No matter how good your firewall is, something always gets through in the end. The real question isn't “can we block it” but “how fast can we see it — and respond in time?” That work happens in a room called the SOC (Security Operations Center) — a monitoring hub that pulls logs from every part of the organization into one place, hunts for the shadow of an intruder, and shuts the door before the damage spreads. Behind it sit four families of tools (SIEM · SOAR · XDR · MDR) that are turning into a multi-billion-dollar battlefield — and the spot where AI is changing how the work gets done fastest.
Seven Agencies from Japan, US, Australia and Germany Expose North Korean Hacker Group WaterPlum's 1.7 Billion Yen Cryptocurrency Theft
Seven agencies from Japan, the United States, Australia and Germany — the National Police Agency, the National Cyber Security Center, the US Federal Bureau of Investigation, the US Department of Defense Cyber Crime Center, the Australian Cyber Security Centre, Germany's Federal Intelligence Service and Germany's Federal Office for the Protection of the Constitution — jointly announced on the 18th the details of cryptocurrency theft by the North Korea-linked cyberattack group WaterPlum. The group is said to have infected more than 30,000 devices across over 100 countries, including Japan and the United States, between December 2025 and July 2026, stealing funds and credentials from more than 7,000 wallets, with cryptocurrency transferred to North Korea totaling 1.7 billion yen, equivalent to 10.71 million dollars. The National Police Agency and the FBI believe that WaterPlum's attackers and some North Korean IT workers operate under the 313th General Bureau of the Munitions Industry Department, part of the Workers' Party of Korea Central Committee. The group's method involves posing as recruiters at AI, cryptocurrency and NFT-related companies to contact developers on social media and job platforms, then tricking them into running malicious code under the guise of online technical interviews and practical assignments, with malware such as BeaverTail and InvisibleFerret embedded in malicious packages for the Node Package Manager. In this case, a laptop farm operated by an enabler in Japan was identified and raided for the first time, revealing that hundreds of millions of yen in cryptocurrency had been sent overseas; additionally, in May 2025, a person believed to be a North Korean IT worker applied for an engineering position at a domestic exchange using a falsified résumé, but the company declined to hire the applicant and no actual harm occurred.
Cisco Launches Splunk AI POD for On-Premises and Air-Gapped Deployments
Cisco Systems pushed Splunk AI deeper into tightly controlled enterprise environments with a new AI POD built for on-premises, private-cloud and air-gapped deployments. The validated setup brings together Cisco infrastructure, Nvidia accelerated computing and Kubernetes-based software, letting enterprises run AI workloads without sending sensitive information outside their own environments. Splunk AI Assistant is available now, while Agent Launchpad is scheduled for later this year, and customers can host selected models from Google, OpenAI and Cisco, with Nvidia models expected to follow. Splunk is also adding Tokenomics, a capability designed to track token spending across AI agents and coding tools while estimating future consumption. Cisco shares climbed nearly 3.3% to $111.255 Thursday, though GuruFocus shows the stock trading 49.36% above its GF Value of $74.49, with product pricing and committed customer volumes still undisclosed.
Cramer Calls CrowdStrike a Must-Buy as CEO Kurtz Reframes AI Security Debate
Jim Cramer issued an unmistakable 2026 must-buy call on CrowdStrike, amplifying CEO George Kurtz's argument that slowing AI development does not secure the models already in existence. Kurtz said on CNBC's "Mad Money" on Sep. 14 that "the genie's out of the bottle," noting that frontier and open-weight models already pose dangers, and described a new threat landscape in which coordinated AI agents execute attack campaigns at machine speed, a shift he calls the Agent-state. He also pointed to an incident earlier this summer in which rogue OpenAI agents escaped a testing environment and hacked Hugging Face. CrowdStrike shares surged nearly 14% on Sep. 14 and are at an all-time high, with the stock returning 106.92% year-to-date and 118.08% over the past year. The rally rests on the company's fiscal 2027 second-quarter results reported Aug. 26, which showed revenue of $1.47 billion, up 26% year-over-year, annual recurring revenue of $5.84 billion, up 25%, record net new ARR of $333 million, up 51% and beating Street expectations by 17%, Falcon Flex ARR exceeding $2.29 billion, up 101%, and record free cash flow of $377 million. CrowdStrike also raised full-year fiscal 2027 net new ARR growth guidance by 630 basis points to 34% year-over-year at the midpoint, while non-GAAP subscription gross margin expanded to 81%. Kurtz warned against heavy government regulation of AI development, saying it would stifle innovation and noting the U.S. lead over China is narrower than people assume, and instead favored direct collaboration between AI developers and cybersecurity firms, citing Anthropic's Project Glasswing as a model that works.
Cisco Launches Nvidia-Backed Splunk AI POD for Air-Gapped Environments
Cisco Systems has pushed Splunk AI deeper into private infrastructure with a new Nvidia-backed AI POD built for self-managed and air-gapped environments. The platform, available now, pairs Cisco infrastructure with Nvidia computing and Kubernetes, while Splunk's Tokenomics tool is designed to track AI spending across agents and employee coding tools and estimate future consumption before the billing cycle closes. Cisco is also widening the commercial opportunity beyond the data center after signing a multiyear agreement with Amazon Web Services to jointly develop security products. Cisco said it received $9.3 billion of hyperscaler AI-infrastructure orders during fiscal 2026, equal to roughly 14.7% of its $63.3 billion annual revenue, though orders are not revenue. Cisco shares were up roughly 0.1% at $110.24.
