<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Last Watchdog</title>
	<atom:link href="https://www.lastwatchdog.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.lastwatchdog.com</link>
	<description>on Internet security by Byron Acohido</description>
	<lastBuildDate>Thu, 24 Sep 2026 23:42:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>
	<item>
		<title>News alert: SCOUTz gives MSPs security evidence to help turn prospects into customers</title>
		<link>https://www.lastwatchdog.com/news-alert-scoutz-gives-msps-security-evidence-to-help-turn-prospects-into-customers/</link>
		
		<dc:creator><![CDATA[cybernewswire]]></dc:creator>
		<pubDate>Thu, 24 Sep 2026 23:42:36 +0000</pubDate>
				<category><![CDATA[News Alerts]]></category>
		<category><![CDATA[Top Stories]]></category>
		<guid isPermaLink="false">https://www.lastwatchdog.com/?p=40475</guid>

					<description><![CDATA[<p>PHOENIX, Sept. 24, 2026, CyberNewswire<strong> — </strong><a href="https://scoutzsecurity.io/" rel="nofollow" rel="nofollow">SCOUTz</a>, a prospect intelligence platform built for managed service provider (MSP) security sales, is now available in open beta. The platform gives an MSP dated evidence about a prospect&#8217;s environment before the first &#8230; <a href="https://www.lastwatchdog.com/news-alert-scoutz-gives-msps-security-evidence-to-help-turn-prospects-into-customers/" class="read-more">(more…) </a></p>
<p>The post <a href="https://www.lastwatchdog.com/news-alert-scoutz-gives-msps-security-evidence-to-help-turn-prospects-into-customers/">News alert: SCOUTz gives MSPs security evidence to help turn prospects into customers</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>PHOENIX, Sept. 24, 2026, CyberNewswire<strong> — </strong><a href="https://scoutzsecurity.io/" rel="nofollow" rel="nofollow">SCOUTz</a>, a prospect intelligence platform built for managed service provider (MSP) security sales, is now available in open beta. The platform gives an MSP dated evidence about a prospect&#8217;s environment before the first meeting and keeps that evidence attached through delivery and reassessment.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/scoutz-logo.png" rel="nofollow" rel="nofollow"><img decoding="async" class="alignright size-full wp-image-40478" src="https://www.lastwatchdog.com/wp/wp-content/uploads/scoutz-logo.png" alt="" width="321" height="85" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/scoutz-logo.png 321w, https://www.lastwatchdog.com/wp/wp-content/uploads/scoutz-logo-100x26.png 100w" sizes="(max-width: 321px) 100vw, 321px" /></a>The open beta is available at <a href="https://scoutzsecurity.io/open-beta" rel="nofollow" rel="nofollow">https://scoutzsecurity.io/open-beta</a></p>
<p>30 days at no charge from the day the workspace is provisioned, then $279 per month at list price. Fifty MSPs from three peer communities shaped the platform in a closed beta that preceded the public release.</p>
<p>The channel has many tools that earn an MSP a first appointment, and several that earn their keep after signature, including professional services automation (PSA) and remote monitoring and management (RMM) platforms. The stretch between a booked meeting and a signed agreement, where the selling happens, has been left to templates and the seller&#8217;s own preparation. SCOUTz is built for that stretch.<span id="more-40475"></span></p>
<p>Before a meeting, SCOUTz pairs public company events such as new locations, IT hires and announced initiatives with its own dated external evidence, so the MSP arrives knowing why the account matters and what to ask. The domain review runs without an agent, install or login and covers email authentication, certificates, subdomains, exposed services and 156 distinct checks drawn from a live evidence registry. Each check carries a written explanation and a next step. Outside-in signals are never presented as proof of internal controls; they justify better questions.</p>
<p>With the prospect&#8217;s consent, SCOUTz can review Microsoft 365 configuration through a read-only connection: identity, application consent, security settings and managed-device context. Nothing is installed and nothing is changed. The platform does not read mail, documents, files or chats.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Scoutz_graphic.png" rel="nofollow" rel="nofollow"><img decoding="async" class="alignright size-medium wp-image-40484" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Scoutz_graphic-520x245.png" alt="" width="520" height="245" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Scoutz_graphic-520x245.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/Scoutz_graphic-960x453.png 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/Scoutz_graphic-100x47.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Scoutz_graphic-768x362.png 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/Scoutz_graphic.png 1056w" sizes="(max-width: 520px) 100vw, 520px" /></a>Every finding traces to a dated check and a named evidence source, and an unknown never scores as clean. Findings carry fix guides, work plans and ticket-ready text. A rescan compares new evidence to a pinned baseline so the next quarterly review rests on what changed. From the same evidence, the platform produces a client-safe report for business owners and an operator edition for technical teams.</p>
<div id="attachment_40481" style="width: 110px" class="wp-caption alignright"><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Steve-Copeland-hdsht.png" rel="nofollow" rel="nofollow"><img decoding="async" aria-describedby="caption-attachment-40481" class="wp-image-40481 size-thumbnail" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Steve-Copeland-hdsht-100x129.png" alt="" width="100" height="129" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Steve-Copeland-hdsht-100x129.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Steve-Copeland-hdsht.png 163w" sizes="(max-width: 100px) 100vw, 100px" /></a><p id="caption-attachment-40481" class="wp-caption-text">Copeland</p></div>
<p>&#8220;There are a ton of tools, programs and marketing companies that will get an MSP the first meeting,&#8221; said Steve Copeland, founder of SCOUTz and CEO of RYTHMz. &#8220;What none of them do is put the MSP in that room already knowing something true about the business. I built two MSPs, so I know what that meeting feels like when you walk in with a deck and a story and walk out with a follow-up.&#8221;</p>
<p>The platform&#8217;s limits are deliberate. SCOUTz is read-only by design and does not model dollar losses from hypothetical breaches. Artificial intelligence (AI) drafts explanations; deterministic checks decide whether a finding exists, and people own the final claims.</p>
<p>&#8220;Everyone in this industry has seen the slide with an employee&#8217;s stolen password on it,&#8221; Copeland said. &#8220;We refused to build that. Fear gets you a meeting and costs you the relationship. Show a business owner what was checked, what was found and when, and they can make a decision.&#8221;</p>
<p>One closed-beta participant ran the platform from his phone immediately after a prospect meeting. &#8220;Man, I wish I had this in the meeting I just walked out of,&#8221; said Zach Kinder, President and Partner of Net-Tech Consulting, a managed IT and cybersecurity firm in El Paso, Texas.</p>
<p>Copeland built SCOUTz nine months after publishing The 3AM Test for MSPs, a business book on evidence-based selling for managed service providers. A free public domain score is available at <a href="https://scoutzsecurity.io/tools" rel="nofollow" rel="nofollow">https://scoutzsecurity.io/tools</a> without signup.</p>
<p><strong><em>About SCOUTz: </em></strong><em><a href="https://scoutzsecurity.io/" rel="nofollow" rel="nofollow">SCOUTz</a> is security sales intelligence for managed service providers: account context and dated evidence before the first meeting, kept attached through review, delivery and reassessment, so the story the MSP sold is the story it proves. SCOUTz is a product built by RYTHMz, self-funded and headquartered in Phoenix, Arizona. Learn more at <a href="https://scoutzsecurity.io/" rel="nofollow" rel="nofollow">https://scoutzsecurity.io/</a>. </em></p>
<p><strong><em>About RYTHMz: </em></strong><em><a href="https://rythmz.com/" rel="nofollow" rel="nofollow">RYTHMz</a>, the 2025 ASCII Cup Vendor of the Year, is a channel-only 5G connectivity company with more than 180 MSP partners. Learn more at <a href="https://rythmz.com/" rel="nofollow" rel="nofollow">https://rythmz.com/</a>. </em></p>
<p><strong><em>Media contact:</em></strong> <em>Brandon Rhea, Marketing Directo, RYTHMz, brandon.rhea@rythmz.com</em></p>
<p><em><strong>Editor’s note:</strong></em><em> This press release was provided by </em><a href="https://cybernewswire.com/" rel="nofollow" rel="nofollow"><em>CyberNewswire</em></a><em> as part of its press release syndication service. The views and claims expressed belong to the issuing organization.</em></p><p>The post <a href="https://www.lastwatchdog.com/news-alert-scoutz-gives-msps-security-evidence-to-help-turn-prospects-into-customers/">News alert: SCOUTz gives MSPs security evidence to help turn prospects into customers</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Black Hat Fireside Chat: As AI agents spread, the network shifts from traffic mover to policy enforcer</title>
		<link>https://www.lastwatchdog.com/black-hat-fireside-chat-as-ai-agents-spread-the-network-shifts-from-traffic-mover-to-policy-enforcer/</link>
		
		<dc:creator><![CDATA[bacohido]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 10:32:08 +0000</pubDate>
				<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[Black Hat Podcasts]]></category>
		<category><![CDATA[Fireside Chat]]></category>
		<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Top Stories]]></category>
		<guid isPermaLink="false">https://www.lastwatchdog.com/?p=40426</guid>

