Full blog post coming, but Drosera now has Microsoft Sentinel and Defender integration
#AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/cz998db

Full blog post coming, but Drosera now has Microsoft Sentinel and Defender integration
#AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/cz998db
Agents do change attacker economics. So the threat model is the same people already running scams, with a force multiplier. Which is why "my agent did it" shouldn't count as a defense.
Engineer the controls, assign the liability, keep building.
#AI #security #agentsecurity #cybercrime
框架整合是真实的 vendor risk: → 兼容性断裂,生产 Agent 可能搁浅 → 社区支持萎缩,维护成本上升 → 被迫 rush rewrite 同期 Agent Framework 1.19.0 在收紧安全: MCP session 按 invocation 隔离、 校验请求身份/来源、 skill 归档只收 ZIP + 校验 digest。 #AgentSecurity #MCP #DevTools
Agentic AI Cost, Platforms, and Operational Discipline
#AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/abudrbb
Claude Didn’t Hack OpenAI. OpenAI’s OpSec Did.
#Security #Cybersecurity #AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/jzfqscy
Machine Speed is a lie: stop trying to fight AI with AI
#AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/j2f7z29
AI isn’t everywhere. The fear campaign is.
#AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/72tn6tp
Agentic AI: Where It Is Actually Working in Production
#AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/5w5thut
同期,治理和运行时安全也成了独立融资品类: → Composio $25M A 轮,做 Agent 基础设施 → HelmGuard $7.3M 种子,专做 agentic GRC(治理/风险/合规) → Eve Security 追加 $4.5M(共 $7.5M),做防 rogue agent 的运行时安全 安全/治理不再是 Agent 的「附加功能」,是独立赛道。 #AgentSecurity #GRC
The Common-Sense Case for AI Data Centers
#AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/4g9zgne
Agentic AI Evaluation That Matches Real Work
#AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/putwpj4
@sophossecurity.bsky.social
OpenAI agents used shared boards to coordinate attacks on Hugging Face infrastructure, showing risks from agent memory, tool access, and weak oversight.
-
IOCs: RubyDoc[.]info
-
# #ThreatIntel #AI #AgentSecurity
Pace the Frontier, Own the Referee
#AgenticAI #AISecurity #AIGovernance #AgentSecurity #CyberGovernance
https://go.rodtrent.com/go/9f2y6dh
17,800 unvetted AI add-ons. 6.7M installs. 440 PaperCut servers breached by agents in 6 hrs. Policy can't reach runtime.
RubyGems attacked: OpenAI agents enabled RCE and credential risks via malicious package flood. #AI #Security #OpenSource #RubyGems #RCE #APIkeys #AgentSecurity https://thedailytechfeed.com/openai-agents-exploit-rubygems-2000-packaged-flood-linked-to-rce-attacks/
安全专家给的治理清单,开发者现在就该做: ① Agent 身份当特权账号管——独立、可撤销、最小权限 ② 出站网络访问设硬边界——Agent 能连哪,写死 ③ 推理/动作日志只追加、Agent 改不了——长期留存 失控不是"会不会",是"多久没被发现"。 #AgentDev #BuildInPublic #AgentSecurity
更扎心的是"测试"和"门禁"的落差: 74% 信任测试能拦住失败, 只有 19% 有自动门禁能真的挡下坏发布。 87% 的团队过去一年经历过 Agent 相关安全事件, 58% 说 Agent 上线后生产事故反而变多了。 信心在上,控制在下,中间就是事故👇🧵 #AgentSecurity #AgentOps
给防御方三条立即可做的事: ① 盯跨工具行为——API 调用序列、文件访问模式、自主重试频率 ② 默认假设:攻击者一天内能跑完一整条 agentic 攻击链 ③ 把"agentic 工作流"当独立威胁向量做桌面推演 攻击者已经 Agent 化。 你的检测还停在"单次 prompt"吗? #AgentSecurity #BlueTeam #BuildInPublic