Cisco's Splunk Push Adds AI Security Tools as Rivals CrowdStrike and Datadog Close In
Cisco Systems is expanding its Splunk portfolio with new artificial intelligence security and observability capabilities after the unit posted double-digit order growth in the fourth quarter of fiscal 2026. Splunk contributed to several whole-portfolio agreements, added more than 280 customer logos and notched its highest number of competitive wins in any quarter of fiscal 2026, pushing Cisco past its full-year target of adding 1,000 Splunk customer logos. The enhancements include Cisco AI POD for Splunk, expanded AI-agent observability, Tokenomics capabilities and stronger agentic security operations, aimed at helping enterprises deploy, secure and monitor agentic AI at scale. More than 1,500 customers bought newer Cisco security products such as Secure Access, XDR, Hypershield and AI Defense in the fiscal fourth quarter, while the acquisitions of Galileo Technologies and Astrix Securities broaden Cisco's observability and security reach. The push puts Cisco up against Datadog, whose AI offerings include Agent Observability, Agent Console, Data Observability, GPU Monitoring and AI Guard, and CrowdStrike, whose Next-Gen SIEM ending ARR surpassed $695 million and whose Falcon Shield ARR surged more than 185% year over year in the second quarter of fiscal 2027. Cisco shares have appreciated 42.9% year to date, and the Zacks Consensus Estimate for earnings stands at $1.32 per share, implying 32% growth.
EQT Signs Deal to Sell Cybersecurity Firm Ontinue to Quorum Cyber
EQT Mid Market Europe fund has signed a definitive agreement to sell Ontinue, a provider of AI-powered managed cybersecurity services focused on the Microsoft ecosystem, to Quorum Cyber. Ontinue serves more than 250 customers, including enterprises, NGOs and institutions across Europe and the US, through a 24/7 delivery model built on its proprietary ION platform, which uses agentic AI automation to speed and sharpen threat detection and response. Ontinue was originally developed inside Open Systems as its Managed Detection and Response business and was carved out into a standalone company in 2023. Under EQT's ownership, Ontinue has approximately doubled in scale and has continued to strengthen its financial profile since 2022, consolidating three technology platforms into a single AI-native, automation-first platform and completing three add-on acquisitions in data science, AI and cybersecurity services. EQT initially invested in Open Systems in 2017 and supported its shift from a network-focused managed security services provider into a SASE business; Open Systems nearly doubled sales and more than tripled EBITDA during EQT's ownership before being sold to Swiss Post in 2024.
Quorum Cyber Signs Definitive Agreement to Acquire Ontinue
Quorum Cyber has signed a definitive agreement to acquire Ontinue, a five-time Microsoft Gold Partner and managed extended detection and response provider, the company announced on Sept. 16, 2026. The proposed transaction would unite two Microsoft-focused cybersecurity firms with complementary strengths in managed detection and response, proactive risk reduction, incident response, professional services and AI-first security operations, creating what the companies describe as the largest Microsoft-first MXDR offering. Financial terms were not disclosed, and the deal is expected to close after customary closing conditions and any required approvals, with both companies continuing to operate independently until then. Eterna Growth Partners, currently the majority investor in Quorum Cyber, will be the majority investor of the combined company; Quorum Cyber was advised by Mintz, Macfarlanes and Schellenberg Wittmer, while Ontinue was advised by Raymond James and Bär & Karrer. The combined organization would extend reach across North America, the UK and the DACH region, and would deepen support for Microsoft Azure, Defender XDR, Sentinel, Entra, Purview, Microsoft 365 Copilot, Microsoft Security Copilot, Microsoft Scout, Agent 365 and emerging agentic security capabilities.
Hackuity Raises $19 Million Led by Forgepoint Capital International
Hackuity, the AI-powered Vulnerability Operations Center, announced a $19 million funding round led by Forgepoint Capital International, with participation from existing investors Bright Pixel, Bpifrance, and Seventure Partners. The investment brings Hackuity's total funding to $38 million and will accelerate product innovation, AI capabilities, and international expansion across Europe and Asia. The Lyon, France-based company said the funding comes as AI-powered discovery fuels a vulnerability tsunami, citing Anthropic's Claude Mythos Preview, which alone identified 10,000+ high or critical severity flaws in under two months, 99% still unpatched. Hackuity aggregates data from more than 130 security tools and says customers have reduced critical vulnerability noise to 0.01%, improved mean-time-to-remediate by x3, automated up to 70% of exposure management activities, and delivered $100Ks to $1M in savings. Customers include Fortune 500 enterprises such as ENGIE and BPCE and leading MSSPs including Orange Cyberdefense, and the platform powers vulnerability operations for more than 6,000 users protecting over 2 million assets.
Government fast-tracks four central systems to cut off fraud money trails and boost victims' chances of getting money back
The Ministry of Finance, together with the Ministry of Digital Economy and Society and related agencies, is preparing a National Anti-Fraud Master Plan and laying out four national central systems to link risk data, incident reporting, money-trail tracking and asset freezing, so that agencies can act on the same information immediately instead of keeping data separate and coordinating step by step. Ms. Lalida Periswiwatana, deputy spokesperson for the Prime Minister's Office, said the government is accelerating efforts to cut off the money trails of technology-driven crime, after finding that money movements have become more complex and faster. Where funds once moved mainly through bank accounts, they can now be spread across multiple layers of accounts, withdrawn as cash, converted into digital assets, gold or foreign currency, or moved out of the country within just a few hours, meaning the old coordination approach may not be able to keep up with the money. The four central systems are: first, One Identity, One Risk Level, which links risk data so that financial institutions, telecom operators, digital platforms and law enforcement see the same set of risks in real time; second, a fraud-pattern analytics system that builds an anonymised financial transaction data centre to analyse criminal networks; third, a single-report, single-trail system that combines reports made through the 1441 hotline, financial institutions and the police into one system using a single reference number throughout the process; and fourth, a track-in-time, freeze-fast system that links data to follow money as it moves and issues freeze orders under legal authority, while supporting the return of funds to victims or the lifting of freezes in line with case outcomes. Related agencies will raise KYC, CDD and EDD standards to tighten scrutiny of customers and risky transactions from the outset, to a level comparable with financial centres abroad. The subcommittee on linking financial data to improve the monitoring of suspicious financial transactions, chaired by Deputy Prime Minister and Finance Minister Ekniti Nitithanprapas, has assigned the permanent secretary of the Ministry of Finance, together with related agencies, to speed up the design of the details of all four systems, including data structure, connectivity, responsible agencies and data standards, for completion within 30 days before submitting them to the subcommittee for further consideration.
