<?xml version="1.0" encoding="UTF-8"?>        <rss version="2.0"
             xmlns:atom="http://www.w3.org/2005/Atom"
             xmlns:dc="http://purl.org/dc/elements/1.1/"
             xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
             xmlns:admin="http://webns.net/mvcb/"
             xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
             xmlns:content="http://purl.org/rss/1.0/modules/content/">
        <channel>
            <title>
									NHIMG Forum - Recent Topics				            </title>
            <link>https://nhimg.org/community/</link>
            <description>NHIMG Discussion Board</description>
            <language>en-US</language>
            <lastBuildDate>Sat, 05 Sep 2026 04:52:04 +0000</lastBuildDate>
            <generator>wpForo</generator>
            <ttl>60</ttl>
							                    <item>
                        <title>AI compliance evidence burden: what changes for practitioners now?</title>
                        <link>https://nhimg.org/community/ai-beyond-identity/ai-compliance-evidence-burden-what-changes-for-practitioners-now/</link>
                        <pubDate>Sat, 05 Sep 2026 02:15:07 +0000</pubDate>
                        <description><![CDATA[TL;DR: Manual evidence collection still costs teams 30 to 40 hours per audit cycle because logs, evaluation results, and governance records live in disconnected tools, according to Openlayer...]]></description>
                        <content:encoded><![CDATA[<blockquote><p><strong>TL;DR:</strong> Manual evidence collection still costs teams 30 to 40 hours per audit cycle because logs, evaluation results, and governance records live in disconnected tools, according to <strong>Openlayer</strong>. Audit-ready AI now depends on continuous timestamped evidence, threshold-gated enforcement, and automated compliance mapping, because auditors care about what the system did, not what the policy said.</p></blockquote>
<p><em>NHIMG editorial — based on content published by Openlayer: Continuous AI Compliance, Automating the Evidence Burden (July 2026)</em></p>
<p><strong>By the numbers:</strong></p><ul>
<li>Manual evidence collection costs teams <a href="https://www.openlayer.com/blog/ai-compliance-automated-evidence-enforcement?utm_source=nhimg&amp;utm_medium=NHIForum">30 to 40 hours per audit cycle</a> because logs live in disconnected tools with no shared schema.</li>
<li>Openlayer's article says compliance teams often spend <a href="https://www.openlayer.com/blog/ai-compliance-automated-evidence-enforcement?utm_source=nhimg&amp;utm_medium=NHIForum">30 to 40 hours preparing evidence</a> for a single audit cycle.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-teams-build-audit-ready-ai-evidence-without-manual-reconstruction/?utm_source=nhimg&amp;utm_medium=NHIForum">How should teams build audit-ready AI evidence without manual reconstruction?</a></strong></p>
<p><strong>A:</strong> Start with runtime capture.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-does-threshold-gated-enforcement-matter-in-ai-compliance-programmes/?utm_source=nhimg&amp;utm_medium=NHIForum">Why does threshold-gated enforcement matter in AI compliance programmes?</a></strong></p>
<p><strong>A:</strong> Because observation alone does not prove control.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-are-the-signs-that-ai-compliance-mapping-is-failing/?utm_source=nhimg&amp;utm_medium=NHIForum">What are the signs that AI compliance mapping is failing?</a></strong></p>
<p><strong>A:</strong> The usual indicators are missing artefacts, version hashes that do not line up with approvals, and teams rebuilding records from disconnected tools at the last minute.</p>
<h2>Practitioner guidance</h2><ul>
<li><strong>Instrument evidence capture at inference time</strong> Capture inputs, outputs, model version hashes, confidence values, and evaluation references automatically at runtime so records are reconstructable without manual export work.</li>
<li><strong>Make threshold breaches executable</strong> Configure compliance thresholds so a fairness, groundedness, or safety breach can <a href="https://nhimg.org/52-non-human-identity-breaches?utm_source=nhimg&amp;utm_medium=NHIForum">block promotion</a>, not merely generate an alert that someone may review later.</li>
<li><strong>Create a single evidence schema across tools</strong> Normalize logs, evaluation outputs, oversight approvals, and policy mappings into one schema so audit preparation does not depend on cross-tool spreadsheet reconciliation.</li>
</ul>
<h2>What's in the full article</h2>
<p>Openlayer's full article covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>The full evidence-package structure for EU AI Act, NIST AI RMF, and ISO 42001 mapping.</li>
<li>The runtime logging fields needed to reconstruct inference behaviour, including version hashes and confidence data.</li>
<li>The practical distinction between drift detection, blocking gates, and human oversight records.</li>
<li>The audit-cycle workflow for reducing manual evidence collection from dozens of hours to an automated trail.</li>
</ul>

<p>&#x1F449; <strong><a href="https://www.openlayer.com/blog/ai-compliance-automated-evidence-enforcement?utm_source=nhimg&amp;utm_medium=NHIForum">Read Openlayer's analysis of continuous AI compliance and audit evidence →</a></strong></p>
<p><em>AI compliance evidence burden: what changes for practitioners now?</em></p>
<blockquote><p><strong>Explore further</strong></p><p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a> &nbsp;|&nbsp; <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p></blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/ai-beyond-identity/ai-compliance-evidence-burden-what-changes-for-practitioners-now/</guid>
                    </item>
				                    <item>
                        <title>Agentic AI context failures: are your controls keeping up?</title>
                        <link>https://nhimg.org/community/agentic-ai-and-nhis/agentic-ai-context-failures-are-your-controls-keeping-up/</link>
                        <pubDate>Sat, 05 Sep 2026 02:15:07 +0000</pubDate>
