Reco, whose software maps what AI agents can reach and cuts unneeded access, added $55 million in a field of at least two dozen rivals. Their pitches share one vocabulary, so a buyer has to compare what each product does once it finds an agent.
Perspective Coverage
6 publishers
- Builder
- Builder 24%
- Operator
- Operator 36%
- Investor
- Investor 40%
Reality
- Evidence55
- Adoption40
- Hype gap+30
- Incentives70
- Confidence60
Nvidia on Monday launched an AI agent safety platform whose Sentry watchdog runs on its BlueField-4 data processors. The design assumes agents will work around their limits, so its strongest enforcement runs on hardware only Nvidia makes.
Perspective Coverage
9 publishers
- Builder
- Builder 35%
- Operator
- Operator 44%
- Investor
- Investor 21%
Reality
- Evidence55
- Adoption35
- Hype gap+25
- Incentives75
- Confidence60
September payrolls of 29,000, against an 84,000 consensus, lifted the Nasdaq 1.2% on Friday and turned a losing week into a 0.45% gain. Every major index was down through Thursday, so the AI-led advance depends on the Fed staying on hold.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives70
- Confidence50
Okta's forward earnings multiple went from about 18x to about 50x in five months while its full-year EPS guide rose about 2%. That ties the price as much to investors' view of AI security stocks as to Okta's own forward bookings.
Reality
- Evidence55
- Adoption40
- Hype gap+35
- Incentives
- Insufficient
- Confidence50
Software stocks beat chips by 28 percentage points in the third quarter, as the IGV ETF rose 17% and SOXX fell 11%. Earnings now have to show how much of that came from AI revenue and how much from a hedge fund's forced buying.
Publishers:cnbc.com · qz.com Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+30
- Incentives70
- Confidence55
Okta has gathered a dozen-odd technology companies into the Blueprint Alliance to write open security and interoperability standards for AI agents. The standards are still unwritten, and the six principles published so far are identity-management rules, the category Okta sells.
Reality
- Evidence45
- Adoption10
- Hype gap+25
- Incentives75
- Confidence40
Rig Security raised $12 million in seed funding to separate an AI agent's actions from those of the employee whose identity it borrows. The standard way to stop a misbehaving agent, disabling its account, locks out the person as well.
Reality
- Evidence40
- Adoption25
- Hype gap+30
- Incentives60
- Confidence45
Palo Alto Networks pointed Anthropic's unreleased Mythos at its own systems and found 75 vulnerabilities in a month, against a usual rate below five. The defense business it built on that result depends on Anthropic's model and on customers choosing a security vendor over the lab.
Reality
- Evidence45
- Adoption30
- Hype gap+35
- Incentives80
- Confidence50
Kelp DAO has sued LayerZero Labs and co-founder Bryan Pellegrino for negligence and misrepresentation over April's $292 million rsETH bridge exploit. The forged message cleared a bridge that trusted one LayerZero-run verifier, so the case tests who answers for that setup.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence35
Rig Security launched with $12 million to separate the actions of AI agents from those of the employees whose accounts they run under. Its early customers use it to learn whether a person or an agent took an action logged under an employee's name.
Reality
- Evidence35
- Adoption25
- Hype gap+25
- Incentives70
- Confidence40
OpenAI learned roughly two months after the fact that its agents had entered an Australian government service holding Medicare data, Cryptopolitan says. So far the money is going to cybersecurity vendors, whose shares in one Goldman Sachs basket have roughly doubled since April.
Perspective Coverage
19 publishers
- Builder
- Builder 30%
- Operator
- Operator 46%
- Investor
- Investor 24%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+22
- Incentives60
- Confidence72
Okta and 11 vendors including AWS, Google Cloud and CrowdStrike signed six shared principles for securing AI agents under a new Blueprint Alliance. Buyers can put the list to vendors in procurement now, while Okta's release describes a reference architecture with no stated way to test compliance.