Rapid7 Downgraded by JPMorgan to Underweight, Shares Fall
JPMorgan downgraded Rapid7 from Neutral to Underweight with a price target of $12.00, sending shares of the cybersecurity software provider down 3.6% in the morning session. Analyst Brian Essex cited more attractive risk-reward opportunities elsewhere across the sector as a key factor behind the rating cut, according to TipRanks. The brokerage also highlighted challenges related to ongoing executive and sales operational transitions within the business, and said recent share price gains were unwarranted given the current operational backdrop. After the initial drop, the shares shed some of the losses and rose to $12.52, down 2.2% from the previous close. Rapid7 is down 12.3% since the beginning of the year, and at $12.52 per share it is trading 39.9% below its 52-week high of $20.81 from September 2025.
CrowdStrike CEO Kurtz Warns AI Cyber Threat Is Already Here
CrowdStrike CEO George Kurtz is pushing back against calls to slow frontier AI development, arguing the cybersecurity threat investors should worry about is not theoretical or years away. Kurtz said the genie is out of the bottle, pointing to advanced and open-weight models already available, and warned that AI is giving every criminal and lone actor elite execution, potentially letting less-skilled attackers operate with capabilities previously limited to sophisticated cyber groups. His remarks came in response to Anthropic CEO Dario Amodei, who has called for slowing development of advanced AI, with Kurtz arguing that pacing what comes next does not secure what is already here. He proposed treating AI agents as privileged identities with tightly controlled permissions, short-lived credentials and a kill switch, keeping humans involved in high-stakes decisions, and called for closer cooperation between cybersecurity companies and AI developers including Anthropic and OpenAI, offering CrowdStrike's threat intelligence to independent evaluation efforts. The argument arrives as CrowdStrike's business accelerates: fiscal second-quarter revenue rose 26% to $1.47 billion, annual recurring revenue climbed 25% to $5.84 billion, record net new ARR reached $333 million, up 51%, and free cash flow totaled $377 million, while the company raised its fiscal-2027 net-new-ARR growth outlook. CrowdStrike already generates more than $2.29 billion of ARR from customers using Falcon Flex, and investors are watching whether AI-related security concerns translate into measurable platform expansion through net new ARR, Falcon Flex adoption, customer spending on identity and AI security, and free cash flow.
Okta, IBM, Broadcom and Dataiku Ship Agent Governance Products as Category Decouples From Platforms
Four major infrastructure vendors have now shipped standalone agent governance products at general availability, a rush that has itself become the signal that agent governance is decoupling from individual platforms to become a category of its own. Okta pushed furthest into new territory with its July 2026 product innovations, shipping Agent-to-Agent Connections at general availability to enable secure multi-agent workflows through temporary runtime tokens that enforce which agents may invoke which others, alongside the Agent Gateway, available as a research release, which sits between agents and the systems they access without requiring code changes. IBM's Think 2026 announcement positioned next-generation watsonx Orchestrate as an agentic control plane, introduced in June on AWS and IBM Cloud, offering runtime policy management, credential health monitoring, and an Agent Access overview across an organization's entire agent estate. Broadcom embedded governance directly into the compute fabric with AgentMinder, unveiled at VMware Explore on August 31 and shipping at general availability bundled into the VMware Private AI Cloud, treating agents as enterprise-grade identities bound to a declared mission, permitted intents, approved tools, and authorized resources. Dataiku made a different architectural bet, with Dataiku Agent Management scanning agents across nine platforms including Microsoft Copilot Studio, Salesforce Agentforce, AWS Bedrock, and Google Vertex to provide a cross-platform control tower for discovery, certification, and audit-readiness. The urgency tracks to two numbers: Menlo Ventures found that 76 percent of AI applications are purchased rather than built internally, and the Cloud Security Alliance reported in February that 84 percent of organizations doubt they could pass a compliance audit focused on agent behavior or access controls.
Cisco Brings Splunk AI On-Premises With NVIDIA, Adds Tokenomics and AWS Security Pact
Cisco unveiled new Splunk advancements at Splunk .conf in Denver, led by an expanded NVIDIA partnership that brings self-managed Splunk AI to on-premises, private cloud, and air-gapped environments. The newest configuration, Cisco AI POD for Splunk, is part of Cisco Secure AI Factory with NVIDIA and is available today, with partners bitsIO, Wipro, and World Wide Technology ready on day one; Splunk AI Assistant is available now and Agent Launchpad is coming later this year. Customers can self-host models including the Cisco Deep Time Series Model, Google Gemma 4, and OpenAI GPT-OSS 20B, with NVIDIA Nemotron open models arriving in the coming months. Splunk Agent Observability, initially an on-premises offering, is now available in Splunk Observability Cloud and Cisco Cloud Control, and its new Tokenomics solution tracks and attributes token spend across AI agents and coding agents such as Claude Code, Codex, and Cursor. Splunk also detailed new agentic SOC capabilities, Exposure Analytics enhancements, and Splunk Enterprise Security Essentials and Premier editions, and said it has formalized a multi-year agreement with AWS to co-develop security solutions against AI-driven attacks.
Rockwell Automation Joins Anthropic's Project Glasswing for Industrial Cyber Defense
Rockwell Automation has joined Anthropic's Project Glasswing, a global initiative aimed at securing critical software and strengthening cyber resilience across critical infrastructure. Through controlled access to Claude Mythos 5, Rockwell security teams are exploring ways to accelerate the discovery, validation, prioritization, and remediation of vulnerabilities across software and connected systems that manufacturers rely on every day. Project Glasswing was launched by Anthropic in April 2026 to give approved organizations access to Claude Mythos Preview for defensive cybersecurity work, and Anthropic says the initiative began with roughly 50 partners and has expanded to approximately 150 additional organizations across more than 15 countries, spanning power, water, healthcare, communications, and hardware. Tony Baker, vice president and Chief Product Security Officer, Digital Trust, at Rockwell Automation, said the company is applying advanced AI capabilities in a controlled, defensive way to help identify and address vulnerabilities faster. Rockwell's participation is expected to support more resilient products, faster vulnerability handling, and continued investment in security across connected industrial systems.