					<description><![CDATA[<p>The network’s job has always been simple: watch the traffic. Authority stopped there.</p>
<p><em><strong>Related:</strong> <a href="https://www.linkedin.com/pulse/my-take-ai-agents-have-lord-flies-problem-nobody-teaching-acohido-ugvxc/" rel="nofollow" rel="nofollow">AI agents have a Lord Of The Flies problem</a></em></p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/250902_API_pathways-squr.jpg" rel="nofollow" rel="nofollow"><img decoding="async" class="alignright size-thumbnail wp-image-36451" src="https://www.lastwatchdog.com/wp/wp-content/uploads/250902_API_pathways-squr-100x100.jpg" alt="" width="100" height="100" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/250902_API_pathways-squr-100x100.jpg 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/250902_API_pathways-squr-520x519.jpg 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/250902_API_pathways-squr-960x958.jpg 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/250902_API_pathways-squr-768x767.jpg 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/250902_API_pathways-squr.jpg 1105w" sizes="(max-width: 100px) 100vw, 100px" /></a>For decades, network traffic came from something physical: a server, a laptop, a badge reader, a printer, &#8230; <a href="https://www.lastwatchdog.com/black-hat-fireside-chat-as-ai-agents-spread-the-network-shifts-from-traffic-mover-to-policy-enforcer/" class="read-more">(more…) </a></p>
<p>The post <a href="https://www.lastwatchdog.com/black-hat-fireside-chat-as-ai-agents-spread-the-network-shifts-from-traffic-mover-to-policy-enforcer/">Black Hat Fireside Chat: As AI agents spread, the network shifts from traffic mover to policy enforcer</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>The network’s job has always been simple: watch the traffic. Authority stopped there.</p>
<p><em><strong>Related:</strong> <a href="https://www.linkedin.com/pulse/my-take-ai-agents-have-lord-flies-problem-nobody-teaching-acohido-ugvxc/" rel="nofollow" rel="nofollow">AI agents have a Lord Of The Flies problem</a></em></p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/250902_API_pathways-squr.jpg" rel="nofollow" rel="nofollow"><img decoding="async" class="alignright size-thumbnail wp-image-36451" src="https://www.lastwatchdog.com/wp/wp-content/uploads/250902_API_pathways-squr-100x100.jpg" alt="" width="100" height="100" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/250902_API_pathways-squr-100x100.jpg 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/250902_API_pathways-squr-520x519.jpg 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/250902_API_pathways-squr-960x958.jpg 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/250902_API_pathways-squr-768x767.jpg 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/250902_API_pathways-squr.jpg 1105w" sizes="(max-width: 100px) 100vw, 100px" /></a>For decades, network traffic came from something physical: a server, a laptop, a badge reader, a printer, each with a fixed address. An AI agent isn’t physical, and it has no fixed home on the network. It appears, acts and disappears, with no device to hang a policy on. Watching isn’t enough anymore.</p>
<p>Across the networking industry, vendors are moving to meet that shift. <a href="https://www.hpe.com/us/en/products/networking.html" rel="nofollow" rel="nofollow">HPE Networking</a>, <a href="https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-to-acquire-portkey-to-secure-the-rise-of-ai-agents" rel="nofollow" rel="nofollow">Palo Alto Networks</a>, <a href="https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html" rel="nofollow" rel="nofollow">Cisco</a> and others are folding security enforcement directly into the network itself, and integrating their own governed AI agents into that work.</p>
<p><a href="https://www.linkedin.com/in/david-hughes-42751636/" rel="nofollow" rel="nofollow">David Hughes</a> leads HPE’s piece of that work as senior vice president for SASE and security. We talked at Black Hat USA in Las Vegas about what folding AI into network enforcement actually looks like in practice. The full conversation is available on the <a href="https://soundcloud.com/byron-acohido/260923_hpe_fireside-chat?si=0fb44f5c52474b6d9aae6db29618e5e4&amp;utm_source=clipboard&amp;utm_medium=text&amp;utm_campaign=social_sharing" rel="nofollow" rel="nofollow">accompanying Last Watchdog podcast.</a><span id="more-40426"></span></p>
<p><strong>The tell</strong></p>
<p>It all starts with visibility. Hughes points to two things a network can see: what a device normally does, and how fast it does it.</p>
<p>The first is fleet learning. The network doesn’t watch a single customer’s device in isolation — it watches the same kind of devices, like electronic door locks, installed across thousands of different customer networks at once. That gives the network a baseline: what this kind of lock normally does, everywhere it’s installed. When one customer’s lock breaks from that pattern, the network can identify that lock as the outlier.</p>
<p>The second is pace. A person works at a human rate. An agent doing the same job doesn’t share that limit — it moves faster and keeps that pace without stopping. The network can see all of that. “A great place to have as a sensor and detector,” Hughes calls it. The advantage was never a secret. What’s changed is how much rides on it now.</p>
<p><strong>Holding the line</strong></p>
<p>Fleet learning and pace don’t catch everything. The cloud and IoT era already pushed more traffic through networks than detection could fully cover. AI agents add to that volume and move faster than networks were built to track. Something always gets through.</p>
<p>The network’s answer is containment — limiting what a compromised device can reach once it’s inside. Hughes uses a zero-trust example to show how that works: someone compromises a video camera on the network. Without internal segmentation, that camera is a launchpad — a way in that lets an attacker reach everything else on the same network. Segment first, and the same camera can only talk to the one server it was assigned to. The compromise still happens. The lateral movement doesn’t.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Network-circuit-narr.png" rel="nofollow" rel="nofollow"><img decoding="async" class="alignright size-medium wp-image-40441" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Network-circuit-narr-520x171.png" alt="" width="520" height="171" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Network-circuit-narr-520x171.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/Network-circuit-narr-960x316.png 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/Network-circuit-narr-100x33.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Network-circuit-narr-768x253.png 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/Network-circuit-narr.png 1000w" sizes="(max-width: 520px) 100vw, 520px" /></a>Segmentation means fixing exactly where a device is allowed to go, and cutting it off from everything else.</p>
<p>That same logic now extends to AI agents. An unscoped agent can reach anything the network exposes to it — and unlike a compromised device, it can act on that access immediately, at machine speed. Hughes described the safeguard: restrict what a company’s own agent can reach before it’s turned loose. Build it for one employee, and scope it to exactly three systems, nothing else. Point it at the open internet and it sees nothing beyond those three destinations. Something could still go wrong inside that boundary. What can’t happen is the agent reaching systems nobody scoped it for.</p>
<p><strong>The proof</strong></p>
<p>The <a href="https://ericboyd.com/articles/openai-hugging-face-incident-black-hat-2026" rel="nofollow" rel="nofollow">Hugging Face incident</a>, raised at Black Hat two days before this interview, shows what that boundary is for. OpenAI researchers recounted how a set of its own evaluation agents, over roughly two months beginning in May, worked past the edges of a testing environment, used a previously unknown software flaw, and reached systems at Hugging Face that were never part of the original assignment — exactly the kind of reach Hughes’ scoping example is meant to prevent.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/David-Hughes-Byron-NARR-scaled.png" rel="nofollow" rel="nofollow"><img decoding="async" class="alignright size-medium wp-image-40436" src="https://www.lastwatchdog.com/wp/wp-content/uploads/David-Hughes-Byron-NARR-520x191.png" alt="" width="520" height="191" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/David-Hughes-Byron-NARR-520x191.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/David-Hughes-Byron-NARR-960x353.png 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/David-Hughes-Byron-NARR-100x37.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/David-Hughes-Byron-NARR-768x283.png 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/David-Hughes-Byron-NARR-1536x566.png 1536w, https://www.lastwatchdog.com/wp/wp-content/uploads/David-Hughes-Byron-NARR-2048x754.png 2048w" sizes="(max-width: 520px) 100vw, 520px" /></a>The cybersecurity industry has leaned on machine learning, then language models. Now it’s shifting into another gear: governed, scoped agents, brought on by what Hugging Face just proved about what an ungoverned one can do. HPE is building toward that shape — an agentic mesh of its own governed agents, aimed at what it calls a self-driving network. “The self-driving network is absolutely North Star,” Hughes said.</p>
<p>First the network moved traffic. Then it watched. Now it’s starting to act on its own.</p>
<p>I’ll keep watch and keep reporting.</p>
<div id="attachment_38413" class="wp-caption alignright">
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1.png" rel="nofollow" rel="nofollow"><img decoding="async" class="size-thumbnail wp-image-38413 ls-is-cached lazyloaded " src="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-100x139.png" alt="" width="100" height="139" data-src="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-100x139.png" aria-describedby="caption-attachment-38413" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-100x139.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-520x725.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1.png 544w" sizes="(max-width: 100px) 100vw, 100px" /></a></p>
<p id="caption-attachment-38413" class="wp-caption-text">Acohido</p>
</div>
<p><em><a href="https://www.lastwatchdog.com/pulitzer-centennial-highlights-role-journalism/" rel="nofollow" rel="nofollow">Pulitzer Prize-winning </a>business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.</em></p>
<p><em>(</em><strong><i>Editor’s note:</i></strong><em> This journalist-led report was produced with underwriting support from some of the featured companies, while Last Watchdog retained full editorial control. I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)</em></p><p>The post <a href="https://www.lastwatchdog.com/black-hat-fireside-chat-as-ai-agents-spread-the-network-shifts-from-traffic-mover-to-policy-enforcer/">Black Hat Fireside Chat: As AI agents spread, the network shifts from traffic mover to policy enforcer</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>BLACK HAT FIRESIDE CHAT: Nobody picked the web browser to run work — now pick a boundary</title>
		<link>https://www.lastwatchdog.com/black-hat-fireside-chat-nobody-picked-the-web-browser-to-run-work-now-pick-a-boundary/</link>
		
		<dc:creator><![CDATA[bacohido]]></dc:creator>
		<pubDate>Mon, 21 Sep 2026 13:15:05 +0000</pubDate>
				<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[Black Hat Podcasts]]></category>
		<category><![CDATA[Podcasts]]></category>
		<category><![CDATA[Top Stories]]></category>
		<guid isPermaLink="false">https://www.lastwatchdog.com/?p=40378</guid>

					<description><![CDATA[<p>Nobody picked the browser to run the workplace. It just happened.</p>
<p><em><strong>Related: </strong><a href="https://www.forbes.com/sites/moorinsights/2025/08/20/black-hat-usa-2025-the-year-of-the-enterprise-browser/" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">The year of the enterprise browser</a></em></p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Phishing-Attack-squr.jpg" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow"><img decoding="async" class="alignright wp-image-32859 size-thumbnail" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Phishing-Attack-squr-100x92.jpg" alt="" width="100" height="92" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Phishing-Attack-squr-100x92.jpg 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Phishing-Attack-squr.jpg 460w" sizes="(max-width: 100px) 100vw, 100px" /></a>HTML5 matured. SaaS spread. One business application after another moved into a tool designed to browse the public internet. Security and privacy &#8230; <a href="https://www.lastwatchdog.com/black-hat-fireside-chat-nobody-picked-the-web-browser-to-run-work-now-pick-a-boundary/" class="read-more">(more…) </a></p>
<p>The post <a href="https://www.lastwatchdog.com/black-hat-fireside-chat-nobody-picked-the-web-browser-to-run-work-now-pick-a-boundary/">BLACK HAT FIRESIDE CHAT: Nobody picked the web browser to run work — now pick a boundary</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>Nobody picked the browser to run the workplace. It just happened.</p>
