<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Agentic Index: security and SOC agents change log</title>
    <link>https://agenticindex.io/rankings/security-soc-agents</link>
    <atom:link href="https://agenticindex.io/feeds/security-soc-agents.xml" rel="self" type="application/rss+xml" />
    <description>Verified changes to security and SOC agents, from the Agentic Index change log. Every entry is dated and sourced from public vendor material.</description>
    <language>en-us</language>
    <copyright>Free to reuse with a visible link to agenticindex.io. Terms: https://agenticindex.io/use-this-data</copyright>
    <lastBuildDate>Thu, 24 Sep 2026 12:00:00 GMT</lastBuildDate>
    <ttl>720</ttl>
    <image>
      <url>https://media.base44.com/images/public/69e4cec10b4126d233ee7ee4/a44c0d34a_generated_image.png</url>
      <title>Agentic Index: security and SOC agents change log</title>
      <link>https://agenticindex.io/rankings/security-soc-agents</link>
    </image>
    <item>
      <title>Tines released Records API v2 with endpoints for reading records and record types, searching records, and aggregating results.</title>
      <link>https://agenticindex.io/change-log/tines</link>
      <guid isPermaLink="false">agenticindex.io:change:tines-xug3l0-2026-09-24</guid>
      <pubDate>Thu, 24 Sep 2026 12:00:00 GMT</pubDate>
      <category>MCP / tool calling / API</category>
      <category>Security / SOC agent</category>
      <category>Agent builder</category>
      <category>Enterprise operations agent</category>
      <description><![CDATA[<p>Tines released Records API v2 with endpoints for reading records and record types, searching records, and aggregating results. Requests can select fields by name or ID and include linked cases, child records, and full artifacts in the same call. The API standardizes response and error handling for workflows that retrieve Records data.</p><p><strong>Why it matters:</strong> Teams building agent workflows against Tines can reduce chained retrieval calls and custom parsing logic. The new version provides a clearer integration surface for retrieving only the operational context a workflow needs.</p><p>Impact: Medium. Verification: Verified. Type: MCP / tool calling / API.</p><p>Evidence: <a href="https://www.tines.com/stories/whats-new/records-v2-api-read-endpoints/">Official changelog</a></p><p>Source: <a href="https://agenticindex.io/change-log/tines">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>depthfirst makes transitive dependency reachability available to customers as part of every software composition analysis scan.</title>
      <link>https://agenticindex.io/change-log/depthfirst</link>
      <guid isPermaLink="false">agenticindex.io:change:depthfirst-1c04xl-2026-09-23</guid>
      <pubDate>Wed, 23 Sep 2026 12:00:00 GMT</pubDate>
      <category>Agent capability</category>
      <category>Security / SOC agent</category>
      <category>Coding agent</category>
      <description><![CDATA[<p>depthfirst makes transitive dependency reachability available to customers as part of every software composition analysis scan. Its agent follows execution paths through intermediate packages and exposes the chain of calls leading from application code to a vulnerable function. The analysis can follow invocation mechanisms that static call graphs miss, including command line startup and framework callbacks.</p><p><strong>Why it matters:</strong> Security teams gain evidence for prioritizing vulnerable dependencies that application code can actually reach. Engineers can inspect the reported path before deciding whether a finding warrants remediation.</p><p>Impact: Medium. Verification: Verified. Type: Agent capability.</p><p>Evidence: <a href="https://depthfirst.com/post/reachability-in-supply-chain-risk">Official blog</a></p><p>Source: <a href="https://agenticindex.io/change-log/depthfirst">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>ContraForce added email alerts when an agent investigation assigns an incident a malicious score at or above a configured threshold.</title>
      <link>https://agenticindex.io/change-log/contraforce</link>
      <guid isPermaLink="false">agenticindex.io:change:contraforce-15imvh-2026-09-22</guid>
      <pubDate>Tue, 22 Sep 2026 12:00:00 GMT</pubDate>
      <category>Observability / auditability</category>
      <category>Security / SOC agent</category>
      <category>Enterprise operations agent</category>
      <description><![CDATA[<p>ContraForce added email alerts when an agent investigation assigns an incident a malicious score at or above a configured threshold. Teams can choose recipients, change the default threshold of 80, and restrict alerts to selected incident severities. Each incident generates at most one such email even if the agent investigates it again.</p><p><strong>Why it matters:</strong> Security teams can route potentially serious agent findings to people without continuously watching the portal. They should validate recipient delivery and set thresholds against their own triage workload to keep the alerts useful.</p><p>Impact: Medium. Verification: Verified. Type: Observability / auditability.</p><p>Evidence: <a href="https://docs.contraforce.com/release-notes#2026-09-22">Official changelog</a></p><p>Source: <a href="https://agenticindex.io/change-log/contraforce">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Palo Alto Networks launched Unit 42 Continuous Frontier AI Defense, an agentic security service available worldwide by annual subscription.</title>