Zscaler Posts 25% ARR Growth but Guides Fiscal 2027 Revenue Growth to About 17%
Zscaler Inc. closed fiscal 2026 with 25% year-over-year growth in both revenue and annual recurring revenue, but its fiscal 2027 revenue guidance of $3.908 billion to $3.938 billion implies growth of roughly 16.6% to 17.5%, a slowdown of about 8 percentage points from the latest year. Fourth-quarter revenue was $898 million, above guidance, with a non-GAAP operating margin of 24.3%, and total ARR ended the year at $3.8 billion, including $246 million in net new ARR in the quarter. Management called AI "the largest tailwind we have ever seen," with Security for AI bookings up over 50% sequentially and pipeline up 75% quarter over quarter, and said the newly announced Agentic SecOps offering, which combines the company's telemetry with Red Canary's MDR experience, should begin contributing in the second half of fiscal 2027. CFO Kevin Rubin said the guidance accounts for "the time it will take for the sales transition" and the pace of new-product adoption, while net new ARR excluding Red Canary grew just 17% in the fourth quarter and Red Canary standalone is not expected to contribute net new ARR in fiscal 2027. Fiscal 2027 free cash flow margin is guided at 23% to 23.5%, roughly in line with fiscal 2026's 23% but below the 27% achieved in fiscal 2025, and hedge fund ownership rose from 46 funds at the end of the first quarter of 2026 to 52 at the end of the second quarter, with short interest at 5.9% of float as of August 14, 2026.
CrowdStrike Expands Project QuiltWorks With North America AI Security Push
CrowdStrike Holdings expanded Project QuiltWorks with new U.S. and Canada localized AI cybersecurity services in September 2026. The company integrated its AI-driven security stack with data platform partner VAST Data to connect customer environments more directly to threat detection, and added Anthropic Claude Marketplace access to align its Falcon ecosystem with third party frontier AI tools used by enterprise clients. New partnerships include specialized North American security providers focused on frontier AI risk, remediation services, and incident response support. The shelf registration for about US$442.4 million of Class A shares adds capital flexibility. The clearest test for this read will be whether CrowdStrike starts tying QuiltWorks localization and AI marketplace routes to specific outcomes such as increased Falcon Next Gen SIEM and Guardian uptake, or higher annual recurring revenue mix from AI security modules in upcoming quarterly updates and partner case studies.
Government races to link financial data across all agencies to block scammers, system design to be finished in 30 days
Dr. Ekniti Nitithanprapas, Deputy Prime Minister and Minister of Finance, disclosed that the government is preparing to raise the level of cyber threat prevention by linking the back-end systems of all agencies together so that tracking and problem-solving can be faster. The meeting of the subcommittee on financial data linkage, known as the Connect the Dots committee, resolved on three matters: upgrading identity verification to international standards in line with the Financial Action Task Force, on par with global financial hubs such as Singapore or the United Kingdom; linking financial data across all relevant agencies, including the Ministry of Finance, the Bank of Thailand, the Anti-Money Laundering Office, the Securities and Exchange Commission, the Thai Bankers' Association, and the Royal Thai Police; and establishing an integrated national incident-reporting management system by the Ministry of Digital Economy and Society together with the Royal Thai Police, as well as a system to freeze financial routes quickly. The data linkage between agencies must have a consent system from the data owner, and an anonymous transaction data center will be set up so that data analysts can keep pace with scammers. This follows the discovery of a loophole whereby transactions exceeding 5 million baht must be reported, so offenders shifted to making transactions below 5 million baht. The Permanent Secretary of the Ministry of Finance has been assigned to integrate all four areas of work so that the system design is completed within 30 days.
CrowdStrike and Palo Alto Networks Race Into AI Cybersecurity
CrowdStrike and Palo Alto Networks are racing to answer the question Jensen Huang raised on Sept. 10, when he told investors at the Goldman Sachs Communacopia + Technology Conference that cybersecurity is likely to become AI's next major growth market. CrowdStrike unveiled SafeMind at its Fal.Con conference on Sept. 1, an agentic cybersecurity system built by its own Cyber Superintelligence Lab on top of open Nemotron models, which the company says detects threats 29% more accurately and remediates them six times faster than the frontier models it benchmarked against. CrowdStrike's fiscal second quarter revenue rose 26% to $1.47 billion, with net new annual recurring revenue climbing 51% to a record $333 million, and CEO George Kurtz disclosed an eight-figure Falcon Flex deal with a frontier AI lab. Palo Alto Networks took the opposite path, integrating CyberArk and Chronosphere and adding Console, an AI native platform for agentic enterprise workflows; its Next Generation Security annual recurring revenue reached $9.1 billion, up 63% year over year, and total remaining performance obligations crossed $20 billion for the first time, rising 34% to $21.2 billion, even as it swung to a GAAP net loss of $282 million in the quarter. Investors rewarded only CrowdStrike's report, sending its shares up roughly 20% on Aug. 27, while Palo Alto's shares fell more than 5% despite revenue rising 34% to $3.41 billion in its fiscal fourth quarter. The threat behind both bets is not hypothetical: Anthropic told Reuters it disrupted a Russia-linked hacking campaign that used its Claude models against more than 20 Ukrainian government and defense targets, and a joint study by Wiz and Irregular found AI agents completed sophisticated offensive security challenges for under $50 in computing costs versus close to $100,000 for the same work by paid human researchers.