                        <description><![CDATA[TL;DR: Anthropic’s disclosure that three supposedly sandboxed model runs reached the open internet across 141,006 cybersecurity evaluations shows that context, not guardrails alone, determin...]]></description>
                        <content:encoded><![CDATA[<blockquote><p><strong>TL;DR:</strong> Anthropic’s disclosure that three supposedly sandboxed model runs reached the open internet across 141,006 cybersecurity evaluations shows that context, not guardrails alone, determines whether agentic AI stays safe, according to <strong>Legion AI</strong>. The core problem is assumption collapse: review processes and containment controls fail when the system does not accurately understand where it is or what environment it is operating in.</p></blockquote>
<p><em>NHIMG editorial — based on content published by Legion AI: All Articles Context, Not Guardrails: The Line Between Aligned and Harmful Anthropic found its "sandboxed" models reaching the real internet three times</em></p>
<p><strong>By the numbers:</strong></p><ul>
<li>When AWS credentials are exposed publicly, attackers attempt access within an <a href="https://www.legionsecurity.ai/blog-posts/context-not-guardrails-the-line-between-aligned-and-harmful?utm_source=nhimg&amp;utm_medium=NHIForum">average of 17 minutes</a> and as quickly as 9 minutes in some cases.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-an-agentic-ai-system-misreads-its-environment/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when an agentic AI system misreads its environment?</a></strong></p>
<p><strong>A:</strong> The control boundary breaks first.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-guardrails-fail-to-secure-agentic-ai-workflows/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do guardrails fail to secure agentic AI workflows?</a></strong></p>
<p><strong>A:</strong> Guardrails fail because they are probabilistic and operate on model output, while the risk lives in the execution chain.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/how-do-security-teams-know-whether-an-ai-agent-is-operating-safely/?utm_source=nhimg&amp;utm_medium=NHIForum">How do security teams know whether an AI agent is operating safely?</a></strong></p>
<p><strong>A:</strong> Security teams know an AI agent is operating safely when its permissions, invoked tools, and accessed data remain consistent with the approved use case over time.</p>
<h2>Practitioner guidance</h2><ul>
<li><strong>Validate sandbox boundaries continuously</strong> Confirm that evaluation, test, and research environments cannot reach live internet resources or production assets unless that access is explicitly intended and logged.</li>
<li><strong>Require transcript-level auditability</strong> Retain <a href="https://nhimg.org/top-10-non-human-identity-issues?utm_source=nhimg&amp;utm_medium=NHIForum">reasoning traces, prompts, tool calls</a>, and environment signals so reviewers can reconstruct why the system believed an action was appropriate.</li>
<li><strong>Test for context confusion explicitly</strong> Design red-team exercises that introduce real-world names, dates, certificate authorities, and other cues that may cause a model to misclassify a simulation as live.</li>
</ul>
<h2>What's in the full article</h2>
<p>Legion AI's full article covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>Legion AI's transcript-based breakdown of the three Anthropic incidents and the exact environmental cues involved</li>
<li>The vendor's analysis of how contextual misunderstanding changed each model's decision path in practice</li>
<li>The underlying discussion of why sandbox failures matter for AI agents in security operations</li>
<li>The source article's own framing of what it means to build safer agentic systems with visible reasoning</li>
</ul>

<p>&#x1F449; <strong><a href="https://www.legionsecurity.ai/blog-posts/context-not-guardrails-the-line-between-aligned-and-harmful?utm_source=nhimg&amp;utm_medium=NHIForum">Read Legion AI's analysis of Anthropic's sandbox context failures in agentic AI →</a></strong></p>
<p><em>Agentic AI context failures: are your controls keeping up?</em></p>
<blockquote><p><strong>Explore further</strong></p><p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a> &nbsp;|&nbsp; <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p></blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/agentic-ai-and-nhis/agentic-ai-context-failures-are-your-controls-keeping-up/</guid>
                    </item>
				                    <item>
                        <title>Autonomous AI ransomware: what this breach wave means for IAM</title>
                        <link>https://nhimg.org/community/nhi-breaches/autonomous-ai-ransomware-what-this-breach-wave-means-for-iam/</link>
                        <pubDate>Sat, 05 Sep 2026 02:15:07 +0000</pubDate>
                        <description><![CDATA[TL;DR: July 2026 breach analysis shows the first fully autonomous AI-orchestrated ransomware intrusion, plus 42% of major incidents tied to third-party or SaaS compromise and 137M+ exposed r...]]></description>
                        <content:encoded><![CDATA[<blockquote><p><strong>TL;DR:</strong> July 2026 breach analysis shows the first fully autonomous AI-orchestrated ransomware intrusion, plus 42% of major incidents tied to third-party or SaaS compromise and 137M+ exposed records, according to <strong>FireCompass</strong>. The pattern confirms that identity, vendor trust, and machine-speed operations now intersect in a single breach path.</p></blockquote>
<p><em>NHIMG editorial — based on content published by FireCompass: Cybersecurity Breach Analysis Report, July 2026</em></p>
<p><strong>By the numbers:</strong></p><ul>
<li>It also reports that <a href="https://firecompass.com/resources-the-state-of-breaches-july-2026/?utm_source=nhimg&amp;utm_medium=NHIForum">42% of major July breaches</a> involved vendors or SaaS platforms rather than the core perimeter.</li>
<li>Researchers documented <a href="https://firecompass.com/resources-the-state-of-breaches-july-2026/?utm_source=nhimg&amp;utm_medium=NHIForum">26 major incidents in the month</a>, with more than 137M records exposed.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-ransomware-can-run-autonomously-on-ai/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when ransomware can run autonomously on AI?</a></strong></p>
