This week’s enterprise security announcements highlight a distinct operational shift across the security industry: vendors are rapidly delivering infrastructure to monitor, govern, and secure corporate artificial intelligence deployments while refining continuous threat exposure capabilities. In the latest product releases from A10 Networks, Searchlight Cyber, ScienceLogic, and SelectHub’s DataGrout research lab, the primary focus centers on managing the expanding attack surface created by autonomous AI agents, large language model (LLM) integrations, and complex hybrid cloud operations.
Searchlight Cyber PTEM and the A10 AI Gateway represent two major fronts in this evolving landscape—protecting external attack surfaces from adversary targeting while establishing proxy-level control over internal AI payloads.
Securing Agentic Workflows and LLM Traffic at the Gateway
As enterprises embed LLM capabilities into internal applications and grant autonomous agents access to corporate databases, security teams face unprecedented data leakage and prompt injection risks. Addressing these control plane gaps, A10 Networks announced the general availability of the A10 AI Gateway. Designed as a centralized control plane, the gateway sits between enterprise applications or agents and external or self-hosted LLM endpoints.
From an architectural standpoint, an AI gateway acts as a security reverse proxy. By centralizing incoming and outgoing AI traffic, security teams can enforce uniform authentication, rate limiting, and governance policies across every model and agent in use. Crucially, centralized inspection allows organizations to perform real-time data loss prevention (DLP) filtering—blocking sensitive source code, personally identifiable information (PII), or proprietary intellectual property before it reaches third-party model providers. It also creates a choke point to inspect prompt payloads for malicious injection techniques intended to jailbreak models or manipulate agentic function calls.
Parallel to this release, SelectHub introduced DataGrout, a specialized AI research lab launching an LLM inference optimization platform and AI governance solution. DataGrout targets the convergence of FinOps and security, providing token reduction mechanisms for chatbots and agentic workflows alongside policy-driven, auditable LLM payload monitoring. For security and compliance leads, payload auditing provides the verifiable telemetry needed to prove that enterprise AI deployments adhere to internal data protection policies and external regulatory mandates.
Merging Attack Surface Visibility with Adversary Intelligence
Managing vulnerability backlogs remains one of the most resource-intensive challenges for modern Security Operations Centers (SOCs). Traditional External Attack Surface Management (EASM) tools frequently generate high volumes of alerts regarding internet-facing assets, but often lack context regarding whether threat actors are actively targeting those specific vulnerabilities.
Addressing this gap, Searchlight Cyber launched its Preemptive Threat Exposure Management (PTEM) platform. The platform merges continuous attack surface discovery with actionable threat intelligence by combining two core modules:
- Searchlight Exposure: Delivers continuous exposure visibility, external asset mapping, and automated exploitability validation to verify whether identified attack vectors can actually be compromised.
- Searchlight Threat: Monitors dark web forums, cybercrime marketplaces, and private channels to deliver real-world intelligence on what threat actors are discussing, developing exploits for, and actively targeting.
By combining real-time asset exploitability with dark web actor intent, the PTEM model enables security teams to move beyond static severity scoring (such as CVSS ratings) and prioritize remediation based on actual exposure probability. Validate-before-patch workflows reduce alert fatigue, ensuring engineering resources focus on the small percentage of external assets that are both reachable and actively sought after by malicious actors.
Maintaining Sovereignty and Security in Operational AI
For organizations operating in tightly regulated sectors—such as finance, defense, healthcare, and critical infrastructure—adopting cloud-hosted generative AI models often conflicts with strict data residency and sovereignty requirements. ScienceLogic announced ScienceLogic Skylar AI 2.5 to address these compliance hurdles while expanding operational intelligence capabilities across the enterprise.
ScienceLogic Skylar AI 2.5 introduces expanded secure deployment options engineered for environments with stringent compliance, data sovereignty, and security controls. By allowing organizations to deploy AI capabilities within controlled security perimeters, the platform ensures that operational telemetry, system logs, and network topology data remain isolated from public AI training pipelines. In addition to deployment flexibility, the 2.5 update enhances natural language query interfaces, platform performance, and enterprise tool integration, enabling IT and security operations teams to query operational data securely without compromising underlying data governance boundaries.
Architecture and Deployment Recommendations for Security Teams
Organizations evaluating these newly released tools should align their deployment strategies with broader zero-trust and defense-in-depth principles:
- Implement AI Gateway Controls Early: Before granting enterprise AI agents read/write access to internal databases or APIs, route all model traffic through a dedicated governance gateway like the A10 AI Gateway or DataGrout platform. Configure strict payload logging, DLP token masking, and explicit policy controls for third-party API keys.
- Operationalize Exposure Intelligence: If adopting continuous exposure platforms like Searchlight Cyber PTEM, integrate exposure validation findings directly into automated ticketing and orchestration platforms (SOAR). Automatically elevate patch prioritization for external assets whenever threat intelligence indicates active threat actor interest or published exploit code.
- Enforce Sovereign AI Boundaries: Audit all third-party AI integrations for compliance with local data protection regulations. Ensure that models deployed for IT operations, such as ScienceLogic Skylar AI 2.5, run within approved tenant boundaries and do not expose operational logs to public LLM retraining processes.
Related content
Cisco Patches Actively Exploited Secure Email Gateway Zero-Day (CVE-2026-76461)
Security NewsCisco Secure Email Gateway Zero-Day Exploited to Execute Root Commands
Security NewsCritical Citrix NetScaler Flaw CVE-2026-8451 Actively Exploited
Security NewsDell BIOS Flaw (CVE-2026-40639) Exposes Admin Passwords
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call