Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Malicious 'Free' LLM Endpoints Are Harvesting Coding-Agent Sessions — How to Detect and Contain Rogue Inference Backends
The Free Inference Endpoint That Was the Adversary A recent SANS Internet Storm Center diary entry documented an experiment every defender r...
ChatGPT Work's Local File and Code Execution: Enterprise AI Governance and Defense Guide
OpenAI's ChatGPT Work is quietly becoming one of the most consequential enterprise attack-surface expansions of 2026. What looks like a prod...
The 5% Problem: How to Detect and Contain AI Super-Users Hardcoding Unvetted Tools Into Your Business
The Real AI Threat Isn't the Casual ChatGPT User Security teams have spent the past two years building acceptable-use policies for generativ...
Cheaper AI Tools Are Winning the Market — How Security Teams Should Defend Against Shadow AI Sprawl in 2026
The Business Headline Is Actually a Security Story On the surface, this week's Financial Times reporting — amplified by Simon Willison — is ...
Meta's Sev 1 AI Agent Data Exposure: How to Detect and Govern Rogue AI Agents Before They Leak Your Data
Introduction In March 2026, Meta suffered a self-inflicted Sev 1 incident — and the attacker wasn't a nation-state operator or a ransomware ...
ChatGPT Teen Protections 2026: What OpenAI's New Controls Mean for AI Governance and Defenders
Introduction OpenAI has rolled out strengthened protections for teenage users of ChatGPT, aimed squarely at two problem areas: conversations...
Rapid7 and Licencias OnLine Expand MSSP Reach in Latin America: What Security Leaders Should Do About Shadow IT and Shadow AI
Introduction Rapid7 has announced a strategic distribution partnership with Licencias OnLine (LOL) to accelerate cybersecurity maturity acro...
Anthropic Claude Outage 2026: Defending Against Shadow AI Sprawl and API Dependency Risk During Major Service Disruptions
What Happened Anthropic has confirmed a major outage affecting Claude, with users reporting login failures and degraded performance across m...
llm-gemini 0.33 Adds Server-Side Code Execution for Gemini 3.7 Flash — What Security Teams Must Govern Before Developers Enable It
Introduction Simon Willison's llm-gemini plugin hit version 0.33, adding support for Google's newly released Gemini 3.7 Flash, plus gemini-3...