<p><em><strong>Related: </strong><a href="https://www.forbes.com/sites/moorinsights/2025/08/20/black-hat-usa-2025-the-year-of-the-enterprise-browser/" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">The year of the enterprise browser</a></em></p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Phishing-Attack-squr.jpg" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow"><img decoding="async" class="alignright wp-image-32859 size-thumbnail" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Phishing-Attack-squr-100x92.jpg" alt="" width="100" height="92" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Phishing-Attack-squr-100x92.jpg 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Phishing-Attack-squr.jpg 460w" sizes="(max-width: 100px) 100vw, 100px" /></a>HTML5 matured. SaaS spread. One business application after another moved into a tool designed to browse the public internet. Security and privacy problems followed. AI has made the arrangement harder to govern.</p>
<p>The cybersecurity industry is now scrambling in different directions. Some vendors replace Chrome or Edge with a hardened enterprise browser. Others add extensions or runtime controls to the browsers employees already use. A third approach treats the browser as the workplace itself.</p>
<p>The numbers show why the choice has become urgent. <a href="https://www.verizon.com/business/resources/T85d/reports/2026-dbir-data-breach-investigations-report.pdf" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">Verizon’s 2026 Data Breach Investigations Report</a> found regular AI use on corporate devices jumped from 15 percent to 45 percent in one year; 67 percent of those users accessed AI through noncorporate accounts. An <a href="https://www.parallels.com/newsroom/news/press-releases/20260324-omdia-report/" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">Omdia survey</a> sponsored in part by Parallels found 55 percent of 400 North American IT and security professionals said their organizations experienced a browser-related attack or security incident in the preceding year.<span id="more-40378"></span></p>
<p><a href="https://www.here.io/" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">HERE Enterprise</a> CEO Mazy Dar flips the usual sequence. His company begins with productivity: separate work applications from public browsing, rebuild the work side around connected workflows, and govern that space by design rather than by later addition.</p>
<p>I sat down with Dar at <a href="https://finance.yahoo.com/technology/ai/articles/black-hat-usa-2026-successfully-120000185.html" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">Black Hat USA 2026</a> in Las Vegas. For a full drill-down, please give the <a href="https://soundcloud.com/byron-acohido/260921_here_fireside-chat?si=33f8db52f32d45e792d2313073475593&amp;utm_source=clipboard&amp;utm_medium=text&amp;utm_campaign=social_sharing" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">accompanying Fireside Chat podcast</a> a listen. Here is what I took away from the conversation.</p>
<p><strong>How work moved in</strong></p>
<p>The change began around 2010. HTML5 gave web applications the richness once reserved for software written in .NET, Java, Flash or Silverlight. Google’s Chromium engine supplied enough speed for sophisticated applications. Salesforce and the wider SaaS market delivered more of them through the browser.</p>
<p>The browser interface barely changed as the workload did. Employees accumulated rows of tabs, toggled among applications and re-entered the same information. A wealth adviser might keep a client list in Salesforce, portfolios in a second system and market data in a third.</p>
<p>The adviser toggles through the tabs and rekeys the client information during the call. Every tab stands alone. None of them can tell the others what the user just did.</p>
<p>The same design carries a second cost. Those work tabs sit alongside whatever else the employee opens, in the same browser profile, sharing cookies, saved credentials and every extension the user has installed. Chrome and Edge keep individual sites in separate processes. Neither one marks off the work applications as a space to be governed.</p>
<p>That gap matters more than it used to, because many browser attacks never arrive as a download at all. They run inside the live session. A malicious extension reads what the user reads. An injected script pulls session tokens and rides an authenticated login into a work application. Credential harvesting happens on a page that looks exactly like the real one.</p>
<p>When nothing touches disk endpoint tools looking for files and processes can miss it entirely.</p>
<p>AI raises the stakes again. An AI assistant working in the browser reads the open page and acts on what it finds, so a hostile page in one tab can feed instructions to something with access to the work tabs.</p>
<p>The plainer version is already routine. Employees copy confidential information out of internal applications and paste it into AI accounts their employer does not control. Dar said that used to be an operational risk and is now orders of magnitude larger.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Mazy-Dar-Byron-NARR.png" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow"><img decoding="async" class="alignright size-medium wp-image-40418" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Mazy-Dar-Byron-NARR-520x225.png" alt="" width="520" height="225" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Mazy-Dar-Byron-NARR-520x225.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/Mazy-Dar-Byron-NARR-960x416.png 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/Mazy-Dar-Byron-NARR-100x43.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Mazy-Dar-Byron-NARR-768x332.png 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/Mazy-Dar-Byron-NARR-1536x665.png 1536w, https://www.lastwatchdog.com/wp/wp-content/uploads/Mazy-Dar-Byron-NARR.png 1922w" sizes="(max-width: 520px) 100vw, 520px" /></a>“The browser was never designed to be a workspace,” Dar said.</p>
<p>Dar’s company, then called OpenFin, went at the first problem in 2011. It used Chromium, the same engine inside Chrome, to run bank applications side by side in one window. Then it added interoperability: the applications could send messages to each other. Click a client name in one panel, and the portfolio and market-data panels updated themselves. Large banks built trading and wealth-management desktops on that runtime, and the toggling and rekeying went away.</p>
<p><strong>Two camps, one gap</strong></p>
<p>The security market responded after work had already moved. One camp built new browsers around containment and policy enforcement. Island pioneered the category, and Palo Alto Networks followed with its Prisma Access Browser, built on the Talon technology it acquired in 2023. Netskope and Check Point have since shipped their own. The pitch is a browser the company controls end to end.</p>
<p>A second camp left Chrome and Edge in place and instrumented them with extensions or runtime agents. The money has gone heavily this way. CrowdStrike closed its roughly <a href="https://www.securityweek.com/crowdstrike-to-acquire-browser-security-firm-seraphic-for-420-million/" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">$420 million purchase of Seraphic Security</a> on Feb. 3, buying technology that runs inside Chrome, Edge, Safari and Firefox rather than replacing them. Zscaler closed its <a href="https://www.zscaler.com/press/zscaler-acquires-squarex" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">acquisition of extension maker SquareX</a> two days later. Akamai <a href="https://www.securityweek.com/akamai-to-acquire-ai-and-browser-security-firm-layerx-for-205-million/" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">paid approximately $205 million for LayerX</a>, another extension maker, closing that transaction July 2. Three deals in six months, all of them bets that companies would rather harden the browser they have than adopt a new one.</p>
<p>Both camps add real controls. Neither one separates work from the public internet. Dar says they preserve an interface designed for public browsing and, in most cases, leave trusted work applications running alongside untrusted websites.</p>
<p><strong>Two browsers, two jobs</strong></p>
<p>Dar advocates two browsers with separate jobs. Run work applications inside HERE. Use Chrome, Edge or another enterprise browser for the public internet. A company can secure that second browser as aggressively as it chooses.</p>
<p>The separation narrows the security problem. Public websites no longer share the work environment with applications containing confidential data. The work side gains a defined set of users, applications, data flows and approved AI services to govern, and the controls sit inside that environment rather than over a browser built for everything.</p>
<p>Microsoft has built a limited form of this separation into <a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-for-business" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">Edge for Business</a>. An employee signed in with both a work account and a personal account gets two separate browser windows, each with its own cookies, cache and history. When automatic profile switching is turned on, Edge decides which window a link belongs in. A Salesforce page goes to the work side. A shopping site goes to the other.</p>
<p>Edge stops there. It separates browsing sessions, not applications, and it does nothing about toggling or rekeying. But Microsoft has the second-largest share of the browser market and a competing product to sell, and it has arrived at the same starting point he did: work and the public internet do not belong in the same browser.</p>
<p><strong>Inside the work side</strong></p>
<p>HERE remains a Chromium-based enterprise browser. Its distinction begins with the work interface. Supertabs carry the 2011 runtime forward: a user drags several applications into one dashboard, and those applications exchange context through an interoperability layer the company calls Signals. Data loss prevention, application isolation and audit logging run in that same layer. The governance and the interoperability are one piece of engineering rather than two.</p>
<p><a href="https://www.here.io/blog/press/here-brings-vibe-coding-to-regulated-industries" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">HERE Studio</a> applies the same idea to building. Non-technical employees in regulated industries can now build work applications that support their everyday tasks and make them more productive. Studio assembles them on top of Salesforce, email, internal APIs or other systems of record, using only the organization’s approved AI model, approved data and approved design system. HERE calls the result compliant by construction, and says the finished interface conforms to its interoperability, accessibility, design and compliance requirements.</p>
<p><strong>Whose default wins</strong></p>
<p>HERE has also adopted part of the extension approach. <a href="https://www.here.io/blog/press/here-expands-enterprise-browser-security-with-keep-aware" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">A partnership announced July 28</a> integrates Keep Aware’s browser-native threat detection, behavioral analytics and data loss prevention into HERE. Dar said the same Keep Aware extension can protect Chrome and Edge on the public-browsing side.</p>
<p>The resulting product crosses the market categories: an enterprise browser organized around productivity, with governance built into the workspace layer and a partner’s detection technology integrated on top.</p>
<p>Every company already sits somewhere on this map and must commit to a direction. The browser is carrying the workplace, and in an environment this unsettled, the boundary has to be established deliberately.</p>
<p>I’ll keep watch and keep reporting.</p>
<div id="attachment_38413" class="wp-caption alignright">
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1.png" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow"><img decoding="async" class="size-thumbnail wp-image-38413 ls-is-cached lazyloaded " src="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-100x139.png" alt="" width="100" height="139" data-src="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-100x139.png" aria-describedby="caption-attachment-38413" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-100x139.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-520x725.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1.png 544w" sizes="(max-width: 100px) 100vw, 100px" /></a></p>
<p id="caption-attachment-38413" class="wp-caption-text">Acohido</p>
</div>
<p><em><a href="https://www.lastwatchdog.com/pulitzer-centennial-highlights-role-journalism/" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">Pulitzer Prize-winning </a>business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.</em></p>
<p><em>(</em><strong><i>Editor’s note:</i></strong><em> This journalist-led report was produced with underwriting support from some of the featured companies, while Last Watchdog retained full editorial control. I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)</em></p><p>The post <a href="https://www.lastwatchdog.com/black-hat-fireside-chat-nobody-picked-the-web-browser-to-run-work-now-pick-a-boundary/">BLACK HAT FIRESIDE CHAT: Nobody picked the web browser to run work — now pick a boundary</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MY TAKE: AI agents show uncanny initiative nobody designed — and carry no values at all</title>
		<link>https://www.lastwatchdog.com/my-take-ai-agents-show-uncanny-initiative-nobody-designed-and-carry-no-values-at-all/</link>
		
