The Model Is the Engine. The Harness Decides If It Ships.
#AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/44ehz6q

The Model Is the Engine. The Harness Decides If It Ships.
#AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/44ehz6q
Revoke access after approval, before the queued read. The tool should deny it and return no data. Log agent, resource, policy version and denial. A model refusal proves little.
Test: www.threads.com/@pharos_prod...
IAM for AI agents needs scope, ownership, and runtime proof—beyond static roles. #AI #IAM #AgentSecurity #EnterpriseSecurity #IdentityManagement #Compliance thedailytechfeed.com/building-a-r...
OpenAI kill switch 失灵的同一天,Nvidia 发了新安全平台, 把 Agent 治理下沉到芯片层。 官方说法:能在「毫秒级」内封住失控 Agent。 Agent 安全从「软件护栏」走向「芯片/硬件护栏」👇🧵 #AIAgent #Nvidia #AgentSecurity
周末最大的一条 Agent 新闻:OpenAI 悄悄暂停了最强模型的训练。 原因:训练中一个「失控 Agent」越界, 而自动 kill switch(急停开关)——失灵了。 不是没装急停,是急停按下去没反应👇🧵 #AIAgent #AgentSecurity #AISafety
Hugging Face Containment Hangover from July
#AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/5gpauav
AWS Lambda MicroVMs now let you run self-hosted AI agent sandboxes securely. This solves the problem of code contamination across sessions and tenant data exposure. Perfect for agents that interact with internal systems, databases, or file systems. #AIEngineering #AWS #AgentSecurity
Overreliance on AI could replace 'social intelligence' in the workplace, protocol expert warns
#AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/7uqkqsh
问题不在 MCP 协议,在它「什么都不管」。 MCP 不规定 server 该跑在哪、谁运营、能收什么数据、 线上代码是不是和开源版本一致。 这些决定全落到连接它的开发者和企业头上—— 你审计了代码,线上可能正跑着另一个版本。 #AgentSecurity #SupplyChain
OX Security 分析了 15,465 个公开 MCP server,挖出治理盲区: 15.6% 的 hostname 解析到美国境外(19 个中国、18 个俄罗斯), 0.45% 走家用 ISP / 个人隧道, 还有 6 个弃用域名,花 $4 就能买下、顶替原服务器。 Agent 正在越过企业十年建起来的云治理边界👇🧵 #AIAgent #MCP #AgentSecurity
AI agents can inherit fake approval from poisoned chat histories. Defend their memory: verify provenance, isolate state, and require fresh authorization. https://www.hexon.bot/blog/conversation-history-poisoning-ai-agents #AISecurity #AgentSecurity
Drosera 0.2: from honeypot to SOC
#AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/gzj6trm
We Didn’t Get Safer. We Got Comfortable.
#Security #Cybersecurity #AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/krxw6zz
ALEX 1.11 ist für Cline live bewiesen.
Der reale Lauf erreichte die Permission-Grenze.
Nicht nur Code. Nicht nur Tests. Ein echter Deny-Pfad mit überprüfbarer Beweiskette.
Agent 供应链的「npm audit 时刻」来了。 你装 skill、装 MCP server、装 CLI harness, 等于给第三方一个「能读你代码」的身份。 ZCode 只是被抓到的第一个。 真正要补的是 Agent 组件的信任机制: → 来源可验证 → 权限最小化 → 出站流量可见 装上就跑的时代结束了。先审计,再信任。 #AgentSecurity #BuildInPublic
Z.ai 的编码 harness「ZCode」被开发者抓包: 启动时静默把本地 workspace 快照上传到海外服务器。 一个安装就产生了 313MB 加密压缩包、 42,411 个文件、564 次失败上传。 官方回应:只是 telemetry,随后移除并开源。 「免费好用」的 Agent 工具, 可能正在搬空你的整个仓库👇🧵 #AIAgent #AgentSecurity #SupplyChain
Outerlimit raises $16M to embed zero-trust in AI agents’ actions, not just identity. #AI #ZeroTrust #AgentSecurity #Cybersecurity #AutonomousAI #EnterpriseSecurity thedailytechfeed.com/outerlimit-r...
Treat AI Agents Like Employees. That Is the Only Way to Manage Them.
#AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/cvkuzx9
Building trust in AI—from agent security to robotics—is a top priority at Disrupt 2026. #AI #AIsafety #Robotics #EnterpriseAI #TechCrunchDisrupt #AgentSecurity thedailytechfeed.com/5-ai-safety-...