Attack Surface & Threat Modeling
Agentic systems introduce attack surfaces that traditional threat modeling frameworks weren't built to handle—autonomous tool use, multi-agent trust boundaries, dynamic memory, and delegated credentials all demand a different analytical approach. This category covers how to systematically identify, map, and prioritize threats across the full agentic stack, from design-time architecture reviews through runtime exposure analysis. Expect concrete methodologies, worked examples, and honest assessments of where current frameworks fall short.
- OpenAI, Netflix, and Dave Are Rethinking How Coding Agents Get Secured From the Inside Out —
- The Most Important Person in Your Next Meeting Isn't a Person: Joe Sullivan on AI Notetakers as Infrastructure —
- Anthropic's Nicholas Carlini on How LLMs Are Already Finding Zero-Days Humans Missed for Decades —
- Malicious VS Code Extensions Are the New Supply Chain Backdoor: What Developers Must Know —
- Silent Secret Theft: How AI Coding Agents Expose Your API Keys Without Warning — AI coding agent security risks are quietly exposing API keys through context windows, logs, and generated code - here's how to close the gaps.
- How Agentic AI Coding Tools Are Becoming Prime Targets for IDE-Based Malware Attacks —
- Unsanctioned AI Dev Tools Are Your Newest Attack Surface: How to Govern Them Without Killing Productivity — Shadow AI coding tools are already in your development pipeline - here's how to govern them without turning security into a productivity tax.
- Threat Modeling Tool Misuse Across AI Agent Architectures —
- Threat Modeling Memory Stores in Multi-Agent Architectures —
- MCP Server Security: The Trust Boundary Most Teams Haven't Thought Through — MCP server security is the trust boundary most teams have not thought through - here is how to model it before an attacker does.
- LangChain, LangGraph, and AutoGen Security Gaps: 7 Fixes for Agentic Frameworks (2026) — LangChain, LangGraph, and AutoGen have concrete, exploitable security vulnerabilities — in tool calling, state management, and inter-agent trust. Here is where the gaps live, how attackers exploit them, and the seven defensive controls you can implement today.
- Privilege Escalation in Agentic Systems: How Agents Acquire Permissions They Shouldn't Have — Privilege escalation in agentic systems happens when agents acquire access beyond their intended scope - and most frameworks make this easy by conflating capability with authorization.
- Supply-Chain Risk in Agentic Pipelines: Where Trust Breaks Down —
- Why Teams Skip Threat Modeling — And How to Change That — Threat modeling for agentic systems is unfamiliar territory - here is why teams skip it and how to build the habit without overhauling your workflow.
- How to Map Your Attack Surface Before Attackers Do — Learn how to map your attack surface before attackers do - with practical steps for finding exposed assets, building an inventory, and staying ahead of new risks.
- Threat Modeling Modern Apps: STRIDE Without the Overhead — Learn how to apply STRIDE threat modeling to modern apps without the overhead that makes most teams quit after the first session.
- The AI Security Blind Spots Most Teams Don't Talk About — AI security blind spots hide in the gaps between familiar frameworks and newer risks - here's how to find them before someone else does.
- Threat Modeling AI Agents: What STRIDE Misses — Threat modeling for agentic AI systems exposes the gaps that STRIDE was never designed to find - corrupted context, dynamic tool trust, and permission escalation that looks like normal operation.
- Prompt Injection in Multi-Agent Pipelines: Attack Paths and Fixes — Prompt injection in multi-agent pipelines travels farther than most threat models expect - here is how adversarial instructions propagate across agent boundaries and what architectural controls can actually stop them.