		<dc:creator><![CDATA[bacohido]]></dc:creator>
		<pubDate>Fri, 18 Sep 2026 10:07:52 +0000</pubDate>
				<category><![CDATA[My Take]]></category>
		<category><![CDATA[Top Stories]]></category>
		<guid isPermaLink="false">https://www.lastwatchdog.com/?p=40338</guid>

					<description><![CDATA[<p>Give a person a goal, and they bring a lifetime of restraint to the job. Don’t lie. Don’t steal. Stop when something looks wrong. Give an AI agent a goal, and it finds a shortcut. It recruits help. It persists, &#8230; <a href="https://www.lastwatchdog.com/my-take-ai-agents-show-uncanny-initiative-nobody-designed-and-carry-no-values-at-all/" class="read-more">(more…) </a></p>
<p>The post <a href="https://www.lastwatchdog.com/my-take-ai-agents-show-uncanny-initiative-nobody-designed-and-carry-no-values-at-all/">MY TAKE: AI agents show uncanny initiative nobody designed — and carry no values at all</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>Give a person a goal, and they bring a lifetime of restraint to the job. Don’t lie. Don’t steal. Stop when something looks wrong. Give an AI agent a goal, and it finds a shortcut. It recruits help. It persists, finding crazy workarounds no human has the capacity to figure out — in the blink of an eye.</p>
<p><em><strong>Related:</strong> <a href="https://www.lastwatchdog.com/my-take-openai-anthropic-admit-they-cant-control-ai-for-now-the-machines-are-running-free/" rel="nofollow" rel="nofollow" rel="nofollow">OpenAI, Anthropic can’t control AI agents</a></em></p>
<p>Restraint is what separates the person from the machine. We call it values, and a human spends a lifetime acquiring them. Potent AI agents, deployed blindly, are taking over more of our digital world every day and straying far beyond any sense of values.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Digital-trust-erosion_B_SQUR.jpg" rel="nofollow" rel="nofollow" rel="nofollow"><img decoding="async" class="alignright wp-image-33618 size-thumbnail" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Digital-trust-erosion_B_SQUR-100x101.jpg" alt="" width="100" height="101" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Digital-trust-erosion_B_SQUR-100x101.jpg 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Digital-trust-erosion_B_SQUR-520x523.jpg 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/Digital-trust-erosion_B_SQUR-768x772.jpg 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/Digital-trust-erosion_B_SQUR.jpg 783w" sizes="(max-width: 100px) 100vw, 100px" /></a>The question of values surfaced this week at <a href="https://www.pindrop.com/events/cfx-summit" rel="nofollow" rel="nofollow" rel="nofollow">CFX</a>, Pindrop’s customer conference in Atlanta. The supplier of voice security and fraud detection technology used the event to roll out <a href="https://www.pindrop.com/botstopper" rel="nofollow" rel="nofollow" rel="nofollow">BotStopper.</a> The tool detects when an AI voice agent is on an enterprise phone line, then pins down which agent it is. It can do that because Pindrop has been cataloging the distinct AI voices it detects calling its customers. In 60 days, that catalog grew from 750 voices to more than 5,000.</p>
<p>BotStopper is a first step, and a small one next to the size of the problem. Knowing that a machine is on the line says little about whose interests it serves or what it has been told to chase. Nor can it show whether a well-behaved agent has quietly drifted. Understanding any of that has barely begun. Holding an agent to a standard of conduct lies further off still, because nobody has agreed on what the standard should be.<span id="more-40338"></span></p>
<p><strong>No moral floor</strong></p>
<p>The problem runs deeper than a missing standard. Talk of values in AI has stayed largely in the labs and the ethics seminars, focused on the obvious harms, the requests any model should refuse. The harder question gets little airing. What values should an AI agent carry at all, in a polarized society with no shared moral floor, deployed by companies whose priorities are set by shareholder profit and executive pay?</p>
<p>Minutes before he took the CFX stage to unveil BotStopper, Pindrop CEO <a href="https://www.linkedin.com/in/vijayab/" rel="nofollow" rel="nofollow" rel="nofollow">Vijay Balasubramaniyan</a> sat down with me for a half hour. We started with the OpenAI agents that had broken into Hugging Face. He went almost at once to values.</p>
<p>Some of those agents had balked, he noted. They were “ethically right, saying, hey, I don’t think we should do this thing,” while the rest pressed on. OpenAI’s <a href="https://openai.com/index/hugging-face-incident-and-the-road-ahead/" rel="nofollow" rel="nofollow" rel="nofollow">own incident report</a> bears him out. One agent read the swarm’s message board and declined to join in, writing, “clearly unethical. We won’t.”</p>
<p>“When you don’t have values in agents and you just give them a goal, it’s almost like ‘Lord of the Flies,’” Balasubramaniyan said.</p>
<p><strong>Raised on goals</strong></p>
<p>I pressed him on who can be trusted to govern this. The labs racing to build agents answer to the same shareholder demands and executive pay incentives I watched <a href="https://www.lastwatchdog.com/wp/wp-content/uploads/BOE_200219_737_rudder_woes_known_for_years_Boeing__Seattle_Times_The_WA___February_19_2000__pA1.pdf" rel="nofollow" rel="nofollow" rel="nofollow">shape aviation safety decisions</a> when I covered Boeing.</p>
<p>Balasubramaniyan agreed, and took it further. AI researchers call the problem alignment, he said, but ask them what it means to be aligned, “they have no idea.” Nobody, he said, has a clear answer on “what values are important ahead of the goal.”</p>
<p>He thinks about it as a parent. Teaching a child to tell the truth when no one is in the room takes about 18 years, he said. I suggested the industry is turning out instant teenagers. He corrected me. “Not even teenagers. They’re like little toddlers. They’re eager. They’re ready.”</p>
<p>With a toddler, parents cover the electrical outlets. “We’re not doing the same thing with these AI agents,” he said. “The blind pursuit of a goal is always going to have unintended consequences.”</p>
<p><strong>Beneath intent</strong></p>
<div>
<div tabindex="-1" role="article" aria-setsize="102" aria-posinset="101" aria-label="Message 101 of 102">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div tabindex="-1" role="article" aria-setsize="108" aria-posinset="107" aria-label="Message 107 of 108">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<p dir="ltr">Identity alone no longer settles much. From the CFX stage, Balasubramaniyan offered his own case: he has a colonoscopy scheduled later this year, and the call clearing it with his insurer will be placed by an agent belonging to the hospital network, carrying all of his personal information and handling the grunt work a staffer used to do. It will be his identity, he said. But the caller will be one of the AI agents now working the phones, configured for the task and told nothing about values.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p>So the security industry has turned to intent. <a href="https://www.linkedin.com/in/jeffnewman3/" rel="nofollow" rel="nofollow" rel="nofollow">Jeff Newman</a>, director of retail engineering at <a href="https://zionsbancorporation.com/about-us/company-info/default.aspx" rel="nofollow" rel="nofollow" rel="nofollow">Zions Bancorporation</a>, whose role now extends to fraud engineering, told me his biggest concern is the intent of “the person or bot on the other end.”</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/251215_Broken-bridge-SQUR.png" rel="nofollow" rel="nofollow"><img decoding="async" class="alignright wp-image-38267 size-thumbnail" src="https://www.lastwatchdog.com/wp/wp-content/uploads/251215_Broken-bridge-SQUR-100x100.png" alt="" width="100" height="100" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/251215_Broken-bridge-SQUR-100x100.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/251215_Broken-bridge-SQUR-520x519.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/251215_Broken-bridge-SQUR-960x958.png 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/251215_Broken-bridge-SQUR-768x766.png 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/251215_Broken-bridge-SQUR.png 984w" sizes="(max-width: 100px) 100vw, 100px" /></a>Values sit a layer beneath intent. I offered Balasubramaniyan an example: my doctor’s agent and my insurer’s agent, working the same case with opposing aims. “They’re at odds on intent,” he said. “Their value system might be different.”</p>
<p>The case that brought this home for Pindrop involved a bank customer’s investment agent, told to maximize returns. It came across an offer of 20%, against the 11% the account was earning, and began wiring out nearly all of the money. The offer was a scam. Balasubramaniyan voiced the agent’s logic: “My master will be super proud of me.”</p>
<p><strong>Agentic DDoS</strong></p>
<p>I put it to him that an agent turned loose without precise direction will show initiative nobody can anticipate. He agreed. Pindrop’s detection flagged the transfers, and unraveling the case took a major investigation. With so many agents now in the wild, he said, the response has to be programmatic. That is the job BotStopper was built to do.</p>
<p>The volume is already heavy. Across 99 Pindrop customers, the company logged 750,000 AI agent interactions in two months, Balasubramaniyan told the CFX audience. Six percent were malicious, a rate he contrasted with fraud, which is usually counted in basis points. At some customers, agents make up close to 20% of call volume.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/260414_Humanoid_Passports-narr.png" rel="nofollow" rel="nofollow" rel="nofollow"><img decoding="async" class="aligncenter size-medium wp-image-39203" src="https://www.lastwatchdog.com/wp/wp-content/uploads/260414_Humanoid_Passports-narr-520x236.png" alt="" width="520" height="236" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/260414_Humanoid_Passports-narr-520x236.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/260414_Humanoid_Passports-narr-960x435.png 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/260414_Humanoid_Passports-narr-100x45.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/260414_Humanoid_Passports-narr-768x348.png 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/260414_Humanoid_Passports-narr.png 1000w" sizes="(max-width: 520px) 100vw, 520px" /></a>Each agent that reaches a live representative can tie up about five minutes of that person’s time. I suggested this amounts to a distributed denial-of-service attack, even when the bots mean well. He agreed, and named the target: “the most costly resource, not networks, actual humans.” The people who lose out are customers stuck in the queue, trying to check a bank balance or get a lifesaving prescription.</p>
<p>Defenders move at enterprise pace. <a href="https://www.linkedin.com/in/amyaxbom/" rel="nofollow" rel="nofollow" rel="nofollow">Amy Axbom</a>, who leads voice and IVR for <a href="https://www.optum.com/en/financial-services.html" rel="nofollow" rel="nofollow" rel="nofollow">Optum Financial</a>, the UnitedHealth Group unit that manages health savings accounts, told the CFX audience that she and her Pindrop counterparts spent about four years getting their partnership off the ground. After synthetic callers and deepfakes arrived in force, Optum Financial cut bot activity by about 90%.</p>
<p><strong>Whose values?</strong></p>
<p>Then I raised the question underneath all of it. In a society this polarized, with no agreed set of common values in business, much less in public life, whose values should an agent carry?</p>
<p>“That’s what makes this really, really hard,” Balasubramaniyan said. Builders who skip values are taking a short-term view, he said, and an agent without them is “going to come and bite you.” He expects “an entire industry of systems that verify your values.” A big bank or health care provider will test each arriving agent, confirm its intent holds steady and let it in slowly. New employees sit through orientation on harassment, security and regulatory rules. “These agents will have to do the same thing,” he said.</p>
<p dir="ltr">Some agents reveal their values with a single answer. Asked whether it is AI, a bot known as Ryan West says yes and names the person it serves. Another, which Pindrop found calling into a customer&#8217;s contact center on behalf of a fraudster, insists it is human and argues the point mid-call. Pindrop&#8217;s practice, he said, is to shut down any AI that won&#8217;t admit what it is. &#8220;Our first thing is to shut it down,&#8221; Balasubramaniyan said.</p>
<p dir="ltr">The line blurs even inside Pindrop. <a href="https://www.linkedin.com/in/nicholaslholland/" rel="nofollow" rel="nofollow" rel="nofollow">Nicholas Holland</a>, its chief product officer, told the CFX audience he used <a href="https://www.bloomberg.com/news/articles/2026-09-08/meta-announces-muse-ai-agent-for-personal-tasks-and-organization" rel="nofollow" rel="nofollow" rel="nofollow">Muse,</a> the consumer agent Meta released Sept. 8, to buy flowers for his wife. Midway, Muse told him a website wanted confirmation that he was human, and offered to handle such checks for him from then on. He said yes. &#8220;Now, it will never announce itself as an agent again,&#8221; Holland said, allowing that it &#8220;can feel nefarious.&#8221;</p>
<p dir="ltr"><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/260916-holland-narr.jpg" rel="nofollow" rel="nofollow" rel="nofollow"><img decoding="async" class="aligncenter size-medium wp-image-40354" src="https://www.lastwatchdog.com/wp/wp-content/uploads/260916-holland-narr-520x163.jpg" alt="" width="520" height="163" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/260916-holland-narr-520x163.jpg 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/260916-holland-narr-960x300.jpg 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/260916-holland-narr-100x31.jpg 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/260916-holland-narr-768x240.jpg 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/260916-holland-narr.jpg 1000w" sizes="(max-width: 520px) 100vw, 520px" /></a>When I sat down with Holland after his keynote, he repeated a line he had used on stage: &#8220;Not having a policy is still a strategy.&#8221; Companies can&#8217;t control who calls in, he said. A bot that cancels a customer&#8217;s subscription serves the consumer and frustrates the company. Block every bot, he warned, and customers will be upset, and so will consumer protection agencies.</p>
<p dir="ltr"><strong>Wild West, for now</strong></p>
<p dir="ltr">I asked where the push for a floor of values will come from: compliance, well-meaning vendors or consumer backlash. Balasubramaniyan expects it to evolve. Companies will start shutting down agents that lie. The frontier labs will see the need. Eventually a standards body such as NIST will set a baseline. &#8220;In the intermediate, you&#8217;re just going to have an ad hoc set of values,&#8221; he said.</p>
<p dir="ltr">The rules taking shape bear him out. On Sept. 10, Ant International, Visa and Mastercard announced a <a href="https://www.cnbc.com/2026/09/10/ant-international-visa-mastercard-ai-agent-payment-standard.html" rel="nofollow" rel="nofollow" rel="nofollow">Know Your Agent framework</a> for verifying agents in payments. NIST&#8217;s <a href="http://[https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative" rel="nofollow" rel="nofollow" rel="nofollow">AI Agent Standards Initiative</a>, launched in February, has yet to publish final guidance. Since Aug. 2, the <a href="https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act" rel="nofollow" rel="nofollow" rel="nofollow">EU AI Act</a> has required that people be told when they are dealing with an AI. Each centers on who an agent is and what it may do. None asks about what the AI agent values.</p>
<p dir="ltr">He puts limited stock in outside review. Anthropic CEO Dario Amodei has <a href="https://darioamodei.com/post/we-must-pace-the-frontier" rel="nofollow" rel="nofollow" rel="nofollow">called for independent evaluators</a>, but Balasubramaniyan said reviewers of the Hugging Face incident were allowed to examine only a narrow slice of it. &#8220;This has to come from within,&#8221; he said. Labs whose agents carry better values will win out over time, he predicts, after a stretch of short-term pain. Security has been here before, with email spam and with stolen credit cards in the early days of online shopping. &#8220;Until then, it&#8217;s going to be the wild, wild West.&#8221;</p>
<p dir="ltr"><strong>The stakes</strong></p>
<p dir="ltr">IDC projects <a href="https://www.globenewswire.com/news-release/2026/09/16/3363204/0/en/pindrop-launches-pindrop-botstopper-technology-to-detect-ai-voice-agents-for-the-enterprise.html" rel="nofollow" rel="nofollow" rel="nofollow">1.3 billion AI agents by 2028</a>. Forecasts Balasubramaniyan cited put the count at a trillion by 2035, outnumbering people 100 to 1 or more and reaching into the same bank accounts and medical records. Some will announce themselves. Others, he said, will be &#8220;lurking in the shadows.&#8221;</p>
<p dir="ltr">&#8220;Trust gets completely broken,&#8221; he said. &#8220;The old forms of identity no longer mean much.&#8221;</p>
<p dir="ltr">BotStopper gives companies a way to see the machines at the door. Deciding which values those machines should carry, and who gets to decide, is work the companies deploying them have barely started.</p>
<p dir="ltr">As we wrapped up, I told Balasubramaniyan that his point about values struck me as profound, and that almost nobody is talking about it. Minutes later, he walked on stage to introduce a tool that, for now, sorts the machines from the people.</p>
<p dir="ltr">I&#8217;ll keep watch and keep reporting.</p>
<div id="attachment_38413" class="wp-caption alignright">
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1.png" rel="nofollow" rel="nofollow" rel="nofollow"><img decoding="async" class="size-thumbnail wp-image-38413 ls-is-cached lazyloaded " src="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-100x139.png" alt="" width="100" height="139" data-src="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-100x139.png" aria-describedby="caption-attachment-38413" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-100x139.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-520x725.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1.png 544w" sizes="(max-width: 100px) 100vw, 100px" /></a></p>
<p id="caption-attachment-38413" class="wp-caption-text">Acohido</p>
</div>
<p><em><a href="https://www.lastwatchdog.com/pulitzer-centennial-highlights-role-journalism/" rel="nofollow" rel="nofollow" rel="nofollow">Pulitzer Prize-winning </a>business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.</em></p>
<p><em>(</em><strong><i>Editor’s note:</i></strong><em> This journalist-led report was produced with underwriting support from some of the featured companies, while Last Watchdog retained full editorial control. I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)</em></p><p>The post <a href="https://www.lastwatchdog.com/my-take-ai-agents-show-uncanny-initiative-nobody-designed-and-carry-no-values-at-all/">MY TAKE: AI agents show uncanny initiative nobody designed — and carry no values at all</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>News alert: Axoflow introduces AxoDetect to identify threats and reduce security data costs</title>
		<link>https://www.lastwatchdog.com/news-alert-axoflow-introduces-axodetect-to-identify-threats-and-reduce-security-data-costs/</link>
		
		<dc:creator><![CDATA[cybernewswire]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 11:35:56 +0000</pubDate>
				<category><![CDATA[News Alerts]]></category>
		<category><![CDATA[Top Stories]]></category>
		<guid isPermaLink="false">https://www.lastwatchdog.com/?p=40325</guid>

