Archive of

DeepKeep AI Lens adds guardrails for AI coding agents

DeepKeep has launched AI Lens for Developers, an extension to its AI usage control and runtime protection modules. It is built to give security teams oversight of coding agents that write, change and run code for developers.

The company says the tool brings policy enforcement, audit visibility and runtime security to agents such as Cursor and Claude Code. According to DeepKeep, this covers ground that most security programs have not had to deal with before.

Why coding agents are a problem

DeepKeep's announcement says 90% of developers use AI coding agents at work at least once a week. These agents run on the developer's endpoint. They can read local files, execute shell commands and call MCP (Model Context Protocol) tools directly on the machine.

Read More


Exabeam Agentic SOC brings AI investigations on-premises

Exabeam has released a set of new capabilities for what it calls the Agentic SOC, extending AI-driven investigation, execution and governance to both cloud and on-premises deployments. The release also includes a modernized LogRhythm SIEM platform for organizations that keep security data inside their own environment. A SIEM (security information and event management) system collects and analyzes logs from across an organization's network.

The company's argument is that analyst workflows alone can no longer keep up with machine-speed threats. Enterprises are also running more goal-driven AI agents and autonomous workflows, and these need to be monitored as well.

Read More


Osavul raises $10M to spot hybrid threats before attacks

Luxembourg-based Osavul, which describes its business as hybrid risk intelligence, has closed a $10 million (EUR 8.5 million) Series A round. A Series A is usually a startup's first major institutional funding round after its early seed money. 33N Ventures led the investment, and Balnord, G+D Ventures and 42CAP also took part.

The round brings Osavul's total funding to roughly EUR 12 million.

What the platform does

Osavul sells an AI platform that analyzes both open and privileged data. Its goal is to detect hostile intent before an attack actually happens. The platform does this across three domains at once: cyber, physical and information.

Read More


FortiMail CVE-2026-104286 zero-day exploited in attacks

Fortinet has disclosed a critical vulnerability in FortiMail, its email security appliance. Attackers are already exploiting it in the wild to run unauthorized code or commands on exposed devices. The flaw is tracked as CVE-2026-104286, carries a CVSS score of 9.8, and sits in the product's management interface.

Patches are not yet out for most affected branches. For now, many administrators can only rely on workarounds.

How the flaw works

In its advisory, published Thursday, Fortinet describes the bug as a combination of two weaknesses. The first is a path traversal issue (CWE-22). The second is improper handling of NULL bytes or NULL characters (CWE-158). Together, they may let an attacker with no credentials write arbitrary files to the underlying system by sending specially crafted HTTP or HTTPS requests.

Read More


Microsoft: Attackers lead defenders in early AI race

Microsoft says cyberattackers are currently getting more out of artificial intelligence than the people defending against them. According to the company, AI helps threat actors find vulnerabilities faster, build malware more quickly and move through compromised networks at a pace security teams struggle to match.

The findings come from Microsoft's 2026 Digital Defense Report, the company's yearly overview of the threat landscape. This year's edition focuses on how AI is reshaping both attack and defense.

Microsoft argues that AI lowers the time, skill and money needed to discover and exploit weaknesses. Attackers and defenders both gain speed, scale and autonomy from the technology. The company expects defenders to catch up eventually, but it says attackers hold the lead for now.

Read More