I Wrote a Book on AI Logging, Runlayer Sues Rippling, and Cyera Bets $1B
Wiz says Atlas found 200+ unknown vulns, Google reset threat actor naming, and 7AI federated search.
Welcome to The Cybersecurity Pulse (TCP)! I’m Darwin Salazar, Head of Growth at Monad and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! 📧
Hi 👋🏽 Hope you’re having a great week wherever you’re reading from!
Big week over here. After four months mapping what eight AI tools log, miss, and let defenders detect, we published A Security Field Guide to AI Tooling Visibility. The 78-page PDF is free and ungated. We’ll also have free hard copies at Black Hat, or you can request one for U.S. shipping.
To my friends and the TCP ecosystem, if I’ve been late to respond, this is a huge reason why 😅..
Hacker Summer Camp is next week, so I also put together a 2026 Hacker Summer Camp Field Guide with my picks for the talks, side events, Vegas side quests, and where to find me. This will be my eighth one, I’ll be there from Monday through Friday.
We also announced the Monad + Scanner security data architecture, pairing clean logs from 350+ sources upstream with fast search, live detections, and investigations across years of logs downstream. Think modular SecOps for humans and agents, without forcing every byte into a SIEM.
Unfortunately for my free time and sanity, security did not cooperate with a quiet news week. It never does actually. Looking forward to getting back to normal life after Blackhat.
Now, onto the news!
Introducing detections.ai Enterprise - coverage and maintenance handled
A new threat drops and you need to move quickly. Run coverage analysis across your whole detection stack, build detections tuned directly for your environment, and deploy them back. In minutes, not days.
But coverage isn’t a one-time win. Detections drift, IOCs go stale, duplicate rules pile up. Our AI agents catch it while you sleep, so nothing slips through unnoticed and your team spends its time on real threats, not upkeep.
TL;DR ✏️
📚 We launched a book on AI tooling native logs: Our 78-page guide maps eight AI log sources and is free, ungated. Covers all the Claudes, OpenAI, Cursor, Gemini and more.
🧪 Wiz builds an autonomous researcher: Atlas uncovered 200+ unknown flaws and autonomously proved each was exploitable.
🥊 MCP trial becomes lawsuit: Runlayer alleges Rippling cloned its gateway after a nearly year-long enterprise trial.
🧬 Cyera to acquire Oasis for $1B: Cyera signed an LOI to acquire Oasis in a reported billion-dollar deal.
🐝 Every agent gets a keypair: Block’s open-source Buzz gives agents distinct identities and signed audit trails.
🏷️ Google resets the alias map: Google unified its naming systems and gave everyone another alias map to maintain.
Plus: a federated SIEM zig, more runtime agent controls, and more startups out of stealth becuase why not!
📚 Book Launch: What eight AI tools log, what they miss, and what defenders can detect
I haven’t worked as a detection engineer in a few years, but AI tooling gave that part of my brain a fresh batch of logs to pick apart and obsess over
In March, our engineering team began mapping what Claude Code emits over OpenTelemetry. I added the detection lens: What gets logged? How do we collect and normalize it? Which fields map to real TTPs? What should we detect? Where are we blind? That framework became seven more chapters:
Claude Code and Claude Cowork
ChatGPT Enterprise and OpenAI Codex
Cursor and GitHub Copilot
Gemini in Google Workspace and Anthropic’s compliance activity log
At Monad, we work with companies including Robinhood, CoreWeave, Lambda, and Rubrik. Building integrations for these sources exposed the weirdness firsthand: nested OpenTelemetry payloads, inconsistent schemas, short retention, missing identifiers, and logs that prove a tool ran without showing what it did.
Four months later, that work became A Security Field Guide to AI Tooling Visibility, a 78-page map of what each source records, misses, and lets defenders realistically detect.
This book is meant for defenders across the SecOps spectrum from detection engineers to SOC analysts to threat hunters to DFIR pros.
Huge thanks to Matt Jane and Curtis Redgate for kicking off the Claude Code telemetry work, and to Kenneth Kaye and Valerie Worman for contributing and helping get the guide over the line.