      <link>https://agenticindex.io/change-log/palo-alto-networks</link>
      <guid isPermaLink="false">agenticindex.io:change:palo-alto-networks-eiecv5-2026-09-22</guid>
      <pubDate>Tue, 22 Sep 2026 12:00:00 GMT</pubDate>
      <category>Agent capability</category>
      <category>Security / SOC agent</category>
      <category>Enterprise operations agent</category>
      <description><![CDATA[<p>Palo Alto Networks launched Unit 42 Continuous Frontier AI Defense, an agentic security service available worldwide by annual subscription. It continuously tests changing environments, validates attack paths across applications, APIs, cloud infrastructure and other assets, and supplies prioritized remediation guidance. A routing system assigns security tasks to frontier and open weight models.</p><p><strong>Why it matters:</strong> Security teams can purchase ongoing exposure testing with remediation guidance as a managed service. Buyers can evaluate continuous coverage and subscription model options alongside their existing periodic assessments.</p><p>Impact: High. Verification: Verified. Type: Agent capability.</p><p>Evidence: <a href="https://investors.paloaltonetworks.com/news-releases/news-release-details/palo-alto-networks-delivers-anthropics-mythos-and-openais-gpt-56">Official announcement</a></p><p>Source: <a href="https://agenticindex.io/change-log/palo-alto-networks">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Intezer rebuilt its MCP server to bring its AI SOC platform into assistants such as Claude, Codex and Cursor, exposing 66 tools across the…</title>
      <link>https://agenticindex.io/change-log/intezer</link>
      <guid isPermaLink="false">agenticindex.io:change:intezer-19o928-2026-09-18</guid>
      <pubDate>Fri, 18 Sep 2026 12:00:00 GMT</pubDate>
      <category>MCP / tool calling / API</category>
      <category>Security / SOC agent</category>
      <description><![CDATA[<p>Intezer rebuilt its MCP server to bring its AI SOC platform into assistants such as Claude, Codex and Cursor, exposing 66 tools across the case lifecycle.</p><p><strong>Why it matters:</strong> Sixty six tools is a large surface to hand an assistant. Security teams should check which tools can close or change a case rather than only read it.</p><p>Impact: Medium. Verification: Verified. Type: MCP / tool calling / API.</p><p>Evidence: <a href="https://intezer.com/blog/intezer-inside-your-ai-workspace">Official blog</a></p><p>Source: <a href="https://agenticindex.io/change-log/intezer">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Noma Security is available through the AWS Security Hub Extended console as its AI security partner, so enterprises can turn on AI…</title>
      <link>https://agenticindex.io/change-log/noma-security</link>
      <guid isPermaLink="false">agenticindex.io:change:noma-security-zkqq6f-2026-09-18</guid>
      <pubDate>Fri, 18 Sep 2026 12:00:00 GMT</pubDate>
      <category>Integrations</category>
      <category>Security / SOC agent</category>
      <category>Agent infrastructure</category>
      <description><![CDATA[<p>Noma Security is available through the AWS Security Hub Extended console as its AI security partner, so enterprises can turn on AI security monitoring from within AWS.</p><p><strong>Why it matters:</strong> Buying through the console an organization already uses shortens procurement. Check which Noma capabilities are included in the Security Hub offering.</p><p>Impact: Medium. Verification: Partially Verified. Type: Integrations.</p><p>Evidence: <a href="https://noma.security/blog/aws-and-noma-building-the-foundation-for-secure-enterprise-ai">Official blog</a></p><p>Source: <a href="https://agenticindex.io/change-log/noma-security">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Swimlane released Turbine 26.4, which adds structured JSON schema outputs from Hero AI actions, custom dynamic webhook responses and…</title>
      <link>https://agenticindex.io/change-log/swimlane</link>
      <guid isPermaLink="false">agenticindex.io:change:swimlane-1ocrhev-2026-09-17</guid>
      <pubDate>Thu, 17 Sep 2026 12:00:00 GMT</pubDate>
      <category>Agent capability</category>
      <category>Security / SOC agent</category>
      <category>Agent builder</category>
      <description><![CDATA[<p>Swimlane released Turbine 26.4, which adds structured JSON schema outputs from Hero AI actions, custom dynamic webhook responses and replay for package imports.</p><p><strong>Why it matters:</strong> Structured outputs make AI actions safe to feed into the next automation step. Free text outputs are where security playbooks break.</p><p>Impact: Medium. Verification: Partially Verified. Type: Agent capability.</p><p>Evidence: <a href="https://swimlane.com/resources/videos/september-2026-turbine-release/">Official announcement</a></p><p>Source: <a href="https://agenticindex.io/change-log/swimlane">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>UnderDefense launched MAXI MCP, a gateway that connects SIEM, EDR and SOC data to assistants and IDEs such as Claude, ChatGPT and Cursor…</title>