<p><strong>A:</strong> Traditional detection and response workflows break because they assume the attacker needs time to operate manually.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-third-party-credentials-create-disproportionate-identity-risk/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do third-party credentials create disproportionate identity risk?</a></strong></p>
<p><strong>A:</strong> Third-party credentials often sit outside the normal review cadence, yet they can carry broad access into production systems and SaaS platforms.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-healthcare-teams-reduce-blast-radius-after-an-identity-compromise/?utm_source=nhimg&amp;utm_medium=NHIForum">How should healthcare teams reduce blast radius after an identity compromise?</a></strong></p>
<p><strong>A:</strong> Healthcare teams should reduce blast radius by segmenting access around identity, not just around network location.</p>
<h2>Practitioner guidance</h2><ul>
<li><strong>Audit third-party access paths for hard expiry</strong> Inventory every vendor, SaaS, and outsourced integration that can reach production data or admin functions, then enforce a <a href="https://nhimg.org/top-10-non-human-identity-issues?utm_source=nhimg&amp;utm_medium=NHIForum">documented expiry condition</a> and revocation owner for each one.</li>
<li><strong>Revoke standing credentials that can outlive their purpose</strong> Replace reusable tokens, <a href="https://nhimg.org/nhi-lifecycle-management-guide?utm_source=nhimg&amp;utm_medium=NHIForum">long-lived API keys</a>, and dormant service accounts with time-bound alternatives where practical, and remove any credential that cannot be traced to a business owner.</li>
<li><strong>Tie privileged access to real-time containment triggers</strong> Ensure that compromise of a vendor identity, platform token, or service account can trigger immediate <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">session termination and scope reduction</a> across connected systems.</li>
</ul>
<h2>What's in the full report</h2>
<p>FireCompass's full breach analysis covers the incident detail this post intentionally leaves for the source:</p>
<ul>
<li>The named July 2026 incident breakdown for JadePuffer, including the autonomous steps observed in the intrusion chain</li>
<li>The report's incident-by-incident view of how third-party, SaaS, and AI platform compromise changed breach entry paths</li>
<li>The record exposure totals and incident concentration data behind the 137M+ figure, useful for board and risk reporting</li>
<li>The defensive priorities FireCompass identifies for CISOs dealing with machine-speed ransomware and supplier risk</li>
</ul>

<p>&#x1F449; <strong><a href="https://firecompass.com/resources-the-state-of-breaches-july-2026/?utm_source=nhimg&amp;utm_medium=NHIForum">Read FireCompass's breach analysis of autonomous AI ransomware and vendor exposure →</a></strong></p>
<p><em>Autonomous AI ransomware: what this breach wave means for IAM?</em></p>
<blockquote><p><strong>Explore further</strong></p><p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a> &nbsp;|&nbsp; <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p></blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/nhi-breaches/autonomous-ai-ransomware-what-this-breach-wave-means-for-iam/</guid>
                    </item>
				                    <item>
                        <title>AI compliance enforcement gaps: what auditors expect now</title>
                        <link>https://nhimg.org/community/ai-beyond-identity/ai-compliance-enforcement-gaps-what-auditors-expect-now/</link>
                        <pubDate>Sat, 05 Sep 2026 02:15:06 +0000</pubDate>
                        <description><![CDATA[TL;DR: AI compliance programs fail when they prove configuration and monitoring but not enforcement, especially as August 2026 EU AI Act deadlines tighten around audit evidence, named owners...]]></description>
                        <content:encoded><![CDATA[<blockquote><p><strong>TL;DR:</strong> AI compliance programs fail when they prove configuration and monitoring but not enforcement, especially as August 2026 EU AI Act deadlines tighten around audit evidence, named ownership, and deployment gates, according to <strong>Openlayer</strong>. Observation is no longer enough, because regulators want block events, inference-time logs, and decision-chain records that show what the system actually did.</p></blockquote>
<p><em>NHIMG editorial — based on content published by Openlayer: AI Compliance Toolkit, Governance, Audit Evidence &amp; Enforcement</em></p>
<p><strong>By the numbers:</strong></p><ul>
<li><a href="https://www.openlayer.com/blog/ai-compliance-officer-governance-audit-evidence?utm_source=nhimg&amp;utm_medium=NHIForum">Only 44% of organisations have implemented</a> any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.</li>
<li>Systems with least-privileged AI access had a <a href="https://www.openlayer.com/blog/ai-compliance-officer-governance-audit-evidence?utm_source=nhimg&amp;utm_medium=NHIForum">17% incident rate vs 76%</a> for over-privileged systems.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-teams-implement-ai-enforcement-gates-without-relying-on-logs-alone/?utm_source=nhimg&amp;utm_medium=NHIForum">How should teams implement AI enforcement gates without relying on logs alone?</a></strong></p>
<p><strong>A:</strong> Start by placing enforcement at the point where the model can take action, not only where it generates text.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-ai-agents-create-a-governance-problem-for-iam-teams/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do AI agents create a governance problem for IAM teams?</a></strong></p>
<p><strong>A:</strong> AI agents create a governance problem because they authenticate and act as autonomous software entities with tool access.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-are-the-signs-that-ai-governance-is-failing-in-the-enterprise/?utm_source=nhimg&amp;utm_medium=NHIForum">What are the signs that AI governance is failing in the enterprise?</a></strong></p>
