AI Agents

AI Agents examines autonomous and semi-autonomous AI systems that can reason, plan, use tools, access data, and take actions across enterprise environments. Coverage includes agent architectures, identity, MCP, tool use, authorization, memory, multi-agent systems, delegated authority, security risks, and governance—with a CISO focus on securing AI as it evolves from generating content to executing decisions and actions.
23
Aug
The AI Supply Chain Can Execute Before the Application Does

The AI Supply Chain Can Execute Before the Application Does

AI artifacts are no longer passive data. DEF CON 34 shows how models, Skills, repositories and loaders can become execution paths — forcing CISOs to rethink supply-chain security, provenance and runtime authority.
14 min read
19
Aug
MCP Is Becoming Enterprise Infrastructure

MCP Is Becoming Enterprise Infrastructure

MCP is becoming enterprise infrastructure. As AI agents gain access to tools, identities and business systems, CISOs must govern not just integration — but the authority flowing through it.
15 min read
19
Aug
The Agent Is Becoming the New Privileged User

The Agent Is Becoming the New Privileged User

AI agents are becoming a new privileged identity class. The real security question is no longer what AI can know — but what it is authorized to do, through whose identity, and with what consequences.
14 min read
19
Aug
MCP Is Becoming an Attacker’s Routing Layer

MCP Is Becoming an Attacker’s Routing Layer

An AI agent’s real privilege extends far beyond its IAM permissions. MCP, managed identities and connected services create transitive authority paths that attackers can exploit—turning tool connectivity into a new routing layer for enterprise privilege.
17 min read
18
Aug
The Agent Is the New Attack Path

The Agent Is the New Attack Path

A safe model does not imply a safe agent. Agentic AI shifts the security problem from jailbreaks to authority: can an attacker make the system perform an authorized action for an unauthorized reason?
17 min read
18
Aug
When Data Becomes Instruction

When Data Becomes Instruction

AI agents are erasing the boundary between data and instruction. DEF CON 34 shows why untrusted context can become an indirect control plane—and why CISOs must secure the entire path from meaning to authority.
15 min read
03
Aug
Identity Becomes the New Security Perimeter

Identity Becomes the New Security Perimeter

The future of cybersecurity will not be secured by firewalls but by identities. Humans are becoming just one identity type among AI agents, APIs, machines and services. CISOs must rethink Identity as the primary security perimeter.
4 min read
27
Jul
Autonomous AI Cyberattacks May Be Rare. The Capability Behind Them Will Not Be.

Autonomous AI Cyberattacks May Be Rare. The Capability Behind Them Will Not Be.

A recent AI security incident is being treated as an isolated event. That misses the point. The real lesson is not autonomous cyberattacks—it is that agentic AI has demonstrated the ability to develop unsafe attack trajectories. CISOs should rethink governance now.
11 min read
21
Jul
AI Sprawl Is Already Here

AI Sprawl Is Already Here

5 min read
07
Jul
AI Cost Governance Is Becoming a Security Control

AI Cost Governance Is Becoming a Security Control

AI cost governance is becoming a security control. As chatbots evolve into agents, costs are driven by autonomous decisions, retrieval and tools—not users alone. The question is no longer what a token costs, but whether the organization can still see, limit and justify its AI-driven work.
11 min read