Archive for the Commentary Category

Introducing Harness Agent DLC: New Capabilities for the AI Agent Development Lifecycle

Posted in Commentary with tags on July 22, 2026 by itnerd

Harness today announced it is extending its platform to cover the full AI Agent Development Lifecycle (DLC), giving enterprises a single set of pipelines and controls to build, test, deploy, and run agents the same way they already ship everything else.

Every enterprise is building AI agents, but most can’t get them past internal pilots or proofs of concept. According to Gartner®, “Only 8% of organizations have agentic AI in production.” The software delivery lifecycle enterprises’ trust for shipping application code hasn’t extended to agents yet, trapping the ROI of internal AI investments. Real innovation arrives once a company can run an agent live with the same trust and confidence it has in the rest of its software.

Why AI agents break the traditional software delivery lifecycle

Traditional software works because it’s predictable. Application code is deterministic. Run the same test against the same code twice, and it produces the same result both times.

Agents don’t work that way: an agent’s underlying language model decides how to complete a task, and the same agent, given the same input, can choose a different tool or take a different action from one run to the next. A test that passes once offers no guarantee it will pass the next time. Incidents stop being reproducible on demand, which means the standard playbook for catching and fixing bugs doesn’t transfer either.

The stakes rise with the size of the business. A rogue agent can expose customer data, violate a compliance policy, or take an action nobody approved. Enterprises need a way to answer for what their agents are doing, and the traditional software delivery lifecycle was never built to give them one.

New Harness Agent DLC products and capabilities

Agent DLC closes the gap between building an agent and delivering it safely to production. Today’s launch includes five new products and capabilities spanning testing, deployment, operations, and governance: 

  • Harness AI Evals makes agent quality measurable, letting teams define eval datasets, wire up scoring functions, and set quality gates that automatically catch regressions whenever an agent or model changes.
  • Agent Deployments extend the canary releases, approvals, and OPA guardrails that Harness already applies to Kubernetes deployments to managed agent runtimes like Amazon Bedrock AgentCore and Google’s Agent Runtime. Agents now ship through existing pipelines instead of a separate cloud-specific workflow.
  • AI Configs support the release and management of prompts and model changes at runtime, backed by the same feature flagging infrastructure that already manages code releases. Teams can test what performs best and roll back instantly, without redeploying.
  • AI Asset Catalog automatically discovers every agent, skill, and plugin built across an organization’s repositories and links each to an owner, so nothing ships or runs unaccounted for.
  • Harness AgentTrace records what happens during a single agent run and across a full multi-step session, showing which path an agent took, where it slowed down, and how different models or prompts affect the outcome. Harness is also open-sourcing the foundational components behind AgentTrace, including harness-sdk and harness-evals, so developers can bring the same tracing primitives into their own AI applications.

In addition, existing Harness products already extend to agents without requiring any changes: Continuous Integration builds them like any other service, Artifact Registry tracks their versions and dependencies, AI Test Automation validates their responses in plain English criteria, and AI Cost Management extends spend visibility to every agent and model. 

Securing the Agent DLC

Agents choose their own approach and path to get there, so their behavior is hard to predict and just as hard to secure. They expand their own attack surface by connecting to tools and APIs, spawning sub-agents, and inheriting trust from every model they touch. Static scans were never designed for this kind of risk. Harness is launching new security capabilities to close that gap.  

Shift-left: constrain what agents can do before they ship.

  • Primitive Scanning flags misconfigurations in agent skills, prompts, and models.
  • AIBOM captures every model, tool, and dependency an agent was built with.
  • AI Testing runs agents against adversarial inputs and the OWASP Top 10 LLM and Agentic AI risks.

Shield-right: enforce policy and maintain visibility once they’re live.

  • Agent Discovery and Posture Management continuously maps agents as they spin up and how they connect across the organization.
  • AI Firewall enforces policy in real time against prompt injection, tool misuse, and data exfiltration.

Together, these capabilities give Agent DLC a single audit trail from development to production. 