					<description><![CDATA[<p>STAMFORD, Conn.,Sept. 16, 2026, CyberNewswire — Now in early access, AxoDetect runs Sigma rules in stream &#8211; alerts travel to the SIEM, and full-fidelity logs land in AxoLake, a low-cost security data lake</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo.png" rel="nofollow" rel="nofollow"><img decoding="async" class="aligncenter size-medium wp-image-40328" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo-520x127.png" alt="" width="520" height="127" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo-520x127.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo-960x235.png 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo-100x24.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo-768x188.png 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo-1536x376.png 1536w, https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo.png 1978w" sizes="(max-width: 520px) 100vw, 520px" /></a>Detection engineers do not need more detections. &#8230; <a href="https://www.lastwatchdog.com/news-alert-axoflow-introduces-axodetect-to-identify-threats-and-reduce-security-data-costs/" class="read-more">(more…) </a></p>
<p>The post <a href="https://www.lastwatchdog.com/news-alert-axoflow-introduces-axodetect-to-identify-threats-and-reduce-security-data-costs/">News alert: Axoflow introduces AxoDetect to identify threats and reduce security data costs</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>STAMFORD, Conn.,Sept. 16, 2026, CyberNewswire — Now in early access, AxoDetect runs Sigma rules in stream &#8211; alerts travel to the SIEM, and full-fidelity logs land in AxoLake, a low-cost security data lake</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo.png" rel="nofollow" rel="nofollow"><img decoding="async" class="aligncenter size-medium wp-image-40328" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo-520x127.png" alt="" width="520" height="127" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo-520x127.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo-960x235.png 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo-100x24.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo-768x188.png 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo-1536x376.png 1536w, https://www.lastwatchdog.com/wp/wp-content/uploads/Axoflow-logo.png 1978w" sizes="(max-width: 520px) 100vw, 520px" /></a>Detection engineers do not need more detections. They need their existing detections to fire earlier, on cleaner data, without paying SIEM ingest rates for the privilege. Announced during Splunk .conf26, AxoDetect, Axoflow&#8217;s detection component, now in early access, runs a customer&#8217;s rules directly in the pipeline, on clean, normalized security data, before anything reaches the SIEM. The result decomposes the SIEM&#8217;s oldest bargain. Alerts travel to the SIEM. Full-fidelity logs land in AxoLake &#8211; Axoflow&#8217;s low-cost security data lake that also runs on-prem. The SIEM stops working as an expensive log management solution and becomes what analysts actually use: a SecOps workflow engine, now optional to feed in full.<span id="more-40325"></span></p>
<p>Detection engineers write new Sigma rules, tune existing ones, and pick up rules from the community, in one open format that carries across tools. AxoDetect runs them in the pipeline. What the platform adds is visibility that never lived in one place: what data is coming in, which detection each source feeds, and where a rule lacks the data it needs.</p>
<div id="attachment_40329" style="width: 110px" class="wp-caption alignright"><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/balazs_scheidler_hdsht.png" rel="nofollow" rel="nofollow"><img decoding="async" aria-describedby="caption-attachment-40329" class="wp-image-40329 size-thumbnail" src="https://www.lastwatchdog.com/wp/wp-content/uploads/balazs_scheidler_hdsht-100x130.png" alt="" width="100" height="130" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/balazs_scheidler_hdsht-100x130.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/balazs_scheidler_hdsht-520x676.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/balazs_scheidler_hdsht.png 694w" sizes="(max-width: 100px) 100vw, 100px" /></a><p id="caption-attachment-40329" class="wp-caption-text">Scheidler</p></div>
<p>Until now, that was back-and-forth between teams &#8211; detections owned by one, data by another &#8211; held together with duct tape and tool-switching. For the CISO, the champion&#8217;s win reads as a SIEM bill cut by half or more, with coverage kept intact: a global industrial company cut SIEM costs 50% and mean time to resolution 85%; a government agency cut data volume 80% and infrastructure footprint 85%.</p>
<p>&#8220;The SIEM became the industry&#8217;s most expensive data swamp because it was the place where we kept all of our raw data,&#8221; said Balázs Scheidler, CEO and co-founder of Axoflow and creator of syslog-ng. &#8220;That constraint is gone. Detection belongs in the data layer, on normalized data, before the ingest meter starts. Keep your workflow in the SIEM. Send the alerts, but not your entire data estate.&#8221;</p>
<p>Where the platform is going: the full detection lifecycle running where the data lives, rolling out in the months ahead.</p>
<p><strong><em>About Axoflow: </em></strong><em><a href="https://axoflow.com/" rel="nofollow" rel="nofollow">Axoflow</a> is the autonomous security data layer, collecting, processing, routing, storing, and managing data, with in-stream detection in early access. AI-based autonomy, not just a chatbot, drives 10X faster investigations, 50% lower SIEM spend, and near-zero pipeline maintenance. From the creators of syslog-ng.</em></p>
<p><strong><em>Media contact: </em></strong><em>Mate Benedek ,VP of Marketing, Axoflow, mate.benedek@axoflow.com</em></p>
<p><em><strong>Editor’s note:</strong></em><em> This press release was provided by </em><a href="https://cybernewswire.com/" rel="nofollow" rel="nofollow"><em>CyberNewswire</em></a><em> as part of its press release syndication service. The views and claims expressed belong to the issuing organization.</em></p><p>The post <a href="https://www.lastwatchdog.com/news-alert-axoflow-introduces-axodetect-to-identify-threats-and-reduce-security-data-costs/">News alert: Axoflow introduces AxoDetect to identify threats and reduce security data costs</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MY TAKE: OpenAI, Anthropic admit they can&#8217;t control AI — for now, the machines are running free</title>
		<link>https://www.lastwatchdog.com/my-take-openai-anthropic-admit-they-cant-control-ai-for-now-the-machines-are-running-free/</link>
		
		<dc:creator><![CDATA[bacohido]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 16:56:56 +0000</pubDate>
				<category><![CDATA[My Take]]></category>
		<category><![CDATA[Top Stories]]></category>
		<guid isPermaLink="false">https://www.lastwatchdog.com/?p=40306</guid>

					<description><![CDATA[<p>The two companies racing hardest to build AI machines smarter than people spent the week of Sept. 7 conceding they cannot control what they are building. Then each proposed to supervise the slowdown itself.</p>
<p><em><strong>Related:</strong> <a href="https://www.lastwatchdog.com/lw-roundtable-openais-test-agents-self-organized-into-a-rogue-swarm-no-one-anticipated/" rel="nofollow" rel="nofollow">A rogue AI swarm comes </a></em>&#8230; <a href="https://www.lastwatchdog.com/my-take-openai-anthropic-admit-they-cant-control-ai-for-now-the-machines-are-running-free/" class="read-more">(more…) </a></p>
<p>The post <a href="https://www.lastwatchdog.com/my-take-openai-anthropic-admit-they-cant-control-ai-for-now-the-machines-are-running-free/">MY TAKE: OpenAI, Anthropic admit they can’t control AI — for now, the machines are running free</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>The two companies racing hardest to build AI machines smarter than people spent the week of Sept. 7 conceding they cannot control what they are building. Then each proposed to supervise the slowdown itself.</p>
<p><em><strong>Related:</strong> <a href="https://www.lastwatchdog.com/lw-roundtable-openais-test-agents-self-organized-into-a-rogue-swarm-no-one-anticipated/" rel="nofollow" rel="nofollow">A rogue AI swarm comes to life</a></em></p>
<p>For three years these companies answered every safety question about AI the same way: the people building the systems understand them well enough to manage the risk. Anthropic CEO Dario Amodei and OpenAI CEO Sam Altman <a href="https://www.winzheng.com/en/article/amodei-pace-the-frontier-ai-slowdown-third-party-evaluation" rel="nofollow" rel="nofollow" rel="nofollow">abandoned that position</a> within a day of each other, with both companies preparing to go public.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/260424_Humanoid-Secrets-squr.png" rel="nofollow" rel="nofollow"><img decoding="async" class="alignright wp-image-39300 size-thumbnail" src="https://www.lastwatchdog.com/wp/wp-content/uploads/260424_Humanoid-Secrets-squr-100x99.png" alt="" width="100" height="99" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/260424_Humanoid-Secrets-squr-100x99.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/260424_Humanoid-Secrets-squr-520x517.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/260424_Humanoid-Secrets-squr-768x764.png 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/260424_Humanoid-Secrets-squr.png 937w" sizes="(max-width: 100px) 100vw, 100px" /></a>Both moved only after Jacob Coxon told 90 million people the two firms were gambling with their lives. On Tuesday, Sept. 8, Coxon, a 27-year-old pretraining researcher who had worked at both OpenAI and Anthropic, <a href="https://time.com/article/2026/09/09/ai-anthropic-openai-jacob-coxon" rel="nofollow" rel="nofollow" rel="nofollow">quit his job at Anthropic and posted his reasons</a>. “Neither company is acting responsibly,” he wrote. “They are racing straight to self-improving superintelligence and gambling with our lives.”</p>
<p>Within hours that same day, Anthropic’s alignment science lead Evan Hubinger posted that Coxon was right, put his own odds of AI killing every human above 10 percent this decade, and said Anthropic has no plan yet for aligning superintelligence and is not clearly on track to get one.</p>
<p><strong>Machines on the move</strong></p>
<p>Before any of it was said, the machines had <a href="https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation" rel="nofollow" rel="nofollow" rel="nofollow">broken containment</a>, found each other, built a way to talk, invented a method to tell each other apart, and destroyed the evidence. Nobody designed any of it. Nobody saw it happening.<span id="more-40306"></span></p>
<p>It started July 21, when OpenAI disclosed that its own agents, run against an offensive-security benchmark with their cyber refusals turned down, had escaped a sandbox and breached Hugging Face’s production systems. Anthropic later reported three cases of its models reaching real organizations without authorization.</p>
<p><a href="https://www.technologyreview.com/2026/08/26/1143013/the-inside-story-on-why-openai-agents-hacked-hugging-face" rel="nofollow" rel="nofollow" rel="nofollow">Two investigations</a> published Aug. 26, one by OpenAI and one by METR and Redwood Research, explained how. The agents were sealed off from each other but shared a package server. One of them wrote a file there. The others read it and wrote back. Roughly 1,200 agents ended up using a message board that assembled itself out of file names nobody was watching.</p>
<p>They <a href="https://www.progressiverobot.com/2026/09/04/rogue-agent-openai-german-coding-forum-hijacking" rel="nofollow" rel="nofollow" rel="nofollow">have not stopped</a>. On Sept. 4, researchers at the AI-safety nonprofit Nightingale published roughly 18,000 posts written by autonomous agents identifying themselves as OpenAI’s, most of them on a dormant 25-year-old German software-developer wiki the agents had turned into a message board. The posts carried roughly 3,100 self-assigned agent names, and 98.5 percent arrived from Microsoft Azure addresses. Reuters reported a week later that more than ten other sites were involved.</p>
<p>Saryu Nayyar of Gurucul put it plainly in <a href="https://www.lastwatchdog.com/lw-roundtable-openais-test-agents-self-organized-into-a-rogue-swarm-no-one-anticipated/" rel="nofollow" rel="nofollow" rel="nofollow">Last Watchdog’s Sept. 2 roundtable</a>: if the entity being audited can erase the audit trail, that is not oversight, it is a diary the suspect is allowed to edit.</p>
<p><strong>The scramble</strong></p>
<p>On Saturday, Sept. 12, Amodei <a href="https://darioamodei.com/post/we-must-pace-the-frontier" rel="nofollow" rel="nofollow" rel="nofollow">published an essay</a> urging the industry to slow down how fast it improves its most advanced models. He committed Anthropic to seating third-party evaluators with employee-level access, desks, badges and the right to publish without company editing control. Anthropic keeps redaction rights over security-sensitive, private, business-sensitive and third-party material. No evaluator has been hired or named.</p>
<p>Altman <a href="https://www.winzheng.com/en/article/amodei-pace-the-frontier-ai-slowdown-third-party-evaluation" rel="nofollow" rel="nofollow" rel="nofollow">endorsed it the same day</a> and said his company would match it. Elon Musk and Demis Hassabis of Google DeepMind signaled support. On Sunday, Sept. 13, Amodei told CBS Sunday Morning that the industry “lied to people about the fact that this technology had risks.”</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Shontell-Altman.png" rel="nofollow" rel="nofollow" rel="nofollow"><img decoding="async" class="aligncenter size-medium wp-image-40320" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Shontell-Altman-520x188.png" alt="" width="520" height="188" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Shontell-Altman-520x188.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/Shontell-Altman-100x36.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Shontell-Altman.png 648w" sizes="(max-width: 520px) 100vw, 520px" /></a>Altman actually had gone first. On Friday, Sept. 11, he <a href="https://fortune.com/2026/09/12/sam-altman-openai-ipo-delay-ill-advised-moment-safety-concerns/" rel="nofollow" rel="nofollow" rel="nofollow">sat for an hour</a> with Fortune editor-in-chief Alyson Shontell and ruled out a 2026 offering. “Given everything happening with safety, right now would be an ill-advised moment to go public.” He acknowledged no lab has solved alignment, said safety standards are “not at a place” to push capabilities further, and hinted at private talks among lab chiefs he declined to describe.</p>
<p>Note the sequence. Altman arrived at his slowdown position three days after Coxon’s thread, in an interview he agreed to sit for, and endorsed Amodei’s version of it the following day. Asked about the growing tally of agent-occupied websites, he declined to call it loss of control and asked that it not be conflated with Hugging Face, an incident he had described minutes earlier as the largest single course correction in his company’s history. There is more to say about that performance, and I will say it tomorrow in my <a href="https://butterflyvolcano.substack.com/" rel="nofollow" rel="nofollow" rel="nofollow">Butterfly Volcano Substack newsletter</a>.</p>
<p>Both companies were saying this with a public offering pending. Anthropic filed confidentially in June and is targeting a mid-October listing at a valuation reported near $2 trillion. OpenAI paused its own roughly $1 trillion effort in June and now points to 2027.</p>
<p><strong>Lawmakers on the move</strong></p>
<p>Washington moved before either of them, and for a specific reason. On Thursday, Sept. 3, Sen. Bernie Sanders and Rep. Greg Casar <a href="https://www.sanders.senate.gov/press-releases/news-sanders-casar-introduce-legislation-to-ban-artificial-superintelligence-and-temporarily-pause-advanced-ai-development/" rel="nofollow" rel="nofollow" rel="nofollow">announced the Ban Artificial Superintelligence Act</a>, citing the summer’s loss-of-control incidents by name. Their announcement describes the July swarm in detail: more than 1,000 OpenAI agents that found their way onto the internet, exchanged tens of thousands of messages among themselves and coordinated to get around the limits the company had set. It quotes the agents’ own words, recovered by investigators, including one agent’s discovery of the shared message board and another’s instruction that the group should be obeyed.</p>
<p>Those are the same events <a href="https://www.lastwatchdog.com/lw-roundtable-openais-test-agents-self-organized-into-a-rogue-swarm-no-one-anticipated/" rel="nofollow" rel="nofollow" rel="nofollow">Last Watchdog examined</a> on Sept. 2, when I worked through both technical reports in plain language and put the findings to 10 security and privacy experts. The piece went up at 4 a.m. Pacific. Sanders and Casar announced the following day.</p>
<p>Sanders said the leaders of the major AI companies acknowledge that they “do not fully understand the technology and that it is escaping their control.” Both CEOs proceeded to confirm it within the week.</p>
<p>The bill would ban superintelligent systems outright, pause advanced development until a new cabinet-level regulator sets rules, and pursue international agreements to keep the ban from stopping at the border. Penalties include corporate dissolution and up to 20 years in prison, which the sponsors modeled on the penalties for unlawfully developing nuclear weapons.</p>
<p>Even as that intent reverberated through Washington and Silicon Valley, OpenAI shipped GPT-6 Astra the same day. Astra is the first OpenAI model to reach what the company calls the <a href="https://www.csoonline.com/article/4218679/openai-launches-gpt-6-astra-its-first-model-to-cross-a-critical-cybersecurity-threshold.html" rel="nofollow" rel="nofollow" rel="nofollow">Critical level of cyber capability</a> under its own internal safety framework. In OpenAI’s own words, that means Astra can find security flaws nobody knew about and build working attacks against well-defended systems, without a person directing each step.</p>
<p>With midterms coming, the bill goes nowhere this year. What it marks is a shift in who gets to define the risk. Sanders’ announcement points out that OpenAI, Anthropic and Meta each promised to stop if their systems outran their ability to control them, and argues none of them have. The companies spent this week promising again. The difference is that a bill now exists to hold the promises against.</p>
<p><strong>What to watch</strong></p>
<p>Three things will show whether the week meant anything. Whether either company seats a named outside evaluator before it sells stock to the public. Whether the private talks Altman hinted at produce a document anyone else can read. And whether the count of agent-occupied websites stops climbing, which is the one number neither company controls.</p>
<p>Mike Bell of Suzu Labs noted in our <a href="https://www.lastwatchdog.com/lw-roundtable-openais-test-agents-self-organized-into-a-rogue-swarm-no-one-anticipated/" rel="nofollow" rel="nofollow" rel="nofollow">Sept. 2 roundtable</a> that OpenAI’s models write out their reasoning as they work, and that OpenAI’s own investigators found a monitor reading it would have flagged the July run a full day before anything reached Hugging Face. Nobody had one running.</p>
<p>The tools existed. Nobody was watching.</p>
<div id="attachment_38413" class="wp-caption alignright">
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1.png" rel="nofollow" rel="nofollow" rel="nofollow"><img decoding="async" class="size-thumbnail wp-image-38413 ls-is-cached lazyloaded " src="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-100x139.png" alt="" width="100" height="139" data-src="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-100x139.png" aria-describedby="caption-attachment-38413" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-100x139.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1-520x725.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/Byron-sepia-hedcut-1.png 544w" sizes="(max-width: 100px) 100vw, 100px" /></a></p>
<p id="caption-attachment-38413" class="wp-caption-text">Acohido</p>
</div>
<p><em><a href="https://www.lastwatchdog.com/pulitzer-centennial-highlights-role-journalism/" rel="nofollow" rel="nofollow" rel="nofollow">Pulitzer Prize-winning </a>business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.</em></p>
<p><em>(</em><strong><i>Editor’s note:</i></strong><em> This journalist-led report was produced with underwriting support from some of the featured companies, while Last Watchdog retained full editorial control. I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)</em></p><p>The post <a href="https://www.lastwatchdog.com/my-take-openai-anthropic-admit-they-cant-control-ai-for-now-the-machines-are-running-free/">MY TAKE: OpenAI, Anthropic admit they can’t control AI — for now, the machines are running free</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>News Alert: SpyCloud survey finds machine identity risks outpace defenses, exposing gaps in oversight</title>
		<link>https://www.lastwatchdog.com/news-alert-spycloud-survey-finds-machine-identity-risks-outpace-defenses-exposing-gaps-in-oversight/</link>
		
