When ransomware hits, decision makers face an impossible ultimatum: pay the ransom or lose business operations. In software development, data criticality also comes to the forefront. That’s because source code isn’t just some trivial data, but primary intellectual property and a revenue driver. Let’s see what’s exactly at stake and how you can minimize the risk of paying a ransom for your tech business.
AI agents comprise models, instructions, data, and tools, so thoroughly investigating potential security risks requires evidence from several components. As Datadog teams build AI agents for internal workflows, we use Datadog AI Guard to monitor how they handle each component during a session. We’ve found that application logs may capture an agent’s final API call without showing which prompt, retrieved content, or tool result led to the action.
Security operations are complex. Teams are constantly balancing investigations, risk, operational health, and day-to-day priorities. Knowing what requires attention and deciding what to do next isn’t always easy. That’s why Arctic Wolf is introducing new experiences designed to make security operations more accessible and easier to manage.
Microsoft is in the process of shaping major changes to Windows code signing that will have the effect of altering the certificate infrastructure, the cryptographic algorithms, and, in the end, how Windows applications will be protected against future quantum computing threats. The changes are of particular importance to developers, IT administrators, security teams, and organizations that are using their custom software or security tools that can do their own code signature validation.
How KomodoSec’s AigentX Penetration Tester and Red Teamer mapped an assumed-breach Active Directory environment, proposed an operator-approved attack plan, and autonomously demonstrated multiple routes toward full domain compromise inside a large enterprise company. Human-controlled strategy. Autonomous execution. Evidence-backed results. THE CHALLENGE.
Let’s catch up on the more interesting vulnerability disclosures and cyber security news gathered from articles across the web this week. This is what we have been reading about on our coffee break! You have a Zimbra server? Not now you don’t…
A model ranks phishing sixth. The security team has spent three years on phishing and knows how often people click. Somebody in the room concludes the model is wrong, or that the security team is attached to its own program, and the meeting stops being useful. Most of these disagreements are not about risk. They are about which question each side answered, and establishing that first resolves a surprising proportion of them without anyone conceding anything.
The OWASP list for agentic applications, published in December 2025, gives security teams a shared vocabulary for what goes wrong when software acts rather than answers. Ten categories covering planning, tools, identity, supply chain, code execution, memory, inter-agent communication, cascading failures, human trust and rogue behavior. Translating that into a financial figure is where programs stall, and the usual attempt makes a specific error.
Coding-agent telemetry, today, cheaply, answers four real questions: which agents are running and operated by whom, what an agent invoked, what happened in a session in order, and whether a run looks abnormal. Part 1 of this series covers that case in full. This part is about the fifth question every security team eventually asks, the one no amount of instrumentation answers on its own: can this record be trusted enough to build a control on it?