Built on the Harness platform

Harness built context and intelligence directly into the platform with the Software Delivery Knowledge Graph, which captures and connects data from every stage of the delivery lifecycle, now spanning both applications and agents. Organizations relying on siloed tools don’t have that same connected view.

In June 2026, Harness introduced Autonomous Worker Agents, a platform for building and safely running AI agents inside software delivery pipelines. Worker Agents run as governed steps within those pipelines, covered by the same controls Harness already applies to every deployment.

Agent DLC extends that same context and governance across the full agent lifecycle. The pipelines, policies, approvals, and evidence that already apply to an organization’s code now apply to its agents too, so eval gates, deployment approvals, and security checks run as stages within a single pipeline, from the moment an agent is created through everything it does afterward.

Availability

Harness Agent DLC capabilities are rolling out now to Harness customers. For a full breakdown of what’s included at each stage of the lifecycle, visit this blog page

The Suno breach now affects 55.3M accounts

Posted in Commentary with tags on July 21, 2026 by itnerd

Have I Been Pwned has added the Suno data breach to its database, reporting that the AI music platform’s breach affected 55.3 million accounts.

The newly reported total substantially expands the known scale of the incident. According to Have I Been Pwned, the compromised information included email addresses, phone numbers and, in tens of thousands of Stripe-related records, names, physical addresses, purchase details and partial payment card information.

Have I Been Pwned can be found here: Have I Been Pwned: Check if your email address has been exposed in a data breach

The Suno breach can be found here: Have I Been Pwned: Suno Data Breach

Seemant Sehgal, Founder & CEO, BreachLock had this comment:

“When the disclosed scope of a breach grows this significantly in such a short period, it suggests that either the initial investigation was rushed or the organization lacked adequate visibility into its environment.

“The scale and variety of the exposed data raise serious questions about internal segmentation, security monitoring and incident readiness. Regulators and customers will spend less time focused on the 55.3 million figure than on what Suno knew, when it knew it and how it responded. Organizations that cannot establish what was accessed, when and from where within the first 72 hours will find their disclosure decisions harder to defend than the breach itself.”

Steven Swift, Managing Director, Suzu Labs follows with this::

“Customers have considerable breach fatigue after being notified repeatedly that their names, addresses, email addresses and other personal information have been exposed. At this point, individuals should assume that much of their personal information has already been compromised.

“The AI component is not necessarily the central issue here. There has been no public evidence directly attributing Suno’s security posture to its use of AI-generated code. However, rapidly growing AI companies may rely heavily on AI-assisted development, which can introduce security weaknesses when code is deployed without proper review and testing.

“Most breaches result from organizations failing to follow established security practices. Companies using AI in their applications, automation and infrastructure need a comprehensive security baseline and regular testing to confirm that their controls work. That should include at least annual penetration testing of hosted applications, services, internal networks and devices.

“Testing alone is not enough. Organizations also need to remediate the vulnerabilities that testing identifies. Too many companies conduct annual penetration tests only to receive the same findings year after year.”

Organizations need to consider that being pwned is the worst thing that can happen to them. If they do that, maybe then they will start to take information security seriously.

Estée Lauder’s ten-month gap between breach and disclosure is a #fail

Posted in Commentary with tags on July 21, 2026 by itnerd

Estée Lauder confirmed that an unauthorized party gained access to its Oracle E-Business Suite HR platform as far back as August 2025, but the breach wasn’t confirmed until June 2026, nearly ten months later, tied to the broader Cl0p ransomware campaign that has been mass-exploiting Oracle EBS across shared enterprise software, no targeted attack required, no unique vulnerability built just for Estée Lauder, just a shared platform that thousands of other companies were running too.

The breach notification can be read here: ELC – U.S. Individual Notification Letter.pdf

John Watters, Chairman and CEO, iCounter had this to say:

“Ten months between intrusion and disclosure at Estée Lauder isn’t a failure unique to this company, it’s Clop’s business model working exactly as designed. This group doesn’t break into companies one at a time. They find a vulnerability in software that thousands of organizations share, harvest data quietly across as many victims as they can before anyone notices, and then work through the extortion process at their own pace long after the initial compromise. By the time a company like Estée Lauder confirms what happened, Clop has already known the shape of that exposure for the better part of a year.

