Agentic AI Security: When Your AI Has Hands
A chatbot that can only talk is a content-moderation problem. A chatbot that can browse, write code, and call APIs is a security problem. Here's what changes architecturally when AI gets hands.
Read MoreCybersecurity and AI security insights — threat analysis, AI red teaming, and practical knowledge from 17+ years on the front lines
A chatbot that can only talk is a content-moderation problem. A chatbot that can browse, write code, and call APIs is a security problem. Here's what changes architecturally when AI gets hands.
Read MoreJailbreaking targets the model's safety alignment, not the application built on top of it. A practitioner's tour of the current technique families and why none of them have a clean fix.
Read More“Autonomous AI pentester” is doing a lot of marketing work right now. Here's an honest split between what's real, what's brittle, and where AI genuinely multiplies a tester's effectiveness today.
Read MoreCTEM gets cited constantly and implemented rarely. A practical, stage-by-stage breakdown of what it actually takes to stand up a continuous exposure management program.
Read MoreRAG doesn't just make an LLM smarter — it adds an entire new component, the vector store, with its own attack surface that traditional AppSec tooling wasn't built to cover.
Read MoreText-based prompt injection is well documented. The same problem now extends to images, audio, and video — and provenance gets a lot harder when the instruction is hiding in a pixel, not a sentence.
Read MoreDownloading a pretrained model is downloading an executable artifact from a third party. The ML supply chain has its own failure modes, distinct from — and less mature than — traditional software supply chain security.
Read More“Monitor your AI systems” is not a detection strategy. Here's the actual telemetry, log fields, and correlation logic that catches prompt injection, jailbreak attempts, and agent misuse in production.
Read MoreTwo attack classes with a long academic literature and a short list of organizations actually defending against them in production: model extraction and membership inference.
Read MoreTier 1 triage automation is real and working. Fully “autonomous SOC” remains more roadmap than reality. A realistic look at where AI-driven security operations actually stand.
Read MoreTen risk categories every team shipping an LLM-integrated application needs to understand — what they actually look like in production, and what to do about each one.
Read MoreThe EU AI Act and the NIST AI RMF aren't legal-team problems alone. What security teams specifically need to operationalize — model inventory, risk classification, oversight, and incident reporting.
Read MoreRansomware operators are weaponizing artificial intelligence to automate reconnaissance, lateral movement, and encryption at unprecedented speed and scale. Here's how AI is reshaping the ransomware landscape—and how defenders can fight back.
Read MoreAI-generated voice cloning has turned phone calls into the new frontier of social engineering. From fake CEO wire transfers to family emergency scams, deepfake audio is bypassing human trust at an unprecedented scale.
Read MoreNation-state actors are stockpiling encrypted data today, betting that quantum computers will crack it tomorrow. The threat isn't hypothetical—it's happening right now. Here's what defenders need to know about the quantum decryption timeline and post-quantum cryptography migration.
Read MorePrompt injection attacks are turning trusted AI assistants into weapons. From calendar invite hijacking to supply chain poisoning via malicious documentation, LLMs are the new attack surface—and most organizations aren't ready.
Read MoreThe Salesforce breach exposed 15,000+ organizations through a single compromised vendor. Supply chain attacks are the perfect storm: maximum impact, minimal detection, impossible to patch. Here's how third-party risks are redefining enterprise security.
Read MoreA single misconfigured S3 bucket exposed 3TB of customer data. An overprivileged IAM role cost $847K in cryptomining fees. Multi-cloud complexity is turning basic security hygiene into advanced calculus—and attackers are passing the test.
Read MoreArtificial intelligence is fundamentally transforming how red teams conduct offensive security operations. From automated reconnaissance to AI-powered attack simulation, explore how machine learning is reshaping the penetration testing landscape.
Read MoreAs cyber threats grow more sophisticated, blue teams are turning to artificial intelligence to level the playing field. From anomaly detection and behavioral analysis to automated incident response, AI is transforming defensive security operations.
Read MoreThe traditional "castle-and-moat" security model is dead. In an era of cloud computing, remote work, and sophisticated threats, Zero Trust Architecture offers a fundamentally different approach: never trust, always verify.
Read MoreContinuous Threat Exposure Management (CTEM) represents a paradigm shift from periodic security assessments to continuous validation. Learn how adversarial validation, breach and attack simulation, and purple teaming create measurable, evidence-based security.
Read More