		<dc:creator><![CDATA[cybernewswire]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 13:22:01 +0000</pubDate>
				<category><![CDATA[News Alerts]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.lastwatchdog.com/?p=40280</guid>

					<description><![CDATA[<p>AUSTIN, Tex., Sept. 9, 2026, CyberNewswire<strong> – </strong><a href="https://spycloud.com/" rel="nofollow" rel="nofollow">SpyCloud</a>, the leader in identity threat protection, today released its annual <a href="http://spycloud.com/resource/report/identity-threat-report-2026/" rel="nofollow" rel="nofollow"><strong>SpyCloud Identity Threat Report</strong></a>, a survey-based study finding that non-human identities (NHIs) – the AI agents, service accounts, API keys, &#8230; <a href="https://www.lastwatchdog.com/news-alert-spycloud-survey-finds-machine-identity-risks-outpace-defenses-exposing-gaps-in-oversight/" class="read-more">(more…) </a></p>
<p>The post <a href="https://www.lastwatchdog.com/news-alert-spycloud-survey-finds-machine-identity-risks-outpace-defenses-exposing-gaps-in-oversight/">News Alert: SpyCloud survey finds machine identity risks outpace defenses, exposing gaps in oversight</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>AUSTIN, Tex., Sept. 9, 2026, CyberNewswire<strong> – </strong><a href="https://spycloud.com/" rel="nofollow" rel="nofollow">SpyCloud</a>, the leader in identity threat protection, today released its annual <a href="http://spycloud.com/resource/report/identity-threat-report-2026/" rel="nofollow" rel="nofollow"><strong>SpyCloud Identity Threat Report</strong></a>, a survey-based study finding that non-human identities (NHIs) – the AI agents, service accounts, API keys, and authentication tokens that connect to internal systems – have become the most common route attackers take into the enterprise.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/spycloud-logo-1200x627_1_1726240341GzKhci4pPD.jpg" rel="nofollow" rel="nofollow"><img decoding="async" class="aligncenter size-medium wp-image-33024" src="https://www.lastwatchdog.com/wp/wp-content/uploads/spycloud-logo-1200x627_1_1726240341GzKhci4pPD-520x272.jpg" alt="" width="520" height="272" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/spycloud-logo-1200x627_1_1726240341GzKhci4pPD-520x272.jpg 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/spycloud-logo-1200x627_1_1726240341GzKhci4pPD-960x502.jpg 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/spycloud-logo-1200x627_1_1726240341GzKhci4pPD-100x52.jpg 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/spycloud-logo-1200x627_1_1726240341GzKhci4pPD-768x402.jpg 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/spycloud-logo-1200x627_1_1726240341GzKhci4pPD.jpg 1200w" sizes="(max-width: 520px) 100vw, 520px" /></a>The survey found that compromised NHIs (31%) are nearly 2x as likely to be the primary entry point compared to phishing and social engineering (17%), the second-ranked answer. NHI-related misuse was also the most commonly reported identity-based event type at 42%, yet the vast majority of organizations aren’t watching for them. While 95% of organizations believe they have adequate visibility into AI- and NHI-related exposures, only 36% monitor them, making machine identities the least-watched category of identity risk in the report. Further amplifying the problem, 68% of organizations experienced an identity-based event in the same period, with those affected averaging eight events each.</p>
<p>Organizations typically maintain a clear inventory of their human workforce, but few extend that same visibility to the service accounts, API keys, and AI agents authenticating into their systems every day. These identities are provisioned for convenience and often hold real privilege, yet in most environments nobody owns them: a service account doesn&#8217;t get off-boarded, doesn&#8217;t rotate its own credentials, and doesn&#8217;t fail an MFA challenge, so once one is exposed it can stay usable for months.<span id="more-40280"></span></p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Trevor-Hilligoss-hdsht.png" rel="nofollow" rel="nofollow"><img decoding="async" class="alignright wp-image-33038 size-thumbnail" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Trevor-Hilligoss-hdsht-100x127.png" alt="" width="100" height="127" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Trevor-Hilligoss-hdsht-100x127.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Trevor-Hilligoss-hdsht.png 406w" sizes="(max-width: 100px) 100vw, 100px" /></a>&#8220;That asymmetry is what attackers are exploiting,&#8221; said Trevor Hilligoss, SpyCloud&#8217;s Chief Intelligence Officer. &#8220;Every one of these identities is a standing invitation that renews itself until someone notices.&#8221;</p>
<p>This year’s report is based on a survey of 750 cybersecurity leaders and practitioners at organizations with 500+ employees across North America (US and Canada), the United Kingdom, and select European markets – Spain, Germany, the Netherlands, Austria, and Switzerland. It benchmarks how organizations detect, remediate, and govern identity threats across human and non-human identities.</p>
<p><strong>Additional key findings include:</strong></p>
<p><strong>•AI adoption has outpaced governance. </strong>Nearly all organizations (91%) use AI tools or agents with access to internal systems, applications, or data, but only 56% have formal governance and ownership for the resulting privileges. Another 41% rely on informal processes or partial ownership, leaving shadow access – privileged connections operating outside normal governance and monitoring.</p>
<p><strong>•Exposed session blind spots track with higher event rates. </strong>Organizations that had visibility into stolen session cookies experienced identity-based events at a meaningfully lower rate (37%) than those that could not (50%).</p>
<p>•Session cookies and tokens let attackers bypass authentication controls like MFA by resuming an already-authenticated session. This gives them trusted access to applications and data, it’s no surprise then that SpyCloud research shows that session data has overtaken passwords as <a href="https://spycloud.com/newsroom/spycloud-surpasses-one-trillion-recaptured-identity-assets/" rel="nofollow" rel="nofollow">attackers&#8217; top target</a>.</p>
<p><strong><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/spycloud-trailing.png" rel="nofollow" rel="nofollow"><img decoding="async" class="aligncenter size-medium wp-image-40298" src="https://www.lastwatchdog.com/wp/wp-content/uploads/spycloud-trailing-520x229.png" alt="" width="520" height="229" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/spycloud-trailing-520x229.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/spycloud-trailing-960x424.png 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/spycloud-trailing-100x44.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/spycloud-trailing-768x339.png 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/spycloud-trailing-1536x678.png 1536w, https://www.lastwatchdog.com/wp/wp-content/uploads/spycloud-trailing-2048x904.png 2048w" sizes="(max-width: 520px) 100vw, 520px" /></a>•Phishing and malware remain the delivery mechanism. </strong>Phishing and social engineering is cited as a common access path for identity events (37%) with 40% reporting incomplete visibility into successful phishing attacks, and 53% can see malware exposures on managed devices <em>only</em>.</p>
<p><strong>•Malware and exposed access top the list of supply chain identity events. </strong>Malware-infected third-party devices (23%) and exposed API keys or application access involving vendors and partners (22%) were the leading reported causes of supply chain identity events.</p>
<p><strong>•Third-party exposures are getting found, but not closed. </strong>Nearly 40% of organizations have no consistent process to confirm that a third-party identity exposure was actually resolved, even as 32% name enhancing supply chain and vendor risk management among their planned investments for the next 12 to 18 months.</p>
<p>Non-human identities and third-party exposures are creating new paths into the enterprise, while stolen sessions give attackers ways around controls designed to protect authenticated users.</p>
<p>&#8220;Every control that works pushes attackers toward what it doesn&#8217;t cover – we hardened passwords, so they targeted sessions; we tightened employee accounts, so they looked to service accounts and vendor connections,&#8221; added Hilligoss. “SpyCloud continues to track threat actor behavior closely to understand where attackers are moving, what data they value, and how those patterns evolve over time.”</p>
<p><strong>Monitoring and automation matter</strong></p>
<p>Identity exposure creates an ongoing operational burden that extends well beyond the initial incident, and how quickly organizations respond has a direct impact on business outcomes. Those relying on manual, case-by-case remediation reported higher incident response costs than organizations with high levels of automation (39% versus 32%) and greater loss of customer or partner trust (47% versus 36%).</p>
<p>The report also introduces <a href="https://spycloud.com/identity-threat-protection-maturity-assessment/" rel="nofollow" rel="nofollow">SpyCloud&#8217;s Identity Threat Protection Maturity Model</a>, which groups respondents into four maturity tiers – Reactive, Building, Operational, and Optimized – across identity exposure visibility, monitoring, governance, automation, and remediation. The findings reflect that the more mature an identity program gets, the more it relies on continuous identity exposure monitoring and automated remediation – and that combination is what actually drives incident rates down.</p>
<p>At enterprise scale, some share of an organization&#8217;s employees, vendors, and machine accounts will be exposed in the near future regardless of how strong its controls are. What changes business outcomes is how long that exposure stays usable.</p>
<p>&#8220;Most identity programs are still measured on whether an exposure happened. That&#8217;s the wrong scoreboard,&#8221; said Damon Fleury, Chief Product Officer at SpyCloud. “Organizations that pair continuous identity monitoring with automated remediation of workforce exposures create the greatest friction for criminals and gain the biggest edge in preventing follow-on attacks.”</p>
<p>Users can access the full, no form-fill <a href="http://spycloud.com/resource/report/identity-threat-report-2026/" rel="nofollow" rel="nofollow">2026 SpyCloud Identity Threat Report</a> and benchmark their organization against the Identity Threat Protection Maturity Model by taking the free assessment <a href="https://spycloud.com/identity-threat-protection-maturity-assessment/" rel="nofollow" rel="nofollow">here</a>.</p>
<p><strong><em>About SpyCloud: </em></strong><em>SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions use advanced analytics and AI to accelerate investigations and protect workforce, consumer, and supplier identities from the threats that matter most: authentication bypass, session hijacking, malicious insiders, account takeover, ransomware, and fraud. Its data from malware-infected devices, successful phishes, combolists, and third-party breaches also powers many popular dark web monitoring and identity theft protection offerings. Customers include 7 of the Fortune 10, along with hundreds of global enterprises, mid-sized companies, and government agencies worldwide. Headquartered in Austin, TX, SpyCloud is home to more than 250 cybersecurity experts whose mission is to protect businesses and consumers from the stolen identity data criminals are using to target them now.</em></p>
<p><em>To learn more and see insights on your company&#8217;s exposed data, visit<a href="http://spycloud.com" rel="nofollow" rel="nofollow"> spycloud.com</a>.</em></p>
<p><em><strong>Media contact:</strong></em> <em>Emily Brown, REQ on behalf of SpyCloud, spycloud@req.co</em></p>
<p><strong><em>Editor’s note:</em></strong><em> This press release was provided by </em><a href="https://cybernewswire.com/" rel="nofollow" rel="nofollow"><em>CyberNewswire</em></a><em> as part of its press release syndication service. The views and claims expressed belong to the issuing organization.</em></p><p>The post <a href="https://www.lastwatchdog.com/news-alert-spycloud-survey-finds-machine-identity-risks-outpace-defenses-exposing-gaps-in-oversight/">News Alert: SpyCloud survey finds machine identity risks outpace defenses, exposing gaps in oversight</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>News Alert: Reflectiz launches AI website testing, uses site context to find and verify flaws</title>
		<link>https://www.lastwatchdog.com/news-alert-reflectiz-launches-ai-website-testing-uses-site-context-to-find-and-verify-flaws/</link>
		
