The Short & Sweet Newsletter, September 2026 edition - Cyber news for beezy CISOs, in under 2 minutes
Your monthly dose of cyber news - short, sweet, and to the point.
#TL;DR
The Latio AI Security Report is out, our Chief AI Officer is speaking in Toronto, and we have new content worth your time. Here's the September digest.
#In case you missed it- FROM OUR BLOG AND CONTENT
- MCP Security. How Sweet discovers every MCP server from live traffic, maps it to its cloud context, and blocks unsafe agent actions before they execute. [Read more in the link down below →]
- Sweet Response. Terminate malicious processes, kill compromised containers, stop affected workloads from redeploying - all from inside Sweet. Reusable playbooks, full audit trail, one workflow. [Read more in the link down below ]
- Eyal Fisher at AWS Summit Tel Aviv - where AI security is heading and how Sweet is building for it.
- 🗣 On-demand videos for you - watch what ShipStation’s CeeSo Birat Niraula and Tal Hornstein, CeeSO at Cast & Crew talk about what Sweet looks like in production.
#If you know, you know - INDUSTRY NEWS
In Latio’s latest AI Security Report, James Berthoty predicts the custom agents will be the 2027 AI security focus that the AI endpoint is today.
His take on Sweet:
"As enterprises shift to agentic infrastructure in 2027, Sweet Security stands out as a leader in AI agent security for the cloud - they are building for exactly the challenge that's coming."
Read the full report in the link
____
From other news - Six sandbox escapes in three months. Cloudflare, Claude Cowork, Claude Code, Cursor, Docker, OpenAI Codex. All found after the fact - including the OpenAI x Hugging Face incident.
If you want to run AI agents safely, sandboxes need to be airtight. But assessing whether a sandbox is compromised isn't a posture problem. You can't scan your way to that answer. By the time a static check runs, the damage is done.
Sandbox security is becoming one of the industry's most pressing challenges. The answer isn't a posture play - it's a runtime one. The only way to know what's happening inside a sandbox is to watch it while it's running.
#Public Service Announcment
Your AI security tooling might not be as open as you think.
Giles Barford makes the case for why openness should be a non-negotiable when evaluating AI security vendors - and what to ask before you sign.
And finally some FOMO about HAPPENING NOW at Sweet Security
Sweet's very own own Yigael Berger is taking the stage at the AI x Cloud Security Summit in Toronto (Oct 6) - and this one is worth showing up for. His session, "The AI Shift: Rethinking the Economics of Cloud Security," breaks down why the metrics we've been using to measure security no longer work in an AI-first world, and what needs to change. If you're in Toronto, come find us.
Talk soon,
The Sweet Team 🍯