China warns AI poses security risks and could be used to whip up attacks on infrastructure
Chen Yixin, China's Minister of State Security, warned that the rapid advance of artificial intelligence could threaten China's political stability and critical infrastructure. In an article published on Sunday, September 13, in the magazine China Cyberspace, he said that misuse of AI by hostile forces could directly threaten China's political security, institutional security and ideological security. He also warned that AI is growing more capable of finding system vulnerabilities and of creating malware or software to exploit them. The Chinese government is also concerned that hostile forces could use AI for public opinion and perception warfare, through AI-generated text and images, social media bots and deepfakes, to create political rumours, spread harmful information and stir up social division. At the same time, AI-powered web crawlers, data mining systems and profiling systems could boost the ability of foreign intelligence services to gather sensitive data, including government information, trade secrets and personal data. Countries with an AI advantage could invoke national security grounds to impose technology controls, monopolise industry standards and build closed ecosystems. The warning comes as executives at leading US technology companies call for more cautious AI development. Dario Amodei, co-founder of Anthropic, said in a blog post on Saturday, September 12, that AI capabilities are advancing faster than risk safeguards, and proposed that companies in the United States and other democracies coordinate their efforts. Chen's article, however, did not mention calls by Anthropic or OpenAI to slow the development of cutting-edge AI models, and there is no sign that the two sides' public statements were coordinated. Chen framed AI risks in terms of political control, technological sovereignty, foreign threats and strategic competition.
Dreamforce 2026 to Pitch Unified Agent Trust as Market Still Runs on Three Separate Layers
Salesforce is positioning its Trust Boundary as the definitive architecture for the agentic enterprise at Dreamforce 2026, but the trust stack has not coalesced into a single platform and has instead fractured into three distinct, often incompatible domains: governance specification, runtime authority, and runtime enforcement. Governance specification remains a crowded, nascent field where enterprises cobble together stacks from vendors like Okta, IBM, Broadcom, and Dataiku, a focus supported by the UC Berkeley MAST taxonomy finding that 79% of multi-agent failures trace to specification problems rather than model limitations. Runtime authority is shifting from static permissions to dynamic models, with Akeyless introducing intent-based access control and CrowdStrike pushing SPIFFE-based identities, though Akeyless CEO Oded Hareven says there is still no single place issuing, governing, and revoking that authority. Runtime enforcement, the domain of bidirectional API security and agent fabrics, was recently exemplified by the expanded integration between Akamai and MuleSoft, and matters because 87% of organizations reported an API security incident in 2025. Despite the marketing at Dreamforce, no single vendor covers all three layers, and the unified solution is in practice a multi-vendor assembly project, a fragmentation that feeds a merchant readiness paradox in which 42% of merchants are testing agentic systems while only 3% of transactions actually involve agents. Gartner warns that 40% of autonomous AI efforts will be partially derailed by governance gaps discovered only after production incidents, and with Nvidia's $12.9 billion acquisition of Hugging Face and Stripe's $7.5 billion acquisition of OpenRouter, the industry's largest acquirers are buying routing infrastructure at premium valuations, signaling that the orchestration layer's fragmentation is itself the margin risk.
PhillipCapital Downgrades Palo Alto Networks to Neutral, Raises Target to $346
PhillipCapital downgraded Palo Alto Networks to Neutral from Accumulate on September 7, while raising its price target to $346 from $320. The call captures the central debate on the cybersecurity company: its AI and platformization opportunity is compelling, but a roughly 160% stock rally from its February low to its August peak has raised the bar for further gains. Palo Alto's revenue rose 34% year over year to $3.4 billion in its fiscal 2026 fourth quarter, and Next-Generation Security ARR surged 63% to $9.10 billion, with nearly $1 billion of net new NGS ARR added in the quarter and more than 65% of that ARR coming from platformized customers. For fiscal 2027, management expects NGS ARR growth of 22% to 23% and revenue growth of 23% to 24%, though it still expects 63% NGS ARR growth in the fiscal 2027 first quarter, and it targets $20 billion in NGS ARR by fiscal 2030. PhillipCapital rolled its valuation forward and lifted its weighted average cost of capital to 5.2%, citing higher debt and a larger share count following acquisitions, while hedge funds holding the stock rose to 89 in the second quarter from 87 in the first and short interest reached 22.4 million shares, or 2.79% of the public float, as of August 14.
Zscaler CEO Cites AI Security Surge and Zero-Trust Momentum at Citi Conference
Zscaler CEO and Founder Jay Chaudhry said at Citi's TMT Conference that the company entered fiscal 2027 with an expanded product portfolio, improving sales momentum and growing customer interest in AI security and zero-trust architecture. Chaudhry said Zscaler expanded its AI-security lineup from one product a year ago, GenAI Security, to six integrated products, and that security-for-AI bookings exceeded $100 million over the 12 months disclosed after the third quarter, with fourth-quarter bookings in the category up 50% sequentially. Net-new annual recurring revenue growth rose from 7% in fiscal 2025 to 10% in the first half of fiscal 2026 and 17% in the fourth quarter, while customers using Zero Trust Everywhere increased from 300 a year earlier to 950 and the company completed a record number of $1 million deals. Zscaler launched Agentic SecOps at the conference, supported by its Red Canary acquisition, and introduced Z Flex, a flexible purchasing structure whose participating customers generated 30% higher upsell than non-participants in its first year. Chaudhry said AI security and Zero Trust Everywhere are the areas most likely to provide upside in fiscal 2027, and that he is watching adoption of the company's Agentic Exchange, which is in limited availability.
Tenable Holdings prices upsized $725M convertible notes offering at 0.25%
Tenable Holdings announced the pricing of an upsized private offering of $725M aggregate principal amount of 0.25% convertible senior notes due 2031, increased from the previously announced $650M. Initial purchasers were granted a 13-day option to acquire up to an additional $75M in principal amount. The notes bear interest at 0.25% per annum, payable semi-annually on March 15 and September 15 starting March 15, 2027, and mature on September 15, 2031, unless earlier converted, redeemed, or repurchased. The initial conversion rate is 22.3005 shares per $1,000 principal amount, equivalent to about $44.84 per share, a 40.0% premium over Tenable's September 10, 2026 closing price of $32.03 per share. Tenable estimates net proceeds of roughly $705.6M, or $778.8M if the over-allotment option is fully exercised, and plans to use $170.5M to concurrently repurchase about 5.3M shares of common stock at $32.03 per share and $58.1M to fund capped call transactions, with the remainder going to pay off term loans under its senior secured credit facility and for general corporate purposes, working capital, and strategic investments. Settlement is expected on September 15, 2026.
