Renn Calloway
Renn Calloway writes about the unglamorous middle layer of agentic security—the orchestration logic, tool registries, and inter-agent message passing that most threat models treat as an afterthought. Having spent years building and stress-testing autonomous pipelines in private-sector environments, Renn brings a red-teamer's instinct for the edge case and an architect's frustration with security controls that look good on paper and fail in production. When not breaking things deliberately, Renn writes about governance gaps, emerging red-team methodologies, and the slow, hard work of making agentic systems trustworthy enough to actually deploy.
Articles by Renn Calloway
- The Most Important Person in Your Next Meeting Isn't a Person: Joe Sullivan on AI Notetakers as Infrastructure —
- AISLE Found 12 Zero-Days in OpenSSL. FENRIR Found 100+ More. What AI-Discovered Vulnerabilities Mean for Defenders — AI-discovered zero-days from AISLE and FENRIR are not a new threat category - they are a volume problem your triage process must handle without panic or shortcuts.
- Rob T. Lee Gave Claude Code Root on a DFIR Workstation - Here's What SANS Learned — Rob T. Lee gave Claude Code root on a SIFT workstation at [un]prompted - and what SANS learned exposes the core misconception behind agentic security in DFIR environments.
- Human Oversight in Agentic Systems: What Governance Actually Looks Like in Production — Human oversight in agentic systems fails not because the controls are missing but because they are designed for the ideal case, not the production one.
- From RBAC to ABAC: A Practical Access Control Roadmap for AI Agents and Autonomous Systems —
- Malicious VS Code Extensions Are the New Supply Chain Backdoor: What Developers Must Know —
- Inside Agentic AI Architectures: How Prompts, Timers, and Skill Modules Shape Agent Behavior —
- How Agentic AI Is Rewriting the Rules of State-Sponsored Cyber Espionage —
- Threat Modeling Tool Misuse Across AI Agent Architectures —
- Threat Modeling Memory Stores in Multi-Agent Architectures —
- MCP Server Security: The Trust Boundary Most Teams Haven't Thought Through — MCP server security is the trust boundary most teams have not thought through - here is how to model it before an attacker does.
- Runtime Monitoring for AI Agents: What to Watch, What to Log, and What to Alert On — Runtime monitoring for AI agents requires semantic observability, not just latency thresholds - here's what to log, what to alert on, and where conventional monitoring fails.
- Supply-Chain Risk in Agentic Pipelines: Where Trust Breaks Down —
- Defensive Architecture Principles Every Security Team Needs — Defensive architecture principles give security teams the structural guardrails to constrain agent behavior before something goes wrong - not after.
- Defense-in-Depth for AI Pipelines: A Layered Control Guide — Defense-in-depth for AI pipelines means layering input, model, output, execution, and monitoring controls so that when one safeguard fails, others are already in place.
- Threat Modeling Modern Apps: STRIDE Without the Overhead — Learn how to apply STRIDE threat modeling to modern apps without the overhead that makes most teams quit after the first session.
- Prompt Injection in Multi-Agent Pipelines: Attack Paths and Fixes — Prompt injection in multi-agent pipelines travels farther than most threat models expect - here is how adversarial instructions propagate across agent boundaries and what architectural controls can actually stop them.