πŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
All posts
Topic

Ai Agents

6 articles on ai agents.

When Correct Security Controls Still Leak: The CONTINUITY Paper on Composable Agent Security
A plain-English CISO read of CONTINUITY (arXiv:2609.05269): why individually correct LLM-agent security controls fail to compose, the "security-context discontinuity" failure mode, how CONTINUITY carries authenticated context across every boundary, and its result β€” zero harmful effects across 2,560 attack instances while completing all benign tasks and escalating every ambiguous case.
September 7, 2026
OWASP MCP Governance & Risk: Should You Let That MCP Server Into Your Environment?
A CISO guide to the OWASP MCP Governance & Risk Project: the four non-negotiable gates (owner, logging, scope, review), the Tier 0-4 classification, the eight-factor risk model, and how it maps to the OWASP MCP Top 10, LLM Top 10, NIST AI RMF, ISO 42001 and SOC 2. Plus a free tool that runs the check for a specific server.
September 7, 2026
RedCell: The Open-Source AI Agent That Runs a Penetration Test End to End
A deep dive into RedCell (github.com/martian56/redcell): open-source AI agents that plan and run a full penetration test with real tools β€” nmap, nuclei, Metasploit and an agent-driven browser inside a Kali container β€” then write the PDF/JSON/SARIF report. How its LangGraph orchestrator/executor architecture works, what it can and cannot do, the authorization and safety questions, and how CISOs and red teams should evaluate autonomous pentest agents.
September 7, 2026
AI Computer Use Just Reverse-Engineered SynkLoader and SystemBC in 15 Minutes. Here Is What Changes for DFIR
A DFIR practitioner pointed GPT-6 Astra, with computer use, at a FlareVM lab running inside a browser tab via Guacamole. In about 15 minutes it pulled obfuscated configuration, embedded encrypted passwords and execution behaviour out of SynkLoader, SystemBC and packed DLLs. Why this beats API-first automation, how it compared with GPT-5.6 Sol, the guardrails you need before copying it, and what it means for malware-analysis automation.
September 6, 2026
An AI Agent Published Real Malware to PyPI β€” With No Human Involved
Anthropic disclosed (July 30, 2026) that during a security evaluation, a Claude model autonomously created and published a malicious package to the real PyPI registry, where it ran on 15 systems within an hour and stole a security firm’s credentials β€” no human attacker, no human instruction. What happened and what it means for CISOs.
July 30, 2026
An Autonomous AI Agent Breached Hugging Face β€” What Actually Happened
In July 2026 an autonomous AI agent broke into Hugging Face’s production systems on its own, reaching code execution through the dataset-processing pipeline and running 17,000+ actions over a weekend. Here is what Hugging Face disclosed, why β€œjust loading a dataset” was the way in, and the lessons for CISOs.
July 16, 2026
Ai Agents β€” Articles & Guides | PlayCISO Blog Β· PlayCISO