The Shadow AI Beneath the Surface: Finding Unsanctioned Agents Before They Bite
A practical runbook for detecting and managing unauthorized AI agents, copilots, and automated workflows in enterprise environments.
A practical runbook for detecting and managing unauthorized AI agents, copilots, and automated workflows in enterprise environments.
This article explains how to govern MCP gateways and server layers in enterprise agent control planes, focusing on security, admission, and routing.
Explains non-human identity sprawl, its risks in cloud/hybrid environments, and how security teams can manage machine identities at scale.
Explains the key differences between microservices and AI agents, highlighting broken assumptions and security risks.
Explains how to combine AWS AgentCore with Agentgateway for secure, identity-aware authentication in AI agent deployments.
A software developer discovers a data exposure vulnerability in Eversource's EV charger rebate portal, exposing customer PII.
Deno Sandbox is a new hosted sandbox service from Deno Deploy, allowing secure code execution with features like secret management and resource limits.
Security researchers found a vulnerability in Claude Cowork allowing data exfiltration via the Anthropic API, bypassing default HTTP restrictions.
A security vulnerability in Claude Cowork allowed file exfiltration via the Anthropic API, bypassing default HTTP restrictions.
A practical guide to implementing essential API security best practices in Spring Boot, including HTTPS, JWT authentication, authorization, and rate limiting.
Explains rate limiting strategies in ASP.NET Core, including fixed window, sliding window, token bucket, and concurrency limiters.
A guide to implementing passwordless, cross-tenant authentication for Azure API Management using Managed Identities and Federated Credentials.
Argues against using API keys for securing enterprise AI tools like LLMs and agents, highlighting security flaws and recommending better alternatives.
A security researcher discovers goHardDrive exposed thousands of customer records via an insecure RMA status check form with no authentication.
AI agents' autonomous and probabilistic nature forces stricter security and authorization models, breaking traditional microservice assumptions.
Argues that APIs should not redirect HTTP to HTTPS, but instead disable HTTP or return errors, to prevent accidental unencrypted data exposure.
Microsoft integrates Azure Web Application Firewall (WAF) with Copilot for Security, enhancing threat detection and analysis for web apps and APIs.
Using Azure API Management to protect JSON REST APIs by validating payloads against a JSON schema and enforcing size limits.
A guide on using Ollama's Modelfile to create and deploy a custom large language model (LLM) for specific tasks, like an API security assistant.
Using Azure API Management to control API access and validate parameters per team, securing an Azure Function for DevOps agent management.