Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Weekly Brief: Threat Intelligence Edition | How AI Agents Help Security Teams Prioritize Risk

In this week's SecurityScorecard Weekly Brief: Threat Intelligence Edition, Richard Hummel explains why third-party risk has become one of the biggest challenges facing security teams, and why humans alone can no longer keep pace. Attackers are moving faster than ever, exploiting vulnerabilities across complex vendor ecosystems long before traditional assessment cycles can react. As Richard notes, the question is no longer, "Am I secure?" It's "Are all of my vendors secure?".

Best Cybersecurity PR Agencies 2026

Most cybersecurity vendors underestimate PR until a crisis forces the issue. A vulnerability is disclosed in their product and the story spirals before a response is drafted. A competitor lands the Gartner Magic Quadrant quote while their own CEO stays invisible. A breach hits the news with no narrative ready. The instinct is to call a generalist agency, but the real problem runs deeper: cybersecurity PR is a specialized discipline that demands technical fluency, relationships inside security trade media, and crisis playbooks built for the unique pressures of the category.

Modernizing the Mission: Splunk Victoria Experience is Now Authorized at FedRAMP High

For public sector organizations and other highly regulated industries, the balance between cutting-edge innovation and strict compliance has often felt like a trade-off. You want the latest features, but security and authorization come first. Today, we’re closing that gap. We’re excited to share that, following our FedRAMP Moderate authorization earlier this year, Splunk Victoria Experience has now officially achieved FedRAMP High authorization as well.

FedRAMP Rev 5 vs. 20x: What CSPs Should Do Right Now

Cloud Service Providers (CSPs) who either currently work with the federal government, are in the process of earning FedRAMP certification, or are considering seeking it, all have a serious choice to make. FedRAMP is changing. If you haven't been watching the world of government compliance, or if you've been putting off making a decision until a deadline gets closer, it's here. As a CSP, what do you need to know, what decision do you need to make, and how will it affect your path with government contracts?

How to Secure AI Agents in the Enterprise: A Practical Guide for CISOs

Building guardrails for AI agents sounds like a policy problem but it is actually a data problem. You cannot enforce boundaries on behavior you cannot see. And you cannot govern identity for actors you have not discovered. That dependency chain is what most enterprise security programs miss in 2026, and it is where exposure quietly accumulates. A human employee who mishandles sensitive data creates a containable event. An AI agent with the same permissions creates a different problem.

The hidden cost of reasonable assurance

For decades, compliance programs, audits, and certifications have operated on a foundational concept: reasonable assurance. Auditors review samples, evaluate controls periodically, and issue opinions based on limited visibility into a point in time. While this model served the analog era well, it is now insufficient for the speed, complexity, and interconnectedness of modern digital enterprises. Today’s organizations operate in real time. Threats emerge instantly. Vendors change continuously.

Every Vendor Decision Is a Security Decision

Managed service providers have never had more influence over their customers’ security outcomes. Every day, MSPs make decisions that affect how organizations authenticate users, secure privileged access, recover from ransomware, manage sensitive data and defend against the latest cyber threats. Their managed companies continue to rely on those decisions as they generally lack the internal resources to evaluate them. That trust creates tremendous value. And it also creates heightened accountability.

How telcos can build a sovereign IaaS platform

Telecommunications providers already play a central role in the cloud economy. They own the networks businesses use to reach cloud services. They operate data centers, regional points of presence, edge locations, support teams and enterprise client relationships. In many markets, they are also trusted local infrastructure providers for businesses, governments and critical services. For years, much of that infrastructure was used to connect clients to someone else’s cloud. That is starting to change.

Your Firewall Rules Are Drifting Right Now. You Just Can't See It

Firewalls are the single most common source of misconfiguration-related breaches, yet they get changed a hundred times a week and audited once a quarter. This is the network security gap AI attackers exploit first. Endpoint gets the budget. Identity gets the roadmap. The firewall gets changed constantly and reviewed rarely. It is also the control most tied to breaches: 42% of security teams pinned a firewall misconfiguration to a breach or near miss last year, ahead of EDR at 40% and identity at 39%.