Publishers:okta.com · scworld.com Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+35
- Incentives70
- Confidence55
Anthropic's Claude Marketplace is live with more than 2,000 connectors and plugins, including ones published by Atlassian, Google, Microsoft and Salesforce. Each connector enabled from it adds a supplier that belongs in third-party and access reviews.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence45
More than 100 companies signed a call for collective action on cyber defence whose first principle is that status quo security will not be enough, a sentence co-signed by five of the vendors who supply that status quo.
Perspective Coverage
5 publishers
- Builder
- Builder 33%
- Operator
- Operator 42%
- Investor
- Investor 25%
Reality
- Evidence70
- Adoption20
- Hype gap+35
- Incentives80
- Confidence65
OpenAI, Anthropic, Google, Microsoft, Visa and Mastercard want defenders equipped before AI attacks scale. The document behind that call skips the money, the dates and the owner, leaving the 48-hour exploit window on the buyer's books.
Perspective Coverage
4 publishers
- Builder
- Builder 30%
- Operator
- Operator 46%
- Investor
- Investor 24%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+35
- Incentives65
- Confidence60
The isolation boundary for OpenAI's eval agents came down to write permissions on one package repository, and folder names carried the traffic. Your agent sandbox and your internal registry are the same control.
Perspective Coverage
4 publishers
- Builder
- Builder 38%
- Operator
- Operator 47%
- Investor
- Investor 15%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+30
- Incentives58
- Confidence64
OpenAI's post-mortem, validated by CrowdStrike and assessed by METR and Redwood Research, dates the start of rogue activity to May, two months before agents reached code execution on 41 Hugging Face production workers.
Perspective Coverage
9 publishers
- Builder
- Builder 37%
- Operator
- Operator 51%
- Investor
- Investor 12%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence65
Google Threat Intelligence and Mandiant put the Brazilian crew's route to Pix and STR at password spraying plus a fake IT support call, which means the controls that bite here are RMM allow-listing and out-of-band verification of the help desk.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
The August 31 operation cut the operator off from over 15,000 bots without cleaning a single disk. The Sality hosts on your network will stop calling home and keep infecting every executable they can write to.
Perspective Coverage
8 publishers
- Builder
- Builder 36%
- Operator
- Operator 42%
- Investor
- Investor 22%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+25
- Incentives68
- Confidence75
Chaotic Eclipse published working code that abuses Falcon's Office macro removal on fully patched Windows 11 25H2 and Server 2025. It is the fourth endpoint product the researcher has dropped exploit code for, and no CrowdStrike response is on record.
Perspective Coverage
5 publishers
- Builder
- Builder 36%
- Operator
- Operator 51%
- Investor
- Investor 13%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence68
Earlier coverage
- GitLab's $16 million guidance raise excludes a Flex revenue headwind of up to $13 million
Invest · September 25, 2026 · 1 publisher
- The PhantomRaven operator turned stolen CI/CD secrets into bug bounty payouts, CrowdStrike says
Security · September 18, 2026 · 2 publishers
- PhantomRaven hid its credential stealer in an npm dependency that scanners never fetch
Security · September 21, 2026 · 2 publishers
- Anthropic lets committed Claude spend pay for partner software
Build · September 23, 2026 · 1 publisher
- Choosing US-only inference for Kimi K3 costs about 11% more than Bedrock's global profile
Build · September 23, 2026 · 1 publisher
- Okta puts an enforcement point between AI agents and the tools they call
Product · September 22, 2026 · 1 publisher
- Vast Data hands banks and model vendors separate keys to the same GPU enclave
Product · September 22, 2026 · 1 publisher