      <link>https://agenticindex.io/change-log/underdefense</link>
      <guid isPermaLink="false">agenticindex.io:change:underdefense-3dt8ha-2026-09-17</guid>
      <pubDate>Thu, 17 Sep 2026 12:00:00 GMT</pubDate>
      <category>MCP / tool calling / API</category>
      <category>Security / SOC agent</category>
      <description><![CDATA[<p>UnderDefense launched MAXI MCP, a gateway that connects SIEM, EDR and SOC data to assistants and IDEs such as Claude, ChatGPT and Cursor, using OAuth 2.1 with read only access.</p><p><strong>Why it matters:</strong> Read only access is the right default for security telemetry in a general assistant. It lets analysts ask questions without giving the assistant the power to change detections.</p><p>Impact: Medium. Verification: Verified. Type: MCP / tool calling / API.</p><p>Evidence: <a href="https://underdefense.com/company-news/underdefense-introduces-maxi-mcp-your-soc-data-where-you-already-work/">Official announcement</a></p><p>Source: <a href="https://agenticindex.io/change-log/underdefense">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Tuskira launched Vector, an autonomous red teaming agent that simulates external attacks and validates an organization's exploitable…</title>
      <link>https://agenticindex.io/change-log/tuskira</link>
      <guid isPermaLink="false">agenticindex.io:change:tuskira-1dt4r9v-2026-09-16</guid>
      <pubDate>Wed, 16 Sep 2026 12:00:00 GMT</pubDate>
      <category>Agent capability</category>
      <category>Security / SOC agent</category>
      <description><![CDATA[<p>Tuskira launched Vector, an autonomous red teaming agent that simulates external attacks and validates an organization's exploitable attack surface against its internal security data.</p><p><strong>Why it matters:</strong> Autonomous red teaming finds what is actually exploitable rather than what is merely vulnerable. Buyers should confirm the agent's scope limits before it touches production.</p><p>Impact: High. Verification: Verified. Type: Agent capability.</p><p>Evidence: <a href="https://www.businesswire.com/news/home/20260916744518/en/Tuskira-Launches-Vector-Autonomous-Red-Team-AI-Agent-That-Identifies-What-Attackers-Can-See-and-Exploit">Press release</a></p><p>Source: <a href="https://agenticindex.io/change-log/tuskira">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Exaforce added Agentless AI Security at Runtime, giving security teams visibility and control over AI agents and agentic apps from…</title>
      <link>https://agenticindex.io/change-log/exaforce</link>
      <guid isPermaLink="false">agenticindex.io:change:exaforce-qajw4l-2026-09-15</guid>
      <pubDate>Tue, 15 Sep 2026 12:00:00 GMT</pubDate>
      <category>Agent capability</category>
      <category>Security / SOC agent</category>
      <description><![CDATA[<p>Exaforce added Agentless AI Security at Runtime, giving security teams visibility and control over AI agents and agentic apps from endpoint to cloud, including the skills and LLM APIs they use.</p><p><strong>Why it matters:</strong> Most organizations cannot yet list the agents running in their environment. Agentless discovery is the fastest way to get that inventory without deploying anything new.</p><p>Impact: High. Verification: Verified. Type: Agent capability.</p><p>Evidence: <a href="https://www.exaforce.com/blogs/introducing-ai-security">Official blog</a></p><p>Source: <a href="https://agenticindex.io/change-log/exaforce">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Horizon3.ai: Horizon3 released an integration that sends validated NodeZero pentest findings into CrowdStrike Falcon Next-Gen SIEM for correlation.</title>
      <link>https://agenticindex.io/change-log/horizon3-ai</link>
      <guid isPermaLink="false">agenticindex.io:change:horizon3-ai-11csue5-2026-09-15</guid>
      <pubDate>Tue, 15 Sep 2026 12:00:00 GMT</pubDate>
      <category>Integrations</category>
      <category>Security / SOC agent</category>
      <description><![CDATA[<p>Horizon3 released an integration that sends validated NodeZero pentest findings into CrowdStrike Falcon Next-Gen SIEM for correlation.</p><p><strong>Why it matters:</strong> Validated findings are more useful in a SIEM than raw scanner output. This helps security teams tie proven exploitable paths to live alerts.</p><p>Impact: Medium. Verification: Verified. Type: Integrations.</p><p>Evidence: <a href="https://horizon3.ai/news/press-release/crowdstrike-falcon-next-gen-siem-integration/">Press release</a></p><p>Source: <a href="https://agenticindex.io/change-log/horizon3-ai">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Lasso Security: Lasso introduced LEAP, AI security guardrails that run on CPUs while aiming for the accuracy of GPU based models, built to evaluate…</title>
      <link>https://agenticindex.io/change-log/lasso-security</link>
      <guid isPermaLink="false">agenticindex.io:change:lasso-security-yudrzc-2026-09-15</guid>
      <pubDate>Tue, 15 Sep 2026 12:00:00 GMT</pubDate>
      <category>Security / enterprise</category>
