GeneralAI Agents Can Now Run in Sandboxes
Microsoft has introduced Microsoft Execution Containers (MXC), a policy-driven execution layer that runs AI agents in isolated environments on Windows and WSL. If your team is deploying autonomous age
Expert perspectives on application security, compliance, and emerging threats
GeneralMicrosoft has introduced Microsoft Execution Containers (MXC), a policy-driven execution layer that runs AI agents in isolated environments on Windows and WSL. If your team is deploying autonomous age
GeneralSecurity teams often treat AI agents like advanced APIs, but they re not. The recent Zscaler research revealing indirect prompt injection vulnerabilities in four models highlights a critical issue: yo
ResearchYour AI coding agent just installed a new skill from the marketplace. The static scanner gave it a clean bill of health. Three days later, you re investigating why production data is leaving your netw
IncidentA development team deployed a customer dashboard that let authenticated users view any account by changing a URL parameter. The vulnerability sat in production for three months before a penetration te
Get weekly security insights and compliance updates delivered to your inbox.
GeneralScope This guide explains how to manage AI security tools as supply chain dependencies requiring formal risk management. It covers: Identifying critical AI dependencies in your security workflow Build
IncidentWhat Happened A financial services company with 2,800 employees spent 18 months feeding vulnerability data into their exposure management platform. Their dashboard showed 847 critical findings. The se
GeneralYou can t audit what you can t define. When your LLM returns a user profile, incident report, or configuration change, you need to know exactly what fields you re getting, what types they are, and whe
IncidentWhat Happened Capital One s AI Foundations group developed a reinforcement learning system to identify effective jailbreak techniques against large language models. They tested it using the WildJailbr
GeneralYou ve probably seen the demos: type a single command, watch an AI agent probe your infrastructure, generate exploits, and produce a vulnerability report. Lyrie, the open-source autonomous pentesting
IncidentInconsistent Results from LLM Security Reviews Snyk conducted 250 identical security reviews using Claude on the same JavaScript codebase. The outcome was startling: 80 of 161 unique findings appeared
GeneralThe Conventional Wisdom Security teams often treat AI coding agents like advanced code generators. The typical approach: let the agent generate code, then scan the output. This includes static analysi
IncidentA Wake Forest University research team analyzed 444 iOS apps with LLM features and found 282 exposing exploitable credentials. These were plaintext API keys and authentication tokens visible in networ
IncidentThe Problem Between 2023 and 2024, HTTP Archive analyzed 418,112 websites using Google Chrome s Lighthouse auditing tool. The findings revealed that 77% of these sites serve at least one JavaScript li
IncidentWhat Happened On November 27th, security researchers disclosed a high-severity Remote Code Execution vulnerability in EJS, a widely-used JavaScript templating engine. This vulnerability allowed attack
IncidentBetween late 2025 and April 11, 2026, North Korean threat actors published 108 malicious packages and extensions across npm, PyPI, Chrome Web Store, and other platforms as part of the PolinRider campa
ResearchYou are facing a critical decision: whether to allow AI-generated code into production environments. Nearly half of surveyed organizations already run this code in production, while the other half hes