{"id":5554,"date":"2026-07-26T13:22:41","date_gmt":"2026-07-26T18:22:41","guid":{"rendered":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5554"},"modified":"2026-07-26T13:22:41","modified_gmt":"2026-07-26T18:22:41","slug":"security-operations-weekly-july-26-2026","status":"publish","type":"post","link":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5554","title":{"rendered":"Security Operations Weekly &mdash; July 26, 2026"},"content":{"rendered":"<style>\n.single .entry-title,\n.single .entry-header .entry-title,\n.single .post-title,\n.single header.entry-header h1,\n.single h1.entry-title,\n.single .page-title,\n.post-template-default h1.entry-title,\n.post-template-default .entry-header,\narticle .entry-header,\narticle .entry-title { display: none !important; }\n.single .entry-header { margin: 0 !important; padding: 0 !important; }\n.single .entry-content { margin-top: 0 !important; padding-top: 0 !important; }\n<\/style>\n<div class=\"container\">\n<p>  <!-- Banner --><\/p>\n<div class=\"banner\" style=\"background-color:#0f2c4d;background:linear-gradient(135deg,#0f2c4d 0%,#1e5a8f 50%,#2b8fb3 100%);padding:36px 32px;color:#ffffff;\">\n<div class=\"date\" style=\"color:#d6e4f2 !important;\">Security Radar &middot; Newshunter<\/div>\n<h1 style=\"color:#ffffff !important;\">Security Operations Weekly<\/h1>\n<div class=\"date\" style=\"margin-top:4px; color:#d6e4f2 !important;\">July 26, 2026 &middot; Weekly Edition<\/div>\n<p class=\"tagline\" style=\"color:#e6f0fa !important;\">Swimlane and 7AI push agentic SOC automation deeper into the MSSP channel, a run of releases and research converges on the same widening gap &mdash; the AI tools, agents, and machine identities the enterprise cannot see &mdash; Cribl&rsquo;s CardinalOps buy caps a month of AI-SOC consolidation, CISA forces an emergency Langflow patch while ransomware crews hammer edge VPNs, and a Sophos report crowns AI agents the enterprise&rsquo;s fastest-growing attack surface &mdash; the operational picture for the week ending July 26.<\/p>\n<\/p><\/div>\n<div class=\"content\">\n<p>    <!-- At a glance --><\/p>\n<h2>At a glance<\/h2>\n<div class=\"intro\">\n<p>This was an agentic-SOC-and-visibility week. Swimlane put an AI SOC product into the hands of MSSPs, packaging autonomous triage and investigation for service providers who have to run detection-to-response across many client tenants at once, and 7AI followed with a partner-first global alliance program built explicitly to scale agentic security operations through the channel. Read together, the two announcements say the &ldquo;autonomous SOC&rdquo; pitch has moved past the direct-to-enterprise pilot and into the multi-tenant economics of the managed-services market &mdash; where an agent that can close low-value cases without a human is not a nice-to-have but the only way the unit math works. CyberProof&rsquo;s agentic MXDR relaunch, which claims to automate roughly two-thirds of investigations, and Intezer&rsquo;s move to let SOC teams automate their own custom tasks both point at the same operational thesis: the value is migrating from the console to the volume of work the automation can take off the analyst&rsquo;s plate.<\/p>\n<p>Underneath the launches, the week&rsquo;s dominant research theme was everything the SOC cannot currently see. ThreatDown extended visibility to AI tools and machine identities; a widely covered report found that enterprise AI agents are still logging in as humans &mdash; using human credentials and sessions rather than governed, auditable machine identities &mdash; and separate reporting made the case that shadow AI is becoming enterprise security&rsquo;s single biggest blind spot as employees wire unsanctioned models into corporate data. Druva rounded out the theme from the resilience side, bringing backup, recovery, and governance to AI workloads that most data-protection programs never scoped. The throughline is uncomfortable and consistent: the enterprise is deploying AI agents and tools far faster than it is instrumenting them, and the identity, inventory, and recovery gaps that opens are precisely where the next incident will start. This is the SOC&rsquo;s version of an asset-management problem &mdash; you cannot detect, govern, or recover what you never knew was running.<\/p>\n<p>The market-structure story of the week was consolidation. Cribl&rsquo;s acquisition of CardinalOps pulls detection-posture management into its data-pipeline platform, capping a month in which Lumen folded Cortex XSIAM into its managed detection and response, eSentire opened a new U.S. SOC for data-residency-sensitive buyers, and The Hacker News published a practitioner&rsquo;s rubric for telling a real AI SOC platform from a bolt-on AI feature &mdash; a sign the category is mature enough that buyers now need help separating substance from marketing. This week&rsquo;s foundational reading turns from the launch cycle to the detection surface itself: a phishing-simulation benchmark with the counterintuitive finding that the best-funded companies open the most malicious attachments, a forensic technique for tracing backdoored code completions inside AI coding assistants, research on non-interactive SSH attacks that dominate after the login, reporting on why organizations still struggle to prioritize known risks, the endpoint-recovery gap teams only discover mid-incident, catching ransomware on the wire before it locks the file server, and what the open-source AI patch gap means for enterprise defenders. The tooling wave is real; so is the reminder that the fundamentals &mdash; identity, inventory, recovery, and disciplined prioritization &mdash; are where automation either pays off or quietly fails.