Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Can we defend against ai-powered attackers?

In this week's Intel Chat, Chris Luft and Matt Bromiley discuss how the same AI capabilities fueling adversaries are available to defenders too. Matt's takeaway: you don't need to buy an AI product to keep pace. The same way an attacker points AI at a code base, defenders can point it at detection rules and telemetry. Chris adds that as more developers use these models to check their own code, the playing field will level out, though the next year or two will likely bring a spike in exploits from lower-skilled attackers leveraging AI before defenses catch up.

Shadow AI - The Hidden Risk in Every Pocket

Shadow AI is already on your employees' phones — and it's invisible to your network controls. This demo follows a real workflow: an employee gets blocked from using an unauthorized AI tool on her corporate laptop, so she switches to her personal phone instead. No VPN, no DLP, no visibility, no corporate controls follow her there.

AI Innovation Challenge: Help Shape the Future of Cybersecurity

Artificial intelligence is transforming cybersecurity, and Managed Service Providers (MSPs) are at the forefront of that evolution. That's why we're launching the WatchGuard AI Innovation Challenge, an opportunity for MSPs to share ideas for AI agents and automations that help security teams work smarter, operate more efficiently, and better protect their customers.

Why we cannot wait for better post-quantum signature algorithms

RSA and ECC, cryptographic algorithms that we’ve all relied on for decades, are vulnerable to the attack of sufficiently advanced quantum computers. Such quantum computers do not exist yet, but they seem to be coming sooner than expected. Luckily, the solution is already available: migrate to ML-KEM encryption and ML-DSA signatures, which are designed to be resistant to quantum attack. They were standardized in 2024 by the U.S.

MCP Supply Chain Security: How Malicious MCP Servers Are Infiltrating Enterprise AI Environments

Every enterprise deploying AI agents is building on a foundation of third-party MCP servers they don’t control, can’t verify, and barely track. The security conversation keeps focusing on the model – prompt injection, jailbreaks, hallucinations. That’s the wrong place to look. We’ve covered why that framing falls short elsewhere too – see System Prompts Are Not Security Boundaries. Business Logic Graphs Are.

AI Pentesting Buyer's Guide: How to evaluate AI pentesting vendors

Pentesting made sense when releases happened every few months. A point-in-time assessment could provide an accurate picture of risk for weeks, sometimes months. Today, engineering teams ship continuously. Our State of AI in Pentesting survey of 200 CISOs and 200 engineering leaders, found that 76% deploy significant changes at least weekly, while nearly 40% deploy daily. Yet only 21% validate security on every release. That gap has consequences.

Prompt Injection and the Rise of Agentic Risk

Boxers will often say, the punches that hurt the most aren’t the ones which are thrown with the most force, but the ones they didn’t see coming. I think the same is true in cybersecurity. It’s not the most advanced technically efficient, 0-day utilizing attacks that have the biggest impact, but rather those quiet ones. With no malware or suspicious login at three in the morning from an IP address in a country your company has never done business with. No alert fires.

When the Classifier Is the Judge: What the Adelphi AI Case Reveals About Automated Verification

Orion Newby was a student at Adelphi University when a single automated score nearly ended his academic career. He had written a course paper himself, working with tutors from a university support program for students with learning and neurological differences. The essay was run through an AI detector, which reported it as AI-written. On the strength of that output, Newby was accused of an integrity violation, the kind of charge that can escalate toward suspension or expulsion on a repeat offense.

Shadow AI has officially entered the enterprise

AI tools have become a workplace staple, but their unsanctioned use has given rise to shadow AI. It refers to the untracked usage of any AI tools or applications without approval or overview of the information technology (IT) or security team. This is substantiated by the Verizon 2026 Data Breach Investigations Report (DBIR) which shows how rapidly the shadow AI trend is growing.