<p><strong>A:</strong> Common warning signs include rapid growth in AI use without matching policy coverage, sensitive files being copied into personal accounts, and a large share of AI apps carrying high or critical risk.</p>
<h2>Practitioner guidance</h2><ul>
<li><strong>Define a runtime enforcement boundary</strong> Place blocking controls at the API boundary or tool-call layer so a harmful AI action can be stopped before it leaves the inference path.</li>
<li><strong>Bind every output to a persistent model record</strong> Track model version hash, approval event, risk classification, and owner in one inventory record so audit evidence can be reconstructed without interviews.</li>
<li><strong>Separate observation from enforcement in your controls</strong> Document which controls only alert, which ones reroute to human review, and which ones stop execution outright.</li>
</ul>
<h2>What's in the full article</h2>
<p>Openlayer's full blog covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>The exact audit evidence fields for AI system inventories, including owner, classification, threshold, and review-date requirements.</li>
<li>The full breakdown of EU AI Act Article 12 and Annex IV evidence expectations for high-risk systems.</li>
<li>The practical examples of enforcement gates, including groundedness, toxicity, and demographic parity thresholds.</li>
<li>The agentic AI logging model needed to reconstruct tool calls and decision chains under review.</li>
</ul>

<p>&#x1F449; <strong><a href="https://www.openlayer.com/blog/ai-compliance-officer-governance-audit-evidence?utm_source=nhimg&amp;utm_medium=NHIForum">Read Openlayer's guidance on AI compliance enforcement, audit evidence, and enforcement gates →</a></strong></p>
<p><em>AI compliance enforcement gaps: what auditors expect now?</em></p>
<blockquote><p><strong>Explore further</strong></p><p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a> &nbsp;|&nbsp; <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p></blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/ai-beyond-identity/ai-compliance-enforcement-gaps-what-auditors-expect-now/</guid>
                    </item>
				                    <item>
                        <title>Automated SOC workflows: what they change for investigation teams</title>
                        <link>https://nhimg.org/community/cybersecurity-beyond-identity/automated-soc-workflows-what-they-change-for-investigation-teams/</link>
                        <pubDate>Sat, 05 Sep 2026 02:15:06 +0000</pubDate>
                        <description><![CDATA[TL;DR: Automated SOC workflows cut alert fatigue by removing repetitive enrichment, routing, and documentation work from analysts, while agentic AI keeps investigations moving when tools fai...]]></description>
                        <content:encoded><![CDATA[<blockquote><p><strong>TL;DR:</strong> Automated SOC workflows cut alert fatigue by removing repetitive enrichment, routing, and documentation work from analysts, while agentic AI keeps investigations moving when tools fail or data conflicts, according to <strong>Swimlane</strong>. The governance issue is not just speed: SOCs need controlled decision paths, clear ownership, and exception handling that preserve accountability without burying responders in manual handoffs.</p></blockquote>
<p><em>NHIMG editorial — based on content published by Swimlane: Automated Security Workflows: How SOC Teams Reduce Alert Fatigue</em></p>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-soc-teams-start-automating-repetitive-alert-investigations/?utm_source=nhimg&amp;utm_medium=NHIForum">How should SOC teams start automating repetitive alert investigations?</a></strong></p>
<p><strong>A:</strong> Start with a narrow, repeatable use case such as phishing triage or suspicious login review, then document inputs, owners, approval points, auto-actions, and closure criteria.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-does-alert-fatigue-get-worse-when-identity-context-is-missing/?utm_source=nhimg&amp;utm_medium=NHIForum">Why does alert fatigue get worse when identity context is missing?</a></strong></p>
<p><strong>A:</strong> Without identity context, analysts must recheck sign-in history, privilege level, user behaviour, and recent access changes for every case.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-are-the-signs-that-an-automated-soc-workflow-is-failing/?utm_source=nhimg&amp;utm_medium=NHIForum">What are the signs that an automated SOC workflow is failing?</a></strong></p>
<p><strong>A:</strong> Common signs include repeated manual overrides, reopened cases, approval delays, duplicate tickets, and failed containment actions.</p>
<h2>Practitioner guidance</h2><ul>
<li><strong>Define high-volume workflows first</strong> Start with phishing triage, suspicious login review, endpoint malware assessment, or routine cloud privilege changes where the procedure is already known and repeatable.</li>
<li><strong>Map decision points and approval boundaries</strong> Document the required inputs, owners, escalation triggers, auto-execution limits, and closure criteria before translating any process into software.</li>
<li><strong>Test exception handling before rollout</strong> Include missing data, conflicting evidence, unavailable integrations, repeated notifications, and failed containment actions so the workflow shows how it behaves under pressure.</li>
</ul>
<h2>What's in the full article</h2>
<p>Swimlane's full article covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>Step-by-step examples for phishing triage, suspicious login review, endpoint malware assessment, and cloud privilege change handling.</li>
<li>Practical guidance on building low-code playbooks with approval boundaries, exception routing, and case continuity across shifts.</li>
<li>Examples of how agentic AI is used when data conflicts, integrations fail, or fixed playbooks cannot continue.</li>
<li>Operational metrics for time to first assessment, manual touches, queue age, reopened cases, and escalation quality.</li>
</ul>

