
News for today:
- [Cato Networks] Licensing program for MSPs for SASE services. Cato Networks released a new licensing program that allows its MSP customers to buy Cato licenses that it can allocate across multiple clients without requiring licensing sign-off by Cato per client deployment. The licenses cover managed SASE services. Available to Cato’s ecosystem of new and existing MSPs and service providers, SMB FlexPool gives partners a committed, partner-level pool of Cato licenses that can be gradually allocated across SMB customers as demand grows. Partners can instantly provision customer accounts, allocate capacity from their pool, and activate Cato services through a self-service workflow, while maintaining full portability of capacity between customers and retaining control of the customer relationship, service packaging, support model, and managed service experience. Cato Networks
- [Sophos] Another OpenAI-powered offering. The new Exploit Path Verification (EPV) capability from Sophos is powered by OpenAI’s frontier cyber models, for assessing cyber vulnerabilities and how they could be exploited (particularly by AI). It is being built to reason over asset and patch state, endpoint protection policy, network reachability, identity and privilege facts, and known exploit availability, and returns a clear evidence-backed exploitability verdict: Confirmed Exploitable, Blocked by a Control, Not Reachable, or Insufficient Evidence. EPV will also be designed to identify chained paths where multiple lower-severity findings combine into one exploitable route, assess whether a control blocks a technique class or only a common public proof of concept, and draft remediation text ready for a ticket. The capability will be advisory and additive by design. Every verdict is labeled as AI-generated with its evidence visible, and Sophos analysts review the results. Sophos
- [Ping Identity] Securing personal agents. Ping Identity released Enterprise Personal Agent Access (EPAA), for discovery and runtime control of personal agents created by employees and developers. [EPAA] discovers personal agents (including shadow AI), associates each session with the user and device behind it, and governs access and actions at runtime within supported environments. This includes desktop assistants such as Claude, and coding agents such as Claude Code. Enterprise Personal Agent Access is available now and is already being piloted with leading global enterprises. Claude is explicitly mentioned; “other supported personal AI agents” is mentioned without specifics. Ping Identity

