#security
Agent incidents, sandboxes, auth and supply-chain risk.
OPSWAT released its AI Inspector at GISEC 2026, scanning incoming files to block hidden prompt injection attacks before data ingestion. Scan and sanitize all incoming files before adding data to search databases.
The EU has begun reviewing Cybersecurity Act 2.0, banning tech that uses parts from high-risk vendors across all supply tiers. Relying on the primary vendor alone fails when sub-chips are unvetted. Companies must audit every component, down to the raw circuit board.
Unit 42 confirmed an attacker used frontier AI to shrink a two‑week corporate network breach to ten hours. Human security teams cannot match automated attack scripts. Defense systems must revoke user tokens and isolate machines within seconds.
Google Cloud launched purpose-built governed enterprise platforms with deterministic citation verification. Unconstrained general models hallucinate citations and run up token bills. Governed domain tools enforce exact document references and fixed costs for legal workflows.
Automated security tools now find external code vulnerabilities, write tests, and submit patches in 4 hours instead of the standard 60-day manual cycle. Connecting scanners directly to code repositories fixes exposed flaws before attackers exploit them.
Get tomorrow's 5 takes in your inbox