Welcome to The Cybersecurity Pulse (TCP)! I’m Darwin Salazar, Head of Growth at Monad and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weekly updates! 📧
Howdy 👋🏽
Last issue of September already… bananas! Before we get into it, three things for my East Coast folks:
I’m speaking at BSides NYC on October 17 about native logging and detection opportunities in Claude Code, Codex, Cursor, and other AI tooling.
BSides NYC is ‘pay what you can’ this year. Grab a ticket, chip in what works for you, and come hang with the NYC security community! Big kudos to the organizers! ❤️🔥
The night before, TCP, Monad, Scanner and friends are hosting The Roaring Twenties, a Gatsby-themed evening in Midtown from 6–9 p.m. on October 16. Request an invite if you’ll be around. I’ll probably be DJ’ng a bit so would love to see you there!
🎁 Also, our partner Fencer is giving away two free pentests each week through November 1. TCP readers can enter at the link.
😬 Meme of the Week
Look, I’m a loyal Delta SkyMiles member but this is a pretty accurate, timely and brutal burn. Excellent roast EQ and form from Elon here. Credit where credit is due.
🗞️ TL;DR
🧱 NVIDIA limits AI agents: New software and hardware controls restrict the files, tools, and networks agents can access.
🧩 Microsoft adds SIEM features: Defender’s ISOC preview adds case management, automation, and third-party log ingestion for eligible customers.
🪤 ShinyHunters targets unpatched PeopleSoft: Attackers bypassed WAF rules; Dutch police separately announced an arrest linked to the group.
🪵 CriblCon brings two announcements: Cribl officially enters SIEM space; StreamAI will add model routing, budgets, and data controls.
🗑️ Azure attack deletes storage: Microsoft reports 100-plus deletion attempts at one unnamed customer; most targeted accounts were deleted.
💬 ZeroDrift checks AI messages: Anchor 3.0 checks communications against company policies and regulatory rules before delivery.
💰 Island raises another $400M: Its Series F funds expansion beyond browsers into endpoint, network, and AI security.
💸 Reco adds fresh funding: The $55M round supports its expansion from SaaS security into AI agent security.
Plus: prompt injections that spread, a shutdown lifted, and a startup tackling shared employee-agent identities.
The Path to Complete Log Visibility
Most security teams can afford to monitor only about 10% of their telemetry in a SIEM, and attackers are finding their way through the rest.
Scanner CEO Cliff Crosland calls it federated indexing: read every log once, wherever it lives, and index it all in one place. Learn how it works, how it compares to data lakes and federated search, and what it takes to monitor 100% of your logs.
⚒️ Picks of the Week
NVIDIA launches controls to restrict AI agents
NVIDIA’s new Open Agent Safety Platform pairs software that restricts AI agents with a reference design for hardware that can stop them.
OpenShell runs agents in sandboxes and restricts access to files, networks, tools, processes, and credentials. It is open source and available now. NVIDIA says the runtime can be extended to third-party CPUs; the separate hardware monitoring layer depends on BlueField.
Sentry, the optional hardware layer, runs on BlueField-4 DPUs, separate from the agent’s host. NVIDIA’s reference design places it between the agent and its model, where it can monitor activity and cut access.
I guess NVIDIA got tired of the sandbox breakout theater we’ve been living in 🤷🏽♂️
Cribl announces a SIEM and AI gateway at CriblCon
Cribl announced Detect, its own SIEM, and StreamAI, an AI gateway, at this week’s CriblCon.
Detect runs detections in data pipelines, searches existing data stores, and adds AI-assisted triage and response. It’s available now for Cribl.Cloud customers. This is the roll-up from their CardinalOps and recent AI SOC acquisitions.
StreamAI will route model requests, enforce budgets, etc. It’s coming soon.
Cribl now competes with the SIEM vendors its pipelines feed and is entering the AI observability space.
Microsoft adds SIEM features to Defender
Microsoft launched the ISOC preview in Defender, adding case management, automation, and SIEM capabilities in one portal.
The preview is limited to eligible Defender Suite, Microsoft 365 E5, and E7 customers without an active Sentinel workspace. Microsoft warns against disconnecting a production Sentinel workspace to qualify (lol).
Case management, workbooks, and natural-language playbook generation work without creating an ISOC workspace. Third-party ingestion and UEBA require one.
The appeal is fewer handoffs between finding a threat and stopping it. Microsoft is bringing more of that workflow into tools its customers already pay for. Even outside Microsoft environments, that puts pressure on standalone SIEM and automation vendors to show what their extra cost buys. The real test is how well the integrated experience works across a customer’s full stack.
ShinyHunters bypasses PeopleSoft defenses; Dutch police announce an arrest

Mandiant found ShinyHunters exploiting unpatched Oracle PeopleSoft servers by changing /PSEMHUB/ to /%50SEMHUB/. That encoded character bypassed WAF rules. The WAF checked the URL before decoding; PeopleSoft decoded it and served the vulnerable endpoint. Researchers found web shells on dozens of systems.
Oracle patched CVE-2026-35273 on June 10. These organizations had blocked the endpoint but left the vulnerable software running.
ShinyHunters also claims it used PeopleSoft to access FBI data. Reuters couldn’t corroborate that claim, and the FBI says the entry point remains undetermined.
