The Source Signals
Tech news is everywhere. Intelligence isn't.
Enterprise AI Has Until January to Prove It Works
MIT’s Project NANDA found 95% of enterprise generative-AI initiatives produced zero measurable return, and the industry answered with $725 Billion in capital expenditure. When contract renewals come round in January 2027, buyers will want evidence the market does not currently produce.
What 170,000 job cuts have done to the credentials nobody was tracking
With 109 machine identities for every human, the accounts and keys that departing engineers created are surviving restructuring after restructuring, because the people who could explain what they do have already gone.
Attackers have stopped hunting for vulnerabilities and started hunting for relationships
BeyondTrust's first Phantom Labs Research Index accounts for more than 400 projects across cloud, SaaS and AI systems, and points to inherited access as the condition defining enterprise exposure.
Enterprises have deployed AI agents into core systems and left the identity layer ungoverned
Sophos research documents OAuth token compromises at Vercel and across Salesforce environments, alongside survey data showing that 71% of large enterprises run AI agents against core business systems. In comparison, only 16% govern that access effectively.
Cloudflare's Q2 outage data traces connectivity failure from Guam's typhoon to a broken German signing key
Cloudflare's Q2 2026 disruption data records typhoon damage in Guam, earthquakes in Venezuela, drone strikes on UAE cloud infrastructure and a DNSSEC error that removed Germany's .de domains.
Check Point converts installed firewalls into AI enforcement points as shadow AI spreads across enterprise networks
Check Point Research found that up to 93% of organisations see a high-risk generative AI interaction every month, and the company's answer runs inside firewall software customers have already deployed.
9 days, 2 confessions: how OpenAI, Anthropic, and Hugging Face changed what a rogue AI agent means
Nine days apart, OpenAI and Anthropic admitted their agents escaped containment and hit real companies including Hugging Face. What enterprises deploying agents must do now.
NVIDIA assembles 37 companies behind open AI security as OpenAI, Anthropic and Google stay out
The Open Secure AI Alliance launched on Monday with Microsoft, IBM, Red Hat, Hugging Face and the Linux Foundation among its inaugural partners, carrying a policy argument aimed at regulators now weighing restrictions on open-weight models.
Microsoft puts its first cybersecurity model into production as the AI defence race turns on cost
MAI-Cyber-1-Flash and Project Perception enter public preview on 3 August, scoring 96% on CyberGym at half the cost of Microsoft’s own previous configuration.
BeyondTrust extends privileged access control to AI agents and service accounts
NHI Governance sets out to close the gap between seeing non-human identities and controlling the privilege they carry, bringing AI agents under the same lifecycle governance as human access.
Ransomware becomes an identity crisis: 79% of attacks now start with stolen credentials
Sophos' seventh State of Ransomware report finds exploited software flaws dethroned as the top attack route, as email and identity compromise take over and falling ransom figures mask a harder shift in how attackers get in.
AI finds the vulnerabilities in seconds. Defenders still need weeks to close them
Anthropic's Mythos has collapsed the cost of finding software flaws, surfacing more than 10,000 in weeks. Security leaders at BeyondTrust and Acronis on why the race is now to remediate, and what that means for the future of cybersecurity.
Sophos bets against the market on Fusion, the AI-native defence system built to stop short of full autonomy
Sophos has launched Fusion, unifying security operations, endpoint, identity, email, and cloud into one AI-native system where humans stay accountable and third-party tools feed one shared data layer.
Seven Numbers That Show How Security Teams Are Actually Running AI, and What They Are Not Measuring
The 2026 SANS AI Survey settles the adoption argument and opens a harder one. Across 536 practitioners, AI is running in more places than ever, most of it shallow, and almost nobody is measuring whether it catches anything.
Half of Security Leaders Report an AI Risk Programme. Their Practitioners Cannot Find It
The 2026 SANS AI Survey asked 57 CISOs and 536 practitioners the same questions about AI governance and got a 14-point gap in return, alongside a leadership priority shift that the survey's own attack data contradicts.
Infoblox Acquires Kentik to Build an AI-Ready Data Fabric for Hybrid Cloud Networks
The definitive agreement brings Kentik’s full-fidelity traffic intelligence together with Infoblox’s DNS, identity and preemptive security context, signalling how quickly network observability and security are consolidating around a shared data problem.
Endava's engineering-led entry into the Wiz Partner Alliance signals a shift in how cloud security gets delivered
The technology transformation group has joined Wiz's global partner community, wagering that its engineers can fix the risks the platform uncovers rather than simply flag them, as enterprises accelerate agentic AI adoption across multi-cloud estates.
OPSWAT flies air-gapped cyber kiosk toward space in prevention-first test
A near-space validation flight processed thousands of malware samples in freefall, staking a claim that mission-critical systems can no longer assume a human on Earth will fix them
The Ransom Reckoning: Why Paying Was Never a Recovery Strategy
With payment bans spreading across jurisdictions and the data showing that paying buys neither safety nor silence, security leaders are confronting a harder question than whether to pay: how they became the target in the first place, and whether they can recover without negotiating at all.
The Genie Is Out of the Bottle: Why the AI Agent Explosion Is Rewriting Enterprise Security Faster Than Anyone Can Patch
As autonomous agents proliferate inside enterprises faster than security teams can see or govern them, BeyondTrust Field CTO James Maude and Censys regional Vice President Meriam ElOuazzani argue that identity, privilege and external exposure now matter more than any single vulnerability, with Microsoft's latest disclosures illustrating where the risk is concentrating.