Legit Security has expanded its Agentic Remediation feature so it now handles vulnerabilities in open-source dependencies, not only in code that a company writes itself. The goal is to take development teams from a vulnerability finding to a verified fix without anyone having to triage the issue by hand.
Until now, the agent worked on static analysis findings in first-party code, meaning code written by a company's own engineers. The new release points the same agent at packages pulled in from outside, which the company describes as the other major source of vulnerabilities in modern software.
Sophos has released Sophos CISO Advantage, a service that uses agentic AI to link day-to-day security operations with longer-term security strategy. The goal is to tell businesses where their cyber risk lies, which fixes to fund first, and whether things are getting better over time.
The company says the output is written in plain language so that business leaders, not only security staff, can understand it, approve budgets and act on it. Sophos describes the offering as a new market category.
From security data to a roadmap
CISO Advantage assesses an organization's environment and maps its controls against established frameworks. These include NIST CSF (the US National Institute of Standards and Technology's Cybersecurity Framework), CIS v8, Cyber Essentials Plus (a UK certification scheme), and NCSC CAF, the Cyber Assessment Framework published by the UK's National Cyber Security Centre.
DeepKeep has launched AI Lens for Developers, an extension to its AI usage control and runtime protection modules. It is built to give security teams oversight of coding agents that write, change and run code for developers.
The company says the tool brings policy enforcement, audit visibility and runtime security to agents such as Cursor and Claude Code. According to DeepKeep, this covers ground that most security programs have not had to deal with before.
Why coding agents are a problem
DeepKeep's announcement says 90% of developers use AI coding agents at work at least once a week. These agents run on the developer's endpoint. They can read local files, execute shell commands and call MCP (Model Context Protocol) tools directly on the machine.
Exabeam has released a set of new capabilities for what it calls the Agentic SOC, extending AI-driven investigation, execution and governance to both cloud and on-premises deployments. The release also includes a modernized LogRhythm SIEM platform for organizations that keep security data inside their own environment. A SIEM (security information and event management) system collects and analyzes logs from across an organization's network.
The company's argument is that analyst workflows alone can no longer keep up with machine-speed threats. Enterprises are also running more goal-driven AI agents and autonomous workflows, and these need to be monitored as well.
Luxembourg-based Osavul, which describes its business as hybrid risk intelligence, has closed a $10 million (EUR 8.5 million) Series A round. A Series A is usually a startup's first major institutional funding round after its early seed money. 33N Ventures led the investment, and Balnord, G+D Ventures and 42CAP also took part.
The round brings Osavul's total funding to roughly EUR 12 million.
What the platform does
Osavul sells an AI platform that analyzes both open and privileged data. Its goal is to detect hostile intent before an attack actually happens. The platform does this across three domains at once: cyber, physical and information.
Guy Fawkes News is financed by advertising. You can choose how you want to use this website:
With advertising: we load an advertising script from a third-party ad network. The ad network may set cookies, use your IP address and device information, and may process data outside the EU. We also count your visits for our own visitor statistics (with a random ID stored in your browser).
Ad-free for €0.99 per month: no advertising and no advertising tracking. Cancel at any time.
You can change your decision at any time via "Cookie Settings" at the bottom of every page.