Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cognition's Jeff Wang on demoting the IDE, with Richard Liu from Anthropic

Zero-Shot Learning is a podcast about how AI gets built, secured, and deployed. Hosted by Nancy Wang, 1Password CTO, and Dev Tagare, Senior Director of Engineering at Google, it’s a builder’s view of the architecture and the complex decisions it takes to ship with AI. This episode features guest co-host Richard Liu, Head of API Products at Anthropic, who sits in for Dev.

Static credentials are still AI's easiest way in

Netwrix's 2026 research found a 4x gap in breach rates between organizations where AI has significantly grown their identity count and those where it hasn't. Static credentials are AI’s easiest way in: passwords, keys, and tokens that never expire and never get checked. AI didn't invent the over-privileged credential, it just found the fastest way to use one.

Beyond the Inbox: How BEC Leads to SSO Abuse

For years, many business email compromise (BEC) investigations have followed a familiar playbook: an attacker phishes credentials, logs into the victim's mailbox, establishes persistence with inbox rules, monitors communications, and waits for an opportunity to steal money or sensitive information. Today, we're seeing something different at LevelBlue. Across multiple recent investigations, we've observed attackers treating a compromised mailbox as just the first step.

Sophos MDR: Define MDR Contacts in Sophos Central

A step-by-step tutorial showing you how to define your Sophos Managed Detection and Response (MDR) authorized contacts and threat response mode in Sophos Central. As a Sophos MDR customer, assigning authorized contacts lets you fully utilize the service. This instructs the Sophos MDR Operations team who to contact and how to take action during an active threat. You're prompted to take these steps in Sophos Central after activating a new Sophos MDR license, and you can modify this information at any time.

OWASP LLM Top 10 2026: the model will be fooled, the question is what breaks

The OWASP GenAI Security Project published the 2026 edition of its Top 10 for LLM Applications. Prompt Injection stayed at number one. Sensitive Information Disclosure stayed at number two. Read the headlines and you would conclude that not much moved. Something did move, and it is not in the rankings. The project leads open by telling you to stop trying to build a model that cannot be fooled, and to build the system around it so that when the model is fooled, nothing important breaks.

What an AI Compliance Audit Involves, Stage by Stage

An AI compliance audit is less mysterious than its absence from most planning suggests. Someone outside the organization reads what you wrote down, then samples real systems to test whether the organization does what the documents describe. The distance between those two things is where findings come from. ‍ Three different exercises get called an AI audit, and they run differently. Certification against a management standard follows a defined two-stage process.

Where Cyber Loss Comes From: Attack Vectors Ranked by Exposure

Security awareness receives a disproportionate share of attention relative to the exposure phishing carries. Modeled against initial access technique, valid account abuse accounts for around a quarter of expected annual loss in a typical portfolio, exploitation of public-facing applications around a fifth, and human error around a seventh. Phishing appears sixth, at roughly seven percent.

MITRE ATT&CK Framework: A Practical Guide for SOC Teams

You are already in the meeting, and the question on the table sounds simple: can the SOC detect a technique tied to a noisy intrusion path? Three analysts answer three different ways because each one is staring at a different dashboard, a different log source, and a different mental model. The MITRE ATT&CK framework gives those people one shared way to describe adversary behavior, so the discussion starts with evidence instead of guesswork.