Vibe coding has compressed the distance between an idea and a runnable application. Natural-language instructions can now produce SwiftUI screens,…
Category: DZone Security Zone
Your Application Has an Unindexed Attack Surface. Do You Know What’s in It?
Security teams usually describe an application through the assets they know about. This includes the production domain, documented APIs, the services…
Data Governance for the Agentic Era
The modern enterprise generates and consumes unprecedented volumes of data across operational systems, customer interactions, partner ecosystems, cloud…
A Firewall for AI Agents: Enforce Authority at Every Tool Call
The right firewall for an AI agent goes between the model and every tool that can cause a side effect. Not a prompt filter, an action firewall. An AI…
Why Continuous Application Security Testing Is No Longer Optional
Your last pentest is already out of date. The moment you shipped new code after that report, your risk profile changed, and nobody re-tested it. That’s…
Part 2: Securing and Scaling Goose-to-Java Agent Traffic With agentgateway
In Part 1 of this series, we built a Quarkus-based MCP tool server and connected it to the Goose AI agent over Streamable HTTP. The tools worked, the demo…
Pipelines on Fire: Why Your CI/CD Tools Are the New Cyber Battlefield
Fifteen years in, and the conversation I have most often with security leads still starts the same way: how’s your perimeter, how’s your endpoint…
Your Email Security Is a DNS Configuration Problem
Every email authentication control you deploy is a DNS record. Not “backed by” DNS, not “uses” DNS. It is a DNS record, and when email security breaks, it…
Part 2: Securing and Scaling Goose-to-Java Agent Traffic With agentgateway
In Part 1 of this series, we built a Quarkus-based MCP tool server and connected it to the Goose AI agent over Streamable HTTP. The tools worked, the demo…
Pipelines on Fire: Why Your CI/CD Tools Are the New Cyber Battlefield
Fifteen years in, and the conversation I have most often with security leads still starts the same way: how’s your perimeter, how’s your endpoint…
Your Email Security Is a DNS Configuration Problem
Every email authentication control you deploy is a DNS record. Not “backed by” DNS, not “uses” DNS. It is a DNS record, and when email security breaks, it…
The Bottleneck of Scaling
Any input/output operation, be it accessing a file, handling an HTTP request, or a database connection, is based on 3 fundamental system concepts — file…
Gossip on Cryptography: Part 3
In this blog, we will continue our discussion from the previous blog, Parts 1 and 2 . If you have not read it, please read it once. So far, we have…
Beyond Agent-Washing: The Engineering Principles Behind Production-Ready AI Agents
An AI agent is not defined by how intelligently it talks. It’s defined by what it’s trusted to do. Give a language model a chat window, and you have an…
Designing a Dynamic Multi-Hierarchy Security Model for Analytics and Decision Support Systems
A simple access check uncovered something alarming: several dashboards still showed employee compensation based on an organizational hierarchy that was no…
Securing Database Connections With Mutual TLS
Stolen credentials served as the entry point in 22% of breaches last year, and in attacks on basic web applications that figure climbs to 88%. Those…
Secure AI Systems: Defending Enterprise Applications Against Agent-Era Threats
The rise of autonomous AI agents within business software demands a fresh approach to security. Unlike earlier chatbot tools, modern agents act with real…
Making User-Generated Sites Embeddable: X-Frame-Options vs CSP Frame-Ancestors
If you let users publish something, such as a page, prototype, or dashboard, sooner or later you want an “embed this” button so they can drop it into a…
Why Your Terraform Drift Alerts Are Useless (And How to Fix Them)
Let me describe a workflow that exists in thousands of engineering organizations right now. Somebody sets up a cron job. It runs terraform plan against…
When Guest Access Becomes an Attack Surface: A Technical Analysis of the City-Forum Campaign
Learn how attackers enumerated Salesforce Experience Cloud and ServiceNow portals — and how defenders can detect and prevent the same abuse. When Guest…
