Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

451 Research report: How agentic AI is redefining identity security

In the short time that AI agents have been a part of the enterprise, they have upended many of our bedrock assumptions about the nature of identity, access, development, and work itself. At 1Password, we’ve been in the trenches of the agentic revolution; we’ve seen its positive impact on productivity, and the serious concerns it raises about security.

Secure AI Written Code Before It Ships: Salt Code

AI coding assistants are transforming how enterprise software gets built. Developers at every level are prompting their way to production-ready APIs, MCP integrations, and agentic workflows faster than any security team can review them. The problem is that none of those assistants knows your internal security standards, regulatory obligations, or risk tolerance. The result is insecure patterns shipping unnoticed, vulnerabilities discovered downstream when fixes are costly, and compliance becoming a guessing game on every commit.

Three Years as a Leader. Built for Where the Market Is Going.

Being recognized as a Leader in the Gartner Magic Quadrant for SASE Platforms for the third consecutive year is an important milestone for Cato Networks. We believe it reflects more than consistent execution. It comes at a time when enterprise networking and security are entering another architectural transition, one driven by AI.

The GitHub Outage: How AI-Native SASE Visibility Turns Disruption into Decision

On August 17, 2026 at 13:40 UTC, GitHub first publicly logged that it was investigating elevated errors and latency issues, later reporting broad impact across web and API traffic, Git operations, Actions, Pull Requests, Issues, Pages, Webhooks, and identity-related services. The outage had significant implications for development teams. When GitHub degrades, developer workflows can stop quickly.

Why Annual Mobile App Security Testing Is Not Enough on Its Own

Annual testing secures a moment. Your app keeps changing. Here is how to cover the interval between assessments. An annual penetration test answers a precise question. Was this version of this application secure when a skilled tester examined it? That answer has real value. It is independent, deep, and finds business logic flaws that no scanner will ever surface. It is also a photograph.

Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack

On August 20, we detected two popular Rust crates from the same maintainer, append-only-vec (4M downloads) and arrayref (244M downloads), were compromised. The attacker added a malicious dependency on a package called proc-macro1, which downloads a remote payload during the build and executes it on the developer's machine.

How to pass Cyber Essentials Plus - Danzell v3.3 Standard

KEEP helps organisations large and small to achieve both Cyber Essentials (CE) and Cyber Essentials Plus (CE+), alongside some of the more stringent standards such as SOC2, though for this insight we will focus on how to ‘pass’ CE+. As you may be aware IASME introduced the Danzell v3.3 standard in mid 2026, which included a number of critical changes that aimed to set the bar ‘higher’ for an organisation who applied for a CE+ assessment.

GitHub Enterprise Cloud with Data Residency

GHE.com introduces migration, identity, and integration changes.– Some GitHub data may still be processed outside the chosen region.– ta residency still needs a separate backup and recovery strategy. For many enterprises, GitHub is now one of the most important parts of the DevOps ecosystem, where teams manage repositories, pull requests, issues, workflows, GitHub Actions, security alerts, project data, and other metadata that keeps software delivery moving.

MSP Central expands its security stack with Device Control

MSPs are maturing endpoint security with patching, vulnerability remediation, and antivirus protection. But one high-impact risk still slips through in many client environments: unmanaged peripheral devices. A single unauthorized USB drive can copy sensitive client data in minutes and introduce malware into otherwise protected systems. This is why we've launched Device Control in MSP Central—an MSP-ready solution capable of governing every device that touches your client endpoints.