Category: AI

Agent harness engineering

Agent harness engineering: the model isn’t the attack surface, the harness is

Agent harness engineering turns models into useful agents. It also hands attackers a new target: the files that tell your agent what it can do.
7 min read
AI Application Security

AI Application Security: What we heard at OWASP Porto & Karlsruhe

AI application security dominated OWASP Porto and Karlsruhe. What ASPM really is, how it differs from SAST, and where AI triage and remediation help.
8 min read
AI risk management

AI risk management: two disciplines, one inventory

Four search terms, two completely different jobs. Managing the risk of AI is not the same discipline as using AI for risk management, and most organisations are staffing one while being sold the other. The interesting part is what happens when you realise they are the same programme.
9 min read
AI Risk Metrics

AI Risk: The Metrics That Tell You Whether Your Agentic AI Strategy Is Working

Every board now asks the same question: what is our AI risk? Most teams answer with adjectives. Here are the AI risk metrics that produce a number, where each one comes from, and what an agentic AI strategy has to cover before any of them mean anything.
9 min read
AI security threats

Top 10 AI security threats and how to map them

Two things get filed under the same heading and they are not the same problem. Attacks on AI systems and attacks powered by AI need different controls, different owners and different evidence. Ten threats, split into the two halves, and the one step that precedes all of them.
10 min read
AI Red Team Tools

AI Red Team Tools Test What Your Model Says. They Don’t Test What Your Agent Does Next

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
9 min read
AI Pentesting Tools

AI Pentesting Tools: What to Look For, and What Agentic Pentesting Actually Changes

AI pentesting tools are four different product shapes. What agentic pentesting changes, seven evaluation criteria, and what it cannot do.
8 min read
What Is the Agentic SDLC

What Is the Agentic SDLC? How AI Agents Are Reshaping Every Phase

Agents now plan, code, review, ship and operate. What the agentic SDLC changes in every phase, and which controls quietly stop working.
9 min read
AI Pentesting

AI Pentesting: Testing AI Systems Like an Attacker Would

Your last pentest tested code. AI pentesting tests behaviour: hijacked prompts, abused tools, leaked data. What to test, and how often.
9 min read
Agentic Coding

Agentic Coding: The Risks, the Best Practices, and 8 Lessons from Early Adopters

Agents now write, install and ship code. The real risks of agentic coding, the practices that contain them & 8 lessons learned the hard way.
10 min read
What Is AI Coding

What Is AI Coding? A Developer’s Guide to Working With, and Securing, AI-Generated Code

What is AI coding, how do AI tools work, and how do you keep AI-generated code secure? A practical guide for developers and teams.
10 min read
AI Governance Framework

Building an AI Governance Framework: A Practical Structure

A policy document alone isn't an AI governance framework. Here's the practical structure, inventory, evidence, and controls, that works.
10 min read