The PDF is free and ungated. We’ll have free hard copies at Black Hat, or you can request one for U.S. shipping while supplies last.
⚒️ Picks of the Week ⚒️
Wiz says Atlas found 200+ unknown vulns as cyber AI goes purpose-built
Wiz built Atlas as a multi-agent vulnerability researcher. It maps code with a code property graph, spins up competing exploit hypotheses, has agents argue over exploitability, then builds an execution environment to prove each finding.
Wiz says Atlas found more than 200 previously unknown vulnerabilities across Kubernetes, the Linux kernel, containerd, gVisor, grpc, and dnsmasq. It also tops CyberGym at 90.9%.
Important caveat: CyberGym Level 1 gives the system vulnerable code and a description, so it measures exploit reproduction, not blank-page discovery.
Purpose-built security AI models are spreading up and down the stack (I highlighted this is the way to go last year):
Google lined up Gemini 3.5 Flash Cyber for a limited-access CodeMender pilot.
Microsoft built MAI-Cyber-1-Flash into MDASH.
Cisco already has a Deep Network Model for troubleshooting and automation, and told The Register that more models are headed to Hugging Face.
Models will continue to evolve but the key is in scoping, orchestration, evals, runtime validation, and cost. The harness is what compounds.
Secure AI and the data that powers it with Varonis
AI adoption is outpacing most teams’ ability to secure it. Varonis Atlas is the only platform that secures AI from the moment it’s built to the moment it’s running in production, with the data context that point solutions can’t match.
See Atlas in action during Black Hat USA at Varonis’ booth (#2948). Can’t make it to Vegas? Book a demo today.
Runlayer sues Rippling over an alleged MCP gateway clone
Runlayer sued Rippling in Manhattan federal court, alleging trade secret theft, unfair competition, and breach of contract after a nearly year-long enterprise trial. Wild drama in SDNY.
Runlayer’s complaint alleges that:
The companies signed a mutual NDA and trial agreement barring Rippling from copying Runlayer’s IP or creating derivative works.
Runlayer shared its roadmap, source code, deployment architecture, and engineering support during the trial.
After commercial talks failed and Runlayer cut access in June, an alleged Rippling insider told CEO Andrew Berman that an internal team was building “almost a 1 to 1 copy.”
Rippling confirmed it is launching an MCP gateway but denied using Runlayer IP. None of Runlayer’s claims have been proven yet.
Block gives every agent its own cryptographic identity
Block open sourced Buzz, a self-hostable workspace where humans and agents share channels, repos, and workflows. Every participant gets a keypair, turning messages, patches, approvals, and workflow actions into signed events.
That tackles a real security problem that I think is blowing up in enterprises currently. Agents often inherit a user session or shared service account, making attribution fuzzy when several agents touch the same tools. Buzz gives each agent a distinct identity, scoped access, and its own audit trail.
Signatures prove which key acted, not whether the action was safe or properly authorized.
7AI launches a federated SIEM as the SecOps stack converges
7AI recently launched Federated SIEM, which lets its agents query, investigate, and act across existing SIEMs, data lakes, and cloud platforms without forcing customers through a migration. It also launched 7AI Build, a way for customers and partners to package their own techniques into workflows and services.
That puts 7AI in more direct competition with Vega, Query, and other federated-search players, not just agentic triage startups.
SecOps categories keep folding into each other. SIEMs now ship threat hunting, detection, response, and triage agents. Pipeline vendors are buying detection content vendors. Agent vendors are moving into search.
Everyone wants to be the SecOps platform. Zig. Zag.
Cyera’s reported $1B Oasis LOI joins data security with agent identity
Cyera signed a letter of intent to acquire Oasis Security in a deal reportedly valued at roughly $1 billion. Cyera maps sensitive data and who can reach it. Oasis inventories non-human identities, including service accounts, workloads, and AI agents, then governs their access. Together, they can answer both sides of the agent security problem: what can this identity do, and what data can it touch?