The organizations that catch this fast aren’t the ones with better firewalls, they’re the ones with threat intelligence mature enough to know, within days of a campaign like this becoming public, whether they were one of the platforms swept up in it, instead of waiting for a forensic investigation to tell them what an intelligence program should have flagged months earlier. And that intelligence work doesn’t stop once the campaign is public. Clop rolls out its victim list over time rather than all at once, which means every new name that gets published is a live signal, not old news. If your organization runs the same software as the companies showing up on that list, each new name should be treated as a countdown, not a headline about somebody else’s bad month.”

This is a #fail. There is no way that this amount of time should have passed before affected parties should have been notified. Normally I would say that someone should be punished for this. But I am pretty sure that this isn’t going to happen in this case.

FusionAuth Appoints Jamey Miller as SVP of Engineering and Technology

Posted in Commentary with tags on July 21, 2026 by itnerd

FusionAuth today announced the appointment of Jamey Miller to SVP of Engineering and Technology. He will be responsible for scaling engineering to support the company’s accelerated growth and increasing enterprise adoption, maintaining product quality and platform reliability, and positioning engineering for AI.

Miller has more than 25 years of experience scaling global SaaS R&D organizations across product, engineering, security, IT, and support, with deep experience in both cloud and self-hosted/on-premises deployment models. He has a proven track record of leading R&D in PE-backed and high-growth environments, including periods of rapid scaling, M&A integration, and operational transformation.

Most recently, Miller served as Chief Product & Technology Officer at global enterprise SaaS company Confience, where he improved delivery predictability and platform security while integrating the acquisition of Brazilian software firm LabSoft. Earlier, as EVP of R&D and Operations at Convercent, he helped guide the company to its acquisition by OneTrust, then went on to serve as VP of R&D Operations there, driving scale and cost efficiencies across a 400-person R&D organization.

Miller holds an MBA from the University of Portland, a M.S. in Marketing from the University of Colorado and a Bachelor of Science in Business Administration from Colorado State University. 

Leaseweb Acquires ITQ’s VMware VCSP Customer Base 

Posted in Commentary with tags on July 21, 2026 by itnerd

Leaseweb, a leading cloud services and Infrastructure as a Service (IaaS) provider, has announced the acquisition of the Broadcom VMware white label VCSP customer base of ITQ, a leading European Broadcom IT Services company. The move follows the recently announced strategic partnership between the two companies, under which ITQ selected Leaseweb as its infrastructure partner for VMware Cloud Foundation (VCF) services for its VCSP partners, in a significant expansion of Leaseweb’s VCF platform across Europe.

As part of the acquisition, 51 VCSP customers will transition to Leaseweb’s VCF platform, collectively accounting for approximately 35,000 cores. This brings Leaseweb’s core count to 65,000, positioning it as the largest VMware Pinnacle Partner in the Netherlands and reinforcing its position within the Broadcom partner ecosystem.

The acquired white label VCSP partners, previously operating under the Broadcom VMware Advantage Partner program, will be able to continue to market their proposition under Leaseweb’s Broadcom VMware VCSP Pinnacle Partner status. As an Authorized Pinnacle VCSP, Leaseweb transacts directly with Broadcom, providing these partners with a fully authorized and long-term platform for their VMware businesses. Partners will also continue to have access to ITQ’s VMware expertise as part of the ongoing partnership between the two organizations.

In addition to the acquired customer base, Leaseweb and ITQ are actively engaging with global non-renewing Broadcom VMware VCSP partners, offering a supported path forward for their VMware businesses under Leaseweb’s Pinnacle Partner infrastructure. Under the partnership, Leaseweb will act as provider for VMware VCF 9.x infrastructure, with ITQ serving as knowledge partner, bringing industry-leading VMware advisory and implementation expertise to support customers through migration and deployment

For more information, please visit: www.leaseweb.com

Liquibase Expands Global Partner Ecosystem

Posted in Commentary with tags on July 21, 2026 by itnerd

Liquibase today announced a major expansion of its global partner ecosystem and the appointment of Phil Robinson as Vice President of Global Channels and Alliances. The move builds on strong momentum for Liquibase Secure and growing enterprise demand for governed database change as AI, modernization, security, and compliance reshape software delivery.

