Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

80% of New Code is AI-Generated - But 40-50% Has Vulnerabilities Find out Why

Is your organization generating up to 80% of its new code with AI? You might be proud of the speed — but are you ready for the security risks? In this video, we reveal the hidden danger: multiple studies show that **40-50% of AI-generated code changes contain vulnerabilities**. Discover why AI coding is accelerating development faster than ever — and why traditional security approaches are no longer enough.

AI hacking makes password spraying faster. Here's how to close the gap

AI hacking tools are compressing the time between finding a target and logging in as them. Password spraying, already responsible for the vast majority of identity attacks, is the technique benefiting most. Attackers use AI hacking methods to optimize timing, rotate infrastructure, and personalize lures at a scale no human operator could match manually.

Why Simple Masking Kills AI Accuracy

Here is a document going into an AI assistant: A simple masking system produces: The information is protected, but the document has become almost impossible for the AI to reason about. It no longer knows who introduced whom, who approved the proposal, or whether the same person appears multiple times. By removing identity, we destroyed the relationships that give the document meaning.

Identity Security for AI

What's scarier than an engineer with prod access? An agent with the same access that never sleeps, never asks, and runs a thousand sessions while you're at lunch. Last year we solved the problem of visibility in the Identity Chain, the concept is that identities are fragmented and it’s hard to get a view from Identity Providers to Infrastructure. Within a year, two things have changed. First, teams are using LLMs & Tools to perform actions on their behalf - fully delegating work to AI Agents.

When AI Agents Run Healthcare Workflows, Business Logic Becomes the New Attack Surface

Healthcare has moved well past pilot projects. AI agents now triage support tickets, draft clinical documentation, manage patient engagement, and coordinate care across systems that were never designed to talk to autonomous software. Autonomous systems can now analyze data, make decisions, trigger actions, and coordinate across clinical systems with minimal human oversight.

Trust Nothing: Tips to Secure AI Tools and Agents

So, you have some AI tools or are thinking about deploying them and want to know a bit about securing them. You are not alone, but there are significant challenges due to the rapidly growing capabilities of AI, and the issues around new types of vulnerabilities we may not be used to thinking of. This is a very challenging area to attempt to secure, but I hope to point you in the right direction and set you up with some resources.

Top 9 AI Penetration Testing Companies for AI/ML/LLMs/MCPs

From inchoate brainstorming sessions in the halls of Dartmouth College to a panoply of funding springs and winters, AI has made its way into the tech stack of not just almost every enterprise but also every household. This, though music to the ears of an AI researcher, rewards a security professional with sweat beads. Even a single AI/ML/LLM or an MCP feature in your product evolves your attack surface, necessitating scouting for the right AI/ML/LLM/MCP penetration testing companies.

Cato CTRL Insights: How One Threat Actor Turned Frontier AI Into an Offensive Platform

A Russian-speaking threat actor known as “Trim” has spent the better part of 2026 systematically dismantling the guardrails on publicly available frontier AI models and rebuilding them as offensive tools. What started in March as a knowledge-sharing post on a Russian cybercrime forum detailing how to break Claude Opus into writing malware, had evolved by June into a fully productized, commercially marketed AI-powered penetration testing platform.

Bringing Claude Enterprise Activity into Cato AI Security

Claude is now a part of many employees’ everyday work. But even as a sanctioned application, it creates a visibility problem for security teams. Sensitive data can move into prompts, files, projects, and conversations, and teams need a practical way to see what happened and whether it violates policy.