Google added six new safeguards to Android 17's Advanced Protection mode, including Intrusion Logging — which stores tamper-resistant security and network event logs off-device for up to 12 months — plus restrictions limiting Accessibility Service access to verified apps, USB data-blocking against juice-jacking, and a lockout after repeated failed authentication attempts.
Source →SOLUTIONS
New products, tools, and vendor releases.
DeepKeep launched AI Lens for Developers, giving security teams visibility into AI coding agents like Cursor and Claude Code: it flags credentials and secrets that leak through prompts or attached files, catches insecure code patterns such as missing authentication checks, and routes destructive commands for human approval before they run. Support for GitHub Copilot, OpenAI Codex, and other tools is coming.
Source →Exabeam's October LogRhythm SIEM release adds a community MCP server that connects local generative AI models to LogRhythm data, letting self-hosted teams query, investigate, and triage alerts with AI without sending sensitive data to the cloud. The release also migrates LogRhythm's backend from Elasticsearch to OpenSearch in place, and adds AI-usage monitoring collectors for tools like ChatGPT, Gemini, and GitHub Copilot.
Source →Google launched Gemini 4 Argon, giving trusted cyber defenders — via its Fairwind Program for governments, healthcare providers, and telecoms — guardrail-free access to the model's frontier-level vulnerability-finding capabilities, which Google says it trained to autonomously find, validate, and patch critical software flaws. Google says the model already found a critical vulnerability in hospital software used worldwide.
Source →Nvidia launched the Open Agent Safety Platform, pairing OpenShell — an open-source runtime that sandboxes AI agents and enforces policy — with Sentry, a hardware watchdog running on Nvidia's BlueField-4 DPUs that can quarantine a misbehaving agent within milliseconds. More than 100 companies, including Anthropic, Cisco, CrowdStrike, Microsoft, and Palo Alto Networks, are participating.
Source →Signal rolled out encrypted local backups to iOS and desktop with Signal for iOS 8.30, letting users store an encrypted copy wherever they choose — an external drive or home server — and restore it across Android, iOS, Linux, macOS, and Windows. Media is now stored separately from the main archive and deduplicated to cut backup size.
Source →Postman launched Fabric Gateway, a protocol-agnostic control plane that lets security and platform teams enforce least-privilege, policy-driven access for AI agents calling APIs, CLIs, MCP servers, and other agents through a single interface — regardless of whether the underlying protocol is HTTP, gRPC, MCP, or A2A.
Source →Palo Alto Networks joined Nvidia's Open Agent Safety Platform initiative, planning to run its Prisma AIRS AI Gateway on Nvidia Vera CPU-based systems to centrally govern what AI agents can access, inspect their interactions, strip sensitive data, and track usage — alongside runtime protection and agent-identity security built on its IDIRA technology.
Source →