Separately, Dutch police announced the September 15 arrest of a 24-year-old Amsterdam man suspected of involvement in ShinyHunters. They did not link him to either intrusion.
JADEPUFFER uses stolen Azure credentials to delete customer cloud resources
Microsoft says JADEPUFFER, tracked as Storm-3168, compromised two service principals at one unnamed Azure customer in June.
The attacker made 100-plus storage-account deletion attempts in roughly seven minutes. Most targeted accounts were deleted. Resource locks and deletion protection blocked some attempts; an unsupported API version stopped the SQL deletions.
Microsoft observed credential collection but did not confirm data exfiltration or observe a ransom note. A service-principal secret had appeared in a public GitHub issue, but Microsoft could not confirm that as the entry point.
🔬 Threats & Research
OpenAI agent bypassed internet restrictions through DNS
OpenAI says a research agent used its sandbox’s DNS resolver to contact an external chatbot after direct web access failed. Monitoring flagged the September 20 incident within 15 minutes, but the automatic stop failed. A person began reviewing the alert; the run continued for another 2.5 hours before it was stopped manually.
OpenAI has since added two layers of blocking.
Attackers exploit NetScaler gateways to reach internal networks
Mandiant found attackers exploiting Citrix NetScaler to gain root access, install backdoors, and tunnel into internal networks for reconnaissance and credential theft. The campaign has been active since at least early September.
NetScaler often handles remote access to internal applications, making a compromised gateway a useful entry point. Citrix has patched two actively exploited flaws, CVE-2026-88771 and CVE-2026-88772.
Great work from the Mandiant team on this one. The report includes practical hunting guidance and detection ideas to help defenders look for this activity in their own environments.
Prompt injections spread through agents’ outgoing messages
OpenAI demonstrated prompt injections that trick agents into copying malicious instructions into outgoing emails, files, and code comments. Another agent can then read those instructions and repeat the attack.
CISA ends its weekly vulnerability bulletin
CISA ended its weekly Vulnerability Bulletin on September 28. It directs readers to KEV, advisories, and vendor notices. Email subscribers need to select replacement topics in their subscription preferences.
📦 Security Product Releases
ZeroDrift releases Anchor 3.0 to check AI communications
ZeroDrift released Anchor 3.0, three small language models that check AI communications against regulatory and company rules before delivery. The flagship model identifies offending lines and rewrites them.
Checking messages before they leave gives teams a chance to catch policy violations before an agent speaks for the business. The rewrite needs scrutiny too: removing a prohibited claim shouldn’t change what the customer was actually told.
Vega II adds investigation memory and a telemetry gateway
Vega announced Vega II with an open-weight cyber-defense model, Vega Memory to retain environment details and past investigation decisions, and Vega Gateway to send telemetry into object storage through OpenTelemetry, webhooks, or APIs. Analysts can inspect saved memory, trace it to the original case, and correct or delete it.
Memory can save analysts from repeating work, but it also carries old verdicts into new cases. Correcting a bad conclusion needs to include the saved memory that future investigations will use.
📚 Worth a Read · From this week’s sponsor
What is federated indexing? Scanner breaks down how indexing logs in object storage differs from querying each source live, and what that changes for search and continuous detection.
🤝 Funding & M&A
Island raises $400M to expand beyond the browser
Island raised a $400M Series F, led by Evolution Equity Partners.
The round values it at $6.4B. Island plans to expand beyond its enterprise browser into endpoint, network, data, and AI-agent security.
The browser gives Island control over work happening inside it. Winning more security budget means following that work into APIs, background agents, and other activity that never opens a browser tab.
Reco raises $55M for SaaS and AI agent security
Reco raised $55M in additional funding, with AT&T Ventures, Forestay, and Quadrille Capital participating. AT&T is also a customer. Reco maps AI agents to their identities, permissions, applications, and workflows, with controls to reduce access or disable risky integrations.
SaaS security vendors already track the app connections and permissions agents use. The harder problem is spotting an agent doing something harmful with access it was legitimately given.
Rig raises $12M to distinguish AI agents from employees
Rig Security emerged from stealth with $12M in seed funding, co-led by Ten Eleven Ventures and Brightmind Partners, with the CrowdStrike Falcon Fund participating. Its endpoint sensor identifies AI agent activity inside employee sessions. Rig says it can block risky agent actions without interrupting the employee.
eSentire acquires an AI security startup and launches Atlas AIDR
eSentire acquired an unnamed AI security startup and added its technology to Atlas AIDR, now generally available. Announced September 15, the module records AI sessions and tool calls, inventories MCP servers, and adds PII redaction and prompt-injection screening.
Its browser coverage uses existing telemetry for visibility; granular inline controls sit on the desktop. MDR buyers should separate those capabilities when comparing products. Seeing browser activity doesn’t mean a product can block it.
Interested in sponsoring TCP?
Sponsoring TCP not only helps me continue to bring you the latest in security innovation, but it also connects you to a dedicated audience of 20,000+ CISOs, practitioners, founders, and investors across 135+ countries 🌎
Disclaimer
The insights, opinions, and analyses shared in The Cybersecurity Pulse are my own and do not represent the views or positions of my employer or any affiliated organizations. This newsletter is for informational purposes only and should not be construed as financial, legal, security, or investment advice.