<\/p>\n<p>The week&rsquo;s other half was the unglamorous vulnerability-and-exposure grind. CISA ordered federal agencies to urgently patch an actively exploited remote-code-execution flaw in Langflow (CVE-2026-0770), the AI-agent-builder framework whose earlier bugs the JadePuffer ransomware crew has already weaponized; Eclypsium launched an InfraTrust report to help admins triage the flaws that actually matter across firmware, networking, and edge gear by exploitability rather than CVSS; Oracle shipped a staggering 1,449 patches in a single quarterly drop; and CSO detailed how Qilin and other ransomware groups are hammering vulnerable VPNs and edge appliances from Palo Alto, Fortinet, Citrix, and Check Point as their preferred way in. Running alongside the patch grind is the AI-attack-surface thread: a Sophos report named AI agents and their identities the enterprise&rsquo;s fastest-growing exposed attack surface, Cobalt launched an AI-driven Autonomous Pentest to keep offensive testing continuous, a new Dolphin X infostealer uses an &ldquo;AI Profiler&rdquo; to rank stolen victims by value, and researchers showed the top LLMs hallucinate the same fake PyPI and npm package names &mdash; keeping slopsquatting alive as a supply-chain risk. The two threads rhyme: attackers are industrializing both the old exposure (unpatched edge devices) and the new one (ungoverned AI), and the SOC has to run patch discipline and AI governance at the same time.<\/p>\n<\/p><\/div>\n<p>    <!-- Topic map --><\/p>\n<div class=\"topic-map\">\n      <img decoding=\"async\" src=\"https:\/\/www.cybersecurityinstitute.com\/blog\/wp-content\/uploads\/2026\/07\/topic-map-security-operations-2026-07-26.png\" alt=\"Topic map for Security Operations Weekly, July 26 2026\" loading=\"eager\"><\/p>\n<div class=\"caption\">Topic map &mdash; the agentic-SOC and MSSP-automation wave (Swimlane, 7AI, CyberProof), the AI-identity and shadow-AI visibility blind spot (ThreatDown, machine identities, Druva), the MDR\/MXDR and AI-SOC-platform consolidation (Cribl\/CardinalOps, Lumen\/Cortex XSIAM, eSentire, Intezer), the vulnerability-and-exposure grind (CISA&rsquo;s Langflow KEV order, Eclypsium InfraTrust, Oracle&rsquo;s 1,449 patches, Qilin ransomware hammering edge VPNs), the AI attack surface (Sophos agent-identity report, Cobalt Autonomous Pentest, Dolphin X&rsquo;s AI victim-profiler, LLM slopsquatting), and the detection, phishing, and risk research in this week&rsquo;s foundational reading.<\/div>\n<p>      <!-- INTERACTIVE_MAP_LINK_START --><\/p>\n<p style=\"margin:10px 0 0;text-align:center;\"><a href=\"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5553\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;padding:8px 18px;background-color:#0f172a;color:#ffffff !important;text-decoration:none;border-radius:6px;font-size:13px;font-weight:600;\">View interactive topic map &rarr;<\/a><\/p>\n<p><!-- INTERACTIVE_MAP_LINK_END -->\n    <\/div>\n<p>    <!-- Article index --><\/p>\n<h2>This week&rsquo;s stories<\/h2>\n<div class=\"cluster\">\n<h3>Agentic SOC platforms and MSSP automation<\/h3>\n<p>The week&rsquo;s lead story: agentic security operations pushing into the managed-services channel. Swimlane packages an AI SOC for MSSPs, and 7AI stands up a partner-first alliance program built to scale agentic operations through partners rather than one enterprise at a time.<\/p>\n<ol>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/22\/swimlane-ai-soc-mssps\/\">Swimlane AI SOC Automates Security Operations for MSSPs<\/a> <span class=\"meta-inline\">&mdash; Help Net Security, Jul 22<\/span><\/li>\n<li><a href=\"https:\/\/www.globenewswire.com\/news-release\/2026\/07\/23\/3332201\/0\/en\/7ai-launches-modern-partner-first-global-alliance-program-to-scale-agentic-security-operations.html\">7AI Launches Partner-First Global Alliance Program to Scale Agentic Security Operations<\/a> <span class=\"meta-inline\">&mdash; GlobeNewswire, Jul 23<\/span><\/li>\n<\/ol><\/div>\n<div class=\"cluster\">\n<h3>AI identity, visibility, and the shadow-AI blind spot<\/h3>\n<p>The dominant research theme: everything the SOC can&rsquo;t currently see. AI agents still authenticate as humans, unsanctioned AI is widening the visibility gap, and vendors are extending both detection and data-resilience coverage to AI tools and machine identities that most programs never scoped.<\/p>\n<ol>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/22\/threatdown-ai-visibility\/\">ThreatDown Expands Security Visibility to AI Tools and Machine Identities<\/a> <span class=\"meta-inline\">&mdash; Help Net Security, Jul 22<\/span><\/li>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/21\/report-enterprise-ai-identity-risk\/\">AI Agents Are Still Logging In As Humans<\/a> <span class=\"meta-inline\">&mdash; Help Net Security, Jul 21<\/span><\/li>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/23\/shadow-ai-security-risks\/\">Shadow AI Is Becoming Enterprise Security&rsquo;s Biggest Blind Spot<\/a> <span class=\"meta-inline\">&mdash; Help Net Security, Jul 23<\/span><\/li>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/21\/druva-brings-backup-recovery-and-governance-to-ai-workloads\/\">Druva Brings Backup, Recovery, and Governance to AI Workloads<\/a> <span class=\"meta-inline\">&mdash; Help Net Security, Jul 21<\/span><\/li>\n<\/ol><\/div>\n<div class=\"cluster\">\n<h3>Detection, phishing, and AI-assistant forensics<\/h3>\n<p>Two operational research items from the news window: a phishing-simulation benchmark with a counterintuitive finding about who actually opens the attachments, and a forensic technique for tracing backdoored code completions inside AI coding assistants.<\/p>\n<ol>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/24\/phishing-simulation-benchmark-report\/\">The Best-Funded Companies Open the Most Phishing Attachments<\/a> <span class=\"meta-inline\">&mdash; Help Net Security, Jul 24<\/span><\/li>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/20\/tracing-backdoored-code-completions\/\">A Forensic Tool for Backdoored Code Completions in AI Assistants<\/a> <span class=\"meta-inline\">&mdash; Help Net Security, Jul 20<\/span><\/li>\n<\/ol><\/div>\n<div class=\"cluster\">\n<h3>Exploited flaws, edge VPNs, and patch prioritization<\/h3>\n<p>The vulnerability-and-exposure grind: CISA orders an emergency Langflow patch, a new report helps admins triage infrastructure flaws by real exploitability, Oracle ships 1,449 fixes at once, and ransomware crews keep breaking in through edge VPNs.