially motivated ransomware group that combines data theft with encryption to increase pressure on victims. They first came onto the threat scene in July 2025. Rather than relying on encryption alone, the group exfiltrates sensitive business data before locking files, leaving organizations to deal with both operational disruption and the risk of stolen information being exposed.