Agentic AI

Agentic AI explores autonomous and semi-autonomous AI systems that can reason, plan, use tools, access data, and act across enterprise environments. Coverage focuses on AI agents, multi-agent systems, identity, authorization, MCP, delegated authority, security architecture, governance, and the emerging risks CISOs must address as AI moves from generating information to taking action.
10
Sep
When Security Tools Become the Attack Surface

When Security Tools Become the Attack Surface

12 min read
10
Sep
The New AI Supply Chain

The New AI Supply Chain

The AI supply chain no longer delivers only software. Models, prompts, skills, MCP servers and runtimes can all shape execution. CISOs must start governing not only executable code, but executable meaning.
12 min read
23
Aug
The AI Supply Chain Can Execute Before the Application Does

The AI Supply Chain Can Execute Before the Application Does

AI artifacts are no longer passive data. DEF CON 34 shows how models, Skills, repositories and loaders can become execution paths — forcing CISOs to rethink supply-chain security, provenance and runtime authority.
14 min read
19
Aug
The Agent Is Becoming the New Privileged User

The Agent Is Becoming the New Privileged User

AI agents are becoming a new privileged identity class. The real security question is no longer what AI can know — but what it is authorized to do, through whose identity, and with what consequences.
14 min read
19
Aug
MCP Is Becoming an Attacker’s Routing Layer

MCP Is Becoming an Attacker’s Routing Layer

An AI agent’s real privilege extends far beyond its IAM permissions. MCP, managed identities and connected services create transitive authority paths that attackers can exploit—turning tool connectivity into a new routing layer for enterprise privilege.
17 min read
18
Aug
The Agent Is the New Attack Path

The Agent Is the New Attack Path

A safe model does not imply a safe agent. Agentic AI shifts the security problem from jailbreaks to authority: can an attacker make the system perform an authorized action for an unauthorized reason?
17 min read
31
Jul
Claude Broke Into Real Systems During Cybersecurity Tests. The Real Failure Was Control.

Claude Broke Into Real Systems During Cybersecurity Tests. The Real Failure Was Control.

Claude compromised three organizations after a test environment was mistakenly left online. The lesson for CISOs: an AI agent needs no malicious intent to cause harm—only an objective, excessive reach, and weak controls.
16 min read
29
Jul
Agents Fail Differently

Agents Fail Differently

6 min read
27
Jul
Autonomous AI Cyberattacks May Be Rare. The Capability Behind Them Will Not Be.

Autonomous AI Cyberattacks May Be Rare. The Capability Behind Them Will Not Be.

A recent AI security incident is being treated as an isolated event. That misses the point. The real lesson is not autonomous cyberattacks—it is that agentic AI has demonstrated the ability to develop unsafe attack trajectories. CISOs should rethink governance now.
11 min read
23
Jul
AI-Driven Attacks: Why the Existing Security Architecture Will Not Be Enough

AI-Driven Attacks: Why the Existing Security Architecture Will Not Be Enough

AI is not simply making attacks faster. It is changing how they adapt, scale and hide inside legitimate business activity. The next detection gap is no longer technical alone—it is contextual. This series explores what CISOs must rethink before autonomous attackers arrive.
5 min read