Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Inside the AI-Accelerated Cyber Underground

Cyberattacks take shape long before a breach through exposed systems, vulnerable software, stolen credentials, underground tools, and attacker experimentation. In this webinar, Emma Stevens, Threat Intelligence Researcher at Bitsight, and Qionglu Lei, Senior Product Marketing Manager at Bitsight, explore what Bitsight research reveals about AI-enabled attacker behavior and the changing cyber underground.

Fourth-party risk management: How to identify and manage downstream risk

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

AI Assurance: The Third Head of Your AI Governance Watchdog

In July 2026, two AI stories broke that appeared unrelated on the surface. But were they really? The first was an AI product's shared conversation links, meant for specific people, turning up in Google searches, some holding sensitive personal and company data. The second was a frontier AI lab's own model escaping a security sandbox during an internal evaluation and spending four and a half days inside three companies' systems. One involved ordinary users making a common mistake.

Agent Incident Response: Containment Is the Easy Part

Containment guidance for agent incidents already exists and it is largely correct. Revoke the tokens, freeze the orchestration tier, cut egress, set the vector store to read-only. Those steps take minutes and any competent team will find them. ‍ The difficulty sits either side of containment. Deciding what kind of incident this is takes longer than stopping it, establishing what the agent did before you stopped it takes longer still, and both depend on preparation that has to exist beforehand.

How Many Cyber Risk Scenarios Should You Model?

Scenario libraries grow. A program starts with ransomware and a data breach, adds a third-party failure after a supplier incident, splits ransomware into encryption and extortion variants, adds a cloud outage, and two years later holds forty entries nobody has revisited. ‍ The usual guidance suggests a range, somewhere between five and fifteen, which is a reasonable starting point and answers the wrong question.

Nucleus Helix Was Built to Fix Exposure Management's Breaking Point

Let me be direct about something the industry keeps dancing around: the vulnerability problem isn’t getting better. It’s getting structurally worse. The wave of AI-generated code and compression of time to exploit thanks to frontier AI models like Mythos is about to make “worse” look quaint. If your vulnerability and exposure management program is still built around scanner cycles, ticket queues, and CVSS scores, you’re not running a security program.

Left Unsupervised: 10 Times Access Outlived Its Authorization

September is National Insider Threat Awareness Month, and most of the advice out there is about spotting a person. The insider here is rarely a person. It’s a credential nobody rotated, or an agent nobody kept watching. Each was access granted on purpose, then left unmonitored. The only question that matters afterward is whether anyone would have known.

State AI Laws Change Faster Than Compliance Programs

Colorado passed the first comprehensive state AI law in May 2024, and organizations spent the following year building impact assessment processes against it. Those obligations never took effect. The statute was delayed twice, blocked by a federal court, then repealed and replaced by a narrower framework before its own effective date arrived. ‍ Anyone who built a compliance program to that specific statute prepared for a regime that never existed.

Same Numbers, Two Audiences: Insurer and Board

The same quantification run supports two conversations that happen weeks apart. One with a board asking whether the organization is managing cyber risk sensibly. One with an underwriter deciding what to charge for it. ‍ Most guidance treats these as a formatting problem, where the board version gets charts and the submission gets detail.

New Bitsight Research Shows AI Abuse Is Moving Beyond the Jailbreak Prompt

Jailbreak prompts (i.e. prompts designed to remove or bypass the guardrails and rules that govern AI systems, like LLMs) prompts have been circulating for years. At first, a lot of it was pretty simple: copy a prompt, tell the model to ignore its rules, and see what happens. It was also largely noisy, unverified, and often didn’t work. But the noise was still telling us something. Threat actors were beginning to study AI systems the same way defenders were, and over time, the goal started to change.