Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

How to Build a Red Team Exercise for AI Workflows

AI agents now retrieve data, generate recommendations, and trigger actions across enterprise systems with little human review in between. That speed is the point, and it is also the problem. A single manipulated prompt or a poisoned data source can push an AI system toward a decision no one signed off on, and most security teams have never tested for it. Building a red team exercise for AI workflows is how you find that gap before an attacker does.

The ECB just gave banks four months to fix AI vulnerability gaps. Most of the work starts in the software supply chain.

On July 7, 2026, the European Central Bank sent a letter to the CEO of every bank it directly supervises with an unambiguous instruction: build a formal action plan against AI-enabled cyberattacks, and submit it to your supervisory team by October 31.

Falcon Secure Access Sets the Standard for Zero Trust Browser Security

The browser has become the enterprise workspace. Employees, contractors, partners, and third parties use browsers to access SaaS applications, internal web apps, admin consoles, collaboration tools, and AI services from anywhere, often across a mix of managed, unmanaged, and personally owned devices. As they do, adversaries are increasingly targeting the browser session itself.

What Tools Help Build and Maintain an AI Asset Inventory?

Managing an artificial intelligence (AI) footprint has emerged as one of the most complex challenges for modern enterprise security and risk teams. As shadow AI, autonomous agents, and embedded third-party models infiltrate corporate environments, traditional methods of software tracking have broken down. Organizations are quickly realizing that maintaining an accurate inventory is not just an IT best practice.

Let's Talk Security: The Control Gap

In this conversation, Forescout CEO Barry Mainz will be joined by Karsten Abata, tech evangelist at Forescout, former cybersecurity practitioner, and co-author of The Control Gap, to discuss how to close the Control Gap: the widening space between seeing cyber risk and having the ability to control it before it becomes operational impact.

Ep. 67 - The Axis of Disruption: APT41, Volt Typhoon, and the China-Russia Cyber Alliance

For years, Beijing and Moscow kept their cyber tools apart. Not anymore. Hosts Tova Dvorin and Adrian Culley unpack the "no limits" partnership gone operational—the ESA/Galileo satellite attack where a Chinese Volt Typhoon cell opened the door and Russian AcidRain wiper code did the damage. We cover: APT41 running Russian exploit kits, Salt Typhoon pre-positioned in US telecom, China's 72-hour zero-day disclosure law feeding vulnerabilities to Russia, and the CVSS-10 Grimbolt flaw. Why continuous validation and a CTEM program are your best defense against the axis of disruption.

TITAN AI Demo Series: Build Custom Assessment Templates in Minutes with TITAN Agent

Building a strong vendor assessment template used to take hours. With our TITAN Agent, it takes minutes. In this installment of SecurityScorecard's TITAN demo series, see how our TITAN Agent builds customized, comprehensive assessment templates — so your team gets to evaluation faster and with more consistency across every vendor engagement.

The End of the VPN: The Rise of Identity-Based Secure Access

Hundreds of MSPs joined our last webinar to discuss the growing security and operational challenges of remote-user VPNs. Since then, the headlines have only reinforced the problem. Fortinet. Ivanti. Palo Alto Networks. SonicWall. Different vendors, same challenge: critical vulnerabilities, credential theft, and ransomware attacks continue to target remote access infrastructure, forcing organizations into a cycle of emergency patching, user disruption, and increased risk.

Why Project Glasswing Changes the Rules of AppSec

The old application security playbook is broken. With Anthropic’s Claude Mythos and the release of Project Glasswing, AI agents can now autonomously chain low-severity bugs into working zero-day exploits, collapsing the time between vulnerability discovery and active exploitation. In this video, Mend.io's Saoirse Hinksmon (Head of Product Marketing) and Daniel Wyrzykowski (Product Manager) break down the structural shifts in the threat landscape and what security teams must do to keep pace.