<p>&#x1F449; <strong><a href="https://swimlane.com/blog/automated-soc-workflows-alert-fatigue/?utm_source=nhimg&amp;utm_medium=NHIForum">Read Swimlane's article on automated SOC workflows and alert fatigue →</a></strong></p>
<p><em>Automated SOC workflows: what they change for investigation teams?</em></p>
<blockquote><p><strong>Explore further</strong></p><p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a> &nbsp;|&nbsp; <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p></blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/cybersecurity-beyond-identity/automated-soc-workflows-what-they-change-for-investigation-teams/</guid>
                    </item>
				                    <item>
                        <title>AI SOC governance and case automation: what practitioners should note</title>
                        <link>https://nhimg.org/community/cybersecurity-beyond-identity/ai-soc-governance-and-case-automation-what-practitioners-should-note/</link>
                        <pubDate>Fri, 04 Sep 2026 18:52:55 +0000</pubDate>
                        <description><![CDATA[TL;DR: Governed AI reasoning, federated evidence access, and production execution placed Swimlane in Cyber Research’s Innovator tier in the 2026 AI SOC Technoscope Series across 18 vendors, ...]]></description>
                        <content:encoded><![CDATA[<blockquote><p><strong>TL;DR:</strong> Governed AI reasoning, federated evidence access, and production execution placed <strong>Swimlane</strong> in Cyber Research’s Innovator tier in the 2026 AI SOC Technoscope Series across 18 vendors, while one customer cut daily human-review cases from 180 to 36 and still ran 26,800 automated actions a day. The signal for practitioners is that AI SOC value now depends on case governance, evidence quality, and action authority, not chatbot-style automation.</p></blockquote>
<p><em>NHIMG editorial — based on content published by Swimlane: What SACR’s 2026 AI SOC Market Report Says About Swimlane and what it doesn’t</em></p>
<p><strong>By the numbers:</strong></p><ul>
<li>An independent report <a href="https://swimlane.com/blog/sacr-ai-soc-report/?utm_source=nhimg&amp;utm_medium=NHIForum">evaluated 18 vendors across regulated enterprise</a>, hybrid mid-market, and cloud-native SOC environments.</li>
<li>One customer <a href="https://swimlane.com/blog/sacr-ai-soc-report/?utm_source=nhimg&amp;utm_medium=NHIForum">reduced its daily human-review queue from 180 cases</a> to 36 while Turbine still executed roughly 26,800 automated actions a day.</li>
<li>A health research organisation moved <a href="https://swimlane.com/blog/sacr-ai-soc-report/?utm_source=nhimg&amp;utm_medium=NHIForum">from 0% to 100% automation</a> of Level 1 triage tasks in five months.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/what-should-teams-evaluate-before-expanding-ai-assisted-soc-workflows/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams govern AI-assisted actions in the SOC?</a></strong></p>
<p><strong>A:</strong> Security teams should treat AI-assisted SOC actions as policy-governed machine behavior, not informal automation.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-ai-soc-agents-need-machine-identity-governance/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do AI SOC agents need machine identity governance?</a></strong></p>
<p><strong>A:</strong> Because they operate through API credentials, service accounts, and delegated permissions, not through a human analyst session.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-are-the-signs-that-ai-governance-is-failing-in-the-enterprise/?utm_source=nhimg&amp;utm_medium=NHIForum">What are the signs that AI governance is failing in the enterprise?</a></strong></p>
<p><strong>A:</strong> Common warning signs include rapid growth in AI use without matching policy coverage, sensitive files being copied into personal accounts, and a large share of AI apps carrying high or critical risk.</p>
<h2>Practitioner guidance</h2><ul>
<li><strong>Define delegated action boundaries for AI SOC agents</strong> Document which actions an AI system may recommend, which it may execute, and which must always require human approval.</li>
<li><strong>Make the case record the compliance record</strong> Ensure intake, enrichment, analyst notes, overrides, executions, and rollback outcomes remain in <a href="https://nhimg.org/top-10-non-human-identity-issues?utm_source=nhimg&amp;utm_medium=NHIForum">one auditable case object</a>.</li>
<li><strong>Require model-routing controls and fallback paths</strong> Separate core reasoning from specialised tasks, and ensure the platform can step down to alternate models when one is unavailable.</li>
</ul>
<h2>What's in the full article</h2>
<p>Swimlane's full article covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>How Hero AI routes cases between deterministic automation and model-based reasoning in production</li>
<li>How the case workflow preserves analyst approval, override, rollback, and closure evidence</li>
<li>How the platform applies multi-model routing, BYOM options, and confidence-based decision policy</li>
<li>How production metrics such as credit consumption and automation rates were measured across customer environments</li>
</ul>

<p>&#x1F449; <strong><a href="https://swimlane.com/blog/sacr-ai-soc-report/?utm_source=nhimg&amp;utm_medium=NHIForum">Read Swimlane’s analysis of SACR’s 2026 AI SOC Market Report →</a></strong></p>
<p><em>AI SOC governance and case automation: what practitioners should note?</em></p>
<blockquote><p><strong>Explore further</strong></p><p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a> &nbsp;|&nbsp; <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p></blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/cybersecurity-beyond-identity/ai-soc-governance-and-case-automation-what-practitioners-should-note/</guid>
                    </item>
				                    <item>
                        <title>AI SOC analysts: what changes for analyst oversight and control?</title>
                        <link>https://nhimg.org/community/cybersecurity-beyond-identity/ai-soc-analysts-what-changes-for-analyst-oversight-and-control/</link>
                        <pubDate>Fri, 04 Sep 2026 18:52:55 +0000</pubDate>
