Resources

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
No items found.
Blog

AI Security: A field guide for cloud security leaders

A field guide for security leaders to cut through AI security noise: a three-part framework for locating any AI risk, understanding who owns it, and finding the gaps in your program before an attacker does.

Lea Edelstein
July 2, 2026
Blog

Five Eyes Cyber Security Agencies Statement: AI will find its way in. The only question left is how prepared your infrastructure was.

The leaders of the Five Eyes cyber security agencies just told all boards the same thing: AI is collapsing the time between vulnerability discovery and exploitation, so stop chasing tools and get the foundations right. We walk through their five practical action items and show how Act handles each one, by shrinking what any attacker or agent can actually reach before the moment it matters.

Hadar Landau
June 30, 2026
Blog

Network and identity each see half your cloud. Your attacker sees both.

Cloud access takes two tests at once, reachability and permission, but enterprises split them across two teams and tools. Your attacker fuses them by default. Here is why that gap is the real problem.

Offir Levy
June 29, 2026
Blog

Five patterns in every cloud. One through-line.

Five problems that show up in almost every cloud environment, from over-powered admins to backups nobody protects to traffic nobody watches leaving. Each one is small on its own. Together they decide how far a single bad day travels.

Kobi Rubin
June 24, 2026
Blog

Your cloud has a new employee. Nobody ran a background check.

AI agents ship with over-permissioned IAM roles and no governance. Here's how to secure the full access chain - model, role, network, identity - before deployment.

Gilad Sharabi
June 18, 2026
Blog

Azure's Shadow Network: The Implicit Paths Your Diagrams Don't Show

Every Azure VNet ships with infrastructure you didn't configure and can't fully see. This is the network that never shows up in your Terraform, your portal, or your CNAPP, and it decides your blast radius long before the first packet moves.

Achia Rosenfeld, Kobi Rubin & Tamir Asfa
June 10, 2026
Blog

Five takeaways from Anthropic's Zero Trust for AI Agents Whitepaper

Anthropic's Zero Trust for AI Agents whitepaper says what we've been saying since day one: the threat is access, not the prompt. Five takeaways that matter most - and where Act fits each one.

Maya Folman Avneri
May 30, 2026
Video

Why connecting a non-deterministic system to production is a bad idea

Giving probabilistic AI systems direct execution privileges in production without strict controls introduces automated uncertainty into your most critical environments.

May 28, 2026
Video

AI agents are shipping with senior engineer access - and zero oversight.

We're handing autonomous AI agents database credentials, API tokens, and deployment privileges without the guardrails needed to control them. It�s the ultimate "move fast and break things" scenario, but the things breaking are your data and security.

May 28, 2026