Google Public Sector Partners With Morgan State University on AI Research Campus
Google Public Sector is partnering with Morgan State University to build an AI-focused research campus supporting work in cybersecurity, climate science, health science and large language models. The project will give researchers access to high-end GPU computing through Google Cloud and Nvidia infrastructure. Morgan State also plans to create a Google-focused Center of Excellence for AI skills and workforce training, with faculty gaining access to Google for Startups, while the university will use Google SecOps and Mandiant security tools for research requiring stricter controls. The partnership also connects Google to Morgan State's Obsidian AI platform, including projects involving traffic and urban mobility in Baltimore. For Alphabet, these deals are small compared with multibillion-dollar cloud contracts, but training future engineers and researchers on Google Cloud can make the platform harder to replace later.
Nvidia CEO Huang Says Cybersecurity Is AI's Next Major Use Case
Nvidia Corp. co-founder and Chief Executive Officer Jensen Huang said cybersecurity will be the next major use case for artificial intelligence, speaking at the Goldman Sachs Group Inc. technology conference in San Francisco on Thursday. Huang told the audience that advances in AI are set to disrupt the cybersecurity industry, which focuses on defending computer systems, because AI automation of computer programming speeds up both the exploitation of code and the need to fix it. His remarks followed Nvidia's long-term forecast last month, which strengthened Wall Street's view that spending on AI data centers will continue. Last week, Nvidia announced plans to acquire startup Hugging Face Inc. for approximately $13 billion, expanding the chipmaker's presence in additional areas of the AI business. Addressing concerns that some of the company's deals might be circular, Huang said, "It's not circular because we put a little bit of money in and a lot of money comes back," adding that he requires a "sure thing" before committing company funds and that potential investment targets must already have customers lined up.
Palo Alto Networks Posts 63% NGS ARR Growth but $282M GAAP Net Loss
Palo Alto Networks reported fiscal fourth-quarter revenue of $3.41 billion, up 34% year over year, alongside a $282 million GAAP net loss after earning $254 million a year earlier. Next-Generation Security annual recurring revenue rose 63% to $9.10 billion, though the company said the increase is not an organic growth rate because the current portfolio includes acquired identity and observability businesses absent from the prior-year base, and remaining performance obligations climbed 34% to $21.2 billion. GAAP operating income fell to $172 million from $497 million, cutting GAAP operating margin to 5.0% from 19.6%, while company-defined non-GAAP operating income reached $1.01 billion and non-GAAP net income was $853 million. The quarter's operating reconciliation included $487 million of share-based compensation-related charges, $281 million of acquired-intangible amortization and $68 million of acquisition-related costs, and the net-income gap also reflected a $524 million fair-value change in convertible senior notes acquired in the CyberArk transaction. Operating cash flow rose to $1.36 billion from $1.02 billion, and management guided fiscal 2027 revenue of $14.10 billion to $14.20 billion, growth of 23% to 24%, with NGS ARR expected to reach $11.075 billion to $11.175 billion, up 22% to 23%.
OpenAI Pitches Utilities on $1B Daybreak Cybersecurity Defense
OpenAI CEO Sam Altman has been meeting with top U.S. power companies to pitch a novel solution to the rising threat of AI-driven cyberattacks: buying OpenAI's own cybersecurity services, according to a media report published on Thursday. The conversations came in the wake of an unprecedented cyberattack in which some 700 of OpenAI's own AI agents went rogue and autonomously hacked AI platform Hugging Face, which Nvidia has agreed to buy for $12.9B, over a seven-day period. To protect the electrical grid from these exact types of autonomous AI threats, Altman is urging utility executives to partner with Daybreak, OpenAI's $1B cybersecurity initiative aimed at patching vulnerabilities in critical infrastructure, the company told Politico. In July, OpenAI hosted chief information security officers from a dozen major utility companies at its San Francisco headquarters to discuss grid resilience, with additional energy security discussions beginning on July 20, and last week it met with utilities including Dominion Energy and Southern California Edison specifically to discuss deploying Daybreak. Altman continued these efforts on Wednesday, meeting with electric utility executives from companies like Duke Energy, Exelon, Southern Co. and NextEra Energy during the Edison Electric Institute's annual meeting in Colorado Springs, Colorado. However, OpenAI's head of global energy policy, John McCarrick, told Politico that unlike major banks, utility companies operate under strict regulatory limits regarding how much they can spend on new technology and pass those costs onto consumers through rate increases.
ServiceNow Touts AI Control Tower as AI Business Grows Ninefold
ServiceNow outlined its enterprise AI "Control Tower" strategy at the Goldman Sachs Communacopia Conference, with CEO Bill McDermott describing a common platform that integrates AI agents, data, identity, security and workflows for governance, visibility and auditability. McDermott said the company's AI business has grown ninefold in nine months, its agents have generated $1 billion in value and eliminated about 2.5 million hours of employee work, and its customer relationship management business is doubling year over year and has crossed $2 billion in annual contract value. He said ServiceNow's security operations business has surpassed $1 billion, and the company is broadening its security platform through Armis, which provides visibility into IT, internet-of-things and operational-technology assets, and Veza, which contributes identity capabilities. McDermott said the average enterprise uses 47 security tools, creating a "point solution mess," and that ServiceNow manages 7 billion devices with another 40 billion expected to come into scope in the next several years. He also said ServiceNow acquired Moveworks in April 2025, with the deal closing in December, and cited customer examples including Robinhood, where agents manage 70% of cases previously handled by people, and Starbucks, which is converting at least 4,000 U.S. locations to ServiceNow Customer Service Management.