      <category>Security / SOC agent</category>
      <category>Agent infrastructure</category>
      <description><![CDATA[<p>Lasso introduced LEAP, AI security guardrails that run on CPUs while aiming for the accuracy of GPU based models, built to evaluate complex agentic workflows. Lasso also announced a $30 million funding round.</p><p><strong>Why it matters:</strong> Guardrails that need GPUs are expensive to run on every agent action. CPU based guardrails make it affordable to check more actions, if the accuracy claim holds on the buyer's own traffic.</p><p>Impact: High. Verification: Verified. Type: Security / enterprise.</p><p>Evidence: <a href="https://www.lasso.security/blog/introducing-leap-cpu-based-ai-security-guardrails-with-gpu-class-accuracy">Official blog</a></p><p>Source: <a href="https://agenticindex.io/change-log/lasso-security">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Magnitude launched the CISO Staff Agent, which lets security leaders query thousands of vendors, products and downstream dependencies in…</title>
      <link>https://agenticindex.io/change-log/magnitude-tprm</link>
      <guid isPermaLink="false">agenticindex.io:change:magnitude-tprm-iqrawb-2026-09-15</guid>
      <pubDate>Tue, 15 Sep 2026 12:00:00 GMT</pubDate>
      <category>Agent capability</category>
      <category>Security / SOC agent</category>
      <description><![CDATA[<p>Magnitude launched the CISO Staff Agent, which lets security leaders query thousands of vendors, products and downstream dependencies in natural language, reasoning across assessments and risk data.</p><p><strong>Why it matters:</strong> Third party risk data is large and rarely read. A queryable agent helps a CISO answer board questions faster, as long as each answer cites the assessment behind it.</p><p>Impact: Medium. Verification: Verified. Type: Agent capability.</p><p>Evidence: <a href="https://magnitude.ai/blog/introducing-ciso-staff-agent-an-ai-chief-of-staff-for-third-party-risk">Official blog</a></p><p>Source: <a href="https://agenticindex.io/change-log/magnitude-tprm">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>RunSybil's September release adds ticketing integrations with Linear and GitHub that push and track security findings automatically, and a…</title>
      <link>https://agenticindex.io/change-log/runsybil</link>
      <guid isPermaLink="false">agenticindex.io:change:runsybil-1lllh3i-2026-09-15</guid>
      <pubDate>Tue, 15 Sep 2026 12:00:00 GMT</pubDate>
      <category>Integrations</category>
      <category>Security / SOC agent</category>
      <description><![CDATA[<p>RunSybil's September release adds ticketing integrations with Linear and GitHub that push and track security findings automatically, and a public API for configuring applications.</p><p><strong>Why it matters:</strong> Findings that land in the engineering team's own tracker get fixed faster than findings in a separate portal.</p><p>Impact: Medium. Verification: Verified. Type: Integrations.</p><p>Evidence: <a href="https://www.runsybil.com/blog/changelog-september-2026">Official blog</a></p><p>Source: <a href="https://agenticindex.io/change-log/runsybil">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Airrived launched Agentic Observability in its Agentic OS, tracing agent behavior end to end, from the integration an agent uses to the…</title>
      <link>https://agenticindex.io/change-log/airrived</link>
      <guid isPermaLink="false">agenticindex.io:change:airrived-63ssxn-2026-09-14</guid>
      <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
      <category>Observability / auditability</category>
      <category>Security / SOC agent</category>
      <category>Agent builder</category>
      <category>Enterprise operations agent</category>
      <description><![CDATA[<p>Airrived launched Agentic Observability in its Agentic OS, tracing agent behavior end to end, from the integration an agent uses to the outcome it produces, including who created it and what permissions it holds.</p><p><strong>Why it matters:</strong> Observability that starts at the permission and ends at the outcome answers the audit question directly: which agent did this, and was it allowed to.</p><p>Impact: High. Verification: Verified. Type: Observability / auditability.</p><p>Evidence: <a href="https://www.businesswire.com/news/home/20260914862881/en/Airrived-Launches-Agentic-Observability-Giving-Enterprises-Real-Time-Visibility-and-Control-Over-Every-AI-Agent-Decision">Press release</a></p><p>Source: <a href="https://agenticindex.io/change-log/airrived">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>UnderDefense launched an on-premise version of its MAXI Agentic AI SOC platform, designed specifically for closed, sovereign, and…</title>
      <link>https://agenticindex.io/change-log/underdefense</link>
      <guid isPermaLink="false">agenticindex.io:change:underdefense-atj9be-2026-09-10</guid>
      <pubDate>Thu, 10 Sep 2026 12:00:00 GMT</pubDate>
      <category>Deployment / data residency</category>
      <category>Security / SOC agent</category>
