Skip to main content

MCP, SASE, and CISA updates across AI and enterprise security - Week of December 15, 2025

Companies mentioned

Overview of Recent Activity

Recent vendor and government updates addressed how AI tools were connected to enterprise automation, how data integration and multicloud architectures were marketed and deployed, and how security governance and vulnerability remediation expectations evolved. Multiple organizations also reported operational and market signals across broadband quality, RAN and SASE spending, credential security integrations, and agentic AI oversight to improve workflow reliability.

Key Themes and Developments

Technology Releases & Product Enhancements

Itential published a step-by-step guide for deploying its Model Context Protocol (MCP) server and integrating it with Microsoft Copilot AI Studio, describing authentication configuration, tool discovery, and a Copilot agent that manages infrastructure.

Vectara launched Tool Validator, a governance component that reviewed agents’ proposed tool calls by flagging erroneous or irrelevant tool calls before execution, suggesting missing tools, and logging errors and adjustments for traceability.

Partnerships & Ecosystem Engagement

Oracle offered Oracle Database@Google Cloud in Canada, with availability in Montreal and Toronto, and stated that Google Cloud and Oracle partners could resell the offering through Google Cloud Marketplace and use existing Google Cloud commitments for procurement.

Commvault integrated Delinea Secret Server with Commvault Cloud to connect a secrets vault to backup and restore workflows, providing storage, rotation, just-in-time issuance of temporary credentials, revocation upon completion, and audit logs.

Infrastructure, Platform, or Deployment Updates

Futuriom reported that agentic AI, observability, and orchestration were converging to enable closed-loop operations across hybrid and multicloud infrastructure, urging enterprises to add governance and orchestration before deployment.

Dell'Oro Group reported SASE market growth of 21% year-over-year in 3Q25 to nearly $3 billion while Access Router spending fell 25%, and it framed SASE as the default architecture for branch, remote, and cloud access as enterprises standardized on cloud-delivered networking and security platforms.

Additional Updates from Other Organizations

CISA published Cross-Sector Cybersecurity Performance Goals (CPG 2.0), adding a governance component focused on accountability, risk management, and integrating cybersecurity into day-to-day operations for IT and OT environments.

CISA also added CVE-2025-58360, an OSGeo GeoServer XML external entity vulnerability, to the Known Exploited Vulnerabilities Catalog after evidence of active exploitation.

Full Update Index

  1. Itential outlines MCP setup for Microsoft Copilot
    Itential details deploying its MCP server and integrating it with Microsoft Copilot AI Studio for tool discovery and workflow automation.
  2. CData Software included in 2025 Gartner Magic Quadrant
    CData Software was included in the 2025 Gartner Magic Quadrant for Data Integration Tools for a second consecutive year.
  3. Singtel named Frost & Sullivan's 2025 Singapore company of the year in cybersecurity
    Frost & Sullivan named Singtel 2025 Singapore Company of the Year in cybersecurity services for national digital resilience.
  4. Dell'Oro Group reports broadband shift from speed to experiential quality
    Dell'Oro Group says broadband will shift from headline speeds to latency, jitter and reliability in 2026.
  5. Dell'Oro Group forecasts stable RAN revenue in 2026
    Dell’Oro Group forecasts RAN revenue to hold steady in 2026, with mixed segment growth and regional variations.
  6. Futuriom Research details agentic AI and orchestration needs
    Futuriom report says agentic AI requires centralized governance and orchestration for hybrid and multicloud operations.
  7. CISA updates cybersecurity performance goals with governance component
    CISA released CPG 2.0, adding a governance component and measurable actions for IT and OT to reach a foundational cybersecurity level.
  8. CISA issues 12 advisories on industrial control systems
    CISA issued 12 ICS advisories covering products from Johnson Controls, Siemens, AzeoTech, OpenPLC_V3, GDCM, and Varex Imaging.
  9. CISA adds GeoServer XXE to KEV catalog
    CISA added CVE-2025-58360, an OSGeo GeoServer XML external entity vulnerability, to the Known Exploited Vulnerabilities Catalog.
  10. Deloitte outlines CES 2026 schedule and sessions
    Deloitte detailed its CES 2026 schedule of sessions, speakers and LinkedIn Live briefings for Jan. 6–9 in Las Vegas.
  11. Dell'Oro Group reports SASE market grew 21% in 3Q25
    Dell'Oro Group reports SASE revenue rose 21% in 3Q25 while Access Router spending fell 25%.
  12. Vectara launches Tool Validator for agentic AI oversight
    Vectara launched Tool Validator to review agents' proposed tool calls, flag errors, suggest fixes, and log adjustments before workflow execution.
  13. Opera Limited opens public access to Opera Neon
    Opera opened public access to Opera Neon, an agentic browser offering subscribers access to top AI models and agent tools.
  14. HFS Research finds ServiceNow services strained by AI
    HFS Research and NewRocket found many ServiceNow programs stalled as AI exposed limits in people-dependent service models.
  15. Oracle offers Database@Google Cloud in Canada
    Oracle offered Oracle Database@Google Cloud in Canada with availability in Montreal and Toronto and a partner resale program.
  16. Xsight Labs details X2 switch use in Starlink V3 satellites
    Xsight Labs announced its X2 Ethernet switch will power Starlink V3 satellites, offering 12.8 Tbps switching and space-qualified testing.
  17. Rapid7 outlines 2026 cybersecurity predictions
    Rapid7 released 2026 cybersecurity predictions citing geopolitical spillover, rising insider threats, and need for contextual intelligence.
  18. RelationalAI receives $22.5 million from Snowflake and AT&T Ventures
    RelationalAI received a $22.5 million investment from Snowflake Ventures and AT&T Ventures to scale its GenAI-native decision intelligence system.
  19. Tenable signs OneGov agreement with GSA
    Tenable signed a OneGov agreement with GSA to offer its FedRAMP-authorized cloud security solution to federal agencies at a discount through March 31, 2027.
  20. Commvault integrates Delinea Secret Server with Commvault Cloud
    Commvault integrated Delinea Secret Server with Commvault Cloud to improve credential security and compliance for joint customers.
  21. Dell'Oro Group reports 21% SASE growth in 3Q2025
    Dell'Oro Group said global SASE revenue rose 21% year-over-year in 3Q2025 to nearly $3 billion; Access Router revenue fell 25%.
  22. Mycom introduces AInsights fault-correlation capability
    Mycom added a fault-correlation capability to its AInsights application to help communications service providers reduce alarm volume and prioritize faults.
  23. Netcraft publishes five cybersecurity predictions
    Netcraft published five predictions for 2026 covering AI vulnerabilities, Phishing-as-a-Service, attack-surface management, seasonal scams, and targets.
  24. IBM partners with Pearson to build AI learning tools
    IBM and Pearson formed a global partnership to build AI-powered learning products for organizations and institutions.
  25. Nordic Semiconductor launches nRF9151 SMA Development Kit
    Nordic Semiconductor launched the nRF9151 SMA Development Kit and released firmware adding NB‑IoT NTN support.

Graph Connections

23 companies named across 18 categories, one of 487 sources referencing Cybersecurity and Infrastructure Security Agency (CISA). Previous coverage: CISA updates cybersecurity performance goals with governance component (December).