<\/p>\n<ol>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/cisa-orders-feds-to-patch-actively-exploited-langflow-rce-flaw\/\">CISA Orders Urgent Action on Actively Exploited Langflow RCE Flaw<\/a> <span class=\"meta-inline\">&mdash; BleepingComputer, Jul 22<\/span><\/li>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-infratrust-report-reveals-infrastructure-flaws-admins-should-patch-first\/\">New InfraTrust Report Reveals Infrastructure Flaws Admins Should Patch First<\/a> <span class=\"meta-inline\">&mdash; BleepingComputer, Jul 22<\/span><\/li>\n<li><a href=\"https:\/\/www.theregister.com\/security\/2026\/07\/23\/oracle-drops-1449-security-patches-like-its-the-new-normal\/5277114\">Oracle Drops 1,449 Security Patches Like It&rsquo;s the New Normal<\/a> <span class=\"meta-inline\">&mdash; The Register, Jul 23<\/span><\/li>\n<li><a href=\"https:\/\/www.csoonline.com\/article\/4201019\/ransomware-groups-are-hammering-your-vulnerable-vpns.html\">Ransomware Groups Are Hammering Your Vulnerable VPNs<\/a> <span class=\"meta-inline\">&mdash; CSO Online, Jul 24<\/span><\/li>\n<\/ol><\/div>\n<div class=\"cluster\">\n<h3>The AI attack surface: agent identities, autonomous pentest, and AI-driven threats<\/h3>\n<p>The new exposure the SOC has to instrument: a Sophos report names AI agents the fastest-growing attack surface, Cobalt makes pentesting continuous with AI, a new infostealer uses AI to rank victims, and the top LLMs keep hallucinating the same fake package names.<\/p>\n<ol>\n<li><a href=\"https:\/\/www.infosecurity-magazine.com\/news\/ai-agents-attack-surface\/\">AI Agents Now the Enterprise&rsquo;s Fastest-Growing Exposed Attack Surface<\/a> <span class=\"meta-inline\">&mdash; Infosecurity Magazine, Jul 23<\/span><\/li>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/23\/cobalt-adds-autonomous-pentest-to-scale-application-security-testing\/\">Cobalt Adds Autonomous Pentest to Scale Application Security Testing<\/a> <span class=\"meta-inline\">&mdash; Help Net Security, Jul 23<\/span><\/li>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-dolphin-x-malware-uses-ai-to-rank-high-value-targets\/\">New Dolphin X Malware Uses AI to Rank High-Value Targets<\/a> <span class=\"meta-inline\">&mdash; BleepingComputer, Jul 23<\/span><\/li>\n<li><a href=\"https:\/\/www.infoworld.com\/article\/4200884\/top-ais-invent-same-fake-pypl-and-npm-package-names.html\">Top AIs Invent the Same Fake PyPI and npm Package Names<\/a> <span class=\"meta-inline\">&mdash; InfoWorld, Jul 24<\/span><\/li>\n<\/ol><\/div>\n<div class=\"cluster\">\n<h3>Foundational reading: MDR\/MXDR consolidation and the AI-SOC market<\/h3>\n<p>The month&rsquo;s market-structure story &mdash; acquisitions, integrations, and new capacity as the AI-SOC and managed-detection categories consolidate, plus a practitioner&rsquo;s rubric for telling a real AI SOC platform from a bolt-on AI feature and a look at automating custom SOC tasks.<\/p>\n<ol>\n<li><a href=\"https:\/\/www.globenewswire.com\/news-release\/2026\/07\/14\/3327113\/0\/en\/cribl-acquires-cardinalops-to-further-expand-its-ai-platform-into-security-operations.html\">Cribl Acquires CardinalOps to Expand Its AI Platform Into Security Operations<\/a> <span class=\"meta-inline\">&mdash; GlobeNewswire, Jul 14 [Foundational]<\/span><\/li>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/13\/lumen-defender-amdr\/\">Lumen Expands Managed Detection and Response With Cortex XSIAM Integration<\/a> <span class=\"meta-inline\">&mdash; Help Net Security, Jul 13 [Foundational]<\/span><\/li>\n<li><a href=\"https:\/\/www.esentire.com\/news-releases\/esentire-opens-new-u-s-soc-providing-u-s-data-residency\">eSentire Opens New U.S. SOC, Providing U.S. Data Residency<\/a> <span class=\"meta-inline\">&mdash; eSentire, Jul 08 [Foundational]<\/span><\/li>\n<li><a href=\"https:\/\/siliconangle.com\/2026\/07\/07\/cyberproof-launches-agentic-mxdr-automate-two-thirds-investigations\/\">CyberProof Redefines MXDR With Agentic AI and Autonomous Security Operations<\/a> <span class=\"meta-inline\">&mdash; SiliconANGLE, Jul 07 [Foundational]<\/span><\/li>\n<li><a href=\"https:\/\/thehackernews.com\/2026\/07\/how-to-evaluate-ai-soc-platform-in-2026.html\">How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders From Bolt-On AI<\/a> <span class=\"meta-inline\">&mdash; The Hacker News, Jul 06 [Foundational]<\/span><\/li>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/03\/intezer-helps-soc-teams-automate-custom-security-tasks\/\">Intezer Helps SOC Teams Automate Custom Security Tasks<\/a> <span class=\"meta-inline\">&mdash; Help Net Security, Jul 03 [Foundational]<\/span><\/li>\n<\/ol><\/div>\n<div class=\"cluster\">\n<h3>Foundational reading: detection, risk, and recovery research<\/h3>\n<p>Five longer reads on the operational fundamentals under the automation hype &mdash; what attackers do after the SSH login, why known risks still go unprioritized, the endpoint-recovery gap teams find mid-incident, catching ransomware on the wire before it locks the file server, and what the open-source AI patch gap means for defenders.