Data Safety and Information Security

Data Safety and Information Security

It's Not Just What Agents Can Do...It's When They Can Do It!
It's Not Just What Agents Can Do...It's When They Can Do It!
Agents don't just perform actions; they execute plans where the safety of each step depends on what has already happened. That makes sequencing an authorization problem. This post explores how policy, delegation data, and multi-signature approval can govern the order in which agents receive authority, not just the scope of it.
·windley.com·
It's Not Just What Agents Can Do...It's When They Can Do It!
Cross-Domain Delegation in a Society of Agents
Cross-Domain Delegation in a Society of Agents
Cross-domain delegation requires more than transferring a credential. In a society of agents, policies define boundaries, promises communicate intent derived from those policies, credentials carry delegated authority, and reputation allows trust to emerge through repeated interactions.
·windley.com·
Cross-Domain Delegation in a Society of Agents
Compromised telnyx on PyPI: WAV Steganography and Credential Theft
Compromised telnyx on PyPI: WAV Steganography and Credential Theft
Analysis of malicious telnyx 4.87.1 and 4.87.2 on PyPI — a package with over 1 million monthly downloads: injected code uses WAV audio steganography to deliver payloads that steal credentials and establish persistence. Attributed to TeamPCP.
·safedep.io·
Compromised telnyx on PyPI: WAV Steganography and Credential Theft
Agentic AI Threat Modeling Framework: MAESTRO | CSA
Agentic AI Threat Modeling Framework: MAESTRO | CSA
MAESTRO (Multi-Agent Environment, Security, Threat, Risk, & Outcome) is a novel threat modeling framework for Agentic AI. Assess risks across the AI lifecycle.
·cloudsecurityalliance.org·
Agentic AI Threat Modeling Framework: MAESTRO | CSA
Secure Communication, Buried In A News App
Secure Communication, Buried In A News App
Cryptography is a funny thing. Supposedly, if you do the right kind of maths to a message, you can send it off to somebody else, and as long as they’re the only one that knows a secret little…
·hackaday.com·
Secure Communication, Buried In A News App
Claude.ai Prompt Injection Vulnerability | Oasis Security
Claude.ai Prompt Injection Vulnerability | Oasis Security
Three Claude.ai vulnerabilities chained into a full attack: prompt injection to silent data exfiltration. Oasis Security research disclosure.
·oasis.security·
Claude.ai Prompt Injection Vulnerability | Oasis Security
platform-security-guide-scraper
platform-security-guide-scraper
A web scraper to download the Apple Platform Security Guide as Markdown for use in Obisidian and elsewhere.
·codeberg.org·
platform-security-guide-scraper
You Can't Hide a Secret from a Process That Runs as You
You Can't Hide a Secret from a Process That Runs as You
I tried six different approaches to protect my credentials from an AI coding agent. Encrypted files, keychain, ACLs, Touch ID, a native addon, sandboxes. Every one failed for the same reason.
·danielepolencic.com·
You Can't Hide a Secret from a Process That Runs as You
The Promptware Kill Chain - Schneier on Security
The Promptware Kill Chain - Schneier on Security
Attacks against modern generative artificial intelligence (AI) large language models (LLMs) pose a real threat. Yet discussions around these attacks and their potential defenses are dangerously myopic. The dominant narrative focuses on “prompt injection,” a set of techniques to embed instructions into inputs to LLM intended to perform malicious activity. This term suggests a simple, singular vulnerability. This framing obscures a more complex and dangerous reality. Attacks on LLM-based systems have evolved into a distinct class of malware execution mechanisms, which we term “promptware.” In a ...
·schneier.com·
The Promptware Kill Chain - Schneier on Security
Wasmtime : The Standalone Runtime Revolutionizing
Wasmtime : The Standalone Runtime Revolutionizing
Wasmtime is a standalone runtime for WebAssembly (Wasm), developed by the Bytecode Alliance, designed to execute WebAssembly modules
·kalilinuxtutorials.com·
Wasmtime : The Standalone Runtime Revolutionizing
What is TruffleHog? ◆ Truffle Security Co.
What is TruffleHog? ◆ Truffle Security Co.
TruffleHog is an open-source secrets scanning tool that digs deep into your code to find secrets, passwords, and sensitive keys that you may have inadvertently committed.
·trufflesecurity.com·
What is TruffleHog? ◆ Truffle Security Co.
What Does The Sonatype 2026 State of the Software Supply Chain Report Reveal?
What Does The Sonatype 2026 State of the Software Supply Chain Report Reveal?
Programming book reviews, programming tutorials,programming news, C#, Ruby, Python,C, C++, PHP, Visual Basic, Computer book reviews, computer history, programming history, joomla, theory, spreadsheets and more.
·i-programmer.info·
What Does The Sonatype 2026 State of the Software Supply Chain Report Reveal?
NIST Special Publication (SP) 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations
NIST Special Publication (SP) 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations
This publication provides a catalog of security and privacy controls for information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats and risks, including hostile attacks, human errors, natural disasters, structural failures, foreign intelligence entities, and privacy risks. The controls are flexible and customizable and implemented as part of an organization-wide process to manage risk. The controls address diverse requirements derived from mission and business needs, laws, executive orders, directives, regulations, policies, standards, and guidelines. Finally, the consolidated control catalog addresses security and privacy from a functionality perspective (i.e., the strength of functions and mechanisms provided by the controls) and from an assurance perspective (i.e., the measure of confidence in the security or privacy capability provided by the controls). Addressing...
·csrc.nist.gov·
NIST Special Publication (SP) 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations
CIS Controls v8
CIS Controls v8
CIS Released version 8.1 in June, 2024
·sans.org·
CIS Controls v8
Prevade Cybersecurity
Prevade Cybersecurity
Prevade, Prevade Cybersecurity, Cyber Security, Information Security, Dallas, Texas, Metaform, Cyber Wargaming, Wargaming, Penetration Testing, Pentesting, Application Security, Cloud Security, Endpoint Security, IoT Security, Mobile Security, Network Security, Physical Security, DevSecOps, Security Design, Security Assessment, Security Management, Security Governance, Security Compliance, Security Training
·prevade.com·
Prevade Cybersecurity
AS16509 Overview | Cloudflare Radar
AS16509 Overview | Cloudflare Radar
Up to date Internet trends and insights from AS16509 AMAZON-02 Amazon Web Services.
·radar.cloudflare.com·
AS16509 Overview | Cloudflare Radar