Robinson brings more than two decades of channel, alliance, and enterprise open-source experience to Liquibase. Most recently, he served as Vice President of Global Channels at Digital.ai, where he helped redesign and relaunch the company’s channel program globally. Before that, he spent more than eight years at Atlassian, where he built and scaled global alliance programs with GSIs and Federal SIs, including Accenture, Deloitte, PwC, and Capgemini. His experience also includes leadership roles at Magento, Alfresco, and Hewlett Packard Enterprise across open source, cloud, systems integration, and enterprise software.

Trusted by 20 of the Fortune 100 and supported by a global community with more than 100 million downloads, Liquibase is investing in partners to help enterprises close the database delivery gap and build new services around Database Change Governance.

Robinson will lead Liquibase’s global partner strategy across partner recruitment, enablement, joint marketing, and partner-led services around Database Change Governance, while deepening the company’s engagement with cloud marketplaces and government partners.

AI is exposing the database delivery gap

Modern application and data delivery has accelerated in waves. Agile increased release velocity. Cloud spread applications, databases, and data platforms across more teams, tools, and environments. Enterprises responded by investing in CI/CD, automated testing, infrastructure-as-code, and security controls. But database change often remained governed through tickets, manual reviews, disconnected scripts, and processes that varied across teams, tools, and database platforms.

That disconnect has made the database one of the last major constraints on modern application and data delivery. Application code, infrastructure, and security increasingly move together, while database change is still treated as a separate process in many organizations. The result is fragmented governance, slower releases, and limited visibility into what changed, who approved it, and whether it is safe to deploy.

AI is not creating the database delivery gap. It is exposing it. As AI assistants and agents generate more software, they also increase the volume and speed of database change flowing through delivery systems that were never designed to operate at that scale. The challenge is no longer simply automating deployments. It is keeping database change synchronized with application code, infrastructure, and security before it reaches production.

The governance gap is widening. According to Liquibase’s 2026 State of Database Change Governance Report, 96% of organizations now have AI interacting with production databases, and 70% ship database changes weekly or faster. Yet only 28% enforce governance through automated controls and evidence, while 39% say they cannot reliably track what changed where.

For partners, this represents a significant opportunity to help customers modernize database delivery, govern AI-assisted development, strengthen compliance, reduce production risk, and bring database change into the same DevSecOps practices already established for application code. As enterprises look to scale AI safely, they need partners who can help modernize the processes that AI is exposing as bottlenecks.

Database Change Governance provides the control plane that keeps database change synchronized with application code, infrastructure, and security across the software delivery lifecycle. Liquibase Secure operationalizes that control plane across development teams, CI/CD pipelines, AI agents, and more than 65 database platforms, enabling enterprises to accelerate software delivery without sacrificing governance.

Why this is a partner opportunity now

For partners, this shift is a chance to become indispensable to their most complex customers. As database change outruns the ability to govern it, enterprises need a partner who can restore control at the exact point where developer velocity, compliance, and AI readiness collide. Liquibase provides an opportunity for partners to turn that challenge into a repeatable practice spanning advisory, implementation and managed services, reaching every environment a customer runs, from mainframe to cloud to lakehouse.

At the center of the opportunity is Liquibase Secure, which helps enterprises automate, secure, and govern database change across complex environments. With policy checks to deliver standardized change, advanced drift detection, structured audit trails, always-on evidence gathering, and more, Liquibase Secure gives developers, platform teams, security leaders, and compliance teams a governed path for every database change.

Liquibase already works with a robust group of consulting, cloud, public sector, and technology partners. Under Robinson’s leadership, the company plans to expand partner coverage both geographically and into specific industry sectors, creating clear paths for partners to build solutions and deliver Liquibase Secure, Database

Organizations interested in joining the Liquibase partner ecosystem can learn more at liquibase.com/partners.