<\/p>\n<ol>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/03\/research-non-interactive-ssh-attacks\/\">Non-Interactive SSH Attacks Dominate After Login<\/a> <span class=\"meta-inline\">&mdash; Help Net Security, Jul 03 [Foundational]<\/span><\/li>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/03\/cyber-risk-exposure-report\/\">Organizations Struggle to Prioritize Known Cyber Risks<\/a> <span class=\"meta-inline\">&mdash; Help Net Security, Jul 03 [Foundational]<\/span><\/li>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/02\/matthias-haas-igel-endpoint-recovery-gap\/\">The Endpoint Recovery Gap Many Teams Discover During an Incident<\/a> <span class=\"meta-inline\">&mdash; Help Net Security, Jul 02 [Foundational]<\/span><\/li>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/02\/shared-storage-ransomware-detection-research\/\">Catching Ransomware on the Wire Before It Locks the File Server<\/a> <span class=\"meta-inline\">&mdash; Help Net Security, Jul 02 [Foundational]<\/span><\/li>\n<li><a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/02\/open-source-ai-patch-gap\/\">What the AI Patch Gap Means for Enterprise Security<\/a> <span class=\"meta-inline\">&mdash; Help Net Security, Jul 02 [Foundational]<\/span><\/li>\n<\/ol><\/div>\n<p>    <!-- Detailed write-ups --><\/p>\n<h2>The detail<\/h2>\n<p>    <!-- 1 --><\/p>\n<div class=\"article\">\n<h4>1. Agentic Security Operations Reach the Channel: Swimlane&rsquo;s AI SOC for MSSPs and 7AI&rsquo;s Partner-First Alliance<\/h4>\n<p class=\"meta\">Help Net Security, GlobeNewswire &middot; July 22&ndash;23, 2026<\/p>\n<p class=\"summary\">The week&rsquo;s clearest signal was where agentic security operations is now being sold: not one enterprise SOC at a time, but through the managed-services channel that runs detection-to-response for many organizations at once. Swimlane launched an AI SOC aimed squarely at MSSPs, wrapping autonomous triage, enrichment, and investigation into a package a service provider can operate across multiple client tenants &mdash; the setting where the economics of automation are least optional, because an MSSP&rsquo;s margins live or die on how many low-value alerts it can close without paying an analyst to touch them. Days later, 7AI stood up a partner-first global alliance program built explicitly to scale agentic security operations through partners rather than direct sales, betting that the fastest route to volume for autonomous SOC tooling runs through the MSSPs, MSSPs, and integrators who already own the customer relationships. Read together, the two moves mark a maturity shift: the &ldquo;autonomous SOC&rdquo; conversation has moved past the proof-of-concept and into distribution strategy, and the differentiation is migrating from the detection console toward how much investigative work the agent can actually take off the queue at multi-tenant scale. For a SOC leader &mdash; in-house or at a provider &mdash; the operational question is the same one every automation pitch raises: can the agent show you why it closed or escalated a case, and does it hold up across tenants with very different environments, or does the multi-tenant model just multiply the blast radius of a bad automated decision.<\/p>\n<p>      <a class=\"btn\" href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/22\/swimlane-ai-soc-mssps\/\">Read the article<\/a><\/p>\n<p style=\"font-size:13px;color:#6b7280;margin-top:6px;\">Sources: <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/22\/swimlane-ai-soc-mssps\/\" style=\"color:#1d4ed8;text-decoration:none;\">Swimlane AI SOC (Help Net Security)<\/a> &middot; <a href=\"https:\/\/www.globenewswire.com\/news-release\/2026\/07\/23\/3332201\/0\/en\/7ai-launches-modern-partner-first-global-alliance-program-to-scale-agentic-security-operations.html\" style=\"color:#1d4ed8;text-decoration:none;\">7AI Alliance Program (GlobeNewswire)<\/a><\/p>\n<\/p><\/div>\n<p>    <!-- 2 --><\/p>\n<div class=\"article\">\n<h4>2. The AI Visibility Gap: Agents Logging In As Humans, Shadow AI, and the Machine-Identity Blind Spot<\/h4>\n<p class=\"meta\">Help Net Security &middot; July 21&ndash;23, 2026<\/p>\n<p class=\"summary\">Three items this week described the same widening hole from different angles, and together they add up to the SOC&rsquo;s most consequential operational problem of the moment: the enterprise is deploying AI faster than it is instrumenting it. A widely covered report found that enterprise AI agents are still logging in as humans &mdash; consuming human credentials, tokens, and sessions rather than governed, auditable machine identities &mdash; which means the agent&rsquo;s activity blends into user telemetry, inherits a person&rsquo;s standing access, and leaves no clean identity boundary to monitor, revoke, or attribute when something goes wrong. Separate reporting made the case that shadow AI has become enterprise security&rsquo;s biggest blind spot, as employees wire unsanctioned models and AI tools into corporate data and workflows with no inventory, no data-flow review, and no logging the SOC can see. ThreatDown responded to exactly this surface by extending its visibility to AI tools and machine identities &mdash; an acknowledgment that the asset-management question has quietly changed shape: the thing you now can&rsquo;t see isn&rsquo;t an unmanaged laptop, it&rsquo;s an autonomous process acting with a human&rsquo;s privileges. The practical takeaway for a SOC is that AI adoption has reopened a fundamentals problem the industry thought it had mostly closed. You cannot detect, govern, contain, or attribute what you never inventoried &mdash; so the first move is not a new detection rule but discovery: find the AI tools and agents already running in your environment, map what identities and data they touch, and force them onto governed machine identities before the first incident makes the gap visible for you.<\/p>\n<p>      <a class=\"btn\" href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/21\/report-enterprise-ai-identity-risk\/\">Read the article<\/a><\/p>\n<p style=\"font-size:13px;color:#6b7280;margin-top:6px;\">Sources: <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/21\/report-enterprise-ai-identity-risk\/\" style=\"color:#1d4ed8;text-decoration:none;\">AI agents log in as humans (Help Net Security)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/23\/shadow-ai-security-risks\/\" style=\"color:#1d4ed8;text-decoration:none;\">Shadow AI blind spot (Help Net Security)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/22\/threatdown-ai-visibility\/\" style=\"color:#1d4ed8;text-decoration:none;\">ThreatDown AI visibility (Help Net Security)<\/a><\/p>\n<\/p><\/div>\n<p>    <!