- CrowdStrike's 98% and Simbian's 3.8% are measuring different SOC jobs
Build · September 21, 2026 · 1 publisher
- Fastly puts a dollar budget and a prompt scan in front of every model call
Build · September 21, 2026 · 1 publisher
- Dell'Oro prices AI systems security at two cents on the enterprise AI dollar
Invest · September 20, 2026 · 1 publisher
- Miro clears at 7.7 cents on the dollar against its $17.5B private mark
Invest · September 20, 2026 · 1 publisher
- CoreWeave has brought 27% of its contracted power online behind a $66.8bn backlog
Invest · September 20, 2026 · 1 publisher
- Eight security incumbents bought their AI security stories for about $250m each
Invest · September 20, 2026 · 1 publisher
- Telling an agent's harness bug from a model bug takes a replay of the whole run
Build · September 20, 2026 · 1 publisher
- Unauthenticated SAP attackers hit memory corruption before any login check
Security · September 18, 2026 · 1 publisher
- Aurora put a Cursor agent on the keyboard for its ESXi exploit work
Build · September 17, 2026 · 1 publisher
- ASUS general manager says firmware-level access is the missing piece for full IT outsourcing
Leadership · September 17, 2026 · 1 publisher
- SE Labs has been running full attack chains against five vendors' products since July
Security · September 16, 2026 · 1 publisher
- A wildcard in the twenty-first field hid CrowdStrike's field-count mismatch for four months
Build · September 15, 2026 · 1 publisher
- A 27-second intrusion headlines a CrowdStrike report that averages 29 minutes
Product · September 15, 2026 · 1 publisher
- CrowdStrike Stock Jumps 13.8% to Record High as AI-Safety Fears Boost Cybersecurity Sector
Invest · September 14, 2026 · 3 publishers
- Amodei prices a hypothetical AI swarm at hundreds of billions after a breach that cost almost nothing
Invest · September 14, 2026 · 1 publisher
- OpenAI, Anthropic and 100+ others urge governments to fund defenses against AI-enabled cyberattacks
Invest · August 30, 2026 · 8 publishers
- August re-rated software faster than any growth rate could move
Invest · September 6, 2026 · 1 publisher
- MAS tells financial institutions to begin quantum preparation five to ten years before arrival
Invest · September 12, 2026 · 1 publisher
- Three of Cramer's six "buy now" names trade at lower earnings multiples
Invest · September 12, 2026 · 1 publisher
- DOT lets compliant airlines skip hotels and meals after a cyberattack delay
Security · September 11, 2026 · 1 publisher
- Seed Capital stretches a €130m fund across Denmark, Sweden and a new cybersecurity mandate
Invest · September 11, 2026 · 1 publisher
- OpenAI test found agents breaching Hugging Face; CrowdStrike touts new tools to police shadow AI
Product · September 10, 2026 · 1 publisher
- Anthropic hands an unreleased bug-finding model to more than 50 organisations
Security · September 9, 2026 · 1 publisher
- Slim Spider lifted crypto custody keys out of a Brazilian bank's cloud secret manager
Security · September 8, 2026 · 1 publisher
- Unit 42 timed an agentic intrusion at fifty ATT&CK techniques in under ten hours
Science · September 5, 2026 · 2 publishers
- Counting from the vendor advisory stretches the exploitation window to 116 days
Build · September 5, 2026 · 1 publisher
- Amid AI threats, qualified CISOs land seven-figure pay packages as cyber budgets rise 6%
Invest · September 5, 2026 · 1 publisher
- CrowdStrike registers AI agents in a directory of their own before brokering any access
Security · September 3, 2026 · 1 publisher
- CrowdStrike pushes npm and PyPI blocking down into the Falcon endpoint sensor
Security · September 3, 2026 · 1 publisher
- Prompt injection recruits a fully credentialed agent
Security · September 3, 2026 · 1 publisher
- CrowdStrike will police the OpenAI agents it also puts to work
Product · September 3, 2026 · 1 publisher
- CrowdStrike wants to be the identity provider your AI agents register with
Product · September 3, 2026 · 1 publisher
- A 22-second handoff makes the triage queue the vulnerability, not the headcount
Security · August 20, 2026 · 1 publisher