      <description><![CDATA[<p>UnderDefense launched an on-premise version of its MAXI Agentic AI SOC platform, designed specifically for closed, sovereign, and air-gapped environments. The system utilizes six specialized AI security agents with over 200 skills and 400 tools to autonomously investigate alerts without sending telemetry outside the customer's perimeter.</p><p><strong>Why it matters:</strong> This release allows critical infrastructure operators, government entities, and highly regulated enterprises to deploy advanced AI security operations without violating strict data residency or cloud connectivity constraints. Buyers can now leverage multi-agent investigation capabilities entirely within their own isolated networks.</p><p>Impact: High. Verification: Verified. Type: Deployment / data residency.</p><p>Evidence: <a href="https://underdefense.com/company-news/underdefense-launches-the-worlds-first-agentic-ai-soc-built-for-closed-sovereign-and-air-gapped-environments/">Official announcement</a></p><p>Source: <a href="https://agenticindex.io/change-log/underdefense">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Vanta released a major update to its Custom Agent and MCP capabilities.</title>
      <link>https://agenticindex.io/change-log/vanta</link>
      <guid isPermaLink="false">agenticindex.io:change:vanta-d0ui5q-2026-09-04</guid>
      <pubDate>Fri, 04 Sep 2026 12:00:00 GMT</pubDate>
      <category>Agent capability</category>
      <category>Security / SOC agent</category>
      <category>Enterprise operations agent</category>
      <description><![CDATA[<p>Vanta released a major update to its Custom Agent and MCP capabilities. Users can now trigger Custom Agent workflows automatically from Knowledge Base additions or vendor assessment milestones, utilize curated agent templates, and ask the Vanta Agent questions about vendor findings and alerts. Non-admins can now also connect to Vanta's MCP server based on their existing permissions.</p><p><strong>Why it matters:</strong> These enhancements significantly expand the automation and conversational capabilities of the Vanta platform. Security teams can now automate more of their compliance and vendor risk management workflows while safely extending MCP access to non-admin users.</p><p>Impact: High. Verification: Verified. Type: Agent capability.</p><p>Evidence: <a href="https://help.vanta.com/en/articles/11345422-product-updates">Official changelog</a></p><p>Source: <a href="https://agenticindex.io/change-log/vanta">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Abnormal AI launched AI Cloud Security, extending its behavioral AI engine to detect risky or malicious AI agent behavior in cloud…</title>
      <link>https://agenticindex.io/change-log/abnormal-ai</link>
      <guid isPermaLink="false">agenticindex.io:change:abnormal-ai-weajbc-2026-09-03</guid>
      <pubDate>Thu, 03 Sep 2026 12:00:00 GMT</pubDate>
      <category>Security / enterprise</category>
      <category>Security / SOC agent</category>
      <category>Enterprise operations agent</category>
      <description><![CDATA[<p>Abnormal AI launched AI Cloud Security, extending its behavioral AI engine to detect risky or malicious AI agent behavior in cloud environments. The new product utilizes OpenAI Daybreak models to power real-time anomaly detection and autonomous investigation.</p><p><strong>Why it matters:</strong> Security teams can now defend against rapid, AI-driven cloud breaches by monitoring both human and non-human identities, including AI agents. This provides automated, machine-speed response capabilities to contain threats that outpace traditional human-led workflows.</p><p>Impact: High. Verification: Verified. Type: Security / enterprise.</p><p>Evidence: <a href="https://abnormal.ai/newsroom/press-releases/abnormal-ai-brings-openai-daybreak-models-into-ai-cloud-security-to-protect-against-rogue-ai">Press release</a></p><p>Source: <a href="https://agenticindex.io/change-log/abnormal-ai">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Torq highlighted its integration and partnership with CrowdStrike at Fal.Con 2026, connecting Falcon telemetry directly to the Torq…</title>
      <link>https://agenticindex.io/change-log/torq</link>
      <guid isPermaLink="false">agenticindex.io:change:torq-8q662i-2026-09-03</guid>
      <pubDate>Thu, 03 Sep 2026 12:00:00 GMT</pubDate>
      <category>Integrations</category>
      <category>Security / SOC agent</category>
      <category>Enterprise operations agent</category>
      <description><![CDATA[<p>Torq highlighted its integration and partnership with CrowdStrike at Fal.Con 2026, connecting Falcon telemetry directly to the Torq Context Graph. This integration enables near-real-time case management and automated remediation of CrowdStrike detections.</p><p><strong>Why it matters:</strong> Security operations teams using CrowdStrike can leverage this integration to automatically transition from threat detection to closed cases. This reduces manual triage time and ensures agentic decisions are grounded in comprehensive environmental telemetry.</p><p>Impact: Medium. Verification: Verified. Type: Integrations.</p><p>Evidence: <a href="https://torq.io/blog/blog-falcon-2026/">Official blog</a></p><p>Source: <a href="https://agenticindex.io/change-log/torq">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Palo Alto Networks has acquired Console, an AI-native platform designed to deliver autonomous agentic capabilities across enterprise…</title>