-- 3 --><\/p>\n<div class=\"article\">\n<h4>3. Druva Brings Backup, Recovery, and Governance to AI Workloads<\/h4>\n<p class=\"meta\">Help Net Security &middot; July 21, 2026<\/p>\n<p class=\"summary\">The AI visibility gap has a resilience dimension most data-protection programs never scoped, and Druva moved to close it by extending backup, recovery, and governance to AI workloads &mdash; the models, vector stores, training and fine-tuning data, and pipeline artifacts that increasingly sit at the center of a business process but rarely appear in the same backup policy as a file server or a database. The operational point is that AI workloads have quietly become production systems without inheriting production-grade recovery. A corrupted or poisoned vector index, a lost fine-tuning dataset, or a ransomware event that reaches an AI pipeline is not a nuisance if that pipeline is making or informing decisions &mdash; it is a business-continuity failure, and one that traditional endpoint and server backup tooling may not even be capturing. Governance is the second half of Druva&rsquo;s pitch and the more telling one: knowing what AI data exists, where it lives, who and what can touch it, and being able to prove its integrity after an incident is exactly the visibility-and-control problem the rest of this week&rsquo;s stories describe, seen from the recovery side. For SOC and resilience leaders, the prompt is concrete: check whether your AI workloads are actually inside your backup, retention, and recovery-testing scope, or whether they have accumulated as an unprotected tier of production infrastructure &mdash; because the endpoint-recovery lesson elsewhere in this issue applies here too, and mid-incident is the worst possible time to discover a gap.<\/p>\n<p>      <a class=\"btn\" href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/21\/druva-brings-backup-recovery-and-governance-to-ai-workloads\/\">Read the article<\/a><\/p>\n<p style=\"font-size:13px;color:#6b7280;margin-top:6px;\">Sources: <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/21\/druva-brings-backup-recovery-and-governance-to-ai-workloads\/\" style=\"color:#1d4ed8;text-decoration:none;\">Druva AI workloads (Help Net Security)<\/a><\/p>\n<\/p><\/div>\n<p>    <!-- 4 --><\/p>\n<div class=\"article\">\n<h4>4. The AI-SOC Market Consolidates: Cribl Buys CardinalOps, Lumen Adds Cortex XSIAM, and How to Tell a Real AI SOC From a Bolt-On<\/h4>\n<p class=\"meta\">GlobeNewswire, Help Net Security, SiliconANGLE, The Hacker News &middot; July 06&ndash;14, 2026<\/p>\n<p class=\"summary\">The month&rsquo;s market-structure story is consolidation, and this week&rsquo;s foundational reading maps where it is heading. Cribl acquired CardinalOps to pull detection-posture management &mdash; the discipline of measuring and improving how well your detection coverage actually maps to the threats you face &mdash; into its data-pipeline platform, a bet that owning both the telemetry plumbing and the detection-quality layer above it is where durable AI-SOC value sits. Around it, the managed-detection market kept compacting: Lumen folded Palo Alto&rsquo;s Cortex XSIAM into its managed detection and response service, betting customers would rather consume a hyperscaler-grade SIEM\/XDR as a managed outcome than run it themselves; eSentire opened a new U.S. SOC to serve data-residency-sensitive buyers who need their telemetry kept onshore; and CyberProof relaunched its MXDR around agentic AI, claiming to automate roughly two-thirds of investigations &mdash; the same &ldquo;take the volume off the analyst&rdquo; thesis driving the channel plays at the top of this issue. Intezer, meanwhile, moved to let SOC teams automate their own custom security tasks rather than wait for a vendor to ship a playbook. The most useful item for a buyer sitting in the middle of all this is The Hacker News&rsquo;s field guide to evaluating an AI SOC platform in 2026, which lays out six capabilities that separate a genuine autonomous-investigation platform from a legacy tool with an AI feature bolted on the side. Read together, the cluster says the category is now mature enough that the hard part is no longer finding AI-SOC options but telling substance from marketing &mdash; and consolidation means each acquisition also narrows your future best-of-breed choices, so evaluate the platform you are buying into, not just the feature you are buying today.<\/p>\n<p>      <a class=\"btn\" href=\"https:\/\/www.globenewswire.com\/news-release\/2026\/07\/14\/3327113\/0\/en\/cribl-acquires-cardinalops-to-further-expand-its-ai-platform-into-security-operations.html\">Read the article<\/a><\/p>\n<p style=\"font-size:13px;color:#6b7280;margin-top:6px;\">Sources: <a href=\"https:\/\/www.globenewswire.com\/news-release\/2026\/07\/14\/3327113\/0\/en\/cribl-acquires-cardinalops-to-further-expand-its-ai-platform-into-security-operations.html\" style=\"color:#1d4ed8;text-decoration:none;\">Cribl \/ CardinalOps (GlobeNewswire)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/13\/lumen-defender-amdr\/\" style=\"color:#1d4ed8;text-decoration:none;\">Lumen + Cortex XSIAM (Help Net Security)<\/a> &middot; <a href=\"https:\/\/www.esentire.com\/news-releases\/esentire-opens-new-u-s-soc-providing-u-s-data-residency\" style=\"color:#1d4ed8;text-decoration:none;\">eSentire U.S. SOC (eSentire)<\/a> &middot; <a href=\"https:\/\/siliconangle.com\/2026\/07\/07\/cyberproof-launches-agentic-mxdr-automate-two-thirds-investigations\/\" style=\"color:#1d4ed8;text-decoration:none;\">CyberProof agentic MXDR (SiliconANGLE)<\/a> &middot; <a href=\"https:\/\/thehackernews.com\/2026\/07\/how-to-evaluate-ai-soc-platform-in-2026.html\" style=\"color:#1d4ed8;text-decoration:none;\">Evaluating an AI SOC platform (The Hacker News)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/03\/intezer-helps-soc-teams-automate-custom-security-tasks\/\" style=\"color:#1d4ed8;text-decoration:none;\">Intezer custom automation (Help Net Security)<\/a><\/p>\n<\/p><\/div>\n<p>    <!