Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Treat Your AI Agents Like Humans or You Are Creating Risk

AI agents are about to act as humans inside your organization. Curtis Koenig, Head of Application Security at Gen, explains why treating them with the same identity and data controls is the single most important step to get ahead of AI risk. "We're going to give these agents the capability to do things as though they were humans. If we are not treating them like we treat our other human users in our organizations, that's where we're creating risk.".

Why Open Source Is the Easiest Target for Supply Chain Attacks

Attackers targeting open source dependencies already have all the code they need. Curtis Koenig, Head of Application Security at Gen, explains the fundamental asymmetry and why building quality fixes at speed is the real challenge for defenders. "An attacker can produce very fast, very ugly code that propagates through as an attack. When we're trying to fix something, the challenge we have is we're always trying to build for quality.".

If AI Can Build the Exploit, It Can Write the Patch

The window between an exploit being discovered and actively used is around eight hours. Curtis Koenig, Head of Application Security at Gen, explains why zero trust and a prepared incident response process remain the foundation for security teams navigating this new threat landscape. "The good news is that if the tool can find a vulnerability and create an exploit, it can find a vulnerability and write a patch as well.".

Detect, Remediate, and Prevent Credential Layer Secrets Sprawl | GitGuardian Overview

Your security stack does its job. But credentials move between your tools: into pipelines, container images, Slack threads, Jira tickets, and local machines. Together they form a credential layer that no single tool was built to see. GitGuardian is the Credential Layer Security platform that helps teams detect, remediate, and prevent secrets sprawl. In this overview, you'll see how GitGuardian: Trusted by 600K+ developers and the most-installed security app on the GitHub Marketplace.

Does a TLS Certificate Need a Common Name?

Technically: no. In practice: maybe. Lot’s of teams are experimenting with shorter duration certificates from Let’s Encrypt to get ready for the 47-day mandate. Those certs come with a big gotcha: no more Common Name. A modern browser is perfectly happy with a TLS certificate that has no Common Name. Your VPN or mail server might have other opinions. And since those are probably things you’d like to keep working, there’s a little more nuance to the answer.

AI Agent Identity Security: Where an Agent's Baseline Lives

Identity governance cannot tell you which AI agent did something. It records which identity is allowed what. In a cluster, one service account often serves several workloads, and every pod is replaced at the next rollout. As a result, the permission record and the behavior record point at different objects. Detection and investigation need a unit of attribution. The Deployment is the right one. It stays stable across restarts and replicas and changes only when someone ships a rollout.

What Is Agentic AI Security? The 3 Layers and Their Owners

Two of the three layers of agentic AI security already have an owner in your organization, and the third has none. Identity falls to IAM and interaction falls to AppSec, because the controls at both layers extend products those teams already run. The behaviour layer covers what the agent does on the infrastructure once it is running, and it sits between a platform team with no security mandate and a SOC with no sense of what normal looks like for an agent. That gap is where a coerced agent works.

How attackers use AI models to find code vulnerabilities

AI models accelerate software development, but attackers use those same capabilities to hunt for pipeline vulnerabilities. Asaf Saar (EVP and Chief Product Officer, Mend.io) and Christian Jensen (VP Engineering, Tricentis) break down why full visibility is required to secure AI-native software.