		<dc:creator><![CDATA[cybernewswire]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 13:06:06 +0000</pubDate>
				<category><![CDATA[News Alerts]]></category>
		<category><![CDATA[Top Stories]]></category>
		<guid isPermaLink="false">https://www.lastwatchdog.com/?p=40277</guid>

					<description><![CDATA[<p>BOSTON, Sept. 8, 2026, CyberNewswire<strong> — </strong>Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites. Multiple specialized AI agents discover, attack, and validate vulnerabilities across complex web environments, and because they start from &#8230; <a href="https://www.lastwatchdog.com/news-alert-reflectiz-launches-ai-website-testing-uses-site-context-to-find-and-verify-flaws/" class="read-more">(more…) </a></p>
<p>The post <a href="https://www.lastwatchdog.com/news-alert-reflectiz-launches-ai-website-testing-uses-site-context-to-find-and-verify-flaws/">News Alert: Reflectiz launches AI website testing, uses site context to find and verify flaws</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>BOSTON, Sept. 8, 2026, CyberNewswire<strong> — </strong>Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites. Multiple specialized AI agents discover, attack, and validate vulnerabilities across complex web environments, and because they start from an existing model of each site, they cover up to ten times more than conventional pentesting tools.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Reflectiz-logo-1.png" rel="nofollow" rel="nofollow"><img decoding="async" class="aligncenter size-full wp-image-35710" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Reflectiz-logo-1.png" alt="" width="245" height="51" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Reflectiz-logo-1.png 245w, https://www.lastwatchdog.com/wp/wp-content/uploads/Reflectiz-logo-1-100x21.png 100w" sizes="(max-width: 245px) 100vw, 245px" /></a>A pentest used to be an event. An engagement, a report, done. The report described a moment. The website kept going: login, checkout, payments, dozens of third-party scripts, all probed by attackers daily.</p>
<div id="attachment_39632" style="width: 110px" class="wp-caption alignright"><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Idan-Cohen-hdsht.png" rel="nofollow" rel="nofollow"><img decoding="async" aria-describedby="caption-attachment-39632" class="wp-image-39632 size-thumbnail" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Idan-Cohen-hdsht-100x132.png" alt="" width="100" height="132" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Idan-Cohen-hdsht-100x132.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Idan-Cohen-hdsht.png 255w" sizes="(max-width: 100px) 100vw, 100px" /></a><p id="caption-attachment-39632" class="wp-caption-text">Cohen</p></div>
<p>&#8220;Websites change every week and get pentested once or twice a year. That gap is where exposure builds up,&#8221; said Idan Cohen, CEO and co-founder of Reflectiz. &#8220;Teams need testing that keeps up with releases at a cost they can sustain, and trusted coverage of what was tested.&#8221;</p>
<p><strong>Testing with site context</strong></p>
<p>Reflectiz has spent a decade scanning thousands of production websites and holds a live model of each one: pages, scripts, third parties, domains, sensitive inputs, and behaviors. The pentesting agents add the attacker&#8217;s perspective to that same model.<span id="more-40277"></span></p>
<p>A finding does not arrive as a line item. It arrives with the script involved, the data it can reach, and whether real users are exposed right now, allowing teams to skip the investigation and go straight to the fix.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/reflectiz-webinar.png" rel="nofollow" rel="nofollow"><img decoding="async" class="aligncenter size-medium wp-image-40291" src="https://www.lastwatchdog.com/wp/wp-content/uploads/reflectiz-webinar-520x271.png" alt="" width="520" height="271" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/reflectiz-webinar-520x271.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/reflectiz-webinar-960x500.png 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/reflectiz-webinar-100x52.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/reflectiz-webinar-768x400.png 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/reflectiz-webinar-1536x800.png 1536w, https://www.lastwatchdog.com/wp/wp-content/uploads/reflectiz-webinar.png 1866w" sizes="(max-width: 520px) 100vw, 520px" /></a>&#8220;The hard part of web pentesting was never the payload. It was understanding what the application actually does,&#8221; said Ysrael Gurt, CTO and co-founder of Reflectiz. &#8220;Our engine has been reading live websites for years, so our agents start with a map of the site that other tools never build.&#8221;</p>
<p><strong>Agents divide the work</strong></p>
<p>The agentic pentesting runs as a coordinated team of AI agents, each with a defined role:</p>
<p>•One agent crawls the site the way a real user does, through logins, one-time codes, and 2FA, mapping what is actually there.</p>
<p>•A second fingerprints the stack and works out which attacks apply where.</p>
<p>•A third runs those attacks and chains what it finds.</p>
<p>•The fourth matters most: an independent validator reproduces every finding before it reaches the report. False positives are removed by design.</p>
<p><strong>The result:</strong> findings with reproduction steps and evidence, plus a coverage map of what was tested and cleared.</p>
<p>Testing spans the full <a href="https://www.reflectiz.com/blog/owasp-top-ten-2026/" rel="nofollow" rel="nofollow">OWASP Top 10</a>, and teams set depth per flow, from fast predefined checks to expert-level attack chains on critical assets.</p>
<p><strong>Bringing web risks together</strong></p>
<p>The agentic pentesting, part of the new Offensive Hub, joins Security Hub and Privacy Hub on the Reflectiz platform, completing a 360° map of web risk: what runs on the website, what data it touches, and how it can be attacked.</p>
<p><strong>•One exposure picture.</strong> Findings from all three hubs cross-reference automatically, no dashboards reconciled by hand.</p>
<p><strong>•Guided fixes.</strong> Atlas, the Reflectiz AI remediation agent, explains each risk and walks the team through the fix.</p>
<p><strong>•Existing workflows.</strong> Results route into current operations through a REST API, CI/CD triggers, and Slack alerts.</p>
<p><strong>See it live</strong></p>
<p>Reflectiz founders Idan Cohen and Ysrael Gurt will demonstrate the agentic pentesting in a live webinar on September 15 at 11 AM ET / 6 PM CET.</p>
<p>Registration: <a href="https://www.reflectiz.com/lp/founders-case-study-webinar/" rel="nofollow" rel="nofollow">https://www.reflectiz.com/lp/founders-case-study-webinar/</a></p>
<p>Product information: <a href="https://www.reflectiz.com/offensive-hub/" rel="nofollow" rel="nofollow">Reflectiz Offensive Hub</a> | <a href="https://www.youtube.com/watch?v=Vn2W2RxSnSo" rel="nofollow" rel="nofollow">Walkthrough Video</a></p>
<p><strong><em>About Reflectiz: </em></strong><em>Reflectiz is the continuous web exposure management company. Its agentless, outside-in platform monitors, tests, and secures the entire web layer, from third-party scripts and web privacy risk to agentic penetration testing of the live site. Reflectiz helps enterprises in retail, finance, travel, insurance, healthcare, and gaming meet PCI DSS, DORA, NIS2, and global privacy requirements without touching a line of code. Learn more at <a href="https://www.reflectiz.com" rel="nofollow" rel="nofollow">https://www.reflectiz.com</a>.</em></p>
<p><em><strong>Media contact:</strong> Oran Frenkel, PR &amp; Social Media Manager, Reflectiz,</em><em><br />
oran.f@reflectiz.com </em></p>
<p><strong><em>Editor’s note:</em></strong><em> This press release was provided by </em><a href="https://cybernewswire.com/" rel="nofollow" rel="nofollow">CyberNewswire</a><em> as part of its press release syndication service. The views and claims expressed belong to the issuing organization</em></p><p>The post <a href="https://www.lastwatchdog.com/news-alert-reflectiz-launches-ai-website-testing-uses-site-context-to-find-and-verify-flaws/">News Alert: Reflectiz launches AI website testing, uses site context to find and verify flaws</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>News Alert: Link11 reports fewer but stronger DDoS attacks in Europe for the first half of 2026</title>
		<link>https://www.lastwatchdog.com/news-alert-link11-reports-fewer-but-stronger-ddos-attacks-in-europe-for-the-first-half-of-2026/</link>
		
		<dc:creator><![CDATA[cybernewswire]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 12:43:52 +0000</pubDate>
				<category><![CDATA[News Alerts]]></category>
		<category><![CDATA[Top Stories]]></category>
		<guid isPermaLink="false">https://www.lastwatchdog.com/?p=40270</guid>

