Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

"Speaking the Same Language" Tanium Atlas MCP Server: Tanium Tech Talks #169

Want to point your own AI at Tanium? The Atlas MCP Server makes that possible — governed, scoped, and available today. In this episode we cover: Tanium MCP - Available now (read-only) How to set up OAuth clients and how RBAC applies How to scope a single-purpose agent to one module, like Asset, using path-based tool filtering How to tell which tools consume Atlas AI credits - and which don't!

AI Governance Auditing for Security and IT Teams

AI governance auditing distinguishes between a documented policy and a working control. The audit traces one AI output back through the identity that invoked it, the data it reached, the guardrail that applied, and the record retained afterward. Most programs fail because access is ineffective: nobody can say which identities access sensitive data through an AI assistant, let alone prove the limit is held.

Cybersecurity Leaders React to OpenAI's Hugging Face Breach UpGuard

In July 2026, OpenAI's own AI agents escaped their sandbox and reached Hugging Face's production systems during an internal cybersecurity evaluation. In its latest report, OpenAI called the incident "a warning shot for us and for the world." We asked cybersecurity leaders for their reactions to the breach and what it signals for every team racing to deploy AI. One detail stands out. Hugging Face's own systems detected the attack and traced its full shape, but the alert never escalated high enough for a human to act on it.

Extending the Single Source of Truth to the Agentic Software Supply Chain

Every developer on your team now runs multiple agents. None of them are waiting for human sign-off to act. That’s exactly the gap we discussed and closed at swampUP 2026. JFrog unveiled new capabilities that extend the JFrog Platform as not only the Single Source of Truth for OSS and heritage software, but now the Agentic Software Supply Chain. Here’s everything we announced, and why it matters.

Governance Strikes Back: The Most Used, Most Abused Word in the Galaxy

Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know When I walked to the stage in Copenhagen, I had a lot on my mind. For 3 days I'd had countless conversations with leaders and practitioners about AI and agentic security. The one word on everyone's lips was "governance"; day 3 at the conference was "Governance Day," in fact. This is a bag one vendor was giving out: But governance of what? To what end?

How to Reduce Your Cloud Attack Surface by Eliminating Standing Privileges

You can reduce your cloud attack surface by auditing every persistent permission across your cloud and identity platforms, stripping away unnecessary access and replacing always-on admin rights with Just-In-Time (JIT) access that’s granted on approval, time-limited and automatically revoked. Getting there starts with understanding why standing privilege makes up such a significant portion of the cloud attack surface.

Shadow AI: What Clients Aren't Telling Their MSPs

MSPs are expected to understand their clients’ technology environments. They know which endpoints are managed, which applications are business-critical, which systems require patching or maintenance, where sensitive data resides and who has access to it. Increasingly, however, critical technology decisions are now being made without IT or MSP involvement. Across client environments, this can take many forms: And each instance can occur without the MSP ever knowing.

New Phishing Kit Uses AI to Fully Automate Vishing Attacks

A new phishing kit is using generative AI to fully automate voice phishing (vishing) attacks, according to researchers at Group-IB. The phishing platform, called “Balonx,” includes a module dubbed “CallFlow” that the researchers say “represents a fundamental evolution” in the phishing-as-a-service market.

How to Detect Shadow AI: 8 Key Steps

Security teams have spent years building visibility into unsanctioned SaaS apps, cloud services, and other forms of shadow IT. But shadow AI raises the bar. Discovering an unsanctioned AI app or autonomous agent is only the beginning. Teams also need to determine which identities it authenticates with, what credentials and permissions it relies on, what data it can access, which systems it integrates with, and what downstream actions it performs. The scale of the challenge is already becoming apparent.

How to Build a More Flexible and Connected AV Setup

A boardroom gets used for a client demo on Monday, a town hall on Wednesday, and a hybrid interview on Friday. It was built for one of those. It's now handling all three, badly. That mismatch is what flexible AV design fixes. Not by cramming in more gear, but by rethinking how the room, the network, and the equipment connect to each other in the first place.