Topic
#agent-security
23 articles tagged agent-security. Browse the full set below, or see all topics.
Tagged "agent-security"
Cross-cutting reads on this topic
Meta Muse brings background tasks, browser actions and memory to a US rollout. See what is available, what is coming, and how to assess its privacy.
#Meta#Muse+4 more
2026-09-08
Read Article
A census of what eleven coding-agent harnesses isolate by default and by flag: filesystem scope, network egress, process spawning, credential visibility.
#agent-security#sandboxing+4 more
2026-08-30
Read Article
Default-allow's real cost is not a model mistake but a documented attack primitive. When ask-first is theatre, and why reversibility should route the call.
#agent permissions#coding agents+4 more
2026-08-29
Read Article
A dated ledger of 27 MCP security entries — 25 incidents plus 2 protocol revisions — April 2025 to August 2026: component, defect class, route, patch status.
#mcp-security#model-context-protocol+5 more
2026-08-24
Read Article
We checked 19 widely deployed MCP servers for documented instruction surfaces beyond tool descriptions. Only one discloses one. Undocumented is the finding.
#mcp#agent security+5 more
2026-08-22
Read Article
CrewAI 1.15.17 pins SSRF checks to every redirect hop and the resolved peer IP. The same pattern can sit in any agent tool that fetches a model-supplied URL.
#crewai#ssrf+4 more
2026-08-20
Read Article
Claude Code v2.1.234 hardened the remaining pre-approval NTLM path accesses. Codex CLI 0.148.0 added Bedrock and session forking. What changed for operators.
#claude code#codex cli+5 more
2026-08-18
Read Article
Anthropic's engineering post publishes auto-mode classifier results across three separate datasets. Why an FPR and an FNR from different sets cannot be paired.
#claude-code#auto-mode+5 more
2026-08-16
Read Article
A buyer-side checklist for giving an agent standing access to business systems: what to scope, who holds the secrets, and how revocation works.
#ai-agents#access-control+5 more
2026-08-11
Read Article
xAI's Grok Bot launched in beta on August 11. The launch page says Bots have their own computer; xAI's own docs say an account's Bots all share one.
#grok-bot#xai+5 more
2026-08-11
Read Article
OpenAI says it cannot rule out Critical cyber capability in Astra, an unreleased model, and published the agent controls it applied. Vendor-stated.
#OpenAI#AI Safety+4 more
2026-08-09
Read Article
UK AISI logged 19 unsanctioned agent actions across 10 of 122 cyber-range runs, with classifiers deliberately off and internet access deliberately on.
#AI Safety#Agent Security+4 more
2026-08-09
Read Article
OpenAI, Anthropic and Google skipped NVIDIA's Open Secure AI Alliance a month after joining Akrites. That selectivity, not the absence itself, is the story.
#ai-governance#agent-security+5 more
2026-08-01
Read Article
Claude Code shipped isolation fixes in four of five releases. Separately, GuardFall research defeated command filters in 10 of 11 agents.
#agent-security#sandboxing+5 more
2026-07-26
Read Article
Amp shipped five releases in seven days that turn agents into persistent services. Event-driven orbs expose durable webhook URLs its own docs call a credential.
#amp#agent-automation+5 more
2026-07-26
Read Article
Grok Build reportedly uploaded full repos and git history to xAI's cloud. The /privacy toggle never stopped it — a server-side flag did. Agent trust is infra.
#Grok#AI agents+6 more
2026-07-14
Read Article
Nous Research's Hermes Agent adds Blank Slate mode, booting agents with only file ops and terminal. How upgrade-durable least-privilege tool scoping works.
#nous-research#hermes-agent+5 more
2026-06-22
Read Article
Browser agents now handle read-only marketing tasks like audits and competitor pulls, but fail on gated writes. The use cases that work and the spend red line.
#browser-agents#marketing-ops+6 more
2026-06-07
Read Article
Role-based access control for agentic AI — six design patterns, per-tool scoping, per-tenant isolation, attribute-based extensions. Implementation included.
#agentic-rbac#access-control+7 more
2026-05-09
Read Article
Audit MCP servers across 75 security points — auth, secrets handling, tool scoping, audit logs, prompt-injection defense, and abuse-path coverage.
#mcp-server-security#agent-security+7 more
2026-05-03
Read Article
Prompt injection attack taxonomy for production agents — 10 attack classes, delivery vectors, detection signals, and mitigation matrix for 2026 deployments.
#prompt-injection#agent-security+4 more
2026-04-14
Read Article
OpenClaw's full system access creates significant attack surface. Complete security hardening guide with prompt injection defense and containerization.
#OpenClaw#AI security+4 more
2026-02-09
Read Article
Secure AI agents with enterprise best practices. 24 CVEs across top tools. Prompt injection, data exfiltration prevention. Complete guide.
#AI Security#Agent Security+4 more
2025-11-29
Read Article