The Source Signals
Tech news is everywhere. Intelligence isn't.
BeyondTrust extends privileged access control to AI agents and service accounts
NHI Governance sets out to close the gap between seeing non-human identities and controlling the privilege they carry, bringing AI agents under the same lifecycle governance as human access.
Ransomware becomes an identity crisis: 79% of attacks now start with stolen credentials
Sophos' seventh State of Ransomware report finds exploited software flaws dethroned as the top attack route, as email and identity compromise take over and falling ransom figures mask a harder shift in how attackers get in.
AI finds the vulnerabilities in seconds. Defenders still need weeks to close them
Anthropic's Mythos has collapsed the cost of finding software flaws, surfacing more than 10,000 in weeks. Security leaders at BeyondTrust and Acronis on why the race is now to remediate, and what that means for the future of cybersecurity.
Sophos bets against the market on Fusion, the AI-native defence system built to stop short of full autonomy
Sophos has launched Fusion, unifying security operations, endpoint, identity, email, and cloud into one AI-native system where humans stay accountable and third-party tools feed one shared data layer.
Seven Numbers That Show How Security Teams Are Actually Running AI, and What They Are Not Measuring
The 2026 SANS AI Survey settles the adoption argument and opens a harder one. Across 536 practitioners, AI is running in more places than ever, most of it shallow, and almost nobody is measuring whether it catches anything.
Half of Security Leaders Report an AI Risk Programme. Their Practitioners Cannot Find It
The 2026 SANS AI Survey asked 57 CISOs and 536 practitioners the same questions about AI governance and got a 14-point gap in return, alongside a leadership priority shift that the survey's own attack data contradicts.
Infoblox Acquires Kentik to Build an AI-Ready Data Fabric for Hybrid Cloud Networks
The definitive agreement brings Kentik’s full-fidelity traffic intelligence together with Infoblox’s DNS, identity and preemptive security context, signalling how quickly network observability and security are consolidating around a shared data problem.
Endava's engineering-led entry into the Wiz Partner Alliance signals a shift in how cloud security gets delivered
The technology transformation group has joined Wiz's global partner community, wagering that its engineers can fix the risks the platform uncovers rather than simply flag them, as enterprises accelerate agentic AI adoption across multi-cloud estates.
OPSWAT flies air-gapped cyber kiosk toward space in prevention-first test
A near-space validation flight processed thousands of malware samples in freefall, staking a claim that mission-critical systems can no longer assume a human on Earth will fix them
The Ransom Reckoning: Why Paying Was Never a Recovery Strategy
With payment bans spreading across jurisdictions and the data showing that paying buys neither safety nor silence, security leaders are confronting a harder question than whether to pay: how they became the target in the first place, and whether they can recover without negotiating at all.
The Genie Is Out of the Bottle: Why the AI Agent Explosion Is Rewriting Enterprise Security Faster Than Anyone Can Patch
As autonomous agents proliferate inside enterprises faster than security teams can see or govern them, BeyondTrust Field CTO James Maude and Censys regional Vice President Meriam ElOuazzani argue that identity, privilege and external exposure now matter more than any single vulnerability, with Microsoft's latest disclosures illustrating where the risk is concentrating.
Vulnerabilities by the minute: TrendAI’s UAE debut and the race to secure agentic AI
Trend Micro’s enterprise security business has launched in the UAE as TrendAI, warning that frontier models will soon surface vulnerabilities at machine speed and pairing the rebrand with an Anthropic partnership and an unresolved agentic governance challenge.
The Deepfake Wire Transfer Has Become Routine, and Most Finance Functions Are Defending the Wrong Perimeter
Fraud attempts using synthetic voice and video have surged by over 2,000% in three years, billions in deepfake losses were absorbed in 2025 alone, and nearly half of Indian adults have been touched by AI voice-cloning scams. Security leaders nonetheless continue to treat weaponised human trust as a communications glitch, and the organisations paying for it rarely discover their exposure until the money has already moved.
Who Controls the Proof Now Controls the Internet
Six separate announcements in one week converged on a single argument about power, that whoever issues the proof holds the leverage.
Media groups and exiled journalists bear the heaviest concentration of cyberattacks against civil society, Cloudflare data shows
New research drawn from more than 3,400 protected domains reveals DDoS campaigns lasting days rather than minutes, vulnerability probing at more than seven times the rate of other customers, and phishing emails that slip past standard authentication before being caught.
The Velocity Gap: Why Record Middle East Cyber Spending Is Losing to AI Attackers
Investment in regional cyber defence is climbing toward record levels, yet Help AG’s State of the Market Report 2026 shows attackers are pulling ahead — compressing time-to-impact by 65% as AI rewrites the relationship between security and time.
A 500 billion query problem hiding inside the enterprise network
Infoblox Threat Intel research finds residential proxies embedded across two-thirds of its cloud customers, putting corporate reputation and IP space at risk without security teams ever seeing it
Business as Usual: How Attackers Are Turning IT Tools Into Backdoors
HP threat researchers found criminals using LogMeIn and ScreenConnect, tax-themed phishing, and AI-assisted scripts to take over PCs without triggering alarms that detect conventional malware.
BeyondTrust Gains Access to Anthropic's Restricted Frontier Model to Hunt Flaws in Its Own Code
The identity security vendor joins Project Glasswing, turning a model Anthropic withholds from the public against the vulnerabilities in software that underpins governments and essential services.
AI security has a detection problem, and Check Point’s 2026 report puts a number on it
Only 13% of organisations can block a malicious prompt and just 5% can stop unsafe AI outputs, according to Check Point’s 2026 Cloud Security Report. Why detection has outpaced prevention.