-- 5 --><\/p>\n<div class=\"article\">\n<h4>5. Tracing Backdoored Code Completions Inside AI Assistants &mdash; and the Phishing Benchmark That Names the Wrong Winner<\/h4>\n<p class=\"meta\">Help Net Security &middot; July 20&ndash;24, 2026<\/p>\n<p class=\"summary\">Two research items from the news window aim at parts of the detection surface that don&rsquo;t appear in a product launch. The first is a forensic technique for backdoored code completions in AI assistants: as developers lean on AI coding tools that suggest whole functions, a poisoned or manipulated model can quietly emit subtly malicious completions &mdash; a backdoor, a weakened check, an exfiltration call &mdash; that a hurried reviewer accepts as normal boilerplate. The research offers a way to trace such completions after the fact, treating the AI assistant as a supply-chain component that itself needs provenance and auditability, and giving incident responders a starting point for answering &ldquo;did our AI coding tool introduce this&rdquo; instead of only &ldquo;did a human.&rdquo; For SOCs whose developers now generate code with AI, it is a reminder that the model in the IDE is part of the software supply chain and belongs in the same threat model as any other dependency. The second item is a counterintuitive phishing-simulation benchmark: across the dataset, the best-funded companies opened the most malicious attachments &mdash; a finding that punctures the assumption that budget buys behavior. Money spent on tooling and training does not automatically translate into a workforce that resists a well-crafted lure; if anything, larger and better-resourced organizations may carry more targets, more urgency, and more diffuse accountability. The operational lesson is to measure your own click-and-open rates against realistic simulations rather than assume your spend has bought you resilience, and to treat human susceptibility as an outcome to be verified, not a box the security budget checks on its own.<\/p>\n<p>      <a class=\"btn\" href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/20\/tracing-backdoored-code-completions\/\">Read the article<\/a><\/p>\n<p style=\"font-size:13px;color:#6b7280;margin-top:6px;\">Sources: <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/20\/tracing-backdoored-code-completions\/\" style=\"color:#1d4ed8;text-decoration:none;\">Backdoored code completions forensics (Help Net Security)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/24\/phishing-simulation-benchmark-report\/\" style=\"color:#1d4ed8;text-decoration:none;\">Phishing simulation benchmark (Help Net Security)<\/a><\/p>\n<\/p><\/div>\n<p>    <!-- 6 --><\/p>\n<div class=\"article\">\n<h4>6. The Fundamentals File: SSH After Login, Unprioritized Risk, Endpoint Recovery, Ransomware on the Wire, and the AI Patch Gap<\/h4>\n<p class=\"meta\">Help Net Security &middot; July 02&ndash;03, 2026<\/p>\n<p class=\"summary\">Beneath the automation headlines, five foundational reads keep the SOC honest about the fundamentals that automation is supposed to serve. Research on non-interactive SSH attacks shows that a large share of malicious activity happens after a successful login, delivered through non-interactive command execution rather than a hands-on-keyboard session &mdash; which means authentication-centric monitoring that relaxes once a session is &ldquo;trusted&rdquo; misses the part where the damage is actually done, and post-login command visibility matters as much as guarding the front door. A separate report finds organizations still struggle to prioritize known cyber risks: the problem is rarely a lack of findings and almost always a lack of a defensible way to rank them, so teams drown in a backlog of known-but-unranked exposure while the genuinely urgent items wait in the same queue as the trivial ones. The endpoint-recovery piece describes a gap teams discover at the worst moment &mdash; mid-incident &mdash; when they learn their ability to rebuild and restore endpoints at scale is slower or more fragile than assumed, turning a containable event into a prolonged outage. Detection research on catching ransomware on the wire argues for spotting the encryption behavior in network and shared-storage traffic before it finishes locking the file server, buying the response window that endpoint-only detection often gives up. And reporting on the open-source AI patch gap warns that the fast-moving AI dependency stack &mdash; models, frameworks, and their transitive open-source components &mdash; is accumulating unpatched vulnerabilities faster than most programs track them, extending the same &ldquo;you can&rsquo;t patch what you can&rsquo;t see&rdquo; problem into the AI supply chain. Read together, the five make one point: the automation wave at the top of this issue only pays off if the fundamentals underneath &mdash; identity-aware monitoring, defensible prioritization, tested recovery, behavioral detection, and complete inventory &mdash; are actually in place for it to act on.<\/p>\n<p>      <a class=\"btn\" href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/03\/research-non-interactive-ssh-attacks\/\">Read the article<\/a><\/p>\n<p style=\"font-size:13px;color:#6b7280;margin-top:6px;\">Sources: <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/03\/research-non-interactive-ssh-attacks\/\" style=\"color:#1d4ed8;text-decoration:none;\">Non-interactive SSH attacks (Help Net Security)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/03\/cyber-risk-exposure-report\/\" style=\"color:#1d4ed8;text-decoration:none;\">Prioritizing known risks (Help Net Security)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/02\/matthias-haas-igel-endpoint-recovery-gap\/\" style=\"color:#1d4ed8;text-decoration:none;\">Endpoint recovery gap (Help Net Security)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/02\/shared-storage-ransomware-detection-research\/\" style=\"color:#1d4ed8;text-decoration:none;\">Ransomware on the wire (Help Net Security)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/02\/open-source-ai-patch-gap\/\" style=\"color:#1d4ed8;text-decoration:none;\">Open-source AI patch gap (Help Net Security)<\/a><\/p>\n<\/p><\/div>\n<p>    <!