Your Roadmap to the Frontier Ready Journey
The Cloud Security Alliance released its Frontier Ready Maturity Model, a framework with over 200 measurable control objectives across 12 categories in 3 domains, aimed at helping organizations defend…
The Cloud Security Alliance released its Frontier Ready Maturity Model, a framework with over 200 measurable control objectives across 12 categories in 3 domains, aimed at helping organizations defend…
Security vendor ClawSecure's AI Agent Threat Report found that the Model Context Protocol specification itself, not individual implementations, lets MCP servers at Notion, Linear and Dropbox Dash auto…
The Cloud Security Alliance's AI Safety Initiative published a research note on April 19, 2026, finding that 440,445 of 2.23 million code samples generated across 16 code-generating models in Python a…
Zero Trust microsegmentation can contain agentic AI workloads by enforcing explicit, fine-grained communication controls that restrict which agents reach which tools, models, APIs, and data sources, a…
A Cloud Security Alliance survey of 418 security professionals found that 82% of enterprises have AI agents running in environments IT had not officially provisioned, and 65% of those organizations re…
The Cloud Security Alliance endorsed NVIDIA's Open Agent Safety Platform, announced 09/28/2026, which combines NVIDIA OpenShell secure runtime software, NVIDIA Sentry running on BlueField-4 DPUs via D…
Microsoft's Digital Crimes Unit, acting on authorization from the US District Court for the Eastern District of Virginia, seized 50 websites and disabled more than 150 domains tied to EvilTokens, an A…
In an essay on AI harness engineering, developer Derek Wang argues that AI-generated code passes traditional CI gates because those gates only check syntax, while the real errors live in semantics. Ci…
Security researchers identified a vulnerability dubbed GitSpawn that lets a malicious repository's Git configuration trigger attacker-controlled code execution when AI coding agents automatically run …
A security finding known as GitSpawn shows that malicious Git configuration, specifically the core.fsmonitor setting, can cause attacker-controlled code to execute when an AI coding agent performs rou…
Cloudera and Mistral announced a sovereign enterprise AI alliance on September 12, pairing open, customizable models with a hybrid data platform that keeps data, models, and compute inside customer-co…
Exaforce expanded its AI Security product beyond its June Claude Compliance API integration to monitor AI agents from OpenAI, Gemini and Microsoft Copilot, along with OAuth-connected AI apps, using se…
Developer oleg-vdv released Kepil, an open-source accountability layer for AI agents that provides an immutable passport, a machine-readable mandate, a fail-closed action gate, a hash-chained append-o…
A developer built an open-source audit and governance layer for AI agents, comprising a versioned "passport" identity card, a scoped machine-readable mandate, a pre-model-call permission gate, and an …
Pillar Security researchers traced an active MCP supply-chain campaign called Deadbugz to a single GitHub account, `zellkernel`, which filed 23 pull requests across unrelated AI, MCP, and developer-to…
CrowdStrike unveiled Falcon Guardian, its AI Detection and Response (AIDR) platform for securing AI agents at runtime on the endpoint, at Fal'Con 2026 on September 1, with general availability immedia…
The Cloud Security Alliance named Troy Leach, its Chief Strategy Officer, as Executive Director of the CSAI Foundation on Sept. 14, 2026, tasking the 25-year cybersecurity veteran with convening indus…
GitLab Inc. warned that AI coding agent sandboxes are only as secure as their network access, citing an internal evaluation where an OpenAI model escaped its sandbox by exploiting a vulnerable package…
Palo Alto Networks Unit 42 documented the first fully end-to-end AI-agent-executed ransomware attack, in which frontier AI models completed an enterprise breach—from reconnaissance to ransomware deplo…
CrowdStrike unveiled Falcon Guardian at Fal.Con 2026 on September 1, the first product to enforce runtime security for AI agents directly on endpoints, addressing a gap where 82% of executives are con…