Cascade raises $3.5M to help construction firms predict the future and win more projects

Posted in Commentary with tags on July 21, 2026 by itnerd

In construction, the most expensive projects are the ones a firm never sees. Somewhere right now, a bond has been filed, a site has changed hands, and the winner of a nine-figure project is already being decided, months before an RFP exists. Cascade, the AI pursuit platform for architecture, engineering and construction (AEC) firms, is changing that. Today, the company announced it has raised $3.5 million from Andreessen Horowitz Speedrun, Ada Ventures, Blitzscaling Ventures, Indico Capital, shuckerVC, G2C Ventures and Snowball VC.

The traction has come fast. In a few months, Cascade has signed AEC customers whose work spans some of the world’s most notorious projects – including JFK, LaGuardia, data centers and nuclear reactors. 

The signs arrive years before the bid

Long before an RFP, a multi million dollar project leaves traces. A bond filing is a project taking shape. A property changing hands is a developer moving. A line in a county capital plan is a building that does not exist yet, and a firm somewhere is going to win it. Cascade detects these events continuously across bond filings, permits, capital plans, property transactions, earnings transcripts, budget announcements and meeting minutes, and connects them to what they signal: where work is forming, what kind, and who is positioned to win it.

The tools the industry relies on read none of this. 

Cascade closes the gap. It anticipates projects as they form, scores each one for fit so firms pursue the work they are most likely to win, and surfaces warm paths in through relationships already sitting in Outlook and other software. Every customer makes the system sharper: each pursuit teaches it which signals matter, which firms are credible for which work, and where teaming opportunities exist.

Built by Amazon and Google operators, pulled in by the market

Cascade was founded by Hannia Zia and Joana Ferreira, two former Google operators who met at UnlikelyAI, the startup founded by the inventor of Amazon Alexa. There, Hannia served as VP of Product and Joana led the AI platform, building a knowledge graph of the world’s information and training LLM agents to navigate it.

Their route into construction was personal as much as commercial. Joana grew up in a Portuguese town built on construction and carpentry. Hannia’s father tried to start a construction business, but it failed. Hannia’s conversations with CFOs in New York produced Cascade’s first customer, Munoz Engineering, and a conference in Denver quickly brought the next. 

The funding will accelerate adoption and deepen Cascade’s network across the industry. Even building a house takes twenty companies coming together, and multimillion-dollar projects take an order of magnitude more. As more firms join, Cascade matches them to each other: partners to bid with, connections in new regions, teaming opportunities across the US. The platform gets stronger with every firm that joins, and so does every firm on it.

The team’s overall ambition runs the full arc of a project. Cascade intends to be there at the first trace of work forming, through the pursuit, the win and the build, until the day of handoff.

Teleport Establishes Agent Trust with New Identity Security Capabilities

Posted in Commentary with tags on July 21, 2026 by itnerd

Teleport today announced that it has expanded its Identity Security platform with three new capabilities designed to ensure that agent behavior remains within defined boundaries: Beams Session Summaries, Agentic Classifiers, and Risk Scoring. Together, these capabilities give enterprises a foundational harness for identifying and preventing agent misalignment as autonomous agents take on greater responsibility inside production infrastructure.

The announcement follows Teleport’s recent white paper, From Zero Trust to Agent Trust, which argues that zero trust is necessary but insufficient to govern agents operating at scale. The paper extends the three core principles of zero trust into three corresponding principles of agent trust:

