TLDR IT 2026-03-26
Agentic security takes over π€, LiteLLM gets hit π¨, Big Tech loses in court βοΈ
Cisco goes all in on agentic AI security (8 minute read)
Cisco launched Duo Agentic Identity and the open-source DefenseClaw framework to secure autonomous AI agents. New tools include AI Defense: Explorer Edition for red teaming and Splunk ES updates for SOC automation. These capabilities allow enterprises to monitor agent activity and enforce least-privilege access across complex AI workloads.
TeamPCP software supply chain attack spreads to LiteLLM (3 minute read)
The TeamPCP supply chain attack has expanded from security tools like Checkmarx and Trivy to the AI ecosystem, compromising the popular Python library LiteLLM. Attackers used stolen credentials to poison PyPI versions 1.82.7 and 1.82.8 with an infostealer designed to harvest cloud secrets, SSH keys, and Kubernetes tokens. Developers are urged to pin their dependencies to version 1.82.6 or earlier and rotate all environment credentials immediately.
MCP Governance: Everyone's Launching It, Few Actually Understand It (5 minute read)
At RSAC, at least six vendors announced MCP governance capabilitiesβbut most aren't actually parsing or enforcing the protocol at a meaningful level. The result: βAI securityβ is being shipped as a checkbox feature while the underlying control layer (how agents interact with tools/data) remains largely unprotected, leaving real gaps like prompt injection and agent supply chain attacks.
How does SecOps feel about AI? Excessive agency (6 minute read)
Security teams are increasingly anxious over "excessive agency," with mentions of AI taking unauthorized actions jumping 1,300% in late 2025. Beyond high-profile accidents like agents deleting databases, practitioners are wary of "AI slop" and insecure code generation that expands an enterprise's attack surface. To counter these risks, SecOps is pivoting toward automated AI red teaming to keep pace with LLM-powered attackers.
AI bubble or build cycle? (6 minute read)
Enterprises should treat AI strategy like a resilience exercise, not a hype bet: keep ROI discipline, diversify vendors, and avoid overcommitting too early. That is a useful frame for IT orgs right now, especially as boards push for AI progress before governance models are mature.
π€
Launches & Partnerships
Enterprise AI agents that won't cause IT nightmares (Sponsor)
LifeMD, BAE Systems, and Nubank use
StackAI to build AI agents that automate time-consuming processes. Loved by IT teams for granular RBAC, delegated permissions, SSO, and 100+ secure prebuilt integrations. White-glove support from AI experts gets CIOs the fastest time to value with AI.
Book a free strategy session today.CrowdStrike Adds Microsoft Defender Support to Falcon SIEM (3 minute read)
CrowdStrike's Falcon Next-Gen SIEM now ingests and analyzes Microsoft Defender for Endpoint data, allowing customers to keep Defender while centralizing detection and response in Falcon. Vendors are now embracing competitor tooling as data sources, accelerating the move toward unified security platforms instead of rip-and-replace strategies.
Introducing Wiz Agents & Workflows: Security at the Speed of AI (7 minute read)
Wiz launched Red, Blue, and Green AI agents to automate offensive testing, threat investigation, and remediation. Integrated with the Wiz Security Graph and new Agentic Workflows, these tools orchestrate autonomous responses. This framework reduces MTTR from hours to minutes by eliminating manual security bottlenecks.
US FCC Bans Imports of Certain Foreign-Made Routers (2 minute read)
The FCC has moved to ban imports of select foreign-made routers, potentially impacting vendors like TP-Link, Netgear, and Asus. For IT teams, this could disrupt procurement and force re-evaluation of network refresh plans, vendor choices, and supply chain dependencies.
90% of Orgs Pressuring Security to Loosen Identity Controls for AI (2 minute read)
New research shows 90% of organizations are pushing security teams to relax identity controls to accelerate AI adoption, while nearly half admit governance is still immature. AI rollout is outpacing identity controls, creating risk in non-human identities and access pathways most teams can't fully see or manage yet.
Channel partners are sleepwalking into an AI code generation trap (5 minute read)
Managed Service Providers face double exposure when recommending AI code tools. With hallucination rates reaching 48% in models like o4-mini, nearly half of generated snippets contain vulnerabilities. MSPs must implement AI governance and CI/CD scanning to protect clients and differentiate their service offerings.
Meta, Google lose US case over social media harm to kids (4 minute read)
A Los Angeles jury found Meta and Google liable in a landmark social media addiction case involving harm to a minor. For IT leaders, the broader takeaway is that digital product design, engagement mechanics, and safety guardrails are facing sharper legal scrutiny, which could raise the stakes for governance and compliance teams.
Curated news ποΈ and trends π in IT strategy π», information security π, and cloud computing βοΈ.
Join 587,000 readers for
one daily email