Astrix Security unveils a four-method AI agent discovery engine and real-time Agent Control Plane at RSAC 2026 β combining NHI fingerprinting, EDR telemetry, and platform integrations to find and govern every shadow AI agent in the enterprise.
Snyk unveils Agent Security and Evo AI-SPM GA at RSAC 2026 β a full-lifecycle enforcement architecture that secures AI coding agents like Claude Code, Cursor, and Devin across environment, artifact, and behavior, with Agent Scan, Studio, and Agent Guard.
SentinelOne goes GA on four products at RSAC 2026: Prompt AI Agent Security for real-time agent governance with MCP monitoring, Prompt AI Red Teaming for continuous AI application testing, Purple AI Auto Investigation for one-click agentic SOC, and AI data pipelines that cut SIEM noise by 80%.
SentinelOne launches Prompt AI Agent Security for real-time MCP server governance, Prompt AI Red Teaming for AI app hardening, and general availability of Purple AI Auto Investigation β agentic forensic investigations that compress hours into minutes.
Cisco's RSAC 2026 keynote introduces Zero Trust Access for AI agents via MCP proxy, DefenseClaw open-source secure agent framework, AI Defense Explorer Edition for self-service red teaming, and six specialized SOC agents. 85% of enterprises pilot AI agents β only 5% reach production.
The Databricks AI Security Framework v3.0 adds 35 agentic-specific risks and 6 new controls covering agent reasoning, memory poisoning, MCP server/client threats, and multi-agent system attacks β bringing the total to 97 risks and 73 controls.
Red Hat AI's 'Bring Your Own Agent' blueprint uses OpenClaw as its reference agent, adding SPIFFE identity, MCP Gateway authorization, Kata Containers isolation, and MLflow tracing β all without touching agent code.
The OWASP GenAI Security Project releases its most comprehensive update yet: agentic red teaming taxonomy, MCP server security guide, GenAI data security risks β plus a live agentic AI Capture the Flag at RSAC 2026.
Salt Security launches the industry's first platform to secure the entire agentic AI stack β mapping how LLMs reason, MCP servers connect, and APIs execute β with the Agentic Security Graph providing real-time visibility into what your AI agents can actually do.
ConductorOne launches AI Access Management β a unified control plane for AI tools, agents, and MCP connections with 3,000+ hosted MCP servers, credential vaulting, and fine-grained tool call authorization. The pitch: if getting approved AI access takes 60 seconds, nobody needs shadow AI.
Entro Security launches Agentic Governance & Administration (AGA) for shadow AI discovery and MCP enforcement. Apono launches Agent Privilege Guard with Intent-Based Access Controls and zero standing privileges. Together, they map the full agent governance stack β both headed to RSAC 2026.
Axiory launches infrastructure for AI agents to autonomously trade FX, stocks, and ETFs via MCP. The shift from dashboards to agent-native finance has begun.
Mimecast's March 2026 platform overhaul introduces adaptive security policies, an AI investigation agent, and an MCP gateway β treating the human layer as the new security control plane as AI agents flood enterprise environments.
Singulr AI launches Agent Pulse β a governance platform that discovers, risk-scores, and enforces policies on autonomous AI agents and MCP servers in real time. Because deploying agents without runtime controls is flying blind.
BlueRock Security scanned 7,000+ MCP servers and found 36.7% vulnerable to SSRF. Trend Micro found 492 exposed with no authentication. The MCP ecosystem has a systemic security problem.
Google's new open-source gws CLI gives AI agents structured access to Gmail, Drive, Calendar, Sheets, and every Workspace API. It includes 100+ agent skills and an MCP server mode that works with OpenClaw out of the box.
CVE-2026-27825 allows unauthenticated remote code execution through mcp-atlassian's Confluence integration. Another reminder that MCP tool security is the weakest link in agent deployments.
Two critical CVEs in Anthropic's Claude Code exploited MCP configuration to achieve remote code execution and API key theft. What OpenClaw users should know about supply chain attacks on AI agents.