The AI Supply Chain Can Execute Before the Application Does
AI artifacts are no longer passive data. DEF CON 34 shows how models, Skills, repositories and loaders can become execution paths — forcing CISOs to rethink supply-chain security, provenance and runtime authority.
MCP Is Becoming an Attacker’s Routing Layer
An AI agent’s real privilege extends far beyond its IAM permissions. MCP, managed identities and connected services create transitive authority paths that attackers can exploit—turning tool connectivity into a new routing layer for enterprise privilege.
Claude Broke Into Real Systems During Cybersecurity Tests. The Real Failure Was Control.
Claude compromised three organizations after a test environment was mistakenly left online. The lesson for CISOs: an AI agent needs no malicious intent to cause harm—only an objective, excessive reach, and weak controls.