Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Preparing for an AI-Powered Future with Amazon CSO Steve Schmidt

Steve Schmidt, SVP and CSO at Amazon, sees firsthand how both defenders and adversaries are using AI to their advantage. In this episode, he joins Adam and Cristian to discuss modern AI models, evolving adversary behavior, and how Amazon is responding to shifts in the threat landscape. “The big change we’ve seen recently is the ability of models to chain things together to produce something interesting,” Steve says. As AI models grow more adept at automatically chaining and acting, he adds, the time to respond has dramatically decreased.

Seeing Every MCP Connection: Zenity Joins the Cursor Marketplace

Cursor has become one of the primary AI coding environments for development teams, and its agents increasingly reach into the outside world through MCP servers: databases, ticketing systems, cloud consoles, and internal APIs. Every connection extends what an agent can do. It also extends what could go wrong if that access goes unmonitored or unchecked.

Agentic AI Security Buyer's Checklist: 15 Questions to Ask Before You Sign

Buying agentic AI security software is a fast-moving decision with high stakes. Get it wrong, and your security team ends up chasing agent activity it cannot see, while attackers exploit business logic gaps that no prompt filter was built to catch. This checklist gives security and platform leaders a structured way to evaluate vendors before signing, based on the questions that actually separate a purpose-built platform from a bolted-on feature.

The Role of Agentic AI in Cybersecurity

Agentic AI has moved from experimental research to live production environments at unprecedented speed, outpacing nearly every technology security leaders have encountered in recent history. Distinguishing themselves from standard chatbots that merely respond and pause, autonomous agents architect multi-step workflows, interface with tools and APIs, maintain contextual memory, and execute operations with minimal human intervention.

The Post-Mythos Era Is Here. Is Your Exposure Management Program Ready?

As AI accelerates vulnerability discovery and exploitation, exposure management can’t stop at visibility and prioritization. Gartner’s post-Mythos outlook points toward more preemptive, autonomous security, and Seemplicity’s Response Options puts that into practice by giving teams multiple context-aware ways to reduce risk quickly, safely, and without waiting for the full fix.

How to Audit AI Compliance from Both Sides of the Table

The tricky thing about AI compliance is that most organizations are going to experience it from both sides. You need to be able to explain how AI is being used inside your own organization, what it can access, and how you're managing the risk. At the same time, you need to understand how your vendors are using AI and whether that introduces new risk into your environment.

What an AI Usage Inventory Cannot Tell You

Three reads from surfaces most organizations already own produce a usable AI usage register in a morning. Entitlement, from the identity provider, showing who is licensed for what. Activity, from network or gateway logs, showing who reached which destination and how much. Identity, from the directory, showing who those people are and which scopes they sit in. ‍ The register answers more questions than people expect.

Approved Tools, Unapproved Agents

Approval works at the tool layer and it works well. A platform is assessed, terms are reviewed, a data processing agreement is signed, the tool enters the register, and named identities are entitled to it. Everything about that maps cleanly. ‍ Then somebody uses the approved platform to assemble an agent that acts on their behalf, with its own reach and its own credentials. The approval covered the application.

1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it

1.1.1.1 now validates DNSSEC signatures made with ML-DSA-44, a post-quantum signature algorithm standardized by the National Institute of Standards and Technology (NIST). This is a first step toward preparing DNSSEC for a future in which today’s signature algorithms are no longer secure. Cloudflare plans to achieve full post-quantum security by 2029. Much of the work so far has focused on TLS, but public-key cryptography is used in many other systems, including DNSSEC.