Fetching from the wire…
Markets2026-06-12 · source-backed
Per Scytale, Delve auto-generates audit evidence, Scytale and Strac run continuous control monitoring, and FlowAssure automates vendor assessments across SOC 2, HIPAA, ISO 27001, GDPR, and PCI. The pitch is architectural: agents handle evidence collection end-to-end instead of the dashboard-and-checklist workflow Vanta pioneered. Compliance is a paperwork problem, and paperwork is exactly what agents are good at eating.
Each link below shares sources, entities, or timing with this story.
Norm Ai (legal/compliance, $120M Series C, July 7) is building supervisory agents to audit customers' other AI deployments. Snyk (devtools/security, GA June 29) shipped Evo ADS to police MCP servers and coding agents at runtime. Vanta (GRC, GA this month) shipped an AI Agent p...
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
DeepDelver's investigation exposed Delve fabricating audit reports with AI-generated templates before any auditor reviewed evidence. "US-based auditors" were cheap Indian certification mills. 494 fake SOC 2 reports and 81 ISO 27001 registrations confirmed compromised, affectin...
This is the most honest thing published about agents this year, and it's from a SaaS blog, not a research lab. SaaStr has been running 20+ AI agents in production for a year, going from 8 or 9 human salespeople to 1.2 humans plus 20 agents. Then they published a post-mortem on...
1. Flip your multi-model pipeline to review-then-generate. Instead of using a reasoning model to plan before code generation, let the specialist generate freely and use reasoning tokens for review. Paper shows 90.2% pass@1 vs 87.2% for the planning pattern. Source 2. Audit you...
A month ago, TeamPCP compromised Trivy's GitHub Actions runners. Then they trojanized LiteLLM on PyPI. Now Wiz Research confirms they've expanded to npm via a worm called CanisterWorm, using stolen publish tokens to push malicious packages across JavaScript's package ecosystem...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.