Blog
- OpenAI, Netflix, and Dave Are Rethinking How Coding Agents Get Secured From the Inside Out —
- The Most Important Person in Your Next Meeting Isn't a Person: Joe Sullivan on AI Notetakers as Infrastructure —
- The Agentic SOC Is Here: How Salesforce, Datadog, and GreyNoise Are Putting Autonomous Agents on the Front Line —
- Google's Heather Adkins and Four Flynn on Weathering AI's "Perfect Storm" of Security Risk — Heather Adkins and Four Flynn's AI security strategy for agentic systems - from treating agents as untrusted intermediaries to hardening prompt injection defenses in
- AISLE Found 12 Zero-Days in OpenSSL. FENRIR Found 100+ More. What AI-Discovered Vulnerabilities Mean for Defenders — AI-discovered zero-days from AISLE and FENRIR are not a new threat category - they are a volume problem your triage process must handle without panic or shortcuts.
- Stripe, Snap, and Sondera on Stopping Prompt Injection Without Neutering Your Agents — Stripe, Snap, and Sondera's practitioners explain why prompt engineering is not a security boundary for agentic systems - and what capability-based authorization actually looks like in production.
- How Snowflake, FFF Enterprises, and Sysdig Are Building AI Governance That Doesn't Kill Innovation — Ragini Ramalingam, Billy Norwood, and Sergej Epp are building enterprise AI governance that actually works - here's the risk-based model replacing the approval-gate approach.
- Rob T. Lee Gave Claude Code Root on a DFIR Workstation - Here's What SANS Learned — Rob T. Lee gave Claude Code root on a SIFT workstation at [un]prompted - and what SANS learned exposes the core misconception behind agentic security in DFIR environments.
- Inside Trail of Bits' AI-Native Transformation: Dan Guido on Building a Security Firm Around Autonomous Agents — Dan Guido and Trail of Bits show why AI-native security consulting requires rearchitecting for autonomous scale - not wrapping LLMs around existing processes.
- Anthropic's Nicholas Carlini on How LLMs Are Already Finding Zero-Days Humans Missed for Decades —
- Human Oversight in Agentic Systems: What Governance Actually Looks Like in Production — Human oversight in agentic systems fails not because the controls are missing but because they are designed for the ideal case, not the production one.
- How to Red-Team an Agentic System: A Practitioner's Methodology — A practitioner's methodology for red-teaming agentic systems - covering tool inventory mapping, authority probing, prompt injection, and lateral movement simulation in autonomous agent environments.
- Incident Response for Agentic AI: What to Do When an Agent Has Already Acted — When an agent has already acted, incident response for agentic AI means reconstructing the action chain, containing real damage, and preventing the same failure from recurring.
- From RBAC to ABAC: A Practical Access Control Roadmap for AI Agents and Autonomous Systems —
- Inside LLM Security Flaws: What the Latest Vulnerability Research Means for Agentic AI Systems —
- Beyond Token Revocation: How VS Code Extensions Can Plant Persistent GitHub Backdoors —
- Malicious VS Code Extensions Are the New Supply Chain Backdoor: What Developers Must Know —
- How Open-Source Security Layers Are Closing the Safety Gaps in Agentic AI Systems —
- Silent Secret Theft: How AI Coding Agents Expose Your API Keys Without Warning — AI coding agent security risks are quietly exposing API keys through context windows, logs, and generated code - here's how to close the gaps.
- Inside Agentic AI Architectures: How Prompts, Timers, and Skill Modules Shape Agent Behavior —