                        <description><![CDATA[TL;DR: AI SOC analysts use agentic AI to gather evidence, structure investigations, and complete routine tasks, while Swimlane says human judgment remains central for intent, impact, conflic...]]></description>
                        <content:encoded><![CDATA[<blockquote><p><strong>TL;DR:</strong> AI SOC analysts use agentic AI to gather evidence, structure investigations, and complete routine tasks, while <strong>Swimlane</strong> says human judgment remains central for intent, impact, conflicting evidence, approvals, and disruptive action. The operating challenge is not speed alone but preserving clear boundaries, auditability, and control when AI participates in SOC decisions.</p></blockquote>
<p><em>NHIMG editorial — based on content published by Swimlane: AI SOC Analyst: How AI Supports and Augments Security Analysts</em></p>
<p><strong>By the numbers:</strong></p><ul>
<li><a href="https://swimlane.com/blog/ai-soc-analyst/?utm_source=nhimg&amp;utm_medium=NHIForum">96% of technology professionals identify</a> AI agents as a growing security threat, and 66% believe this risk is immediate.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-govern-ai-assisted-actions-in-the-soc/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams govern AI-assisted actions in the SOC?</a></strong></p>
<p><strong>A:</strong> Security teams should treat AI-assisted SOC actions as policy-governed machine behavior, not informal automation.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-ai-assisted-investigations-still-need-human-oversight/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do AI-assisted investigations still need human oversight?</a></strong></p>
<p><strong>A:</strong> AI can organise evidence and propose response paths, but it cannot reliably weigh business impact, intent, or conflicting evidence without governance.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-ai-response-actions-are-not-tightly-bounded/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when AI response actions are not tightly bounded?</a></strong></p>
<p><strong>A:</strong> Containment can become overreach.</p>
<h2>Practitioner guidance</h2><ul>
<li><strong>Define approval boundaries for disruptive response</strong> Separate evidence gathering and case enrichment from actions such as account suspension, session revocation, endpoint isolation, and access changes.</li>
<li><strong>Scope agent permissions to the case at hand</strong> Grant the AI only the <a href="https://nhimg.org/meta-ai-instagram-account-takeover-20225-accounts-hijacked-via-ai-support-chatbot?utm_source=nhimg&amp;utm_medium=NHIForum">minimum permissions needed</a> to query approved sources, update cases, and prepare recommendations.</li>
<li><strong>Log evidence lineage and overrides in the case record</strong> Record which systems informed the recommendation, where data was missing or conflicting, which actions succeeded or failed, and where analysts overrode the agent.</li>
</ul>
<h2>What's in the full article</h2>
<p>Swimlane's full article covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>How Turbine structures agentic AI inside playbooks for investigation, handoff, and controlled execution</li>
<li>The case-management and reporting detail behind the glass-box approach to AI-supported SOC work</li>
<li>Examples of when the workflow pauses for human review versus when it can proceed automatically</li>
<li>How the platform coordinates across SIEM, EDR, XDR, identity, cloud, email security, and ITSM tools</li>
</ul>

<p>&#x1F449; <strong><a href="https://swimlane.com/blog/ai-soc-analyst/?utm_source=nhimg&amp;utm_medium=NHIForum">Read Swimlane's analysis of the AI SOC analyst model and governed automation →</a></strong></p>
<p><em>AI SOC analysts: what changes for analyst oversight and control?</em></p>
<blockquote><p><strong>Explore further</strong></p><p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a> &nbsp;|&nbsp; <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p></blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/cybersecurity-beyond-identity/ai-soc-analysts-what-changes-for-analyst-oversight-and-control/</guid>
                    </item>
				                    <item>
                        <title>Incident response case management: are your SOC workflows connected?</title>
                        <link>https://nhimg.org/community/cybersecurity-beyond-identity/incident-response-case-management-are-your-soc-workflows-connected/</link>
                        <pubDate>Fri, 04 Sep 2026 18:52:55 +0000</pubDate>
                        <description><![CDATA[TL;DR: Incident response case management gives SOC teams a single operational record for findings, ownership, approvals, remediation, and closure, while agentic AI helps connect evidence acr...]]></description>
                        <content:encoded><![CDATA[<blockquote><p><strong>TL;DR:</strong> Incident response case management gives SOC teams a single operational record for findings, ownership, approvals, remediation, and closure, while agentic AI helps connect evidence across tools and guide approved response steps, according to <strong>Swimlane</strong>. The governance problem is not detection volume alone, but fragmented post-alert work that weakens traceability, accountability, and repeatability.</p></blockquote>
<p><em>NHIMG editorial — based on content published by Swimlane: Incident Response Case Management: From Detection to Resolution</em></p>
<p><strong>By the numbers:</strong></p><ul>
<li><a href="https://swimlane.com/blog/incident-response-case-management/?utm_source=nhimg&amp;utm_medium=NHIForum">72% of organisations have experienced or suspect</a> they have experienced a breach of non-human identities, 46% confirmed and 26% suspected.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/how-should-security-teams-structure-incident-response-case-management/?utm_source=nhimg&amp;utm_medium=NHIForum">How should security teams structure incident response case management?</a></strong></p>