Funding context:
Oasis had raised $195 million in total.
Its latest round was a $120 million Series B led by Craft Ventures, with Cyberstarts, Sequoia Capital, and Accel participating.
Cyera raised a $600 million Series G in June, led by Evolution Equity Partners at a $12 billion valuation.
The market spent years treating data security and identity as adjacent categories. Not any more.
Google standardizes threat names, Google-style
As if the industry needed any more threat group naming conventions 🤦🏽♂️
Google Threat Intelligence Group has begun rolling Mandiant and Threat Analysis Group’s parallel naming systems into two-word cryptonyms. China-linked groups end in CASTLE, Iranian groups in ION, North Korean groups in NEPTUNE, Russian groups in RELIC, and cybercriminal clusters in COMET.
“We’re seeing an uptick in ransomware by NEPTUNE BLizzard Forrest Cozy Fuzzer”
🔮 The Future of Security 🔮
AI Security
Hush raises $30M for agent governance rooted in identity
Hush Security raised a $30 million Series A, with Akamai joining existing investors Battery Ventures and YL Ventures.
Its platform registers AI agents, removes standing credentials, grants scoped just-in-time access at runtime, records each action, and provides a centralized kill switch. Hush started with non-human identity security and is extending that control plane to agents. That is more concrete than another AI inventory dashboard, but the proof will be how broadly it can enforce short-lived access across enterprise apps and agent frameworks.
Cloud Security
Act Security exits stealth with $60M to shrink cloud attack paths
Act Security emerged from stealth with $60 million across a seed led by Team8 and Bessemer Venture Partners and a Series A led by Notable Capital. Hetz Ventures, Claltech, Startpoint Capital, and SVCI also participated. Founded by the team behind Medigate, Act maps cloud access paths and enforces boundaries around what humans, workloads, and AI agents can reach. It does not patch the vulnerabilities. The “root cause of every breach” pitch runs hot, but shrinking attack paths is saner than treating every CVE like a fire drill.
Data Security
Cyberhaven Flow follows data through human and agent workflows
Cyberhaven took the wraps off Flow, now in early access with broader availability expected in the coming quarter. It connects data lineage, identity, and behavior across endpoints, browsers, and cloud services as humans and agents touch sensitive data. It captures prompts, tool calls, file reads, and responses, then carries classification and data loss prevention policy forward as content gets copied, split up, or transformed. Embedded agents help with configuration, detection, and analysis. Preserving context through the workflow is the useful part. The question is how much lineage survives once agents hop across vendors, clouds, and private systems.
Email Security
AegisAI raises $36M to fight AI-generated spear phishing
AegisAI raised a $36 million Series A led by Battery Ventures, with Accel and Foundation Capital participating. Founded by former Google security leaders Cy Khormaee and Ryan Luo, the startup uses its own language models and a fleet of agents to inspect email intent, identity, links, attachments, QR codes, and behavioral signals. It is also pushing Vanguard, a threat-hunting agent that looks beyond the inbox.
Identity and Access Management
Saviynt brings runtime authorization to AI identities
Saviynt is pushing agent governance into the runtime with Zuma. The platform discovers AI agents and non-human identities, maps owners and permissions, and governs their lifecycle. Zuma Access evaluates each action using identity, context, risk, policy, and stated intent; Zuma Governance handles access reviews, audit trails, ownership, and containment.
Security Operations
Fig brings CI/CD mechanics to detection engineering
Fig is bringing a software-engineering workflow to detections, parsers, and configuration changes. Its security data lineage graph maps dependencies across the stack, then lets teams simulate changes against the live environment before deployment. Changes can be tested, versioned, rolled back, and continuously checked for broken detection flows.
Fig calls it the first true CI/CD for SecOps.
Interested in sponsoring TCP?
Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries 🌎
Bye for now 👋🏽
That’s all for this week… ¡Nos vemos la próxima semana!
Disclaimer
The insights, opinions, and analyses shared in The Cybersecurity Pulse are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.






