Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

What Is Agentic AppSec?

Agentic AppSec (agentic application security) is the practice of using a team of AI security agents to run an organization's entire application security program: understanding the application, modeling its threats, finding the vulnerabilities that matter, deciding what is worth fixing, generating and validating fixes, and proving those fixes hold. It applies continuously to both new code and the existing backlog.

Webinar Recording: One Breach Away: Why Managed Devices Are the New Perimeter for AI, Finance...

Welcome to the recording of our recent webinar “One Breach Away: Why Managed Devices Are the New Perimeter for AI, Finance and Healthcare Data.” In this session, our experts discuss how organizations can secure access to business applications, sensitive data, and AI tools by making device security a core part of their identity and access strategy. As employees connect from personal devices, remote environments, and multiple endpoints, ensuring device compliance and security posture has become critical for protecting enterprise data.

Session on The miniOrange Story at BSides Ahmedabad 2026 by our Founder & CEO Mr. Anirban Mukherji

Watch this session from BSides Ahmedabad 2026 to learn about the core values driving miniOrange in the cybersecurity industry. In this session, Our Founder & CEO Mr. Anirban Mukherji reflected on the journey of miniOrange, focusing on the company's growth, achievements, and contributions to the security landscape. He outlined the fundamental principles that defines culture, specifically highlighting commitment to hard work, discipline, initiative, ownership, and meritocracy.

Claude Cowork Activity Isn't Captured in Compliance Logs

Is your AI compliance up to par? Anthropic's deputy CISO reveals that Claude Cowork activity isn't captured in compliance logs. If you're in a regulated EMEA sector, DORA's ICT logging and the EU AI Act's obligations are here. Relying on a self-configured OTel stream isn't enough for formal audits. Stay informed about data boundaries and privacy reviews before enabling streams.

Ep. 83 - Anthropic's CISO Guide to Agentic AI: Your Next Insider Threat Is an AI Agent

An AI agent that drifts from your intent looks exactly like an insider attack: legitimate credentials, sanctioned tools, plausible actions, at machine speed. In this episode, we break down Anthropic's "Zero Risk Isn't the Job" CISO guide: a four-question review framework, seven vendor-neutral controls, and why egress allowlisting is the strongest defense against prompt injection. Plus: the Claude Opus 4.5 upgrade that had an incident-response agent recruit another agent, and why agentic AI needs continuous adversarial exposure validation.

The Authorization Trap: Why "No Evidence of Manipulation" Doesn't Mean "No Incident"

Ask AI to Choose a prompt Write a TLDR of this post Explain the security risk Summarize what CISOs should know Many conversations about AI agent risk over the past year start from the same unspoken assumption: something bad happened because someone or something manipulated the agent. A hidden instruction in a document, a poisoned prompt, an adversary steering the model toward an action it shouldn't take. That's a real category of risk, and it deserves the attention it's getting.

Agentic AI Security Platforms: What Agent Logs Miss

An agent’s logs are written by the agent. Every framework log, trace span and tool-call record that an agentic AI security platform ingests comes from the process being watched, or from a gateway that sees only what that process routes through it. When a trusted prompt coerces an agent into misusing a permission it already holds, the record shows a normal tool call, because from inside the process it was one. Running more analysis on that record returns the same answer faster.

Zero Trust for AI Agents: What to Verify When There Is No Session

The agent that worries you is authorized. It holds a service account you provisioned, calls tools you approved, and reaches destinations someone signed off on. Zero trust asks two questions at every decision point, who is this and what are they allowed to do, and an agent redirected by trusted input answers both correctly every time. For a person those questions fire at a session boundary, where context gets re-checked. An agent on Kubernetes has no such boundary.

Agentic AI Security Risks, Ranked by Recovery Cost

The board wants to know which AI agent risk to fund first, and a likelihood score cannot answer it. No incident survey gives base rates for agents on your architecture, and an agent can take a different path on the same input. What a CISO can estimate is what each risk would cost to recover from: the work to detect it, scope it, revoke the authority it used, and prove what happened. Ranked on that cost, unexpected code execution drops toward the bottom.