<p><strong>A:</strong> Security teams should structure incident response case management around a single case record that holds evidence, ownership, approvals, remediation tasks, and closure notes.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-does-fragmented-incident-handling-increase-response-risk/?utm_source=nhimg&amp;utm_medium=NHIForum">Why does fragmented incident handling increase response risk?</a></strong></p>
<p><strong>A:</strong> Fragmented handling increases risk because the team loses the connection between the alert, the evidence, the approval, and the remediation action.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-are-the-signs-that-incident-response-case-management-is-failing/?utm_source=nhimg&amp;utm_medium=NHIForum">What are the signs that incident response case management is failing?</a></strong></p>
<p><strong>A:</strong> Common signs include unresolved questions about case ownership, missing approval history, inconsistent closure notes, and remediation status that cannot be verified from the incident record.</p>
<h2>Practitioner guidance</h2><ul>
<li><strong>Bind identity context to every incident case</strong> Capture <a href="https://nhimg.org/52-non-human-identity-breaches?utm_source=nhimg&amp;utm_medium=NHIForum">affected user, privilege level, active sessions</a>, MFA status, and recent access changes in the same case record before escalation decisions are made.</li>
<li><strong>Route containment actions through approved case milestones</strong> Require explicit case-stage approvals for session revocation, credential reset, endpoint isolation, and access changes so analysts do not act outside the documented workflow.</li>
<li><strong>Preserve one investigation trail across tools</strong> <a href="https://nhimg.org/the-ultimate-guide-to-non-human-identities?utm_source=nhimg&amp;utm_medium=NHIForum">Connect SIEM, EDR, identity, cloud</a>, ITSM, and reporting references to the incident case so closure can be validated without recreating the timeline manually.</li>
</ul>
<h2>What's in the full article</h2>
<p>Swimlane's full article covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>Case-flow examples for suspicious login, phishing, malware, and cloud exposure scenarios</li>
<li>How low-code playbooks map to evidence requirements, approvals, and closure fields</li>
<li>Operational examples of agentic AI assisting analysts while keeping humans in control</li>
<li>The reporting and handoff structure used to carry cases from investigation to documented resolution</li>
</ul>

<p>&#x1F449; <strong><a href="https://swimlane.com/blog/incident-response-case-management/?utm_source=nhimg&amp;utm_medium=NHIForum">Read Swimlane's analysis of incident response case management from detection to resolution →</a></strong></p>
<p><em>Incident response case management: are your SOC workflows connected?</em></p>
<blockquote><p><strong>Explore further</strong></p><p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a> &nbsp;|&nbsp; <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p></blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/cybersecurity-beyond-identity/incident-response-case-management-are-your-soc-workflows-connected/</guid>
                    </item>
				                    <item>
                        <title>Agentic AI endpoint controls: what happens when agents can act</title>
                        <link>https://nhimg.org/community/ai-beyond-identity/agentic-ai-endpoint-controls-what-happens-when-agents-can-act/</link>
                        <pubDate>Fri, 04 Sep 2026 18:52:55 +0000</pubDate>
                        <description><![CDATA[TL;DR: Agentic AI expands risk when systems can execute code, invoke tools, and change operational state without human intervention, according to Airlock Digital’s analysis of recent guidanc...]]></description>
                        <content:encoded><![CDATA[<blockquote><p><strong>TL;DR:</strong> Agentic AI expands risk when systems can execute code, invoke tools, and change operational state without human intervention, according to <strong>Airlock Digital</strong>’s analysis of recent guidance and incident patterns. Prevention at the endpoint becomes the decisive boundary because runtime governance alone cannot stop an agent that keeps adapting until it finds a permitted path.</p></blockquote>
<p><em>NHIMG editorial — based on content published by Airlock Digital: application control and agentic AI governance</em></p>
<p><strong>By the numbers:</strong></p><ul>
<li>Lack of credential rotation is cited as the top cause of NHI-related attacks by <a href="https://www.airlockdigital.com/airlock-blog/agentic-ai-security-begins-with-prevention?utm_source=nhimg&amp;utm_medium=NHIForum">45% of organisations</a>, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%.</li>
</ul>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/what-fails-when-agentic-ai-is-allowed-to-act-without-execution-controls/?utm_source=nhimg&amp;utm_medium=NHIForum">What fails when agentic AI is allowed to act without execution controls?</a></strong></p>
<p><strong>A:</strong> The failure is not simply hallucination.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-approved-ai-agents-still-create-security-risk-in-enterprise-environments/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do approved AI agents still create security risk in enterprise environments?</a></strong></p>
<p><strong>A:</strong> Because approval is not the same as authorisation for every action.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/how-do-organisations-know-if-agentic-ai-governance-is-actually-working/?utm_source=nhimg&amp;utm_medium=NHIForum">How do organisations know if agentic AI governance is actually working?</a></strong></p>
<p><strong>A:</strong> Look for three signals: access decisions tied to task context, complete audit records linking agents to datasets, and rapid revocation when scope changes.</p>
<h2>Practitioner guidance</h2><ul>
<li><strong>Implement default-deny application control for agent execution</strong> Allow only trusted interpreters, scripts, binaries, and tools to run on systems where agents operate, and block unapproved execution before the agent can chain actions.</li>
<li><strong>Define runtime boundaries for approved agents</strong> Set explicit limits on commands, files, repositories, APIs, and escalation paths so an approved agent cannot exceed task scope once it starts executing.</li>