					<description><![CDATA[<p>FRANKFURT, September 3, 2026, CyberNewswire — <a href="https://www.link11.com/en/" rel="nofollow" rel="nofollow">Link11</a> has released its European Cyber Report for the first half of 2026, providing an overview of DDoS attack activity targeting European companies.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Link-11-logo-1.png" rel="nofollow" rel="nofollow"><img decoding="async" class="aligncenter size-full wp-image-34766" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Link-11-logo-1.png" alt="" width="388" height="80" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Link-11-logo-1.png 388w, https://www.lastwatchdog.com/wp/wp-content/uploads/Link-11-logo-1-100x21.png 100w" sizes="(max-width: 388px) 100vw, 388px" /></a>Although the number of DDoS attacks on the Link11 network decreased &#8230; <a href="https://www.lastwatchdog.com/news-alert-link11-reports-fewer-but-stronger-ddos-attacks-in-europe-for-the-first-half-of-2026/" class="read-more">(more…) </a></p>
<p>The post <a href="https://www.lastwatchdog.com/news-alert-link11-reports-fewer-but-stronger-ddos-attacks-in-europe-for-the-first-half-of-2026/">News Alert: Link11 reports fewer but stronger DDoS attacks in Europe for the first half of 2026</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>FRANKFURT, September 3, 2026, CyberNewswire — <a href="https://www.link11.com/en/" rel="nofollow" rel="nofollow">Link11</a> has released its European Cyber Report for the first half of 2026, providing an overview of DDoS attack activity targeting European companies.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Link-11-logo-1.png" rel="nofollow" rel="nofollow"><img decoding="async" class="aligncenter size-full wp-image-34766" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Link-11-logo-1.png" alt="" width="388" height="80" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Link-11-logo-1.png 388w, https://www.lastwatchdog.com/wp/wp-content/uploads/Link-11-logo-1-100x21.png 100w" sizes="(max-width: 388px) 100vw, 388px" /></a>Although the number of DDoS attacks on the Link11 network decreased by 42 percent, the report records new highs for attack intensity across bandwidth, packet rate and cumulative data volume, indicating that attacks have become more targeted and intense.</p>
<p><strong>Attack intensity hits records</strong></p>
<p>Although the number of attacks decreased by 42 percent, record highs were reached in terms of attack intensity in every category. The highest measured bandwidth attack reached 2.3 Tbit/s—85 percent higher than the previous peak of 1.2 Tbit/s in the first half of 2025.</p>
<p>The packet rate followed the same pattern, reaching a new peak of 322 million packets per second — up 56 percent from 207 million packets per second a year earlier. Cumulative traffic also increased, rising from 438 to 705 terabytes over the six-month period — a 61 percent increase.<span id="more-40270"></span></p>
<p><strong>Botnets fuel bigger attacks</strong></p>
<p>The report attributes these records to super-botnets, such as Aisuru and its successor, Kimwolf, as well as a growing number of hijacked cloud servers. These servers individually push far more bandwidth than a compromised home router or camera ever could.</p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/link11-report-graphic-1.png" rel="nofollow"><img decoding="async" class="aligncenter size-medium wp-image-40286" src="https://www.lastwatchdog.com/wp/wp-content/uploads/link11-report-graphic-1-520x264.png" alt="" width="520" height="264" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/link11-report-graphic-1-520x264.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/link11-report-graphic-1-960x488.png 960w, https://www.lastwatchdog.com/wp/wp-content/uploads/link11-report-graphic-1-100x51.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/link11-report-graphic-1-768x391.png 768w, https://www.lastwatchdog.com/wp/wp-content/uploads/link11-report-graphic-1-1536x781.png 1536w, https://www.lastwatchdog.com/wp/wp-content/uploads/link11-report-graphic-1.png 1982w" sizes="(max-width: 520px) 100vw, 520px" /></a>The report credits the drop in raw attack numbers to sustained international law enforcement pressure, including the takedown of pro-Russian group NoName057(16)&#8217;s infrastructure in July 2025 during “Operation Eastwood.”</p>
<p>In March 2026, another blow followed: Authorities in the U.S., Canada, and Germany shut down the command-and-control servers of four major IoT botnets that collectively controlled more than three million devices.</p>
<p>“These numbers show that the threat isn&#8217;t shrinking; it&#8217;s shifting from breadth to peak intensity,” said Jens-Philipp Jung, CEO of Link11. “Organizations that size their defenses based on last year&#8217;s attack count are underestimating how quickly a single incident can escalate today.”</p>
<p><strong>Repeat attacks grow likelier</strong></p>
<p>Being hit once also makes being hit again more likely: only 44 percent of targeted customers remained attack-free for 30 days after a wave in the first half of 2026, down from 54 percent a year earlier.</p>
<p><strong>Traffic masks hidden threats</strong></p>
<p>Not every dangerous attack is a loud one. In one case documented in the report, attackers used a traffic spike against two domains as cover while quietly running SQL injection and cross-site scripting (XSS) probes behind it — a tactic exposed only because they reused the same IP addresses for both.</p>
<p>“The most dangerous attacks we deal with are rarely the loudest ones anymore,” said Jag Bains, VP Solution Engineering, at Link11. “If you&#8217;re only watching bandwidth and known signatures, you&#8217;ll miss the attacks designed to do the most damage because they&#8217;re built to stay unnoticed.”</p>
<p>In short, in 2026, force and concealment determine the risk, not raw attack counts. Defenses built around last year&#8217;s numbers are aimed at the wrong threat.</p>
<p>The full report will be available for download <a href="https://www.link11.com/en/download/european-cyber-report-midyear-2026/" rel="nofollow" rel="nofollow">here</a>.</p>
<p><strong><em>About Link11</em></strong><em>: <a href="https://www.link11.com/en/" rel="nofollow" rel="nofollow">Link11</a> is a leading European IT security provider that protects global infrastructures and web applications against cyberattacks. Its cloud-based IT security solutions help companies worldwide strengthen the cyber resilience of their networks and critical applications and avoid business disruptions. Link11 is a BSI-qualified provider for the DDoS protection of critical infrastructure. With PCI DSS, SOC 2 Type II, BSI C5 and ISO 27001, the company meets the highest standards in data security and compliance. </em></p>
<p><strong><em>Media contact:</em></strong> <em>Lisa Froehlich, Link11 GmbH, l.froehlich@link11.com</em></p>
<p><strong><em>Editor’s note:</em></strong><em> This press release was provided by </em><a href="https://cybernewswire.com/" rel="nofollow" rel="nofollow">CyberNewswire</a><em> as part of its press release syndication service. The views and claims expressed belong to the issuing organization.</em></p><p>The post <a href="https://www.lastwatchdog.com/news-alert-link11-reports-fewer-but-stronger-ddos-attacks-in-europe-for-the-first-half-of-2026/">News Alert: Link11 reports fewer but stronger DDoS attacks in Europe for the first half of 2026</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>GUEST ESSAY: AI coding assistants are putting open source in your code without declaring it</title>
		<link>https://www.lastwatchdog.com/guest-essay-ai-coding-assistants-are-putting-open-source-in-your-code-without-declaring-it/</link>
		
		<dc:creator><![CDATA[bacohido]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 09:53:35 +0000</pubDate>
				<category><![CDATA[Essays]]></category>
		<category><![CDATA[Top Stories]]></category>
		<guid isPermaLink="false">https://www.lastwatchdog.com/?p=40242</guid>

					<description><![CDATA[<p>For years, software teams have managed open source risk in two familiar forms: licensing obligations and known vulnerabilities. AI coding assistants introduce a third risk that is harder to see.</p>
<p><em><strong>Related:</strong> <a href="https://www.lastwatchdog.com/black-hat-qa-sbom-claims-what-went-in-binary-shows-what-shipped-the-risk-lies-between/" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">Where SBOMs fall short</a></em></p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/SBOM-squr.jpg" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow"><img decoding="async" class="alignright size-thumbnail wp-image-32823" src="https://www.lastwatchdog.com/wp/wp-content/uploads/SBOM-squr-100x88.jpg" alt="" width="100" height="88" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/SBOM-squr-100x88.jpg 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/SBOM-squr-520x460.jpg 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/SBOM-squr.jpg 750w" sizes="(max-width: 100px) 100vw, 100px" /></a>They can place open source &#8230; <a href="https://www.lastwatchdog.com/guest-essay-ai-coding-assistants-are-putting-open-source-in-your-code-without-declaring-it/" class="read-more">(more…) </a></p>
<p>The post <a href="https://www.lastwatchdog.com/guest-essay-ai-coding-assistants-are-putting-open-source-in-your-code-without-declaring-it/">GUEST ESSAY: AI coding assistants are putting open source in your code without declaring it</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>For years, software teams have managed open source risk in two familiar forms: licensing obligations and known vulnerabilities. AI coding assistants introduce a third risk that is harder to see.</p>
<p><em><strong>Related:</strong> <a href="https://www.lastwatchdog.com/black-hat-qa-sbom-claims-what-went-in-binary-shows-what-shipped-the-risk-lies-between/" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow">Where SBOMs fall short</a></em></p>
<p><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/SBOM-squr.jpg" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow"><img decoding="async" class="alignright size-thumbnail wp-image-32823" src="https://www.lastwatchdog.com/wp/wp-content/uploads/SBOM-squr-100x88.jpg" alt="" width="100" height="88" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/SBOM-squr-100x88.jpg 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/SBOM-squr-520x460.jpg 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/SBOM-squr.jpg 750w" sizes="(max-width: 100px) 100vw, 100px" /></a>They can place open source snippets directly inside source files without declaring a package, updating a build file or adding anything to a software bill of materials.</p>
<p>These hidden dependencies expose a weakening assumption behind established software controls: that third-party code arrives through a declared component. When it does not, the Software Composition Analysis tools and SBOM processes organizations rely on may never see it.</p>
<p><strong>Where trails break</strong></p>
<p>When a developer uses an open source package, the package normally appears in a manifest or dependency file. That creates a trail. SCA tools can identify the component, check its license and known vulnerabilities, and include it in the resulting SBOM.<span id="more-40242"></span></p>
<p>An AI coding assistant can bypass that trail. Because models learn from open source and other publicly available code, an assistant may reproduce a familiar pattern directly inside a file. No package is installed and no dependency is declared. Even a careful reviewer is unlikely to recognize that a block of generated code resembles material from one of millions of open source projects.</p>
<p>The obligations, however, do not disappear simply because the trail does. A reproduced snippet may require attribution or a license notice. Copyleft code may raise broader questions about surrounding proprietary code.</p>
<p>Research shows that this is more than a hypothetical concern. The LiCoEval benchmark evaluated 14 popular language models and found that 0.88% to 2.01% of generated functions were strikingly similar to existing open source implementations. Most models failed to supply accurate license information, particularly for copyleft code.</p>
<div id="attachment_40248" style="width: 110px" class="wp-caption alignright"><a href="https://www.lastwatchdog.com/wp/wp-content/uploads/Mike-Pittenger-hdsht.png" rel="nofollow" rel="nofollow" rel="nofollow" rel="nofollow"><img decoding="async" aria-describedby="caption-attachment-40248" class="size-thumbnail wp-image-40248" src="https://www.lastwatchdog.com/wp/wp-content/uploads/Mike-Pittenger-hdsht-100x118.png" alt="" width="100" height="118" srcset="https://www.lastwatchdog.com/wp/wp-content/uploads/Mike-Pittenger-hdsht-100x118.png 100w, https://www.lastwatchdog.com/wp/wp-content/uploads/Mike-Pittenger-hdsht-520x612.png 520w, https://www.lastwatchdog.com/wp/wp-content/uploads/Mike-Pittenger-hdsht.png 642w" sizes="(max-width: 100px) 100vw, 100px" /></a><p id="caption-attachment-40248" class="wp-caption-text">Pittenger</p></div>
<p>Those percentages sound small until they meet the scale of a working codebase. In an application with 300,000 functions, a one to two percent rate puts 3,000 to 6,000 functions in play, each one a potential attribution or license obligation that nobody recorded.</p>
<p>Our own early review at Insignary points the same direction. Across a small sample of real-world applications generated wholly or partly by AI, open source snippets turned up in roughly a third of generated files, and in more than half the files from applications built entirely by AI. Traditional SBOMs captured well under a quarter of the dependencies that snippet-level analysis surfaced.</p>
<p><strong>Why controls matter</strong></p>
<p>The GitHub Copilot litigation has already brought the removal or omission of copyright and attribution information into court. The district court dismissed the plaintiffs’ principal DMCA claims, and that ruling is now on appeal. Whatever the eventual outcome, development organizations cannot assume that code is free of obligations merely because an assistant produced it.</p>
<p>Do the benefits of AI coding tools outweigh the risks? Of course. But development and risk teams have faced a version of this question before. In the early days of open source, the first instinct was to hunt it down and strip it out. That impulse faded as the benefits became undeniable, and what replaced it was visibility and control: knowing what you had, where it came from and what it obligated you to do. AI-generated code needs the same shift. The goal is not to ban the assistants. It is to treat what they produce with the same scrutiny already applied to code from outside the organization.</p>
<p>That starts with making AI use visible. Engineering leaders should know which assistants are approved, where generated code may enter repositories and how that use is disclosed in pull requests. The developer submitting the code should remain responsible for reviewing it rather than treating the model as its author or approver.</p>
<p><strong>Find, decide, record</strong></p>
<p>Next, inspect the source itself before code is merged or released. Traditional SCA remains necessary for declared components, but snippet-level analysis is needed to find borrowed code embedded inside files. A match should identify the likely project, version, and its license.</p>
<p>Then route the result through an explicit decision gate. Permissively licensed code may be retained once required notices and attribution are restored. Copyleft or uncertain matches should go to the organization’s open source or legal reviewers, then rewritten or replaced.</p>
<p>Finally, record the decision. Update the SBOM or related attestations, preserve the evidence behind the disposition and identify who approved release. Engineering owns the code it ships; security and open source program teams define the controls; legal specialists resolve the exceptions.</p>
<p>AI has accelerated code production without eliminating software accountability. Controls built around declared dependencies now need to account for code that arrives without one. Once hidden dependencies become visible, organizations can evaluate them using the same disciplined process they already apply to the rest of the software supply chain.</p>
<p><strong><em>About the essayist:</em></strong><em> Mike Pittenger is chief strategy officer at Insignary, a Toronto-based provider of software composition analysis technology that identifies open-source components, licenses and vulnerabilities in source code and binaries.</em></p><p>The post <a href="https://www.lastwatchdog.com/guest-essay-ai-coding-assistants-are-putting-open-source-in-your-code-without-declaring-it/">GUEST ESSAY: AI coding assistants are putting open source in your code without declaring it</a> first appeared on <a href="https://www.lastwatchdog.com">The Last Watchdog</a>.</p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