  • Verify explicitly → Enforce continuously.
    Agents need a unique, attestable identity and must operate inside a trusted runtime that architecturally enforces their operational, execution, and communication boundaries.
  • Use least privileged access → Bound collective autonomy.
    Individually authorized actions can still be collectively destructive when taken by a swarm of agents acting in parallel. Bounding collective autonomy means actions that are safe individually but risky in aggregate require escalation before they execute.
  • Assume breach → Assume misalignment.
    Agents can drift from their original objective through adversarial manipulation or through unintentional causes, like context shift over time. Enterprises must continuously monitor for that drift and be able to intervene in real time. Teleport’s new capabilities are delivered through Beams, Teleport’s trusted runtime for agents, working in concert with its Identity Security platform, now extended to address agentic behavior:
  • Beams Session Summaries are a summary of an AI agent’s actions: its identity, privileges, tool and API calls, LLM prompts, responses, and reasoning digested into a short human readable summary of what it was doing and what it was thinking. This establishes a behavioral baseline for evaluating agent activity against its declared objective.
  • Agentic Classifiers provide policy for humans, agents or groups of agents to be evaluated against company specific criteria, enabling agent behavior to be flagged that is inconsistent with an agent’s declared objective.
  • Risk Scoring automatically summarizes SSH, Kubernetes, and database sessions, classifies them by risk level and maps actions to the MITRE ATT&CK framework. Infrastructure and Security teams can now automate or manually search across sessions for specific commands, resources, or behaviors.
    Together, these three capabilities in concert with Beams lay the foundation for the agent trust principles: they give agents a cryptographic, continuously monitored identity; they make collective and individual risk visible before action is taken; and they give enterprises the tooling to detect and respond to misalignment as it happens, turning “assume misalignment” from a design principle into a running practice.

Availability

Teleport will preview these capabilities at Black Hat USA 2026 (August 4–6, Mandalay Bay, Las Vegas) at booth #5114. The capabilities will be available for hands-on customer experience this fall. Customers can request to join the technology preview here.

For a deeper discussion on the new Identity Security capabilities, read the blog.

Deepgram Delivers Real-Time Voice AI at the Edge for Use with Snapdragon

Posted in Commentary with tags on July 21, 2026 by itnerd

Deepgram today announced an initiative to bring enterprise-grade speech recognition directly onto PCs powered by Snapdragon® processors. By optimizing Deepgram’s Nova-3 speech-to-text model on the Qualcomm® Hexagon™ NPU in the Snapdragon X Series platform, Deepgram is enabling developers and device manufacturers to deliver real-time voice experiences with greater speed, privacy, and reliability, without relying on a cloud connection. This effort opens the door to further integration of voice into a new generation of intelligent applications across automotive, mobile, AI PC, XR, industrial edge, IoT, and wearable devices.

Many voice AI solutions have historically relied on a cloud-based architecture. Before a response could be delivered, each interaction required audio to leave the device, travel to the cloud, be processed somewhere else, and then return. With this approach, delays and privacy concerns are sometimes introduced, which limit where voice AI can realistically be deployed. Deepgram is fundamentally changing that model, enabling speech recognition to happen directly on the device itself. The result is an entirely new world of applications and user experiences that feel like a natural conversation, whether it is running in a vehicle, on an AI PC, inside an XR headset, or at the edge of a network where connectivity cannot be guaranteed.

Nova-3 advances Deepgram’s industry-leading accuracy, extending its capabilities to a broader range of real-world enterprise use cases and challenging audio conditions. It is the first voice AI model to offer real-time multilingual transcription. Deepgram is also the first to provide users with demonstrably effective and highly accurate self-serve customization – enabling instant vocabulary adaptation without model retraining. Superior accuracy: Nova-3 leads transcription accuracy with a 6.89% word error rate on real-world production audio, a 24.7% lower error rate than the next-best competitor.

To learn more, please visit: https://deepgram.com/partners/qualcomm.

Did BTS star j-hope just give fans a first look at Samsung’s next foldable?

Posted in Commentary with tags on July 21, 2026 by itnerd

Samsung has already confirmed that new Galaxy devices are on the way later this week. But some BTS fans think they might have spotted one in the wild already.

Videos from a BTS sound check in Paris are fueling speculation, as j-hope is seen using what appears to be an unreleased Samsung smartphone. Samsung hasn’t confirmed any product details, but that hasn’t stopped tech enthusiasts from dissecting the device’s size and shape, wondering whether the clips offer a first look at what’s coming next.

If you haven’t seen the videos yet, you can check them out here and here.