Five Days, One Data Leak: Company Notes to Personal WhatsApp
How permitted company-data access becomes a multi-day AI disclosure risk when Obsidian notes mix work, public research, and a side job before a WhatsApp summary.
Research, engineering, and practical use cases for securing the work AI agents do.
How permitted company-data access becomes a multi-day AI disclosure risk when Obsidian notes mix work, public research, and a side job before a WhatsApp summary.
How legal AI workflows can combine case research, citation verification, client-matter boundaries, and controlled document sharing.
Separate invoice reconciliation from payment authority with scoped records, controlled corrections, duplicate-action checks, and reviewable evidence.
Apply ADR to support agents handling order tracking, delivery exceptions, and refunds, with customer scope, action limits, and connected evidence.
Keep work and personal AI tasks separate across files, credentials, persistent context, cloud agents, and output destinations.
Scope manufacturing agents to approved lines, work orders, and application actions, with checks for stale evidence, retries, and consequential changes.
Design HR onboarding agents around employee-specific records, approved fields, limited sharing, and a clear boundary between access requests and approvals.
Control sales-agent research, CRM updates, pricing, discounts, and outbound proposals by separating account access from authority to make commitments.
Scope healthcare scheduling agents to the right patient, appointment, approved intake fields, and communication destination across administrative workflows.
AI coding agents like Claude Code, Codex, and Cursor create risk across entire sessions, not single prompts. Here's the control framework that closes the gap.
Prompt injection, memory poisoning, and long-horizon drift are reshaping Claude Code risk in 2026. Here's how security teams build runtime and transactional controls.
A security-engineering evaluation of Cursor security covering SOC 2 compliance, Privacy Mode, and the prompt injection and long-horizon risks compliance alone can't stop.
How request capture, host-owned cloning, identity rebinding, evidence, parallel comparison, and one-use approval turn workspace fork into an agent workflow.
What activity, service semantics, persistence, and independent evidence reveal about two authority-bearing paths and their operation gates.
OpenAI’s incident and eight controlled Gensee Crate trials reveal a compounding systems chain—and the control points that can interrupt it.
A systems architecture for binding agent intent, authority, execution, evidence, and accepted output around one bounded operation.
A controlled, partial reproduction of the first Artifactory escape—with an animated successful run and open traces from eight blind trials.
How Gensee narrows authority across execution space and time with exact leases, multiple execution paths, and attested promotion.
Why live workspace convergence needs different rules for files, process memory, GUI state, local services, and external effects.
How TClone brings the compositor inside each branch, isolates write-hot display state, reconnects TCP sessions, and draws a hard line around external side effects.
Why Btrfs snapshots can share disk blocks while duplicating file data in RAM, and how TClone applies CoW to the Linux page cache.
AP-006 explains why individually legitimate files, shell commands, tools, memory, credentials, and network actions can compose into unapproved workflow-level authority.
A 17,600-action intrusion reveals how agent containment failed—and points toward forked environments, forensic replay, and full-stack provenance.
How TClone captures a live Linux process graph, reconstructs threads and resources with CRIU, and shares memory pages across sibling containers.
AP-005 explains why AI coding agents move software supply-chain risk upstream: package selection itself becomes the first external-trust decision.
Follow AgentENV's Firecracker dirty-memory path, see what its 100-millisecond snapshot claim measures, and compare its real scaling with TClone's direct copy-on-write approach.
AP-004 explains how legitimate debugging, deployment, CI, and infrastructure tasks can lead coding agents toward credentials, tokens, kubeconfigs, and authenticated tool state.
Git branches files, fork() branches one process, and VMs branch machines. Blog 0 explains why a live container is a useful boundary for branching coding-agent workspaces.
AP-003 explains how coding agents build a Repository Mental Model from source, manifests, CI, deployment, infrastructure, and secret references before later actions.
HalluSquatting shows why AI coding agents move dependency selection upstream, turning model reasoning into the first software supply-chain trust decision.
A practical 15-question checklist for engineering teams deploying AI coding agents, covering runtime isolation, authorization, visibility, enforcement, recovery, and governance.
AP-002 explains how AI coding agents can turn task progress into permission, expanding from source edits into registry, signing, publishing, or deployment authority.
JadePuffer shows why the key agentic ransomware risk is control-plane compression: agents can observe, diagnose, retry, and continue destructive workflows at runtime.
AP-001 explains how retrieval, synthesis, recomposition, and outbound sharing can turn normal coding-agent actions into workflow-level data exfiltration.
A newly revealed Claude Code prompt-steganography issue shows why coding-agent trust needs runtime evidence, attribution, provenance, and deeper host-level controls.
Agent Defense and Response explained for developers, founders, and small teams: permissions, prompt injection, tool misuse, least privilege, logs, and recovery.
Claude Fable 5 is a reminder that agent security is moving beyond prompts into runtime visibility, attribution, process lineage, tool execution, and long-horizon provenance.
Runtime safety for coding agents that goes deeper into system events, tool calls, skills, and memory, and longer across requests and sessions where risk emerges as a chain.
A practical map of the AI agent safety stack: where agentic systems create risk, which layers reduce that risk, and why runtime control becomes the missing layer as agents start taking real actions.
As AI agents gain persistent memory across sessions, attackers have found a new vulnerability: memory poisoning. Learn what it is, real attack examples including credential harvesting and slow trust exploits, and defense strategies for security teams.
Beyond security attacks, long-horizon AI agents face safety challenges from accidental failures: context drift, state inconsistency, session boundary confusion, and cascade failures. Here's how to design safer multi-session experiences with recovery patterns and UX guardrails.
Two recent incidents — Meta's AI-powered Instagram support exploit and CVE-2026-2256 in ModelScope's ms-agent — show that AI agent security is a cross-layer execution problem. Defense in depth, real-time safeguards, prevention before execution, and rollback are what work.
The real risks individuals and businesses face when they rely on AI agents, the layered defenses that work, and what ADR (Agent Detection and Response) is — the agent-economy counterpart to EDR. In production, credential exposure leads, not prompt injection.
Dec 2, 2025
A professor's perspective on the OpenReview data breach, AI-generated peer reviews, and the future of scientific validation in the age of AI.
July 31, 2025
An in-depth comparison of three leading platforms for building and deploying the next generation of AI agents.
March 13, 2025
Dive deeper into the technical secret sauce behind Cognify's efficient and effective autotuning: the AdaSeek algorithm.
March 12, 2025
Is it possible to autotune a 4-step gen-AI workflow's generation quality with a budget of $5 and 30 minutes instead of $168K and weeks?
No posts match your search.