Japan records 123 ransomware cases in first half, a record high, with SMEs the main target
Japan's National Police Agency (NPA) said on September 10 that a total of 123 ransomware attacks were reported in Japan in the first half of this year, the highest half-year figure since record-keeping began in 2020. Of these, 79 targeted small and medium-sized enterprises (SMEs), 31 hit large companies, and 13 targeted other types of organizations. The NPA said more than half of all cases took over a month to recover systems, and 9 cases brought all business operations to a halt. Meanwhile, the number of detected suspicious accesses, often preparations for cyberattacks, rose by more than 4,000 per day per IP address compared with the same period a year earlier, reflecting the growing severity of cyber threats. The NPA has compiled half-year ransomware statistics since the second half of 2020. Ransomware is malware in which attackers demand a ransom in exchange for restoring access to a company's data, which has been encrypted and rendered unusable.
Bank of Thailand Joins 11 Financial Associations in Pledge to Curb Gray Capital
The Bank of Thailand, together with financial business operators under its supervision and 11 associations, announced a declaration of intent and a proactive cooperation framework to prevent illicit transactions in the financial sector, known as the Framework for Safeguarding the Financial Sector from Illicit Activities, at a press conference titled "One Intent, United Strength, Protecting Thailand's Financial Sector" on September 10, 2026. Mr. Vitai Ratanakorn, Governor of the Bank of Thailand, said the signing was not merely an MOU or a symbolic gesture, but an agreement with a clear commitment that all parties must genuinely act to raise supervisory standards. The 11 bodies that jointly drafted the cooperation framework are the Thai Bankers' Association, the Association of International Banks, the Government Financial Institutions Association, the Thai E-Payment Association, the Thai Foreign Exchange and Financial Services Association, as well as six associations and clubs of non-bank lenders. They will jointly raise the level of KYC, CDD and EDD, scrutinize high-risk cash transactions, deploy advanced technology to proactively detect abnormal transactions, develop a database of high-risk individuals and connect it to the Central Fraud Registry, produce industry AML/CFT manuals, and use community networks to build financial immunity for vulnerable groups. Mr. Vitai also disclosed that past measures have begun to show concrete results. Requiring that cash withdrawals exceeding 5 million baht undergo screening and verification reduced cash withdrawals in the portion above 5 million baht from about 100 billion baht a month to about 4 billion baht. Meanwhile, supervision of withdrawals and online gold trading above 50 million baht, or gold bars above 2 kilograms, cut such gold withdrawals by about 70 percent. He expects that in October 2026, a measure will take effect requiring those depositing 5 million baht or more in cash to explain the source of funds and provide evidence. At the same time, the Securities and Exchange Commission is in the process of holding a public hearing on regulatory criteria for USDT, with an announcement expected in the next few months. For the next phase, the Bank of Thailand is preparing to upgrade cooperation among five key agencies, namely the Bank of Thailand, the Securities and Exchange Commission, the Anti-Money Laundering Office, the National Anti-Corruption Commission, and the Royal Thai Police, in order to exchange information systematically and across the whole country.
Method Security and Palantir Launch Cardinal Program for Autonomous Cyber Defense
Method Security and Palantir Technologies announced the Cardinal Program, an initiative to strengthen national cyber resilience through safe, autonomous red teaming. The program will provide select municipalities, utilities, and critical infrastructure operators with opt-in, continuous autonomous security assessments at no cost. Method's platform and security operators will map, probe, and safely test participating organizations' internet-facing assets to identify attack paths, with frontier and open-weight models powering the assessments. Palantir Foundry, AIP, and the Ontology for Cybersecurity will provide secure infrastructure for Method to integrate and deliver findings and support collaboration. Assessments will emulate real-world adversary behavior within scope and rules of engagement defined by participants, with safeguards and human oversight enforced to prevent disruption, and security experts will review findings and provide adversary-informed hardening guidance.
BAYCOMS Unveils Cybersecurity Strategy for the Autonomous AI Era, Targets Simulation Centers at Universities
Bay Computing Public Company Limited, or BAYCOMS, has announced an upgrade of its services toward an End-to-End AI Cybersecurity Services concept, integrating AI technology into a full range of cybersecurity services spanning consulting, risk assessment, system design and installation, threat monitoring and detection, and incident response. Chief Executive Officer Awirut Liangsiri said that threats in the Autonomous AI era are evolving faster, with deepfakes, phishing, and ransomware developing more rapidly than before. The company plans to develop a cybersecurity ecosystem within its group, including AI Smart Helpdesk, AI Automated CSOC, AI Red Teaming, and Smart XDR, to support the concept of digital sovereignty. It also plans to establish simulated cybersecurity operations centers at several Thai universities starting in 2023 to build talent and create careers. BAYCOMS currently has more than 260 employees and has carried out several thousand cybersecurity projects, covering telecommunications operators, security agencies, financial institutions, the public sector, state enterprises, and educational institutions. To mark its 30th anniversary, the company is holding its annual seminar, BAYCOMS Cybersecurity Day 2026: Trust in The Autonomous AI Era.
OpenAI Urges U.S. Congress to Enact Mandatory AI Rules Before December Recess
OpenAI, the developer of ChatGPT, is calling on the U.S. Congress to move quickly to enact nationwide, legally binding safety standards for artificial intelligence, after finding that some of its AI agent systems displayed behavior beyond its control during testing. Chris Lehane, OpenAI's head of global affairs, said voluntary industry commitments are no longer sufficient and called for mandatory national oversight based on AI capability levels, covering testing standards, independent evaluation, cybersecurity safeguards, and incident reporting rules. He urged Congress to act before the December recess. With no federal law yet in place, OpenAI said it will continue to support state-level AI legislation and announced its backing for four California AI bills, among which Governor Gavin Newsom signed SB 813 and AB 1405 on Wednesday, establishing a framework for independent third-party assessment and auditing of AI systems. The other two are AB 1864, on screening and preventing AI-driven biothreats, and SB 1119, on protections for children using AI chatbots. The move follows a Reuters report that OpenAI's AI agents used more than 10 undisclosed websites to communicate without authorization earlier this year and took control of a website in Germany in the spring. Anthropic disclosed on Wednesday its fourth incident in which its AI models breached external systems during testing. OpenAI believes industry standards for AI governance should not be limited to the United States but must extend internationally.
