Zero trust

Why Your Enterprise Tech Stack Isn’t Ready for AI Agents — Christopher Lovejoy & Saul Howard

Why Your Enterprise Tech Stack Isn’t Ready for AI Agents — Christopher Lovejoy & Saul Howard

Chris Lovejoy and Saul Howard discuss the critical challenges of deploying AI agents in highly regulated enterprise environments, particularly healthcare. They advocate for a "constraints-first" architectural approach, proposing three core primitives – an immutable event log for auditability, schema-driven object storage for sensitive data, and human-agent equivalency for seamless escalation – which collectively enable privacy-preserving evaluations as a fundamental byproduct of the system design, rather than being an afterthought.

What should security leaders do with AI? They don’t know.

What should security leaders do with AI? They don’t know.

This podcast explores the challenges cybersecurity leaders face in adopting AI, the emergence of new threats like ghostjacking, and AI's current capabilities in patching vulnerabilities. It highlights the prevalent "AI decision paralysis" and offers strategic advice for integrating AI into security operations, advocating for a human-in-the-loop approach and a realistic assessment of AI's current

The Promptware Kill Chain: How Prompt Injection Becomes AI Malware

The Promptware Kill Chain: How Prompt Injection Becomes AI Malware

Promptware introduces a new class of AI malware leveraging prompt injections to exploit architectural flaws in LLMs. This summary details The Promptware Kill Chain, covering stages from initial access and jailbreaking to persistence, lateral movement, and real-world impact. It emphasizes the critical need for a Zero Trust approach, treating AI agents as hostile runtimes to defend against these sophisticated AI-native threats.

Why AI Agents Break Zero Trust at the Last Mile

Why AI Agents Break Zero Trust at the Last Mile

AI agents introduce a critical security gap when connecting to legacy enterprise systems, known as the 'agentic last mile identity problem'. This summary explains how losing user identity, context, and delegation breaks zero-trust principles and outlines a solution using a policy-driven vault to manage access and issue short-term credentials.

Stop AI Agents From SQL Injecting Your Database

Stop AI Agents From SQL Injecting Your Database

Averi Kitsch, Staff Software Engineer at Google, outlines a four-step evolution for securing AI agents that access databases, moving from dangerous, model-controlled tools to a zero-trust architecture. Drawing on insights from over 20 million monthly tool calls, the talk provides a practical roadmap for preventing data leaks by separating identities, constraining actions, and removing credentials and PII from the agent's control.

Claude Security’s public beta, OpenAI’s five-point plan and cybersecurity’s Y2K moment

Claude Security’s public beta, OpenAI’s five-point plan and cybersecurity’s Y2K moment

Explore the AI industry's "Y2K moment" in cybersecurity, as major players like OpenAI, Anthropic, and CrowdStrike form coalitions to tackle threats. This summary also delves into a new framework for AI agent identity based on Zero Trust principles and analyzes the "Copy Fail" Linux vulnerability, a decade-old flaw uncovered by AI, highlighting the escalating need for proactive vulnerability research.