News – July 31, 2026

News for today:

  • [Okta] Permiso Security to Okta. Okta announced the acquisition of Permiso Security, for its detection and mitigation smarts in multi-cloud environments. Permiso provides security teams with the tools to discover, protect, and respond to threats across every identity, using more than 2,500 research-driven signals across 70+ identity partners, such as overprivileged access, unused permissions, anomalous agent behavior and tool usage, policy violations, and high blast radius behavior, in real time. Once integrated with Okta’s identity security fabric, these capabilities will help organizations mitigate critical operational blind spots by extending advanced runtime detection and response across all identity types. Okta
  • [MIND] DLP agents – AI-powered. MIND announced its AI DLP Agents, for AI-powered DLP operations. Instead of requiring security teams to operate DLP day-to-day, the MIND AI DLP Agents perform the work that has traditionally consumed data security programs. They work alongside security teams as a force multiplier, increasing their effectiveness and scalability while freeing them to focus on reducing risk and enabling both business and innovation. The MIND AI DLP Agents specialize in the most time-consuming work our customers identified: classification, policy production, issue investigation, and remediation, among others. The agents are available via AI clients due to MIND’s MCP interface. MIND
  • [Pentera] AI-native web app pentesting. Pentera added new AI-native web app pentesting capabilities to its platform, for finding and proving exploitable risk before attackers do. Fueling Pentera’s AI-native attack agents is a decade of offensive research and real attack data from thousands of enterprise environments. The data turns into learned attack skills. At runtime the agents do their own reconnaissance, gain a foothold, reason through the application’s logic, and pick the next move like a real adversary. Where the attack path continues, so does Pentera with rigid safety guardrails: from the application into the infrastructure, cloud, and identity systems. Pentera
  • [Horizon3] AI-powered web app pentesting. Horizon3 added AI-powered web app pentesting to its platform, giving organizations the ability to assess exploitability using new AI-reasoned pentesting. NodeZero WebApp Pentesting closes the gap by delivering production-safe autonomous testing that spans web applications, infrastructure, cloud, data, and identity. It proves what is actually exploitable, quantifies the business consequence of each attack path, and maps those paths to the tactics of known threat actors, enabling companies to accurately prioritize and urgently fix vulnerabilities that matter. Horizon3
  • [Infoblox] External attack surface management play. Infoblox announced its entry into the external attack surface management market, using its DNS expertise to discover exposed internet-facing assets. Infoblox’s External Attack Surface Management capability instantly discovers internet-facing assets without software installation, credentialed access or active scanning. It identifies and prioritizes exposures based on exploitability and business impact, including DNS hygiene issues often missed by traditional solutions. Infoblox
  • [HackerOne] H1 Remediation launched. HackerOne added a new capability to its platform for accelerating remediation by creating developer-ready fix plans for validated, exploitable findings. Unlike AI coding assistants that generate fixes without security validation, H1 Remediation works only from validated, exploitable findings. Those findings come from across the platform: security researchers identifying real-world impact through H1 Bounty, pentesters working through H1 Agentic Pentesting, and continuous exposure signals from H1 Continuous Testing. For each of these findings, Hai, HackerOne’s agentic AI orchestrator, traces root cause to the actual lines of code, and generates a developer-ready fix plan informed by context from the customer’s actual environment and grounded in the codebase. The result is a complete picture that gives engineering teams the confidence to act on findings they know are real. HackerOne
  • [SailPoint] Cursor Enterprise connector. SailPoint released its Cursor Enterprise connector, for integrating SailPoint Atlas with the Cursor coding agent platform. The connector gives security teams the power to see and govern every human and AI agent interacting with their codebase. By integrating AI-native development workspaces directly into SailPoint Atlas, organizations can more confidently unleash the productivity of AI-driven software development without compromising the security of their software supply chain, extending the governance model used for other business-critical systems to the AI-native developer environments. SailPoint

Discover more from Osterman Research

Subscribe now to keep reading and get access to the full archive.

Continue reading