<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sase on CuraSec</title><link>https://curasec.metacog.co.kr/tags/sase/</link><description>Recent content in Sase on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 16 Jul 2026 12:18:39 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/sase/index.xml" rel="self" type="application/rss+xml"/><item><title>SASE AI Blind Spot: Packet Inspection Insufficient for Modern Workflows</title><link>https://curasec.metacog.co.kr/insights/2026-07-16-sase-has-an-ai-blind-spot-inspecting-packets-is-no-longer-en/</link><pubDate>Thu, 16 Jul 2026 12:18:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-16-sase-has-an-ai-blind-spot-inspecting-packets-is-no-longer-en/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Useful framing on why TLS inspection alone misses data exfiltration through AI tools and browser extensions; worth incorporating into threat model reviews for SaaS-heavy environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Highlights a detection gap where sensitive data leaves via AI assistants and browser extensions outside traditional proxy visibility — relevant context for evaluating current log coverage.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your security architecture relies heavily on SASE/proxy inspection, commission a review this quarter of unsanctioned AI tool usage and whether current controls cover browser-based data egress.&lt;/li>
&lt;/ul></description></item></channel></rss>