GeneralAI Agent Visibility Won't Save You
Your security team can see the AI agents running across your SaaS platforms, developer environments, and cloud workflows. You ve cataloged them, mapped their API calls, and maybe even built a dashboar
Expert perspectives on application security, compliance, and emerging threats
GeneralYour security team can see the AI agents running across your SaaS platforms, developer environments, and cloud workflows. You ve cataloged them, mapped their API calls, and maybe even built a dashboar
GeneralThe Conventional Wisdom Security teams are revisiting their incident response playbooks from the worm era, convinced that lessons from Code Red, Nimda, and Slammer will help secure AI systems. The ide
GeneralScope This guide focuses on post-incident forensic analysis for AI-generated code when you suspect your coding assistant has been compromised through training data poisoning. You ll learn how to evalu
GeneralYour developers are shipping AI agents that need database passwords, API keys, and service account credentials. Meanwhile, your security team is discovering these secrets hardcoded in configuration fi
Get weekly security insights and compliance updates delivered to your inbox.
GeneralYour web agents can read natural language. So can attackers. Cross-Site Prompting (XSP) exploits the same trust boundary weakness as Cross-Site Scripting, but instead of injecting JavaScript, attacker
GeneralYou ve locked down your API keys, you re running static analysis on your codebase, and your network security team has implemented zero trust for human users. When your engineering team proposes deploy
GeneralThe Conventional Wisdom Security teams are rushing to buy AI agent security platforms. The pitch sounds reasonable: AI agents move too fast for humans to monitor, they access systems autonomously, and
GeneralYou clone a repository, open it in your editor, and malicious code executes before you ve reviewed a single line. This isn t a theoretical attack; it s how untrusted search path vulnerabilities work i
GeneralMany believe you can secure AI models just like software artifacts. Sign them with the same tools, scan them with the same scanners, and apply the same supply chain controls you use for container imag
GeneralExecutive Order 14028 pushed agencies, contractors, and enterprises to invest in SBOMs, signing, and provenance. Three years later, you ve got transparency into your software composition. You know wha
GeneralWhen an AI agent autonomously plans, writes, tests, and ships code, your security checkpoints need to adapt. Traditional AppSec gates won t catch what happens when an agent pulls in a malicious skill
GeneralThe Conventional Wisdom Run your SAST and DAST tools, fix what they flag, and you ve secured your application. The dashboard shows green. The compliance report looks solid. Your automated security pip
GeneralScope This guide focuses on detecting, responding to, and preventing compromised npm packages in production development environments. It includes pre-installation verification, runtime monitoring, inc
GeneralThe conventional wisdom : If we train AI models better, add more safety guardrails, and fine-tune their behavior, we ll solve the prompt injection problem. It s a training issue, not a design flaw. Wh
GeneralStatic scanning tools can t keep up with obfuscated AI agent skills. Research from Hong Kong University of Science and Technology shows that SkillCloak, a tool designed to hide malicious code in AI ag
GeneralYour vendor just sent you an SBOM. You need to know if it s actually useful or just compliance theater. CISA updated their SBOM guidance to require information for all components with no minimum depth