      <link>https://agenticindex.io/change-log/palo-alto-networks</link>
      <guid isPermaLink="false">agenticindex.io:change:palo-alto-networks-1lpsg0l-2026-09-01</guid>
      <pubDate>Tue, 01 Sep 2026 12:00:00 GMT</pubDate>
      <category>Funding / partnership</category>
      <category>Security / SOC agent</category>
      <category>Enterprise operations agent</category>
      <description><![CDATA[<p>Palo Alto Networks has acquired Console, an AI-native platform designed to deliver autonomous agentic capabilities across enterprise operations. The acquisition will integrate Console's technology into the Cortex security operations portfolio to automate security investigation, prioritization, and response workflows.</p><p><strong>Why it matters:</strong> Security teams evaluating Cortex will benefit from upcoming autonomous agents capable of gathering context, determining alert priority, and executing remediation tasks. This integration aims to reduce analyst overhead and streamline incident response processes.</p><p>Impact: High. Verification: Verified. Type: Funding / partnership.</p><p>Evidence: <a href="https://www.paloaltonetworks.com/company/press/2026/palo-alto-networks-acquires-console-to-agentify-security">Press release</a></p><p>Source: <a href="https://agenticindex.io/change-log/palo-alto-networks">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Token Security introduced Enzo, an AI-native identity security application builder that allows users to create live applications…</title>
      <link>https://agenticindex.io/change-log</link>
      <guid isPermaLink="false">agenticindex.io:change:token-security-xctdxu-2026-08-26</guid>
      <pubDate>Wed, 26 Aug 2026 12:00:00 GMT</pubDate>
      <category>Workflow orchestration</category>
      <category>Security / SOC agent</category>
      <description><![CDATA[<p>Token Security introduced Enzo, an AI-native identity security application builder that allows users to create live applications, workflows, dashboards, and automations using natural language. The solution is built directly into the Token Security platform and requires no additional infrastructure or coding.</p><p><strong>Why it matters:</strong> Security and identity teams can rapidly operationalize their data and build custom automations without relying on developer resources. This significantly reduces the time and friction required to deploy tailored security workflows.</p><p>Impact: High. Verification: Verified. Type: Workflow orchestration.</p><p>Evidence: <a href="https://www.token.security/blog/introducing-enzo-by-token-security-the-ai-native-identity-security-application-builder">Official blog</a></p><p>Source: <a href="https://agenticindex.io/change-log">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Tines launched autonomous AI agents within its workflow automation platform.</title>
      <link>https://agenticindex.io/change-log/tines</link>
      <guid isPermaLink="false">agenticindex.io:change:tines-f2lcwd-2026-08-25</guid>
      <pubDate>Tue, 25 Aug 2026 12:00:00 GMT</pubDate>
      <category>Agent capability</category>
      <category>Security / SOC agent</category>
      <category>Agent builder</category>
      <category>Enterprise operations agent</category>
      <description><![CDATA[<p>Tines launched autonomous AI agents within its workflow automation platform. These agents enable customers to build intelligent, context-aware workflows that can act independently, suggest next steps, and collaborate with users in real time.</p><p><strong>Why it matters:</strong> This major release allows security teams to move beyond deterministic logic and incorporate full AI autonomy or human-in-the-loop copilots into their SOC workflows, significantly expanding the platform's automation capabilities.</p><p>Impact: High. Verification: Partially Verified. Type: Agent capability.</p><p>Evidence: <a href="https://drj.com/industry_news/tines-launches-agents-to-deliver-full-spectrum-workflow-automation">News article</a></p><p>Source: <a href="https://agenticindex.io/change-log/tines">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Tines released version 43.0.0 for self-hosted environments, introducing support for Tines primitives in Apps and a new Workbench for Cases.</title>
      <link>https://agenticindex.io/change-log/tines</link>
      <guid isPermaLink="false">agenticindex.io:change:tines-1kqxj2f-2026-08-25</guid>
      <pubDate>Tue, 25 Aug 2026 12:00:00 GMT</pubDate>
      <category>Deployment / data residency</category>
      <category>Security / SOC agent</category>
      <category>Agent builder</category>
      <category>Enterprise operations agent</category>