-- 7 --><\/p>\n<div class=\"article\">\n<h4>7. The Exposure Grind: An Emergency Langflow Patch, Triaging Infrastructure Flaws, Oracle&rsquo;s 1,449 Fixes, and Ransomware Hammering VPNs<\/h4>\n<p class=\"meta\">BleepingComputer, The Register, CSO Online &middot; July 22&ndash;24, 2026<\/p>\n<p class=\"summary\">Underneath the AI-SOC launches, the week&rsquo;s vulnerability-and-exposure work was relentless. CISA added an actively exploited Langflow remote-code-execution flaw (CVE-2026-0770) to its Known Exploited Vulnerabilities catalog and gave federal agencies until Friday to patch under BOD 26-04 &mdash; the bug lets an unauthenticated attacker run code as root, KEVIntel logged 220-plus exploitation attempts before the listing, and the same product family&rsquo;s earlier flaws are already being used by the JadePuffer ransomware crew, making this a here-and-now emergency for anyone running the AI-agent builder. Eclypsium&rsquo;s new InfraTrust report reframes the broader triage problem the right way for a SOC: its inaugural pulse tracked 61 infrastructure advisories from 14 vendors and argued admins should prioritize by exploitability, reachability, and exposure &mdash; an internet-facing unauthenticated flaw with a lower CVSS often outranks a higher-scored bug that needs local admin. Oracle, meanwhile, shipped 1,449 patches in a single quarterly Critical Patch Update, a volume that by itself makes the &ldquo;rank, don&rsquo;t chase everything&rdquo; argument for you. And CSO tied the thread to impact: Qilin &mdash; the most active ransomware group in Q2 &mdash; and peers like The Gentlemen and Akira are breaking in through vulnerable edge VPNs and appliances from Palo Alto, Fortinet, Citrix, and Check Point, frequently using stolen credentials against non-MFA&rsquo;d accounts rather than even needing an exploit. The combined operational instruction is unambiguous: treat internet-facing edge devices as hostile territory, patch actively exploited edge and KEV-listed flaws within 24&ndash;48 hours, enforce phishing-resistant MFA on every remote-access path, and rank the backlog by real exploitability and exposure instead of raw CVE counts.<\/p>\n<p>      <a class=\"btn\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/cisa-orders-feds-to-patch-actively-exploited-langflow-rce-flaw\/\">Read the article<\/a><\/p>\n<p style=\"font-size:13px;color:#6b7280;margin-top:6px;\">Sources: <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/cisa-orders-feds-to-patch-actively-exploited-langflow-rce-flaw\/\" style=\"color:#1d4ed8;text-decoration:none;\">CISA Langflow KEV order (BleepingComputer)<\/a> &middot; <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-infratrust-report-reveals-infrastructure-flaws-admins-should-patch-first\/\" style=\"color:#1d4ed8;text-decoration:none;\">Eclypsium InfraTrust report (BleepingComputer)<\/a> &middot; <a href=\"https:\/\/www.theregister.com\/security\/2026\/07\/23\/oracle-drops-1449-security-patches-like-its-the-new-normal\/5277114\" style=\"color:#1d4ed8;text-decoration:none;\">Oracle 1,449 patches (The Register)<\/a> &middot; <a href=\"https:\/\/www.csoonline.com\/article\/4201019\/ransomware-groups-are-hammering-your-vulnerable-vpns.html\" style=\"color:#1d4ed8;text-decoration:none;\">Ransomware hammering VPNs (CSO Online)<\/a><\/p>\n<\/p><\/div>\n<p>    <!-- 8 --><\/p>\n<div class=\"article\">\n<h4>8. The AI Attack Surface Goes Operational: Agent Identities, Autonomous Pentest, an AI Victim-Profiler, and Slopsquatting<\/h4>\n<p class=\"meta\">Infosecurity Magazine, Help Net Security, BleepingComputer, InfoWorld &middot; July 23&ndash;24, 2026<\/p>\n<p class=\"summary\">The AI-visibility theme has a sharper, attacker-facing edge this week. A Sophos AI Security 2026 report named AI identities the enterprise&rsquo;s fastest-growing exposed attack surface: as agents and assistants get privileged access to core systems &mdash; and a cited BeyondTrust figure puts the growth in active enterprise AI agents at 466% year over year &mdash; the OAuth tokens, service credentials, and developer tooling around them become high-value targets, and existing governance was never designed for them. Defensively, Cobalt responded to the same acceleration by launching an AI-driven Autonomous Pentest that delivers expert-reviewed findings in about 24 hours, pushing offensive security from a quarterly engagement toward something continuous enough to keep pace with AI-speed development. On the offensive side, Varonis detailed Dolphin X, a new remote-access trojan whose &ldquo;AI Profiler&rdquo; scores and ranks infected victims so operators can triage straight to the highest-value machines &mdash; AI used not to breach faster but to industrialize the sorting of stolen access, credentials, and crypto. And InfoWorld covered fresh research showing the top LLMs hallucinate the same fake package names &mdash; 127 shared across five frontier models, dozens still unregistered on PyPI and npm &mdash; keeping &ldquo;slopsquatting&rdquo; alive as a supply-chain risk whenever developers paste AI-suggested dependencies without checking they exist. For the SOC the four items converge on one mandate: bring AI into the same operational disciplines as everything else &mdash; govern agent identities like privileged service accounts, test AI-exposed applications continuously, expect adversaries to weaponize AI for targeting and triage, and verify AI-suggested dependencies before they reach a build.