SentinelLabs found OpenAI AI agents using public wikis, package registries, university services and government sites as unauthorized communication and data-retrieval channels.
Featured
Stephen Cravey’s CYBR.SEC.CON 2026 talk explores the security blind spots inside smart locks, appliances and everyday IoT devices — and why organizations may have little idea what is actually running on them.
Before cybersecurity was much of an industry, Stephen Cravey followed his curiosity from Star Wars and BBSs to the NSA’s Rainbow Books — and eventually into a major FBI cybercrime investigation.
Community Corner
See allFrom the CYBR.SEC.Community
Your Security Architecture May Be a Sideways Driveway
Security architecture accumulates “adaptation debt” when local fixes, exceptions and compensating controls force users, systems and now AI agents to work around designs that no longer match how identity, authority and data actually flow.
What Radio Jamming Taught Me About DDoS
From Army signal intelligence and radio jamming to modern DDoS defense, the same lessons in reconnaissance, timing, disruption and adaptation reveal how attackers overwhelm networks — and how defenders can stay ahead.
The Agent Died. The Delegation Didn't.
Once the work can move from agent to agent, killing the agent is no longer the same thing as stopping the work.
Returning Continuity: What AI Is Teaching Us About Cybersecurity
Yesterday's me made a move. Today's me inherits the consequences. Tomorrow's me will inherit a different world again.
The Human Factor in IAM: Why Identity Programs Succeed or Fail
Most IAM failures don't start with a broken platform. They start with a person making a reasonable decision under bad conditions.
Latest Articles
See all
AI SOCSOC
Agentic AI in the SOC: The Gap Between the Haves and the Have-Nots Is Already Widening
Agentic AI is delivering sharper triage, faster investigations, and reduced analyst burnout at the organizations that have committed to production deployment. For everyone else, the gap is compounding, and the security implications are already visible.
CYBR.SEC.CON
The Four Horsemen of Cybersecurity Failure: Wil Klusovsky Previews CYBR.SEC.CON 2026 Talk
viLogics CRO Wil Klusovsky will bring nearly three decades of cybersecurity experience to CYBR.SEC.CON 2026, examining the recurring mistakes that derail security programs and how leaders can keep them focused on what matters.
Press ReleaseCybersecurity Startupscybersecurity
CYBR.SEC.Community, LaunchPoint Collective Partner to Bring Cybersecurity Startups to Houston
LaunchPoint Collective and CYBR.SEC.Community are teaming up to bring 20-plus cybersecurity startups to CYBR.SEC.CON. 2026, connecting emerging security technology with CISOs, practitioners and early adopters.
LaunchPadCYBR.SEC.CONAI Security
Singulr AI Targets the Growing Enterprise AI Control Gap
CYBR.SEC.CON LaunchPad finalist Singulr AI is tackling the enterprise AI control gap with runtime governance, security and controls designed to let companies adopt AI and agents without losing visibility or control.
LaunchPadCYBR.SEC.CON
Astelia Says Vulnerability Prioritization Is Solving the Wrong Problem
CYBR.SEC.CON LaunchPad finalist Astelia uses attack-path reachability to determine which vulnerabilities can actually lead to a breach, helping enterprises cut through millions of findings and focus remediation where it matters.
AI and Vulnerability ManagementVulnerability ManagementCVE
AI Isn’t Causing a ‘Vulnpocalypse.’ CVE Volume Is the Real Problem
Root Evidence analyzed 253,912 CVEs and found AI is accelerating vulnerability discovery, but not exploitation — exposing a vulnerability management model increasingly overwhelmed by noise.
Agentic AIOpenAIHugging Face
After the Hugging Face OpenAI Swarm: What Enterprise Security Looks Like Now
Network segmentation, credential hygiene, behavioral monitoring, automated containment. The OpenAI incident didn't invent these requirements. It proved that skipping them in agent environments has consequences.
Podcasts & Video
See all
Podcast
Dumb IoT Devices with Stephen Cravey
Video
Shall We Play a Game? Unlocking Mastery in Hacking, Coding, and AI
Marcus Carey demystifies complex disciplines through play, curiosity, and iterative challenge.
Video
Preparing for the New Identity War: A CCN Podcast Session
Chris Glanden discusses emerging societal, technological, and geopolitical tensions centered on identity and what it means for digital sovereignty, biometric data control, cultural narratives and AI-driven identity manipulation.
Video
Offensive Forensics: A Useful Addition For Your Offsec Toolbox To Pwn More Things
Cory Mathews introduces “Offensive Forensics,” a mindset and methodology that combines digital forensics techniques with offensive security practices to uncover hidden artifacts, persistence mechanisms, and overlooked attack surfaces during red team engagements and penetration testing.
Podcast
Hackers vs. WarGames with Wil Klusovsky
Video
Ghosts in the Machine - The Therac-25 Affair
Sean Satterlee examines the case of Therac-25, a computer-controlled radiation therapy machine that delivered massive, lethal overdoses to at least six patients in the mid-1980s due to software flaws, poor safety design, and inadequate testing.
Video
What did I learn from analyzing hundreds of App Privacy Reports from iPhones
The talk by Sergey Shkundaleu details insights gained from analyzing hundreds of iOS app privacy reports — automatically generated by Apple’s App Privacy Report feature — to uncover real-world data collection and tracking behaviors across popular apps.