      <description><![CDATA[<p>Tines released version 43.0.0 for self-hosted environments, introducing support for Tines primitives in Apps and a new Workbench for Cases.</p><p><strong>Why it matters:</strong> Enterprise buyers with strict data residency requirements using the self-hosted deployment can now leverage advanced app building and case management features previously unavailable in their environments.</p><p>Impact: Medium. Verification: Verified. Type: Deployment / data residency.</p><p>Evidence: <a href="https://www.tines.com/stories/docs/self-hosted/release-notes/#august-25th-2026-43-0-0">Official documentation</a></p><p>Source: <a href="https://agenticindex.io/change-log/tines">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Equixly released its August 2026 product update, introducing Attack Trace to show how the agent executes attacks alongside new AI Red…</title>
      <link>https://agenticindex.io/change-log/equixly</link>
      <guid isPermaLink="false">agenticindex.io:change:equixly-1kexl67-2026-08-24</guid>
      <pubDate>Mon, 24 Aug 2026 12:00:00 GMT</pubDate>
      <category>Agent capability</category>
      <category>Security / SOC agent</category>
      <description><![CDATA[<p>Equixly released its August 2026 product update, introducing Attack Trace to show how the agent executes attacks alongside new AI Red Teaming controls. The update also delivers faster penetration testing scans, workspace upgrades, Discovery tags, and bulk actions.</p><p><strong>Why it matters:</strong> Security teams gain deeper visibility into the AI agent's attack paths and more granular control over red teaming exercises. The addition of faster scans and workspace management tools helps enterprises scale their continuous offensive security testing more efficiently.</p><p>Impact: Medium. Verification: Verified. Type: Agent capability.</p><p>Evidence: <a href="https://equixly.com/blog/2026/08/24/equixly-august-2026-product-update-see-how-the-agent-got-there-and-more/">Official blog</a></p><p>Source: <a href="https://agenticindex.io/change-log/equixly">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>AlertD introduced native support for the AWS Security Health Improvement Program (SHIP) and opened early access for partners.</title>
      <link>https://agenticindex.io/change-log</link>
      <guid isPermaLink="false">agenticindex.io:change:alertd-10ltyma-2026-08-23</guid>
      <pubDate>Sun, 23 Aug 2026 12:00:00 GMT</pubDate>
      <category>Security / enterprise</category>
      <category>SRE / DevOps agent</category>
      <category>Security / SOC agent</category>
      <description><![CDATA[<p>AlertD introduced native support for the AWS Security Health Improvement Program (SHIP) and opened early access for partners. The platform's agents can now automatically execute the full SHIP assessment, covering 319 questions across SATv2 and SRA Verify as a built-in profile.</p><p><strong>Why it matters:</strong> Security and DevOps teams can automate AWS security assessments without manual effort. By running the full SHIP question set natively, organizations can continuously verify their security posture against the AWS Security Reference Architecture.</p><p>Impact: High. Verification: Verified. Type: Security / enterprise.</p><p>Evidence: <a href="https://alertd.ai/blog/ai-agents-for-aws-ship-powered-by-alertd">Official blog</a></p><p>Source: <a href="https://agenticindex.io/change-log">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>ContraForce expanded its audit trail to cover Standard Operating Procedure (SOP) and security rule changes.</title>
      <link>https://agenticindex.io/change-log/contraforce</link>
      <guid isPermaLink="false">agenticindex.io:change:contraforce-14gpeuv-2026-08-19</guid>
      <pubDate>Wed, 19 Aug 2026 12:00:00 GMT</pubDate>
      <category>Observability / auditability</category>
      <category>Security / SOC agent</category>
      <category>Enterprise operations agent</category>
      <description><![CDATA[<p>ContraForce expanded its audit trail to cover Standard Operating Procedure (SOP) and security rule changes. The SOP Center now features a dedicated Audit tab that records the creation, updating, deletion, and linking of SOPs, as well as the enabling or disabling of security rules.</p><p><strong>Why it matters:</strong> Security teams and MSSPs can now maintain strict governance over their automated response procedures. This visibility ensures that any modifications to critical security rules or SOPs are fully tracked and attributable to specific users.</p><p>Impact: Medium. Verification: Partially Verified. Type: Observability / auditability.</p><p>Evidence: <a href="https://docs.contraforce.com/release-notes">Official changelog</a></p><p>Source: <a href="https://agenticindex.io/change-log/contraforce">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Intezer launched Workflows, a native automation and response builder integrated directly into its AI SOC platform.</title>
      <link>https://agenticindex.io/change-log/intezer</link>
      <guid isPermaLink="false">agenticindex.io:change:intezer-z9vs1p-2026-08-19</guid>
      <pubDate>Wed, 19 Aug 2026 12:00:00 GMT</pubDate>
      <category>Workflow orchestration</category>
      <category>Security / SOC agent</category>