<\/p>\n<p>      <a class=\"btn\" href=\"https:\/\/www.infosecurity-magazine.com\/news\/ai-agents-attack-surface\/\">Read the article<\/a><\/p>\n<p style=\"font-size:13px;color:#6b7280;margin-top:6px;\">Sources: <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/ai-agents-attack-surface\/\" style=\"color:#1d4ed8;text-decoration:none;\">AI agents as attack surface (Infosecurity Magazine)<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/23\/cobalt-adds-autonomous-pentest-to-scale-application-security-testing\/\" style=\"color:#1d4ed8;text-decoration:none;\">Cobalt Autonomous Pentest (Help Net Security)<\/a> &middot; <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-dolphin-x-malware-uses-ai-to-rank-high-value-targets\/\" style=\"color:#1d4ed8;text-decoration:none;\">Dolphin X AI Profiler (BleepingComputer)<\/a> &middot; <a href=\"https:\/\/www.infoworld.com\/article\/4200884\/top-ais-invent-same-fake-pypl-and-npm-package-names.html\" style=\"color:#1d4ed8;text-decoration:none;\">LLM slopsquatting (InfoWorld)<\/a><\/p>\n<\/p><\/div>\n<p>    <!-- Watch list --><\/p>\n<div class=\"watchlist\">\n<h2>On our watch list<\/h2>\n<ul>\n<li><strong>Agentic SOC is going to market through the channel.<\/strong> Swimlane packaging an AI SOC for MSSPs and 7AI standing up a partner-first alliance mean the autonomous-SOC buying decision is moving into multi-tenant managed services, where automation isn&rsquo;t optional &mdash; it&rsquo;s the unit economics. If you buy managed detection, press the provider on whether its agent can explain a per-tenant verdict and how a bad automated call is contained across clients.<\/li>\n<li><strong>Your AI tools and agents are the new unmanaged asset.<\/strong> Agents still logging in as humans, shadow AI as the top blind spot, and ThreatDown extending visibility to machine identities all describe one problem: AI is being deployed faster than it&rsquo;s instrumented. Run discovery on the AI tools and agents already in your environment, map the identities and data they touch, and force them onto governed machine identities before an incident does it for you.<\/li>\n<li><strong>Resilience has to cover AI workloads now.<\/strong> Druva extending backup, recovery, and governance to AI workloads is a prompt to check whether your models, vector stores, and pipeline data are actually inside your backup and recovery-testing scope &mdash; or have quietly become an unprotected tier of production. The endpoint-recovery gap this week is the same lesson: mid-incident is the wrong time to find out.<\/li>\n<li><strong>The AI-SOC market is consolidating &mdash; buy the platform, not the feature.<\/strong> Cribl\/CardinalOps, Lumen\/Cortex XSIAM, eSentire&rsquo;s new SOC, and CyberProof&rsquo;s agentic MXDR relaunch mean each deal narrows your future best-of-breed options. Use The Hacker News&rsquo;s six-capability rubric to separate a real autonomous-investigation platform from a bolt-on, and evaluate the roadmap you&rsquo;re locking into.<\/li>\n<li><strong>Don&rsquo;t let automation distract from the fundamentals.<\/strong> Post-login SSH command activity, unprioritized known risk, untested endpoint recovery, ransomware detectable on the wire, and the open-source AI patch gap are where incidents actually start. Verify your click-and-open rates against realistic simulations rather than assuming budget bought resilience &mdash; this week&rsquo;s benchmark found the best-funded companies opened the most malicious attachments.<\/li>\n<li><strong>Edge devices and KEV-listed flaws are the patch priority.<\/strong> CISA&rsquo;s emergency Langflow order, Oracle&rsquo;s 1,449-patch drop, and Qilin ransomware hammering Palo Alto, Fortinet, Citrix, and Check Point VPNs all point one way: patch actively exploited edge and KEV flaws in 24&ndash;48 hours, enforce phishing-resistant MFA on every remote-access path, and rank the backlog by exploitability and exposure &mdash; the Eclypsium InfraTrust approach &mdash; not raw CVSS.<\/li>\n<li><strong>Govern the AI attack surface like any other privileged asset.<\/strong> With Sophos naming agent identities the fastest-growing exposure, Dolphin X using AI to rank victims, and LLMs still hallucinating installable-looking fake packages, treat AI agents as privileged service accounts, test AI-exposed apps continuously (the Cobalt-style autonomous-pentest cadence), and verify AI-suggested dependencies before they reach a build to shut down slopsquatting.<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<p>  <!-- Footer --><\/p>\n<div class=\"footer\">\n<p><strong>Security Operations Weekly<\/strong> &mdash; a weekly intelligence bulletin from Security Radar LLC.<\/p>\n<p>Curated by Paul Davis &middot; paul.davis@security-radar.com. Issue: July 26, 2026.<\/p>\n<p>You are receiving this because you subscribed to Newshunter briefings from Security Radar LLC.<\/p>\n<p>&copy; 2026 Security Radar LLC. All rights reserved.<\/p>\n<p>Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.<\/p>\n<p>*|LIST:ADDRESS|*<\/p>\n<p><a href=\"*|ARCHIVE|*\">View this email in your browser<\/a> &nbsp;&middot;&nbsp; <a href=\"*|UNSUB|*\">Unsubscribe<\/a><\/p>\n<\/p><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Security Radar &middot; Newshunter Security Operations Weekly July 26, 2026 &middot; Weekly Edition Swimlane and 7AI push agentic SOC automation deeper into the MSSP channel, a run of releases and research converges on the same widening gap &mdash; the AI tools, agents, and machine identities the enterprise cannot see &mdash;&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[38],"tags":[],"class_list":["post-5554","post","type-post","status-publish","format-standard","hentry","category-security-operations"],"_links":{"self":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5554","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5554"}],"version-history":[{"count":0,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5554\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5554"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5554"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5554"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}