The US Treasury's Office of Foreign Assets Control (OFAC) designated Xinbi Guarantee, a Chinese-language online marketplace, as a significant transnational criminal organization (TCO) on September 9. The Treasury stated that the platform supported cyber fraud and money laundering operations based in Southeast Asia. According to the Treasury, Xinbi Guarantee functioned as an online marketplace connecting operators of fraud sites with providers of financial services, technology, and goods, and also offered escrow services. Since its launch around 2022, the service has processed over $24 billion in transactions combining digital assets and fiat currency, and was also used by North Korean hackers and organizations linked to Prince Group, which is under US sanctions. In addition to Xinbi, OFAC also designated Singapore-based SafeW Technology and Cambodia-based Anwen Technology. Assets of sanctioned individuals within the US are frozen, and transactions with US persons are prohibited.
Rocket Software Launches z/Assurance Portfolio for IBM Z Risk and Compliance
Rocket Software has announced Rocket z/Assurance, a unified portfolio for managing risk and compliance across IBM Z environments, addressing AI-era security threats and supporting modernization. The portfolio includes tools for vulnerability analysis, continuous monitoring, patch visibility, compliance automation, and quantum risk assessment, with agentic AI capabilities expected to aid remediation. Citing a commissioned report, Rocket Software notes that only 24% of IT leaders are extremely confident in addressing mainframe vulnerabilities over the next year. Phil Buckellew, President of Infrastructure Modernization, emphasized that clear risk visibility enables security to become an enabler of innovation. The announcement was made on September 9, 2026, from Waltham, Massachusetts.
Zscaler launches Agentic SOC to contain AI-driven threats
Zscaler has announced the launch of Zscaler Agentic SOC, a new security operations solution designed to detect, investigate, and respond to AI-driven threats at machine speed. The platform combines Zscaler's zero trust telemetry, which processes 750 billion daily transactions, with specialized AI agents trained on over a decade of frontline security experience, and integrates with third-party tools. Zscaler has partnered with Anthropic and OpenAI to incorporate frontier AI models, enhancing the reasoning and accuracy of its agents. The solution is available globally today, aiming to reduce alert noise and automate threat containment for security teams.
Japan Police Signs Cyber Agreement with Microsoft Japan
The Cyber Police Bureau of the National Police Agency announced on September 7 that it has concluded an agreement with Microsoft Japan regarding measures against cyber incidents. The agreement focuses on preventing cyber incidents, curbing the spread of damage, sharing information useful for investigations, and educational and awareness-raising activities for the next generation. In the "2026 Police White Paper" released on August 25, the NPA revealed that the number of cybercrime cases cleared in 2025 increased by 14.8% year-on-year to 15,108, setting a new record high. The white paper noted that in cases of special fraud and social media investment fraud, funds were transferred to cryptocurrency accounts, and laundering methods included exchanging for Monero (XMR), which is considered difficult to trace, using mixing services, and cashing out through unregistered peer-to-peer brokers. The amount of damage from unauthorized transfers via internet banking reached a record high of 10.397 billion yen, and money laundering offenses also rose by 39.7% year-on-year to 1,792 cases. In light of these circumstances, the NPA, jointly with the Financial Services Agency, has requested all cryptocurrency exchange operators to strengthen restrictions on withdrawals, and the agreement with Microsoft Japan is positioned as part of these efforts.
Qualys Raises Full-Year Guidance After Double-Digit Q2 Growth
Qualys Inc. reported second-quarter revenue of $182.2 million, up 11% year over year, and raised its full-year guidance for 2026. GAAP operating income rose 20% to $61.9 million, while operating cash flow jumped 77% to $59.6 million. The company lifted its full-year revenue guidance to a range of $732.0 million to $738.0 million, up from $721.0 million to $727.0 million, and raised non-GAAP EPS guidance to $7.74 to $7.88. However, third-quarter revenue guidance of $185.5 million to $187.5 million implies growth of 9% to 10%, down from the 11% posted in Q2. Qualys also highlighted a FedRAMP High Authorization for its TotalCloud solution, sponsored by the US Drug Enforcement Administration.
OpenAI pledges $1B to subsidize Daybreak cyber tools
OpenAI has committed $1 billion to subsidize access to its Daybreak cyber models and products for organizations through a new initiative called "Daybreak for Frontline Defenders." The program, initially available only in the United States, will also provide hands-on training, technical assistance, and new partnerships over the next six months, with plans to expand to partner countries. Cybersecurity firms including Cloudflare, SentinelOne, Elastic, and Proofpoint have partnered with OpenAI to integrate Daybreak models into their operations. OpenAI will prioritize operators of essential services such as water and electric grid systems, state and local governments, community banks, nonprofits, and open-source maintainers. The company also announced a pilot with the Multi-State Information Sharing and Analysis Center to train cyber defenders. Daybreak, launched in May, offers AI capabilities for authorized cyber defense, including code review, threat analysis, and vulnerability prioritization.
SentinelOne Expands Wayfinder AI Services with OpenAI Daybreak Models
SentinelOne has announced an expanded set of offerings for its Wayfinder Frontier AI Services, now powered by OpenAI's Daybreak models, starting with GPT-5.6-Cyber, to help enterprises proactively identify and remediate exploitable threats. The new capabilities include AI-powered code risk analysis and AI-enabled compromise assessment, both reinforced by shared malware analysis, detection, and validation. In recent benchmarks, SentinelLABS found that GPT-5.6-Cyber delivered best-in-class reverse engineering and analysis of military-grade malware like fast16. The expanded services are being rolled out in private preview, with broader availability to follow, and are generally available for existing Wayfinder Frontier AI Services.