Year: 2026

The critical mcp-remote RCE (CVE-2025-6514, CVSS 9.6) exposes how AI clients over-trust MCP servers — see what identity-first Zero Trust reachability would...
This week: an 800-CVE Oracle patch day, an unauthenticated AI platform RCE, and what identity-first reachability would have stopped....
The EU AI Act, governance sprawl, and stalled AI ROI have turned AI oversight into a board-level duty. See what executives need...
New survey of 200 CISOs and CTOs shows infrastructure vulnerability concerns are highest among the people building AI platforms, not securing them....
NetFoundry's Reachability Watch tracks new network CVEs and actively exploited KEVs every two weeks — see what identity-first reachability would have stopped....

At A Glance For the past few years, non-human identity has been the kind of problem security teams acknowledged in a slide...

New survey data reveals why 69% of security leaders are least confident securing machine workloads, nearly 10x the concern for human users....

Picture an infant standing at the top of a long, steep staircase. She’s curious, mobile, and has absolutely no concept of what...

100% of CISOs and CTOs Say AI Is Expanding Their Attack Surface — and Securing Machine-to-Machine Connectivity Is Now Their Biggest Blind...

New survey of 200 CISOs and CTOs reveals why AI deployments stall in security review — and what the delay is costing...
NetFoundry makes mutual TLS (mTLS) automatic and effortless — no PKI to build, no certificates to manage, no code to rewrite. See...
Zero Trust Security means never trust, always verify. Learn the 5 pillars (identity, device trust, microsegmentation, least privilege, and encryption) and how...
AI workloads are dismantling the assumptions IT, OT, and defense networks are based on: controlled boundaries....
Firewall rules were designed for a world where connections came from known IP addresses, operated by humans, on predictable schedules. AI agents...
How network and security architects can secure MCP servers with Zero Trust: eliminate public exposure, bind agent identity, and govern every session....

Here’s a thought experiment. You’ve deployed a WAF. You have an API gateway with rate limiting. You have DDoS protection. You’ve tuned...