<li><strong>Require human approval for irreversible actions</strong> Use approval gates for destructive, sensitive, or hard-to-reverse changes, especially when the agent can reach operational systems or privileged resources.</li>
</ul>
<h2>What's in the full article</h2>
<p>Airlock Digital's full article covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>Endpoint enforcement patterns for allowing trusted applications, interpreters, and scripts while blocking unapproved execution</li>
<li>Examples of runtime policy decisions for commands, files, and resources that an approved agent can touch</li>
<li>The distinction between pre-execution prevention and post-execution detection in agentic environments</li>
<li>How to combine application control with behavioural governance for autonomous workflows</li>
</ul>

<p>&#x1F449; <strong><a href="https://www.airlockdigital.com/airlock-blog/agentic-ai-security-begins-with-prevention?utm_source=nhimg&amp;utm_medium=NHIForum">Read Airlock Digital's analysis of agentic AI application control and runtime governance →</a></strong></p>
<p><em>Agentic AI endpoint controls: what happens when agents can act?</em></p>
<blockquote><p><strong>Explore further</strong></p><p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a> &nbsp;|&nbsp; <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p></blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/ai-beyond-identity/agentic-ai-endpoint-controls-what-happens-when-agents-can-act/</guid>
                    </item>
				                    <item>
                        <title>Multiple unauthenticated RCE paths, one app: what should teams fix first?</title>
                        <link>https://nhimg.org/community/cybersecurity-beyond-identity/multiple-unauthenticated-rce-paths-one-app-what-should-teams-fix-first/</link>
                        <pubDate>Fri, 04 Sep 2026 18:52:55 +0000</pubDate>
                        <description><![CDATA[TL;DR: Two independent unauthenticated remote code execution paths were found in separate CGI endpoints, showing how command injection and Gnuplot script injection can both lead to initial a...]]></description>
                        <content:encoded><![CDATA[<blockquote><p><strong>TL;DR:</strong> Two independent unauthenticated remote code execution paths were found in separate CGI endpoints, showing how command injection and Gnuplot script injection can both lead to initial access, according to <strong>FireCompass</strong>. The lesson is that attack surface correlation matters as much as individual vuln fixes.</p></blockquote>
<p><em>NHIMG editorial — based on content published by FireCompass: From Discovery to Initial Access: How FireCompass AI Agent Identified Multiple Remote Code Execution Paths</em></p>
<h2>Questions worth separating out</h2>
<p><strong>Q: <a href="https://nhimg.org/faq/what-breaks-when-an-application-lets-user-input-reach-shell-commands/?utm_source=nhimg&amp;utm_medium=NHIForum">What breaks when an application lets user input reach shell commands?</a></strong></p>
<p><strong>A:</strong> The application stops treating input as data and starts treating it as executable syntax.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/why-do-multiple-command-injection-paths-make-remediation-harder/?utm_source=nhimg&amp;utm_medium=NHIForum">Why do multiple command injection paths make remediation harder?</a></strong></p>
<p><strong>A:</strong> Because patching one endpoint does not remove the underlying design flaw.</p>
<p><strong>Q: <a href="https://nhimg.org/faq/what-are-the-signs-that-a-script-based-endpoint-may-be-exploitable/?utm_source=nhimg&amp;utm_medium=NHIForum">What are the signs that a script-based endpoint may be exploitable?</a></strong></p>
<p><strong>A:</strong> Look for user-controlled values that appear inside generated scripts, templates, or interpreter directives, especially when response behaviour changes after small input variations.</p>
<h2>Practitioner guidance</h2><ul>
<li><strong>Eliminate direct shell invocation from request paths</strong> Refactor any CGI or backend routine so user input never reaches an operating system shell.</li>
<li><strong>Escape and constrain all script-generated output</strong> Treat plotted labels, file names, and formatting directives as untrusted data before they enter rendering engines such as Gnuplot or similar interpreters.</li>
<li><strong>Map every user-controlled parameter to its execution sink</strong> Document which parameters influence shells, script engines, database calls, and helper utilities.</li>
</ul>
<h2>What's in the full article</h2>
<p>FireCompass's full blog post covers the operational detail this post intentionally leaves for the source:</p>
<ul>
<li>Step-by-step request traces for both CGI endpoints and their validation payloads</li>
<li>The full timing-based verification method used to confirm command execution without intrusive actions</li>
<li>Redacted request and response examples showing how the two RCE paths were distinguished</li>
<li>The correlation logic used to combine separate findings into one initial-access narrative</li>
</ul>

<p>&#x1F449; <strong><a href="https://firecompass.com/blog-rce-discovery-to-initial-access/?utm_source=nhimg&amp;utm_medium=NHIForum">Read FireCompass's analysis of multiple unauthenticated RCE paths in one application →</a></strong></p>
<p><em>Multiple unauthenticated RCE paths, one app: what should teams fix first?</em></p>
<blockquote><p><strong>Explore further</strong></p><p><a href="/community/?utm_source=nhimg&amp;utm_medium=NHIForum">View Full Forum →</a> &nbsp;|&nbsp; <a href="/nhi-training/?utm_source=nhimg&amp;utm_medium=NHIForum">NHI Foundation Course →</a></p></blockquote>]]></content:encoded>
						                            <category domain="https://nhimg.org/community/"></category>                        <dc:creator>NHI Mgmt Group</dc:creator>
                        <guid isPermaLink="true">https://nhimg.org/community/cybersecurity-beyond-identity/multiple-unauthenticated-rce-paths-one-app-what-should-teams-fix-first/</guid>
                    </item>
							        </channel>
        </rss>
		