      <description><![CDATA[<p>Intezer launched Workflows, a native automation and response builder integrated directly into its AI SOC platform. The feature allows users to create custom response logic, such as isolating hosts or updating tickets, using natural language via Intezer's Model Context Protocol (MCP).</p><p><strong>Why it matters:</strong> Security teams can automate post-investigation remediation without maintaining a separate SOAR platform or writing custom API integrations. This consolidation reduces tool-switching and allows automated actions to trigger immediately once an investigation reaches a verdict.</p><p>Impact: High. Verification: Partially Verified. Type: Workflow orchestration.</p><p>Evidence: <a href="https://www.globenewswire.com/news-release/2026/08/19/3347709/0/en/intezer-launches-workflows-to-complete-the-ai-soc-lifecycle.html">Press release</a></p><p>Source: <a href="https://agenticindex.io/change-log/intezer">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Cribl has acquired the technology assets and intellectual property behind Radiant Security's AI-native SOC product.</title>
      <link>https://agenticindex.io/change-log/radiant-security</link>
      <guid isPermaLink="false">agenticindex.io:change:radiant-security-5zlsf4-2026-08-19</guid>
      <pubDate>Wed, 19 Aug 2026 12:00:00 GMT</pubDate>
      <category>Funding / partnership</category>
      <category>Security / SOC agent</category>
      <description><![CDATA[<p>Cribl has acquired the technology assets and intellectual property behind Radiant Security's AI-native SOC product. The acquisition covers Radiant's software for autonomous alert triage, investigation, and resolution, which Cribl plans to adapt as an application on its telemetry data platform.</p><p><strong>Why it matters:</strong> This acquisition signals a major shift in the product's roadmap and deployment model, as the standalone AI SOC technology will be integrated into Cribl's data pipeline ecosystem. Buyers evaluating Radiant Security must now consider Cribl's platform architecture and future support for the standalone product.</p><p>Impact: High. Verification: Partially Verified. Type: Funding / partnership.</p><p>Evidence: <a href="https://siliconangle.com/2026/08/19/cribl-buys-radiant-securitys-ai-soc-tech-in-second-security-deal-of-2026/">News article</a></p><p>Source: <a href="https://agenticindex.io/change-log/radiant-security">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>CrowdStrike expanded its Project QuiltWorks cyber risk framework to small and mid-sized businesses globally.</title>
      <link>https://agenticindex.io/change-log/crowdstrike</link>
      <guid isPermaLink="false">agenticindex.io:change:crowdstrike-7wl9o5-2026-08-13</guid>
      <pubDate>Thu, 13 Aug 2026 12:00:00 GMT</pubDate>
      <category>Pricing / packaging</category>
      <category>Security / SOC agent</category>
      <category>Agent builder</category>
      <category>Multi-agent platform</category>
      <description><![CDATA[<p>CrowdStrike expanded its Project QuiltWorks cyber risk framework to small and mid-sized businesses globally. Supported by a network of distributors including Pax8 and TD SYNNEX, the expansion provides smaller organizations with access to CrowdStrike's frontier AI risk protection capabilities.</p><p><strong>Why it matters:</strong> Smaller organizations and managed service providers can now deploy CrowdStrike's AI risk protection tools that were previously targeted at enterprise customers. This enables SMBs to establish formal governance and defense against AI-driven threats using standard distributor channels.</p><p>Impact: Medium. Verification: Partially Verified. Type: Pricing / packaging.</p><p>Evidence: <a href="http://ir.crowdstrike.com/press-releases">Press release</a></p><p>Source: <a href="https://agenticindex.io/change-log/crowdstrike">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
    <item>
      <title>Qevlar AI released Identity Hunt, an identity analysis engine that runs autonomously whenever a user observable appears in an investigation.</title>
      <link>https://agenticindex.io/change-log/qevlar-ai</link>
      <guid isPermaLink="false">agenticindex.io:change:qevlar-ai-kl6vdt-2026-08-13</guid>
      <pubDate>Thu, 13 Aug 2026 12:00:00 GMT</pubDate>
      <category>Agent capability</category>
      <category>Security / SOC agent</category>
      <description><![CDATA[<p>Qevlar AI released Identity Hunt, an identity analysis engine that runs autonomously whenever a user observable appears in an investigation. The agent automatically builds a 30-day behavioral baseline for the specific user and evaluates authentication logs in under 10 seconds to return an actionable verdict, even if the primary alert is not identity-related.</p><p><strong>Why it matters:</strong> Security teams often lack the time to manually analyze identity context for every alert, allowing attackers using compromised credentials to evade detection. By automating this baseline check on every investigation, buyers can catch credential abuse and account takeovers that would otherwise be dismissed as legitimate user activity.</p><p>Impact: High. Verification: Verified. Type: Agent capability.</p><p>Evidence: <a href="https://www.qevlar.com/blog/identity-hunt">Official blog</a></p><p>Source: <a href="https://agenticindex.io/change-log/qevlar-ai">Agentic Index change log</a>. Free to reuse with a link back. <a href="https://agenticindex.io/use-this-data">Terms</a>.</p>]]></description>
    </item>
  </channel>
</rss>
